Risk & Compliance AI Skill Templates
13 structured AI Skills for risk & compliance work. Each one is a sequenced, auditable method — open it in Studio, adapt it to your approach, or export it to ChatGPT, Claude or Copilot.
Data Subject Access Request (DSAR) Engine
Assesses a data subject access request end to end and returns a governed decision on whether to fulfil it, fulfil it in part, refuse it with reasons or extend the deadline, having verified identity, mapped the request to the systems that actually hold the data and held the outcome for a data protection sign-off before anything is disclosed.
0 stepsAudit evidence mapping
Pairs a full evidence set against every audit assertion or PBC item to produce a coverage matrix, naming the assertions nothing supports and the documents supporting nothing.
5 stepsFindings consolidation
Fans multiple audit or review reports into individual findings, deduplicates repeats, and sorts them by severity into one consolidated register with sources retained.
6 stepsClaims Coverage Triage Engine
Reads a submitted claim against the policy wording that governs it and returns a coverage assessment showing whether it appears covered, potentially excluded or in need of specialist review, mapped clause by clause and never issued without a handler's sign-off.
0 stepsIncident Severity & Response
Assesses a reported incident against your response playbook and policies, assigns the severity band the evidence supports, and returns the matching response plan with the notifications, owners and timelines that band requires.
0 stepsPrivacy / Data-Transfer Approval
Assesses personal-data processing and cross-border transfers against privacy policy and jurisdiction rules, producing a documented approval outcome with conditions, policy evidence and grounds for referral.
0 stepsRegulatory gap assessment
Assesses current policies, controls and supporting evidence against regulatory requirements, producing a gap assessment and prioritised remediation plan for reviewer approval.
11 stepsControl gap assessment (SOC 2 / ISO 27001)
Extracts documented controls and framework requirements, then grades every requirement covered, partial or absent for SOC 2 or ISO 27001 readiness.
7 stepsRCSA questionnaire → risk register
Runs a scored risk and control self-assessment questionnaire and calculates residual risk identically every time, producing a register comparable across teams and quarters.
5 stepsRegulatory change impact assessment
Researches a named regulation live, extracts every obligation with its clause reference, and maps each one against your own policies and controls to produce an obligation-level gap report with owners.
7 stepsCross-portfolio liability cap aggregation
Reads every liability cap in a contract portfolio, derives actual exposure as a number, and aggregates it by entity, flagging uncapped contracts separately.
14 stepsCase escalation risk
Ranks open cases by the risk of escalation using how comparable cases actually ended, flags the ones that look unusual against the norm, and returns a triage queue a rule-based process would miss.
10 stepsRegulation scan
Researches regulatory change in a defined area, classifies the findings, and states the implications for your specific business context.
4 steps