Compliance Readiness Check
Pressure-testing any compliance program before starting a new framework, planning an audit calendar, or preparing for certification stage 1.
What it does
Pressure-testing any compliance program before starting a new framework, planning an audit calendar, or preparing for certification stage 1.
Procedure
When this skill is activated, Chalie follows these steps:
- Use
memoryto recall any prior compliance assessments, known gaps, or active certifications already documented. - Use
memoryto surface any stored framework selections, then identify all applicable compliance frameworks by asking about industry, customer requirements, and geography — flag any commonly missed overlays (NYDFS for financial services, HIPAA for healthcare, ISO 42001 for AI systems). - Use
documentto map overlaps between the identified frameworks — record where a single evidence artifact satisfies controls in multiple frameworks to reduce audit effort. - Use
documentto verify and record that every evidence artifact has a single accountable owner with a documented refresh cadence — shared ownership without accountability is the most common cause of stale evidence. - Use
calendarto check the audit calendar: confirm surveillance audits are not stacking in the same window, auditor independence is maintained, and small teams have a rotation plan. - Use
searchto verify the current status of any relevant harmonized standards, regulatory deadlines, or framework updates that could affect scope. - Use
scheduleto note the management review cadence: recommend one quarterly cross-framework review covering all applicable frameworks rather than separate reviews per framework. - Use
documentto save a compliance readiness report with: frameworks in scope, evidence inventory gaps, ownership assignments, audit calendar, and prioritized remediation actions.
Version
v1 (curated)