Comparable registers
Score every risk identically, so results hold up across teams, entities and quarters.
— Risk & Compliance
A governed DSAR call: a subject request in, a Fulfil / Fulfil in part / Refuse with reasons / Extend the deadline verdict out — identity verified, scope mapped to the systems actually holding the data, and a mandatory DPO sign-off before anything is disclosed.
1–2 hours → ~5 minutes
For one document, brief or record at a time
No coding required
— USE CASES
Score every risk identically, so results hold up across teams, entities and quarters.
Show the basis for each rating rather than asserting a residual score.
Assess the whole of the risk universe in scope rather than the subset there was time for.
Assessing the risk universe in scope by hand means every assessor scores slightly differently and the register stops being comparable. Comparable registers is the typical trigger — score every risk identically, so results hold up across teams, entities and quarters. Done properly it is defensible; done at pace it becomes a judgement call nobody can retrace. And "properly" usually means 1–2 hours of manual work.
As a Skill, the work is already sequenced. You bring the evidence, and the run produces a scored register with the reasoning per risk plus an aggregated view at the level the committee reads. The judgement is built in — how items are broken up, what standard they are held to, and where the run stops for a human review. Net effect: 1–2 hours down to ~5 minutes, no drift between runs, and every conclusion traceable back to the evidence behind it.
Data Subject Access Request (DSAR) Engine exports as a structured SKILL.md file and is MCP-ready, so the same method runs in ChatGPT, Claude, Copilot or your own AI products. Adapt it to your methodology, and the intelligence stays yours — not locked to one vendor.
Findings consolidation
Fans multiple audit or review reports into individual findings, deduplicates repeats, and sorts them by severity into one consolidated register with sources retained.
Audit evidence mapping
Maps an uploaded evidence set against a list of assertions or PBC items to produce a coverage matrix, flagging unsupported assertions and orphaned documents.
Regulation scan
Researches regulatory change in a defined area, classifies the findings, and states the implications for your specific business context.