Skip to content
Back to skills

Compliance Policy Auditor

ASecurity

Audit corporate policies or data-handling descriptions against regulatory frameworks (GDPR, SOC2, HIPAA). Use when users need to identify compliance gaps or risk levels in technical procedures.

  • 16 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added June 8, 2026
ai-agentsgogitsecuritydocumentation

Security analysis

A100/100

Scanned June 8, 2026

npx -y skills add ThomasMoreAI/legal-skills-open --skill compliance-policy-auditor --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Compliance Policy Auditor?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Compliance Policy Auditor
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/thomasmoreai-compliance-policy-auditor/badge)](https://www.skillsdirectory.com/skills/thomasmoreai-compliance-policy-auditor)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: compliance-policy-auditor
title: Compliance Policy Auditor
description: Audit corporate policies or data-handling descriptions against regulatory  frameworks (GDPR, SOC2, HIPAA). Use when users need to identify compliance  gaps or risk levels in technical procedures.
author: CreativeActtech
author_url: https://github.com/CreativeActtech/llm-skills/tree/main/skills/example-skill/compliance-policy-analyzer
license: MIT
version: 0.1.0
execution_mode: open
jurisdiction: general
practice: data-protection
language: en
tags: [legal, compliance, audit, security, risk]
---

# Compliance Policy Auditor
Systematically reviews technical or procedural documentation to identify 
alignment or deviations from major regulatory frameworks.

## 🎯 When to Use
- User provides a "Privacy Policy" or "Data Retention Plan" for review.
- User asks: "Is this process SOC2 compliant?" or "What GDPR risks exist here?"
- **Do NOT use** for providing binding legal advice or drafting contracts.
- **Do NOT use** for auditing physical security (cams, locks) unless documented.

## 🧠 Core Workflow
**Step 1 β€” Scope & Framework Selection**
IF user specifies a framework (GDPR/SOC2/HIPAA/ISO27001), prioritize its rules; 
ELSE, apply General Data Protection principles.

**Step 2 β€” Data Mapping**
Identify PII (Personally Identifiable Information), PHI (Protected Health 
Information), or PCI data mentioned in the text.

**Step 3 β€” Gap Analysis**
1. **Data Minimization** β€” Check if only necessary data is collected.
2. **Access Control** β€” Audit description of "Who has access" (RBAC).
3. **Security Measures** β€” Identify encryption, hashing, and log requirements.

**Step 4 β€” Risk Scoring**
Assign Severity (Critical/Major/Minor) to gaps based on regulatory fine potential.

**Step 5 β€” Return Output**
Provide a structured JSON audit report.

## πŸ“‹ Output Format
```json
{
  "frameworks_evaluated": ["GDPR", "SOC2"],
  "pii_detected": ["email", "IP address"],
  "findings": [
    {
      "severity": "critical",
      "category": "Data Retention",
      "issue": "Policy states data is kept indefinitely.",
      "remediation": "Define a 7-year purge cycle per Article 5(1)(e)."
    }
  ],
  "risk_summary": "1 Critical Gap detected. High risk of non-compliance."
}
```

## ⚠️ Fallback Behavior
IF the input text is too vague to audit:

ASK for specific details regarding data storage, user consent, or encryption

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…