1kalin/afrexai-regulatory-compliance/SKILL.md
# Regulatory Compliance Audit Run a full regulatory compliance audit for any business. Covers US, UK, and EU frameworks across 8 compliance domains with gap analysis, risk scoring, and remediation timelines. ## When to Use - Annual or quarterly compliance reviews - Pre-audit preparation (SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS) - New market entry requiring regulatory assessment - Board or investor due diligence on compliance posture - Post-incident compliance gap analysis ## How It Works ###
npx skillsauth add openclaw/skills 1kalin/afrexai-regulatory-complianceInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Run a full regulatory compliance audit for any business. Covers US, UK, and EU frameworks across 8 compliance domains with gap analysis, risk scoring, and remediation timelines.
Based on the business profile (industry, geography, data types, revenue), determine which frameworks apply:
| Framework | Triggers | |-----------|----------| | SOC 2 Type II | B2B SaaS, handles customer data | | GDPR | Any EU customer data, EU employees | | HIPAA | Any PHI (healthcare, benefits, wellness) | | PCI DSS | Processes, stores, or transmits card data | | ISO 27001 | Enterprise clients requesting certification | | SOX | Public company or preparing for IPO | | CCPA/CPRA | >$25M revenue OR >50K CA consumers | | NIST AI RMF | Deploying AI/ML in production | | UK DPA 2018 | UK operations or UK customer data | | FCA/PRA | UK financial services |
Score each domain 1-5 (1=non-existent, 5=mature):
Domain 1: Data Governance
Domain 2: Access Control & Identity
Domain 3: Security Operations
Domain 4: Business Continuity
Domain 5: Vendor & Third-Party Risk
Domain 6: HR & Personnel Security
Domain 7: AI & Automation Governance
Domain 8: Financial & Reporting Controls
For each gap identified:
| Likelihood | Impact | Risk Score | Action Timeline | |-----------|--------|------------|-----------------| | High | High | Critical | Fix within 30 days | | High | Medium | High | Fix within 60 days | | Medium | High | High | Fix within 60 days | | Medium | Medium | Medium | Fix within 90 days | | Low | High | Medium | Fix within 90 days | | Low | Medium | Low | Next quarterly review | | Low | Low | Informational | Annual review |
Build a 90-day plan:
Days 1-30: Critical Gaps
Days 31-60: Systematic Improvements
Days 61-90: Evidence & Documentation
| Company Size | Annual Compliance Budget | Key Cost Drivers | |-------------|------------------------|-----------------| | 10-50 employees | $30K-$80K | SOC 2 audit ($15-30K), tools ($10-20K), training ($5-10K) | | 50-200 employees | $80K-$250K | + DPO/compliance hire ($80-120K), pen testing ($15-40K) | | 200-1000 employees | $250K-$800K | + GRC platform ($50-150K), multiple audits, legal counsel | | 1000+ employees | $800K-$3M+ | + Dedicated compliance team, continuous monitoring, regulatory filings |
Cost of non-compliance (real examples):
Generate a compliance report with:
| Industry | Primary Frameworks | Special Considerations | |----------|-------------------|----------------------| | SaaS/Technology | SOC 2, GDPR, CCPA | AI governance, open source licensing | | Healthcare | HIPAA, HITRUST, FDA (if devices) | PHI everywhere, BAAs required | | Financial Services | SOX, PCI DSS, GLBA, FCA/PRA | Transaction monitoring, AML/KYC | | Legal | ABA ethics, GDPR, privilege rules | Client confidentiality, conflict checks | | Construction | OSHA, environmental, bonding | Safety records, subcontractor compliance | | E-commerce | PCI DSS, CCPA/GDPR, FTC | Payment data, consumer protection, returns | | Manufacturing | ISO 9001, OSHA, EPA, export controls | Supply chain compliance, ITAR/EAR | | Real Estate | Fair Housing, AML, state licensing | Property data, transaction compliance | | Recruitment | EEOC, GDPR (candidate data), ban-the-box | AI hiring bias (NYC Local 144), background checks | | Professional Services | Industry-specific licensing, SOC 2 | Client data handling, engagement letters |
Get the full compliance implementation toolkit for your industry:
Bundles: Playbook $27 | Pick 3 $97 | All 10 $197 | Everything $247
tools
Use when the user wants to connect to, test, or use the McDonalds service at mcp.mcd.cn, including checking authentication, probing MCP endpoints, listing tools, or calling McDonalds MCP tools through a reusable local CLI.
development
Web scraping platform — Twitter/X data, Vinted marketplace, and general web scraping API
development
SlowMist AI Agent Security Review — comprehensive security framework for skills, repositories, URLs, on-chain addresses, and products (Claude Code version)
data-ai
去除中文文本中的 AI 写作痕迹,使其读起来自然。基于维基百科 AI 写作特征指南,检测 24 种 AI 模式。触发词:humanizer-cn、去除 AI 痕迹、去除 AI 写作痕迹、中文文本人性化。