Claude Skills for GRC

Claude Skills for Governance, Risk & Compliance (GRC)

A set of governance, risk and compliance skills: ISO 27001, SOC 2, GDPR, HIPAA, PCI DSS, NIST, the EU AI Act and other frameworks

Skill

Low risk

We rate an entry low when it mostly gives the agent instructions and reference material.

Why this level

  • The skills consist of instructions and reference material on regulatory frameworks and run no code of their own
All reasons and checks

sushegaad/claude-skills-governance-risk-and-compliance

Install

Manual install

/plugin marketplace add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
/plugin install iso27001@grc-skills soc2@grc-skills gdpr-compliance@grc-skills

The marketplace is named grc-skills. Install only the frameworks you need; the skill names are listed in the README.

This is third-party code. Review the repository files before installing.

What it does

The set turns Claude into a compliance assistant across dozens of regulatory frameworks at once: ISO 27001 and 27701, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF and 800-53, PCI DSS, CMMC 2.0, DORA, the EU AI Act, ISO 42001, CCPA, LGPD and many more. Each skill runs a structured gap analysis against the chosen framework, drafts policies and procedures with the required blocks and sections, documents controls in an audit-ready format, builds risk registers and treatment plans, and assembles evidence checklists. Skills load automatically when the conversation touches their topic and cite specific clauses of the standards. They install as .skill files in the Claude apps or as plugins through the marketplace in Claude Code, and are updated regularly.

Who it is for. For information security, privacy and compliance professionals, plus developers and advisors who need verifiable answers about regulatory frameworks.

Good fit when

  • You need a gap analysis against ISO 27001, SOC 2 or another framework
  • You need draft policies, a risk register or an evidence checklist for certification
  • You need an answer on specific framework requirements with clause references

Not a fit when

  • You need formal legal advice or a certified auditor's opinion
  • Your task is unrelated to regulatory compliance and risk management

Example request

Run a gap analysis of our system against ISO 27001 2022 and draft an access control policy

Limitations

The skills give expert orientation and drafts but do not replace a formal audit, legal advice or certification. The material covers international and industry frameworks and does not include Russian requirements. Outputs should be checked against current standard texts, since regulators update their requirements.

How to disable. Disable or remove the unneeded .skill files in the Claude apps, and if installed via the marketplace, remove the plugins with /plugin.

Security check

  • The skills consist of instructions and reference material on regulatory frameworks and run no code of their own

README in short

The README describes a large set of Claude skills for governance, risk and compliance, covering dozens of frameworks from ISO 27001 and SOC 2 to the EU AI Act and various national industry rules. Skills are explained as installable knowledge packages that load automatically and work by progressive disclosure: a main SKILL.md plus references loaded on demand. Installation is by downloading a .skill file and uploading it to a Claude app, or through the marketplace in Claude Code with the grc-skills manifest. The author reports an in-house benchmark over 180 scenarios where the skill-assisted setup scored higher than the baseline model without skills. MIT licensed, updated monthly.

FAQ

Will this replace an auditor or a lawyer?

No. The skills speed up preparation: gap analysis, draft policies, risk registers and evidence checklists. They do not replace a formal audit, certification or legal opinion.

Do I have to install all the skills?

No. You can install only the frameworks you need, for example ISO 27001 and SOC 2, via individual .skill files or the marketplace.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIClaude Skills for GRC

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.