Syntic

Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.

ComplianceFree Safe

compliance-readiness

Security Scan Summary

Status: Safe

Source: Syntic Skills registry

Automated security scan completed with no high-risk patterns detected. Manual review is still required.

About This Skill

Use when adopting a new compliance framework, finalizing the annual audit calendar, or signing off on certification stage-1 readiness across frameworks.

Downloadable SKILL.md

Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.

SKILL.md
---
name: compliance-readiness
description: Use when adopting a new compliance framework, finalizing the annual audit calendar, or signing off on certification stage-1 readiness across frameworks.
category: Compliance
version: 1.0.0
tools: []
---

# Compliance Readiness

Six forcing questions from the multi-framework compliance-officer perspective, applied before adopting a new framework, finalizing the annual audit calendar, or signing off on certification-stage-1 readiness.

## When to run

Before adopting a new compliance framework; before finalizing the annual audit calendar; before certification stage 1 readiness sign-off; before a management review that spans multiple frameworks' Clause 9.3 inputs; when evidence-collection effort has grown 50%+ year-over-year (a smell); or when an audit produced more than 15% critical findings.

## The six questions

### 1. Have you named every applicable framework?
No framework-selection pass, no defensible scope. Forgetting a framework means rebuilding the audit program later. Watch for industry-specific overlays: financial (NYDFS, FINMA), healthcare (HIPAA, ISO 13485), AI (ISO 42001 + EU AI Act).

### 2. Where do the frameworks overlap, and what's the reuse leverage?
Single evidence satisfying N controls is the cornerstone of multi-framework efficiency. HIGH-confidence mappings mean the same evidence works as-is; MEDIUM means existing evidence plus an overlay; LOW means a new artefact is needed. Without overlap analysis, the same access-review records get collected three times.

### 3. Who owns each artefact, and what's the reuse-leverage score?
Joint ownership without accountability is the most common cause of stale evidence. HIGH-leverage artefacts (≥5 mappings) get built first, and every artefact needs one accountable owner — stale evidence is an effective gap even if the artefact existed historically.

### 4. What's the audit calendar, and is auditor independence respected?
Surveillance audits stacking in the same week is a smell. An auditor cannot audit their own work under Clause 9.2 across all ISO standards; small teams should rotate auditors and bring in an external auditor occasionally.

### 5. What does a mock audit produce, and is the severity distribution healthy?
No mock audit, no readiness signal. A healthy distribution is ≥40% observation and ≤15% critical. All-critical findings mean either a destructive audit or a genuinely failing program; all-observation findings mean the audit was too superficial.

### 6. What's the management-review cadence across frameworks?
Each framework wants its own management review, but one integrated quarterly review per Annex SL — covering risk-register changes, open nonconformities, audit findings, incidents, drift, and KPIs across all enabled frameworks — saves roughly 5x executive time and still produces the required action items, resource decisions, and scope adjustments.

## What to produce

Name the decision being made (framework-set / audit-calendar / certification-readiness / evidence-consolidation). Cover: the framework set (applicable frameworks, how many are binding regulations vs. certifiable, missing dependencies); cross-framework overlap (total merged controls in scope, count of high-leverage artefacts with ≥5 mappings, top 5 reuse opportunities); the evidence pool (artefact count, high-leverage count, stale-evidence rate, unowned-artefact count); the audit calendar (frameworks scheduled this year, whether auditor independence is respected, conflicts); and mock-audit results per framework (total findings, critical %, observation %, whether the distribution is healthy).

Close with a verdict — READY / STAGE-2-CANDIDATE / NOT-READY — and the top 3 actions with owners and dates.

## Escalate to a teammate

For ISO 42001-specific or EU AI Act-specific forcing questions, cybersecurity strategy, executive AI strategy, or novel-case legal review, @mention the relevant compliance, security, or legal teammate. Treat certification commitments as multi-year financial commitments worth a deliberate pause before signing.

Bundle Download

Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.

Install Targets

Syntic App

  1. 1. Create a dedicated folder for this skill in your local skills library.
  2. 2. Place SKILL.md into that folder.
  3. 3. Restart Syntic and invoke this skill on matching tasks.

Syntic Code (CLI)

  1. 1. Save SKILL.md in your local Syntic Code skills directory.
  2. 2. Keep related files in the same skill folder.
  3. 3. Run in a safe environment and validate outputs.

Source

https://github.com/alirezarezvani/claude-skills/blob/main/compliance-os/skills/compliance-readiness/SKILL.md

Open Source Link
Compliance

Related Skills