compliance-gap-analysisUse when a compliance officer, security analyst, or auditor needs to assess an organization's controls against a regulatory framework (GDPR, SOC 2, ISO 27001...
Install via ClawdBot CLI:
clawdbot install archlab-space/compliance-gap-analysisGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated Sep 30, 2026
A B2B SaaS startup's CTO needs to prove security posture to enterprise prospects. The skill guides an assessment against SOC 2 common criteria, collects evidence per control domain, and produces a gap analysis matrix with a prioritized remediation roadmap before the auditor arrives.
A healthcare compliance officer assesses administrative, physical, and technical safeguards against HIPAA after a re-accreditation audit. The skill walks through PHI-handling domains, records unknown controls as gaps, and generates risk-rated findings and a breach-notification readiness plan.
A payments team maps their cardholder data environment against PCI-DSS requirements. The skill evaluates network security, access control, and monitoring domains, flags scope gaps like third-party processors, and outputs a remediation roadmap for the QSA assessment.
An international retailer expanding to the EU needs to assess data subject rights, cross-border transfers, and processor agreements. The skill collects evidence per GDPR domain, identifies gaps, and produces a prioritized plan for appointing a DPO and updating privacy notices.
A public sector security analyst evaluates their cybersecurity posture against NIST CSF's Identify, Protect, Detect, Respond, and Recover functions. The skill captures vague answers with follow-up questions, rates unmapped controls, and delivers an executive-ready gap analysis for funding requests.
A company offers subscription-based tools and expert guidance for organizations to self-assess against regulatory frameworks. The skill automates structured assessments and report generation, reducing manual consulting hours and scaling to many clients.
A small advisory firm uses the skill to standardize client engagements across GDPR, SOC 2, and ISO 27001. Consultants run the guided assessment in workshops, then deliver a branded gap analysis and remediation roadmap as a paid project deliverable.
Enterprises deploy the skill as an internal capability for their security and audit teams to run recurring assessments. It reduces reliance on external auditors for pre-assessments and centralizes evidence collection across business units.
💬 Integration Tip
Integrate with existing GRC or evidence-collection tools (e.g., Vanta, Drata) so statuses and risk ratings export directly into the report matrix. Pre-load framework control lists as structured data to prevent the agent from inventing requirements and to keep questions consistent across sessions.
Scored Sep 30, 2026
基于睿观的产品图片政策合规检测,通过视觉相似度匹配识别潜在违规商品。当用户提到政策合规检查、产品图片合规、违规检测、禁售商品筛查、基于图片的合规审查、上架前风险排查、policy compliance detection, product compliance review, violation detectio...
AI 合同风险审查服务。当用户需要审查合同、检查法律风险、分析合同条款、 审阅法律文书时使用本技能。覆盖违约责任、知识产权、付款条件、验收标准、 保密义务、管辖法院等15类法律风险。支持快速扫描和深度审查两档服务。 触发词:合同审查、审核合同、检查合同、法律风险、条款分析、法务审查、 合同风险、审合同、法律审查、...
产品图片的图形商标检测与相似度搜索。当用户提到商标检测、图形商标搜索、Logo侵权检查、商标相似度分析、图片商标风险评估、产品图片商标筛查、graphic trademark detection, logo infringement, trademark similarity, trademark risk, i...
面向电商产品Listing的文字商标检测与侵权风险分析。当用户提到商标检测、商标风险检查、品牌侵权筛查、产品标题商标扫描、文字商标查询、Listing合规检查、知识产权风险评估、text trademark detection, trademark infringement, brand infringement...
GDPR and German DSGVO compliance automation. Scans codebases for privacy risks, generates DPIA documentation, tracks data subject rights requests. Use for GD...
CAPA system management for medical device QMS. Covers root cause analysis, corrective action planning, effectiveness verification, and CAPA metrics. Use for...