— Risk & Compliance

Regulatory change impact assessment

Researches a named regulation live, extracts every obligation with its clause reference, and maps each one against your own policies and controls to produce an obligation-level gap report with owners.

  • Risk & Compliance
  • Traceable reasoning
  • Runs anywhere
Preview methodology

1–2 weeks → ~15 minutes

For a typical multi-document review workflow

No coding required

Input
The regulation or framework name
Output
An obligation-level coverage matrix with clause references
Runs in
Skillsize · ChatGPT · Claude · Copilot
Export
SKILL.md · MCP
Time saved
~1–2 weeks per run

— USE CASES

What people use Regulatory change impact assessment for

New regulation readiness

Establish, obligation by obligation, where existing policy already covers you and where it does not.

Board and regulator briefings

Show coverage status against named clauses instead of a general commitment to compliance.

Remediation scoping

Turn the gaps into a costed work list with a suggested owner attached to each obligation.

What it works from

  • The regulation or framework name
  • Your policy, control and process documents
  • The entities or jurisdictions in scope

What you get back

  • An obligation-level coverage matrix with clause references
  • Named gaps with remediation actions and suggested owners
  • Live-researched obligations rather than model recollection

— HOW IT BEHAVES

How Regulatory change impact assessment produces its result

The mechanics behind this specific template — what it reads, what it calculates, and where a human stays in the loop.

Coverage across the risk universe in scope, both directions

A coverage pass shows which risks are supported by evidence and which are not — including requirements with nothing behind them and material that supports nothing.

Whole sets of risk registers, controls and policy documents at once

All of your risk registers, controls and policy documents is processed as one set, so patterns across documents surface instead of being read one file at a time.

Live research on the risk universe in scope

Current external sources on the risk universe in scope are researched during the run rather than recalled from training data, and every source travels with the output.

Composed as work product

Findings on the risk universe in scope are written up as a document that reads like professional output, with each claim tied back to a risk.

Why this is expensive by hand

For a named regulation — EU AI Act, DORA, CSRD — this template researches the obligations live, extracts each one with its clause reference, then maps them against your policies and controls. In practice it shows up as new regulation readiness: establish, obligation by obligation, where existing policy already covers you and where it does not. It is the kind of work that decides whether a recommendation survives scrutiny — and the kind that quietly eats 1–2 weeks of senior time whenever it comes round.

How this Skill produces it

As a Skill, the work is already sequenced. You bring the evidence, and the run produces an obligation-level coverage matrix with clause references plus named gaps with remediation actions and suggested owners. What sits between input and output is the codified method: thresholds, sequencing and the points where a human confirms a call — all of it visible and editable in the Skill. In effect, 1–2 weeks of senior time compresses into ~15 minutes — and the output is comparable across clients, quarters and colleagues instead of shaped by whoever ran it.

Who it's for

  • Internal audit and risk functions
  • Compliance and controls teams
  • Second-line functions reporting to committees
  • Risk consultants running assessments

Run it in Skillsize — or export it anywhere

Regulatory change impact assessment exports as a structured SKILL.md file and is MCP-ready, so the same method runs in ChatGPT, Claude, Copilot or your own AI products. Adapt it to your methodology, and the intelligence stays yours — not locked to one vendor.

ChatGPTClaudeCopilotAI Products (MCP)
Risk & Compliance

Data Subject Access Request (DSAR) Engine

Assesses a data subject access request end to end and returns a governed decision on whether to fulfil it, fulfil it in part, refuse it with reasons or extend the deadline, having verified identity, mapped the request to the systems that actually hold the data and held the outcome for a data protection sign-off before anything is disclosed.

Risk & Compliance

Findings consolidation

Fans multiple audit or review reports into individual findings, deduplicates repeats, and sorts them by severity into one consolidated register with sources retained.

Risk & Compliance

Audit evidence mapping

Pairs a full evidence set against every audit assertion or PBC item to produce a coverage matrix, naming the assertions nothing supports and the documents supporting nothing.

Risk & Compliance

Claims Coverage Triage Engine

Reads a submitted claim against the policy wording that governs it and returns a coverage assessment showing whether it appears covered, potentially excluded or in need of specialist review, mapped clause by clause and never issued without a handler's sign-off.

Risk & Compliance

Incident Severity & Response

Assesses a reported incident against your response playbook and policies, assigns the severity band the evidence supports, and returns the matching response plan with the notifications, owners and timelines that band requires.

Risk & Compliance

Privacy / Data-Transfer Approval

Assesses personal-data processing and cross-border transfers against privacy policy and jurisdiction rules, producing a documented approval outcome with conditions, policy evidence and grounds for referral.