New regulation readiness
Establish, obligation by obligation, where existing policy already covers you and where it does not.
— Risk & Compliance
Researches a named regulation live, extracts each obligation with its clause reference, and maps it against uploaded policies to produce a gap report.
1–2 weeks → ~15 minutes
For a typical multi-document review workflow
No coding required
— USE CASES
Establish, obligation by obligation, where existing policy already covers you and where it does not.
Show coverage status against named clauses instead of a general commitment to compliance.
Turn the gaps into a costed work list with a suggested owner attached to each obligation.
— HOW IT BEHAVES
The mechanics behind this specific template — what it reads, what it calculates, and where a human stays in the loop.
A coverage pass shows what is supported and what is not — including requirements with nothing behind them and material that supports nothing.
A folder of material is processed as one set, so cross-document patterns surface instead of being read one file at a time.
Current external sources are researched during the run rather than recalled from training data, and the sources travel with the output.
Findings are written up as a document that reads like professional output rather than raw model text.
Every risk & compliance team needs regulatory change impact assessment — and almost none of them do it the same way twice. In practice it shows up as new regulation readiness: establish, obligation by obligation, where existing policy already covers you and where it does not. It is the kind of work that decides whether a recommendation survives scrutiny — and the kind that quietly eats 1–2 weeks of senior time whenever it comes round.
As a Skill, the work is already sequenced. You bring the evidence, and the run produces an obligation-level coverage matrix with clause references plus named gaps with remediation actions and suggested owners. What sits between input and output is the codified method: thresholds, sequencing and the points where a human confirms a call — all of it visible and editable in the Skill. In effect, 1–2 weeks of senior time compresses into ~15 minutes — and the output is comparable across clients, quarters and colleagues instead of shaped by whoever ran it.
Regulatory change impact assessment exports as a structured SKILL.md file and is MCP-ready, so the same method runs in ChatGPT, Claude, Copilot or your own AI products. Adapt it to your methodology, and the intelligence stays yours — not locked to one vendor.
Regulation scan
Researches regulatory change in a defined area, classifies the findings, and states the implications for your specific business context.
Control gap assessment (SOC 2 / ISO 27001)
Extracts documented controls and framework requirements, then grades every requirement covered, partial or absent for SOC 2 or ISO 27001 readiness.
Audit evidence mapping
Maps an uploaded evidence set against a list of assertions or PBC items to produce a coverage matrix, flagging unsupported assertions and orphaned documents.