compliance-tracking
anthropics/knowledge-work-plugins
Track compliance requirements, controls, and audit readiness across SOC 2, ISO 27001, GDPR, and other frameworks.
What is compliance-tracking?
Helps organizations map compliance controls to regulatory frameworks, prepare for audits, and maintain evidence of compliance. Use this when you need to track compliance status, prepare for audits, document controls, or analyze gaps against standards like SOC 2, ISO 27001, GDPR, HIPAA, or PCI DSS.
- Map controls to framework requirements and document control owners
- Maintain audit calendars with deadlines and evidence collection timelines
- Track evidence location and collection status for each control
- Perform gap analysis comparing requirements to current state
- Generate compliance status dashboards and audit prep checklists
- Create prioritized remediation plans with compliance timelines
How to install compliance-tracking
npx skills add https://github.com/anthropics/knowledge-work-plugins --skill compliance-trackingHow to use compliance-tracking
- 1.Identify the compliance framework(s) relevant to your organization (SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, etc.)
- 2.List all controls or requirements you need to track
- 3.Document control owners, current status, and evidence locations
- 4.Use the skill to generate a control inventory mapping requirements to controls
- 5.Create an audit calendar with key dates and evidence collection deadlines
- 6.Run a gap analysis to identify missing controls or evidence
- 7.Generate compliance dashboards and remediation plans
Use cases
- Preparing for a SOC 2 Type II audit by organizing controls and gathering evidence
- Mapping GDPR requirements to internal processes and identifying data handling gaps
- Creating an ISO 27001 control inventory with ownership and effectiveness tracking
- Building an audit calendar with evidence collection deadlines for multiple frameworks
- Conducting a compliance gap analysis to prioritize remediation efforts
- Compliance officers and managers
- Security and risk teams
- Internal audit functions
- Organizations preparing for external audits
- Companies managing multi-framework compliance (SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS)
compliance-tracking FAQ
The skill covers SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS, with extensibility for other frameworks. It helps map controls to any regulatory requirement.
Yes. The skill is designed to help organizations managing compliance across multiple frameworks simultaneously by organizing controls and evidence centrally.
It generates compliance status dashboards, gap analyses, audit prep checklists, evidence collection plans, and prioritized remediation roadmaps.
It organizes controls, tracks evidence readiness, maintains audit calendars with deadlines, and identifies gaps so you can prepare systematically before audits.
No. The skill helps you document where evidence is stored and when it was collected, but it doesn't require pre-configured storage systems.
Full instructions (SKILL.md)
Source of truth, from anthropics/knowledge-work-plugins.
name: compliance-tracking description: Track compliance requirements and audit readiness. Trigger with "compliance", "audit prep", "SOC 2", "ISO 27001", "GDPR", "regulatory requirement", or when the user needs help tracking, preparing for, or documenting compliance activities.
Compliance Tracking
Help track compliance requirements, prepare for audits, and maintain regulatory readiness.
Common Frameworks
| Framework | Focus | Key Requirements |
|---|---|---|
| SOC 2 | Service organizations | Security, availability, processing integrity, confidentiality, privacy |
| ISO 27001 | Information security | Risk assessment, security controls, continuous improvement |
| GDPR | Data privacy (EU) | Consent, data rights, breach notification, DPO |
| HIPAA | Healthcare data (US) | PHI protection, access controls, audit trails |
| PCI DSS | Payment card data | Encryption, access control, vulnerability management |
Compliance Tracking Components
Control Inventory
- Map controls to framework requirements
- Document control owners and evidence
- Track control effectiveness
Audit Calendar
- Upcoming audit dates and deadlines
- Evidence collection timelines
- Remediation deadlines
Evidence Management
- What evidence is needed for each control
- Where evidence is stored
- When evidence was last collected
Gap Analysis
- Requirements vs. current state
- Prioritized remediation plan
- Timeline to compliance
Output
Produce compliance status dashboards, gap analyses, audit prep checklists, and evidence collection plans.
Related skills
More from anthropics/knowledge-work-plugins and the wider catalog.

compose-outreach
Generate personalized outreach messages using Common Room signals and web research.

contact-research
Research any contact using Common Room data—email, social handle, or name lookup with enriched profiles and engagement signals.

content-creation
Draft marketing content across channels with templates, SEO guidance, and proven formulas.

content-strategy
>

contract-review
>

cowork-plugin-customizer
Customize Claude Code plugins for your organization's specific tools and workflows.