claude-skills/compliance-os
Claude 0f88555485
chore(versioning,docs): normalize stale versions to 2.9.0 + refresh counts
Version normalization (scope: only plugins/skills older than 2.7.0):
- Bumped 52 plugin.json + 21 SKILL.md `version` fields from pre-2.7.0
  values (1.0.0 / 2.0.x / 2.2.x / 2.3.x / 2.4.x / 2.5.x) to 2.9.0.
  Left 2.7.0+ packages untouched. Tool mirrors (.codex/.gemini/.vibe/
  .hermes) excluded. All manifests still pass check_plugin_json --all.

Doc count refresh (recomputed raw figures: 338 skills, 16 domains,
62 plugins, 533 Python tools, 676 references):
- marketplace.json: both descriptions + metadata.version -> 2.9.0.
- Root README: headline, badges (Skills 338, Agents 51+, Commands 87+),
  intro counts, convert section (338 skills / 9 tools), and the full
  domain table rebuilt to 16 domains summing to 338 (adds research-ops,
  business-operations, commercial, compliance-os; corrects product 17,
  marketing 46, c-level 66, ra-qm 18, finance 4, engineering 51/78).
- Fixed stale per-skill README `Version:` lines left inconsistent by the
  bump (andreessen, c-level-agents, product-team, senior-qa).
- Fixed stale domain README footers (product-team 17/17, c-level 66/66,
  project-management 9/9).
- CLAUDE.md scope line, structure tree, highlight, and footer synced to
  the raw figures.

https://claude.ai/code/session_01PUNmQVE4WYvcrzpq2anC3D
2026-05-27 05:22:59 +00:00
..
.claude-plugin chore(versioning,docs): normalize stale versions to 2.9.0 + refresh counts 2026-05-27 05:22:59 +00:00
agents feat(compliance-os): Phase 2 — per-framework audit playbooks + personas + commands 2026-05-13 19:09:19 +00:00
skills feat(compliance-os): Phase 3 — 12 frameworks + 205 mock audit scenarios + reuse index 2026-05-13 20:47:06 +00:00
README.md feat(compliance-os): multi-framework meta-orchestrator for compliance teams 2026-05-13 17:48:33 +00:00

compliance-os

Compliance OS — a meta-orchestrator for multi-framework compliance programs. Configure which frameworks apply; compute overlap; simulate audits; consolidate evidence across frameworks.

What this is

Most compliance teams run multiple frameworks in parallel: ISO 27001 + SOC 2 for security, ISO 13485 + FDA QSR for medical devices, ISO 42001 + EU AI Act for AI, GDPR + sector privacy law for personal data. Each framework lives in its own skill (we have 14 existing ra-qm-team skills + 2 new compliance-team-* plugins for ISO 42001 and EU AI Act).

But teams need:

  1. A way to configure which of the 9 frameworks apply per company profile
  2. Cross-framework overlap — many controls are the same across frameworks; one piece of evidence often satisfies multiple
  3. Audit simulation — practice internal audits before the real ones
  4. Unified evidence pool — collect evidence once, satisfy multiple frameworks

Compliance OS provides exactly that. Four stdlib Python tools + 4 in-depth references + 3 cs-* personas + 3 /cs:* commands.

Supported frameworks (9)

ID Framework Companion skill
ISO 27001 Info security ISMS ra-qm-team/skills/information-security-manager-iso27001/ + isms-audit-expert/
ISO 13485 Medical device QMS ra-qm-team/skills/quality-manager-qms-iso13485/ + qms-audit-expert/
ISO 42001 AI Management System ra-qm-team/skills/iso42001-specialist/ (new)
ISO 14971 Medical device risk mgmt ra-qm-team/skills/risk-management-specialist/
EU AI Act Regulation (EU) 2024/1689 ra-qm-team/skills/eu-ai-act-specialist/ (new)
EU MDR 745 Medical device regulation ra-qm-team/skills/mdr-745-specialist/
GDPR Data protection ra-qm-team/skills/gdpr-dsgvo-expert/
SOC 2 Trust services criteria ra-qm-team/skills/soc2-compliance/
FDA QSR 21 CFR 820 ra-qm-team/skills/fda-consultant-specialist/

Quick start

# Configure which frameworks apply for your company
python skills/compliance-os/scripts/framework_selector.py

# Compute overlap between selected frameworks
python skills/compliance-os/scripts/cross_framework_mapper.py

# Simulate an internal audit
python skills/compliance-os/scripts/audit_simulator.py

# Generate unified evidence checklist
python skills/compliance-os/scripts/evidence_pool_generator.py

All four tools run with embedded samples if no JSON is provided. All use stdlib only.

Slash commands

Command Purpose
/cs:compliance-readiness 6-question forcing interrogation for compliance program readiness
/cs:aims-audit 6-question forcing interrogation specific to ISO 42001 internal audit
/cs:ai-act-readiness 6-question forcing interrogation specific to EU AI Act compliance

cs-* persona agents

Agent Voice
cs-compliance-officer Multi-framework orchestrator. "Which frameworks apply, and where do they overlap?"
cs-aims-iso42001 AIMS implementation operator. "What's the gap against Clauses 4-10?"
cs-ai-act-compliance EU AI Act Article-cited operator. "What's the risk tier per Article 6?"

What this is NOT

  • NOT executive AI/risk strategy. For board-level AI / data / risk decisions, see c-level-advisor/.
  • NOT a replacement for the per-framework skills. This orchestrates them. The per-framework skills do the deep work.
  • NOT a binding legal opinion. Cross-framework mappings reflect published guidance; novel cases need outside counsel.

License

MIT.