PluginBench
Skill
Official
Review
Audit score 70

compliance-tracking

anthropics/knowledge-work-plugins

Track compliance requirements, controls, and audit readiness across SOC 2, ISO 27001, GDPR, and other frameworks.

What is compliance-tracking?

Helps organizations map compliance controls to regulatory frameworks, prepare for audits, and maintain evidence of compliance. Use this when you need to track compliance status, prepare for audits, document controls, or analyze gaps against standards like SOC 2, ISO 27001, GDPR, HIPAA, or PCI DSS.

  • Map controls to framework requirements and document control owners
  • Maintain audit calendars with deadlines and evidence collection timelines
  • Track evidence location and collection status for each control
  • Perform gap analysis comparing requirements to current state
  • Generate compliance status dashboards and audit prep checklists
  • Create prioritized remediation plans with compliance timelines

How to install compliance-tracking

npx skills add https://github.com/anthropics/knowledge-work-plugins --skill compliance-tracking
Claude Code
Cursor
Windsurf
Cline

How to use compliance-tracking

  1. 1.Identify the compliance framework(s) relevant to your organization (SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, etc.)
  2. 2.List all controls or requirements you need to track
  3. 3.Document control owners, current status, and evidence locations
  4. 4.Use the skill to generate a control inventory mapping requirements to controls
  5. 5.Create an audit calendar with key dates and evidence collection deadlines
  6. 6.Run a gap analysis to identify missing controls or evidence
  7. 7.Generate compliance dashboards and remediation plans

Use cases

Good for
  • Preparing for a SOC 2 Type II audit by organizing controls and gathering evidence
  • Mapping GDPR requirements to internal processes and identifying data handling gaps
  • Creating an ISO 27001 control inventory with ownership and effectiveness tracking
  • Building an audit calendar with evidence collection deadlines for multiple frameworks
  • Conducting a compliance gap analysis to prioritize remediation efforts
Who it's for
  • Compliance officers and managers
  • Security and risk teams
  • Internal audit functions
  • Organizations preparing for external audits
  • Companies managing multi-framework compliance (SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS)

compliance-tracking FAQ

What compliance frameworks does this skill support?

The skill covers SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS, with extensibility for other frameworks. It helps map controls to any regulatory requirement.

Can I track multiple compliance frameworks at once?

Yes. The skill is designed to help organizations managing compliance across multiple frameworks simultaneously by organizing controls and evidence centrally.

What kind of output does this skill produce?

It generates compliance status dashboards, gap analyses, audit prep checklists, evidence collection plans, and prioritized remediation roadmaps.

How does this help with audit preparation?

It organizes controls, tracks evidence readiness, maintains audit calendars with deadlines, and identifies gaps so you can prepare systematically before audits.

Do I need to set up evidence storage before using this skill?

No. The skill helps you document where evidence is stored and when it was collected, but it doesn't require pre-configured storage systems.

Full instructions (SKILL.md)

Source of truth, from anthropics/knowledge-work-plugins.


name: compliance-tracking description: Track compliance requirements and audit readiness. Trigger with "compliance", "audit prep", "SOC 2", "ISO 27001", "GDPR", "regulatory requirement", or when the user needs help tracking, preparing for, or documenting compliance activities.

Compliance Tracking

Help track compliance requirements, prepare for audits, and maintain regulatory readiness.

Common Frameworks

FrameworkFocusKey Requirements
SOC 2Service organizationsSecurity, availability, processing integrity, confidentiality, privacy
ISO 27001Information securityRisk assessment, security controls, continuous improvement
GDPRData privacy (EU)Consent, data rights, breach notification, DPO
HIPAAHealthcare data (US)PHI protection, access controls, audit trails
PCI DSSPayment card dataEncryption, access control, vulnerability management

Compliance Tracking Components

Control Inventory

  • Map controls to framework requirements
  • Document control owners and evidence
  • Track control effectiveness

Audit Calendar

  • Upcoming audit dates and deadlines
  • Evidence collection timelines
  • Remediation deadlines

Evidence Management

  • What evidence is needed for each control
  • Where evidence is stored
  • When evidence was last collected

Gap Analysis

  • Requirements vs. current state
  • Prioritized remediation plan
  • Timeline to compliance

Output

Produce compliance status dashboards, gap analyses, audit prep checklists, and evidence collection plans.