Claude Skills for GRC
Claude Skills for Governance, Risk & Compliance (GRC)
A set of governance, risk and compliance skills: ISO 27001, SOC 2, GDPR, HIPAA, PCI DSS, NIST, the EU AI Act and other frameworks
Low risk
We rate an entry low when it mostly gives the agent instructions and reference material.
Why this level
- The skills consist of instructions and reference material on regulatory frameworks and run no code of their own
Install
Manual install
/plugin marketplace add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
/plugin install iso27001@grc-skills soc2@grc-skills gdpr-compliance@grc-skillsThe marketplace is named grc-skills. Install only the frameworks you need; the skill names are listed in the README.
This is third-party code. Review the repository files before installing.
What it does
The set turns Claude into a compliance assistant across dozens of regulatory frameworks at once: ISO 27001 and 27701, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF and 800-53, PCI DSS, CMMC 2.0, DORA, the EU AI Act, ISO 42001, CCPA, LGPD and many more. Each skill runs a structured gap analysis against the chosen framework, drafts policies and procedures with the required blocks and sections, documents controls in an audit-ready format, builds risk registers and treatment plans, and assembles evidence checklists. Skills load automatically when the conversation touches their topic and cite specific clauses of the standards. They install as .skill files in the Claude apps or as plugins through the marketplace in Claude Code, and are updated regularly.
Who it is for. For information security, privacy and compliance professionals, plus developers and advisors who need verifiable answers about regulatory frameworks.
Good fit when
- You need a gap analysis against ISO 27001, SOC 2 or another framework
- You need draft policies, a risk register or an evidence checklist for certification
- You need an answer on specific framework requirements with clause references
Not a fit when
- You need formal legal advice or a certified auditor's opinion
- Your task is unrelated to regulatory compliance and risk management
Example request
Run a gap analysis of our system against ISO 27001 2022 and draft an access control policyLimitations
The skills give expert orientation and drafts but do not replace a formal audit, legal advice or certification. The material covers international and industry frameworks and does not include Russian requirements. Outputs should be checked against current standard texts, since regulators update their requirements.
How to disable. Disable or remove the unneeded .skill files in the Claude apps, and if installed via the marketplace, remove the plugins with /plugin.
Security check
- The skills consist of instructions and reference material on regulatory frameworks and run no code of their own
README in short
The README describes a large set of Claude skills for governance, risk and compliance, covering dozens of frameworks from ISO 27001 and SOC 2 to the EU AI Act and various national industry rules. Skills are explained as installable knowledge packages that load automatically and work by progressive disclosure: a main SKILL.md plus references loaded on demand. Installation is by downloading a .skill file and uploading it to a Claude app, or through the marketplace in Claude Code with the grc-skills manifest. The author reports an in-house benchmark over 180 scenarios where the skill-assisted setup scored higher than the baseline model without skills. MIT licensed, updated monthly.
FAQ
Will this replace an auditor or a lawyer?
No. The skills speed up preparation: gap analysis, draft policies, risk registers and evidence checklists. They do not replace a formal audit, certification or legal opinion.
Do I have to install all the skills?
No. You can install only the frameworks you need, for example ISO 27001 and SOC 2, via individual .skill files or the marketplace.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents