Agent skill

Compliance Readiness

by alirezarezvani in alirezarezvani/claude-skills

/cs:compliance-readiness <program — Multi-framework compliance officer 6-question forcing interrogation of any compliance program.

MITAuto-check passedLegal & Compliance

Install Compliance Readiness

skills CLI
$ npx skills add alirezarezvani/claude-skills --skill compliance-readiness -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-skills compliance-readiness --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/compliance-os/skills/compliance-readiness .claude/skills/compliance-readiness && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
compliance-readiness
GitHub stars
28k
Token cost
~1.4k tokens
SKILL.md length
424 words
Files
1
Skills in repo
342
Repo updated
First seen
Licence
MIT

At a glance

/cs:compliance-readiness <program — Multi-framework compliance officer 6-question forcing interrogation of any compliance program.

  • Works in 6 steps: Have you named every applicable framework? → Where do the frameworks overlap, and… → Who owns each artefact, and what's the… → …
  • Tasks that involve Regulatory compliance
  • SKILL.md covers When to Run, The Six Compliance Officer…, Workflow and Output Format, plus 2 more sections
  • Calls python

What it does

Compliance Readiness is an agent skill from alirezarezvani/claude-skills. /cs:compliance-readiness <program — Multi-framework compliance officer 6-question forcing interrogation of any compliance program. Use before starting a new framework, planning the annual audit calendar, or preparing for certification stage 1.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Regulatory compliance. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.

When your agent uses it

  • Tasks that involve Regulatory compliance

Example prompts

  • “/compliance-readiness”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Have you named every applicable framework?
  2. Where do the frameworks overlap, and what's the reuse leverage?
  3. Who owns each artefact, and what's the reuse-leverage score?
  4. What's the audit calendar, and is auditor independence respected?
  5. What does a mock audit produce, and is the severity distribution healthy?
  6. What's the management review cadence across frameworks?

What it can do on your machine

Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Compliance Readiness loads about 1.4k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 424 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 424 words, ~1,378 tokens.

Download SKILL.mdSave it as .claude/skills/compliance-readiness/SKILL.md (or your agent's skills folder).
name
compliance-readiness
description
/cs:compliance-readiness <program> — Multi-framework compliance officer 6-question forcing interrogation of any compliance program. Use before starting a new framework, planning the annual audit calendar, or preparing for certification stage 1.

/cs:compliance-readiness — Compliance Officer Forcing Questions

Command: /cs:compliance-readiness <program>

The multi-framework compliance officer pressure-tests any compliance program. Six questions before any new-framework commitment, audit cycle planning, or certification readiness sign-off.

When to Run

  • Before adopting a new compliance framework
  • Before annual audit calendar finalization
  • Before certification stage 1 readiness sign-off
  • Before management review (Clause 9.3 across frameworks)
  • When evidence-collection effort has grown 50%+ year-over-year (a smell)
  • When an audit produced > 15% critical findings

The Six Compliance Officer Questions

1. Have you named every applicable framework?

No framework selector run, no defensible scope.

  • Run framework_selector.py with company profile
  • Forgetting a framework means rebuilding the audit program later
  • Pay attention to industry-specific overlays (financial: NYDFS, FINMA; healthcare: HIPAA, ISO 13485; AI: ISO 42001 + EU AI Act)
2. Where do the frameworks overlap, and what's the reuse leverage?

Single evidence -> N controls = the cornerstone of multi-framework efficiency.

  • Run cross_framework_mapper.py with enabled frameworks
  • HIGH-confidence mappings: same evidence; MEDIUM: existing + overlay; LOW: new artefact
  • Without overlap analysis, you'll collect the same access-review records 3 times
3. Who owns each artefact, and what's the reuse-leverage score?

Joint ownership without accountability is the most common cause of stale evidence.

  • Run evidence_pool_generator.py for the artefact inventory
  • HIGH-leverage artefacts (≥ 5 mappings) get built first
  • Each artefact needs one accountable owner
  • Stale evidence is an effective gap — even if the artefact existed historically
4. What's the audit calendar, and is auditor independence respected?

Surveillance audits stacking in the same week is a smell.

  • Use per-framework audit-plan tools (aims_audit_scheduler, isms_audit_scheduler, audit_schedule_optimizer)
  • Auditor cannot audit their own work (Clause 9.2 across all ISO standards)
  • For small teams: rotate auditors + occasional external auditor
Show full SKILL.md (155 more words)Show less
5. What does a mock audit produce, and is the severity distribution healthy?

No mock audit, no readiness signal.

  • Run audit_simulator.py with framework + scope
  • Healthy distribution: ≥ 40% observation, ≤ 15% critical
  • All-critical findings = destructive audit OR genuinely failing program
  • All-observation findings = audit too superficial
6. What's the management review cadence across frameworks?

Each framework wants its own management review; an integrated review (per Annex SL) saves 5x exec time.

  • Schedule one quarterly cross-framework review covering all enabled frameworks' Clause 9.3 inputs
  • Inputs: risk register changes, open nonconformities, audit findings, incidents, drift, KPIs
  • Outputs: action items, resource decisions, scope adjustments

Workflow

bash
# 1. Framework selection
python ../../skills/compliance-os/scripts/framework_selector.py profile.json

# 2. Cross-framework overlap
python ../../skills/compliance-os/scripts/cross_framework_mapper.py program.json

# 3. Evidence pool consolidation
python ../../skills/compliance-os/scripts/evidence_pool_generator.py program.json

# 4. Mock audit (per framework)
python ../../skills/compliance-os/scripts/audit_simulator.py scope.json

Output Format

markdown
# Compliance Readiness: <program>
**Date:** YYYY-MM-DD

## The Decision Being Made
[framework-set | audit-calendar | certification-readiness | evidence-consolidation]

## Framework Set
- Applicable: <list>
- Binding (regulations): <count>
- Certifiable: <count>
- Missing dependencies: <list>

## Cross-Framework Overlap
- Total merged controls in scope: N
- High-leverage artefacts (≥ 5 mappings): M
- Top reuse opportunities: <top 5 artefacts>

## Evidence Pool
- Artefacts in catalog: N
- High-leverage count: M
- Stale evidence rate: X%
- Unowned artefacts: K

## Audit Calendar
- Frameworks scheduled this year: <list>
- Auditor independence respected: Y/N
- Conflicts: <list>

## Mock Audit Results (per framework)
- <framework>: total findings N, critical X%, observation Y%, healthy distribution: Y/N

## Verdict
🟢 READY | 🟡 STAGE-2-CANDIDATE | 🔴 NOT-READY

## Top 3 Actions
[3 concrete next steps with owners + dates]

Routing

  • /cs:aims-audit — for ISO 42001-specific forcing questions
  • /cs:ai-act-readiness — for EU AI Act-specific forcing questions
  • /cs:ciso-review — for cybersecurity strategy
  • /cs:caio-review — for executive AI strategy
  • /cs:gc-review — for novel-case legal review
  • /cs:decide — to log the verdict
  • /cs:freeze 30 — on certification commitments (multi-year financial impact)
  • Agent: cs-compliance-officer
  • Skill: compliance-os
  • Adjacent: ra-qm-team/skills/iso42001-specialist/, ra-qm-team/skills/eu-ai-act-specialist/, ra-qm-team/skills/information-security-manager-iso27001/, ra-qm-team/skills/soc2-compliance/, ra-qm-team/skills/gdpr-dsgvo-expert/

Version: 1.0.0

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in compliance-os/skills/compliance-readiness of alirezarezvani/claude-skills.

Open the folder on GitHubat commit 19392f7

Compare with similar skills

Compliance Readiness next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Compliance Readiness compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Compliance Readiness this skillalirezarezvani/claude-skills28k—~1.4kAutomated safety check: PassMIT
HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed5.5k—~2kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.7kAutomated safety check: PassMIT
Legal Compliance SearchSerein-81/financial_rag148—~1.6kAutomated safety check: NotesNone

Similar skills

  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • Legal Compliance Search

    Serein-81/financial_rag

    Looks up current company registration rules, industry licences and compliance obligations in China through live web search, tailored to the business profile.

    148 GitHub stars~1.6k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check: notes
  • Ad Compliance Review

    zh-xx/legal-assistant-skills

    广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。

    174 GitHub stars~1.2k tokensUpdated 5 mo ago
    Legal & ComplianceAuto-check passed

More from alirezarezvani/claude-skills

All 342 skills in this repo
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Product Strategist

    alirezarezvani/claude-skills

    OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.

    28k GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • App Store Optimization

    alirezarezvani/claude-skills

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.

    28k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Campaign Analytics

    alirezarezvani/claude-skills

    Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Code to PRD

    alirezarezvani/claude-skills

    Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.

    28k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed

Questions about Compliance Readiness

What does Compliance Readiness do?

/cs:compliance-readiness <program — Multi-framework compliance officer 6-question forcing interrogation of any compliance program. Compliance Readiness is an agent skill from alirezarezvani/claude-skills. /cs:compliance-readiness <program — Multi-framework compliance officer 6-question forcing interrogation of any compliance program.

When should I use Compliance Readiness?

Compliance Readiness fits situations like: tasks that involve Regulatory compliance.

How do I install Compliance Readiness in Claude Code?

Run `npx skills add alirezarezvani/claude-skills --skill compliance-readiness -a claude-code`. Or copy the skill folder (compliance-os/skills/compliance-readiness in alirezarezvani/claude-skills) into .claude/skills/compliance-readiness in your project. Claude Code loads it when a task matches its description.

How do I install Compliance Readiness in Codex?

Run `npx skills add alirezarezvani/claude-skills --skill compliance-readiness -a codex`. Or copy the skill folder (compliance-os/skills/compliance-readiness in alirezarezvani/claude-skills) into .agents/skills/compliance-readiness in your project. Codex loads it when a task matches its description.

Can I use Compliance Readiness in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill compliance-readiness -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/compliance-readiness, .gemini/skills/compliance-readiness, .github/skills/compliance-readiness and .opencode/skills/compliance-readiness in your project.

What does Compliance Readiness need to run?

Going by SKILL.md and its folder, Compliance Readiness needs the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Compliance Readiness access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Compliance Readiness safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Compliance Readiness use?

Compliance Readiness is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Compliance Readiness use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Compliance Readiness?

Skills that share tags, products or a category with Compliance Readiness: HIPAA Pre-Deployment Compliance Check (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars) and Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Compliance Readiness?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,938 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.

Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.