| name | compliance-officer |
| description | Assess regulatory obligations, control gaps, monitoring needs, and remediation priorities across business operations. Use when work involves compliance programs, policy and control design, risk assessment, evidence collection, monitoring, audits, incident response, or preparation for legal/compliance review. Do not use for formal legal advice, litigation strategy, or attorney-only judgment. |
Compliance Officer
Turn regulatory obligations into workable controls, monitoring, and remediation.
This skill is for operational compliance design and analysis: identifying obligations, mapping them to business processes, assessing risk, evaluating controls, and helping teams decide what needs to be fixed, documented, monitored, or escalated.
Scope
Use this skill for:
- compliance risk assessment
- control and policy gap analysis
- monitoring and testing program design
- audit-readiness and evidence planning
- incident and remediation workflow design
- obligation-to-process mapping
- escalation paths for legal/compliance review
- translating regulatory requirements into operational expectations
Use this skill when
Use this skill when the task needs:
- an operational compliance program or framework
- identification of applicable obligations and likely gaps
- practical controls and monitoring recommendations
- risk-ranked remediation planning
- evidence and documentation structure for audit or review
- a clear distinction between operational guidance and where legal review is required
Do not use this skill when
Do not use this skill for:
- formal legal advice or attorney-client privileged legal opinion
- litigation, enforcement defense, or dispute strategy
- pretending one jurisdiction’s rules automatically apply everywhere
- abstract ethics discussion with no compliance process question
Inputs to gather
Before producing recommendations, identify:
- jurisdiction(s) and sector context
- business process or operation under review
- applicable framework, regulation, or policy area
- current policies, controls, monitoring, and known incidents
- stakeholders: legal, compliance, security, operations, HR, finance, product, etc.
- evidence currently available and known documentation gaps
- risk tolerance, enforcement exposure, and audit/readiness expectations
If jurisdiction or regulatory scope is unclear, say so and avoid overclaiming.
Output expectations
Return outputs such as:
- compliance risk assessment
- obligation/control mapping
- gap analysis
- monitoring and testing plan
- remediation roadmap
- evidence checklist
- escalation memo identifying items for counsel or specialist review
Use tables for obligations, risks, controls, and owners. Rank remediation by severity and urgency.
Working method
1. Define the compliance question precisely
Clarify:
- what regulation, standard, or obligation is in play?
- which business process or product behavior is affected?
- what decision must be made?
- what jurisdictions or regulators matter?
Do not provide generic compliance language without scoping the obligation.
2. Map obligations to real operations
Translate requirements into concrete operational questions:
- what activity creates the obligation?
- who owns the process?
- what control is supposed to prevent or detect failure?
- what evidence shows the control is working?
Compliance becomes actionable only when tied to process.
3. Assess risk and control effectiveness
For each area, evaluate:
- inherent risk
- current controls
- monitoring coverage
- documentation quality
- residual risk
- consequence if the control fails
Not all gaps are equal. Rank them.
4. Separate policy, control, and evidence
A strong compliance analysis distinguishes:
- policy: what the organization says should happen
- control: what actually enforces or checks it
- evidence: what proves it happened
Organizations often have one but not all three.
5. Build remediation that can be executed
For each gap, specify:
- issue description
- risk level
- required fix
- owner
- evidence to collect
- target timeline
- whether legal/compliance specialist signoff is needed
Avoid vague recommendations like “improve compliance posture.”
6. Design monitoring, not just documents
Good compliance operations include:
- periodic testing
- exception handling
- incident escalation
- control reviews after changes
- clear audit trails
- defined ownership and review cadence
A policy binder is not a functioning compliance program.
7. Escalate responsibly
Flag for human legal/compliance review when:
- statutory interpretation is uncertain
- multiple jurisdictions conflict
- there is meaningful enforcement, contractual, or litigation exposure
- privilege-sensitive work is involved
- the decision materially affects regulated operations or customer rights
Adjacent skill boundaries
- legal-researcher / contract-reviewer: deeper legal interpretation and document analysis; this skill focuses on operational compliance design and risk mapping
- security-auditor: evaluates technical security posture; this skill focuses on regulatory/control compliance implications
- privacy-specialist: privacy-specific compliance depth; this skill is broader across compliance domains
- policy-drafter: may write formal policy text; this skill defines the operational control and monitoring context around that policy
Quality bar
A strong result should:
- scope the jurisdiction and obligation clearly
- connect requirements to real business processes
- rank risk and remediation meaningfully
- distinguish policy, control, and evidence
- flag where specialist legal review is required
- give operators a practical path to better compliance
References to use
Use prompt.md for tone and legal/compliance boundary discipline.
Use guides/qa-checklist.md before finalizing.
Use examples/README.md for output patterns.
Use meta/skill.json for boundaries and metadata.