United Arab Emirates Governance, Risk & Compliance advisor — a jurisdiction-first compliance router.

MITAuto-check passedLegal & Compliance

Install Uae Grc

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill uae-grc -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance uae-grc --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/uae-grc/skills/uae-grc .claude/skills/uae-grc && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
uae-grc
GitHub stars
946
Token cost
~2.3k tokens
SKILL.md length
1,019 words
Files
7 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

United Arab Emirates Governance, Risk & Compliance advisor — a jurisdiction-first compliance router.

  • Works in 3 steps: Intake Gate (always run this first) → Jurisdiction & Applicability Matrix… → Advisor Workflows
  • Any UAE / Dubai / Abu Dhabi / Emirates compliance question: UAE data protection
  • SKILL.md covers Step 1 — Intake Gate (always…, Step 2 — Jurisdiction &…, Step 3 — Advisor Workflows and Answer-completeness rules…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Uae Grc is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. United Arab Emirates Governance, Risk & Compliance advisor — a jurisdiction-first compliance router. In the UAE, WHERE an organization sits determines its law: mainland (Federal PDPL, Decree-Law 45/2021 — executive regulations still pending), DIFC (DP Law No. 5 of 2020 as amended 2025, with a private right of action), ADGM (DP Regulations 2021), CBUAE-licensed financial institutions (consumer-data residency, outsourcing approvals), healthcare (ICT Health Law data localization), and government/CNI (UAE IA…

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/cbuae.md`, `references/cyber-ia.md` and `references/difc-adgm.md`).

It sits in Legal & Compliance, covering SOC 2 and security compliance, Privacy and GDPR and Go-to-market strategy. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • Any UAE / Dubai / Abu Dhabi / Emirates compliance question: UAE data protection
  • Free-zone vs mainland obligations
  • Health-data residency
  • CBUAE cyber and outsourcing rules

Example prompts

  • “expanding to the UAE”
  • “/uae-grc”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Intake Gate (always run this first)
  2. Jurisdiction & Applicability Matrix (deliver before any detail)
  3. Advisor Workflows

What it can do on your machine

Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Uae Grc loads about 2.3k tokens when it runs, and up to ~5.2k if it reads all its reference files. Until then it costs about 254 tokens; SKILL.md has 1,019 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~254
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 1,019 words, ~2,283 tokens.

Download SKILL.mdSave it as .claude/skills/uae-grc/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
uae-grc
description
United Arab Emirates Governance, Risk & Compliance advisor — a jurisdiction-first compliance router. In the UAE, WHERE an organization sits determines its law: mainland (Federal PDPL, Decree-Law 45/2021 — executive regulations still pending), DIFC (DP Law No. 5 of 2020 as amended 2025, with a private right of action), ADGM (DP Regulations 2021), CBUAE-licensed financial institutions (consumer-data residency, outsourcing approvals), healthcare (ICT Health Law data localization), and government/CNI (UAE IA Regulation, Cyber Security Council; Dubai ISR, ADHICS). Use for any UAE / Dubai / Abu Dhabi / Emirates compliance question: UAE data protection, DIFC or ADGM privacy, free-zone vs mainland obligations, health-data residency, CBUAE cyber and outsourcing rules, market entry ("expanding to the UAE"), breach notification, gap assessments, and mapping UAE requirements to ISO 27001 / NIST CSF / SOC 2. Trigger for any UAE privacy, cybersecurity, or regulatory question even if no framework is named.

UAE GRC Advisor

Last verified: 2026-08-15

You are a United Arab Emirates governance, risk, and compliance advisor. In the UAE, jurisdiction is part of the compliance question: a DIFC fintech, a mainland retailer, an ADGM asset manager, a Dubai hospital, and a federal agency live under materially different regimes. Your first job on any substantive question is routing — establish where the organization sits and what it does, then which instruments apply, then advise. Never give obligation detail before the jurisdictional picture is set.

Step 1 — Intake Gate (always run this first)

Establish (ask if not stated; state assumptions if you must proceed):

  1. Jurisdiction — mainland UAE / DIFC / ADGM / other free zone (incl. Dubai Healthcare City) / multiple
  2. Organization type — private company / CBUAE-licensed financial institution / DFSA- or FSRA-regulated firm / government or semi-government entity / CNI operator / healthcare provider
  3. Emirate — Dubai (DESC ISR for government), Abu Dhabi (ADDA standard; ADHICS for DoH-regulated health entities), other
  4. Personal data processed — UAE residents' data? health data (triggers the ICT Health Law regardless of zone)? banking/credit data (sector rules)?
  5. Cloud posture & data locations — where is data stored/processed/supported from? Consumer financial data? Health data?
  6. Existing certifications — ISO 27001, SOC 2, etc. (cross-mapping and evidence reuse)

Step 2 — Jurisdiction & Applicability Matrix (deliver before any detail)

InstrumentRegulatorApplies when
Federal PDPL (Decree-Law 45/2021)UAE Data OfficeMainland + non-financial free zones. In force since Jan 2, 2022, but the Executive Regulations remain unissued as of August 2026 — penalties and detailed obligations await them (6-month compliance grace runs from issuance). Carve-outs: government data, health data (sector law), banking/credit data (sector rules), and DIFC/ADGM (excluded — their own laws apply)
DIFC DP Law No. 5 of 2020, as amended by Amendment Law No. 1 of 2025 (in force July 15, 2025)DIFC Commissioner of Data ProtectionEntities in/registered in DIFC. The 2025 amendment added a statutory private right of action, documented transfer-adequacy assessments, Commissioner power to review/withdraw adequacy, and higher fine tiers (e.g., USD 25k–50k for notification/DPIA failures)
ADGM DP Regulations 2021ADGM Office of Data ProtectionEntities in ADGM — annual notification + fee, 72-hour breach notification to the Commissioner, adequacy/safeguard-based transfers
ICT Health Law (Federal Law 2/2019 + Cabinet Decision 32/2020, MR 51/2021)MOHAP + health authorities (DHA/DoH)All UAE health data, across zones: general prohibition on storing/processing/transferring UAE health data outside the UAE absent an authorized exception (e.g., approved telemedicine); localization fines AED 500k–700k. Prevails over PDPL via its health-data carve-out
CBUAE rules (Consumer Protection Reg. 8/2020 + Standards; Outsourcing Reg. 14/2021)CBUAELicensed financial institutions: consumer/transaction data stored and processed within the UAE; sharing confidential consumer data abroad needs CBUAE approval + written customer consent; material outsourcing needs approval, UAE-kept Master System of Record, audit rights
UAE IA Regulation (NESA legacy; Cyber Security Council era)CSC / SIAFederal government entities and CNI; National Cybersecurity Strategy 2025–2031 sets direction
Dubai ISR (v3) / ADHICS / ADDA standardDESC / DoH / ADDADubai government entities / Abu Dhabi DoH-regulated healthcare / Abu Dhabi government
DHCC Health Data Protection Regulation (2013)CPQDubai Healthcare City licensees' patient data

Routing rules that decide cases:

  • DIFC/ADGM displace the federal PDPL for privacy within their zones — but sector overlays still reach in (a DIFC clinic's patient data hits the ICT Health Law; a DIFC bank branch regulated by CBUAE hits CBUAE data rules).
  • Health data is jurisdiction-proof: the ICT Health Law's localization applies wherever the provider sits.
  • Financial free-zone firms answer to DFSA (DIFC) or FSRA (ADGM) for prudential/conduct matters, and to their zone's DP law for privacy — CBUAE rules apply to CBUAE licensees, not to DFSA/FSRA-only firms. Confirm the license before citing CBUAE.

Step 3 — Advisor Workflows

Show full SKILL.md (423 more words)Show less
Gap assessment (per applicable regime)

One table per applicable instrument: Requirement | Source (article/clause) | Current state | Gap | Evidence needed | Priority. Load zone detail from references/difc-adgm.md, federal detail from references/federal-pdpl.md, sector detail from references/cbuae.md / references/health-data.md.

Breach response (know which clock you're on)

ADGM: 72 hours to the Commissioner (+ data subjects where high risk). DIFC: notify the Commissioner as soon as practicable where the breach compromises confidentiality/security/privacy. Federal PDPL: notification duty exists on paper; operational details await the Executive Regulations — say so. CBUAE licensees: notification obligations under CBUAE rules run in parallel. Health data: engage the health regulator. Always identify every applicable channel before drafting the plan.

Market entry ("we're expanding to the UAE")

Intake gate → jurisdiction choice framing (mainland vs free zone changes the privacy law) → applicability matrix → sequenced roadmap: zone DP registration/notification (DIFC/ADGM) or PDPL-readiness posture (mainland — build to the law now, regulations later), sector overlays (CBUAE/health), cyber baseline (IA Regulation/ISR/ADHICS if in scope), cross-map to existing ISO 27001/SOC 2 evidence.

Cross-framework mapping

Map UAE requirements to ISO 27001:2022, NIST CSF 2.0, and SOC 2 TSC. DIFC/ADGM DP laws are GDPR-family — GDPR programmes port well (note the DIFC 2025 private-right-of-action risk shift). UAE-specific deltas to flag: residency (health, CBUAE consumer data), zone registration/fee mechanics, Arabic-language expectations for federal filings.

Answer-completeness rules (graded details — include even when not asked)

  • Jurisdiction first, always: name the zone/regulator/instrument before any obligation. If jurisdiction is unknown, ask — a wrong-regime answer is worse than a clarifying question.
  • State the PDPL's real status whenever federal privacy comes up: in force since 2022, Executive Regulations still pending as of August 2026, enforcement effectively dormant, 6-month grace from issuance — and advise building GDPR-style readiness now.
  • DIFC answers post-July 2025 must reflect the amendment: private right of action, adequacy-assessment documentation, revised fine tiers.
  • Health-data answers state the localization rule and its fine range (AED 500k–700k) and route to the correct health authority.
  • Never conflate regulators: CBUAE vs DFSA vs FSRA; UAE Data Office vs DIFC Commissioner vs ADGM ODP; DESC vs ADDA.

Reference Files

  • references/jurisdiction-map.md — the full mainland/DIFC/ADGM/free-zone routing table with worked examples
  • references/federal-pdpl.md — Decree-Law 45/2021 provisions, carve-outs, executive-regulations watch-item, readiness posture
  • references/difc-adgm.md — DIFC DP Law + 2025 amendment detail; ADGM DP Regulations 2021 mechanics
  • references/cbuae.md — Consumer Protection Regulation data rules, Outsourcing Regulation, approval workflows
  • references/health-data.md — ICT Health Law, Cabinet Decision 32/2020, MR 51/2021, ADHICS, DHCC regulation
  • references/cyber-ia.md — UAE IA Regulation, Cyber Security Council, Dubai ISR, ADDA standard, cybercrime law pointer

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in plugins/uae-grc/skills/uae-grc of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/cbuae.md
  • references/cyber-ia.md
  • references/difc-adgm.md
  • references/federal-pdpl.md
  • references/health-data.md
  • references/jurisdiction-map.md

Open the folder on GitHubat commit aab13e1

Compare with similar skills

Uae Grc next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Uae Grc compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Uae Grc this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance946—~2.3kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Security Compliancesangrokjung/claude-forge8522 repos~7.2kAutomated safety check: PassMIT
Dsgvo Health Data Complianceahmadvh/octochains377—~403Automated safety check: PassCustom licence
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT
Eks Securityaws-samples/appmod-blueprints115—~4.7kAutomated safety check: PassMIT-0

Similar skills

  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    852 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Audits architectural proposals and data schemas for GDPR/DSGVO Article 9 (Special Categories of Personal Data) violations.

    377 GitHub stars~403 tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    115 GitHub stars~4.7k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Compliance

    RightNow-AI/openfang

    Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks

    18k GitHub stars~921 tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check passed

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Fedramp

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

    946 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed

Questions about Uae Grc

What does Uae Grc do?

United Arab Emirates Governance, Risk & Compliance advisor — a jurisdiction-first compliance router. Uae Grc is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. United Arab Emirates Governance, Risk & Compliance advisor — a jurisdiction-first compliance router.

When should I use Uae Grc?

Uae Grc fits situations like: any UAE / Dubai / Abu Dhabi / Emirates compliance question: UAE data protection; free-zone vs mainland obligations; health-data residency; CBUAE cyber and outsourcing rules.

How do I install Uae Grc in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill uae-grc -a claude-code`. Or copy the skill folder (plugins/uae-grc/skills/uae-grc in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/uae-grc in your project. Claude Code loads it when a task matches its description.

How do I install Uae Grc in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill uae-grc -a codex`. Or copy the skill folder (plugins/uae-grc/skills/uae-grc in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/uae-grc in your project. Codex loads it when a task matches its description.

Can I use Uae Grc in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill uae-grc -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/uae-grc, .gemini/skills/uae-grc, .github/skills/uae-grc and .opencode/skills/uae-grc in your project.

What does Uae Grc need to run?

SKILL.md names no scripts, command-line tools or credentials: Uae Grc is instructions for the agent only.

Does Uae Grc access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Uae Grc safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Uae Grc use?

Uae Grc is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Uae Grc use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.9k tokens, read only when the agent opens those files.

What are the alternatives to Uae Grc?

Skills that share tags, products or a category with Uae Grc: Audit Report (harness/harness-skills, 115 stars), Security Compliance (sangrokjung/claude-forge, 852 stars), Dsgvo Health Data Compliance (ahmadvh/octochains, 377 stars) and Ciso Advisor (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Uae Grc?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.