Risk & Compliance AI Skill Templates

13 structured AI Skills for risk & compliance work. Each one is a sequenced, auditable method — open it in Studio, adapt it to your approach, or export it to ChatGPT, Claude or Copilot.

Decision Engine

Data Subject Access Request (DSAR) Engine

Assesses a data subject access request end to end and returns a governed decision on whether to fulfil it, fulfil it in part, refuse it with reasons or extend the deadline, having verified identity, mapped the request to the systems that actually hold the data and held the outcome for a data protection sign-off before anything is disclosed.

0 steps
Delivery

Audit evidence mapping

Pairs a full evidence set against every audit assertion or PBC item to produce a coverage matrix, naming the assertions nothing supports and the documents supporting nothing.

5 steps
Diagnostic

Findings consolidation

Fans multiple audit or review reports into individual findings, deduplicates repeats, and sorts them by severity into one consolidated register with sources retained.

6 steps
Decision Engine

Claims Coverage Triage Engine

Reads a submitted claim against the policy wording that governs it and returns a coverage assessment showing whether it appears covered, potentially excluded or in need of specialist review, mapped clause by clause and never issued without a handler's sign-off.

0 steps
Decision Engine

Incident Severity & Response

Assesses a reported incident against your response playbook and policies, assigns the severity band the evidence supports, and returns the matching response plan with the notifications, owners and timelines that band requires.

0 steps
Decision Engine

Privacy / Data-Transfer Approval

Assesses personal-data processing and cross-border transfers against privacy policy and jurisdiction rules, producing a documented approval outcome with conditions, policy evidence and grounds for referral.

0 steps
Diagnostic

Regulatory gap assessment

Assesses current policies, controls and supporting evidence against regulatory requirements, producing a gap assessment and prioritised remediation plan for reviewer approval.

11 steps
Diagnostic

Control gap assessment (SOC 2 / ISO 27001)

Extracts documented controls and framework requirements, then grades every requirement covered, partial or absent for SOC 2 or ISO 27001 readiness.

7 steps
Diagnostic

RCSA questionnaire → risk register

Runs a scored risk and control self-assessment questionnaire and calculates residual risk identically every time, producing a register comparable across teams and quarters.

5 steps
Diagnostic

Regulatory change impact assessment

Researches a named regulation live, extracts every obligation with its clause reference, and maps each one against your own policies and controls to produce an obligation-level gap report with owners.

7 steps
Diagnostic

Cross-portfolio liability cap aggregation

Reads every liability cap in a contract portfolio, derives actual exposure as a number, and aggregates it by entity, flagging uncapped contracts separately.

14 steps
Delivery

Case escalation risk

Ranks open cases by the risk of escalation using how comparable cases actually ended, flags the ones that look unusual against the norm, and returns a triage queue a rule-based process would miss.

10 steps
Diagnostic

Regulation scan

Researches regulatory change in a defined area, classifies the findings, and states the implications for your specific business context.

4 steps

Other categories