本文へ移動
cccskills
無料GitHub で公開

codexkit-compliance-gap-review

Compare policies, procedures, onboarding files, or operating evidence against a named compliance framework such as AML/KYC, privacy, internal controls, or audit readiness. Use when a team needs a gap matrix, control checklist, remediation priorities, or evidence request list. Do not use when no target framework is specified or when formal legal or regulatory sign-off is required.

インストール方法を見る

含まれるファイル(2)

  • SKILL.md3.4 KB
  • agents/openai.yaml250 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Compliance Gap Review

Purpose

Transform a vague compliance concern into a concrete gap assessment and remediation view.

When to use

  • A team needs to assess readiness against AML, KYC, privacy, audit, or control expectations.
  • Policies and evidence exist but no one has mapped gaps clearly.
  • Leadership needs remediation priorities, not just a checklist dump.

When not to use

  • No target framework, policy baseline, or standard is named.
  • The request requires a formal legal opinion or regulator submission.

Inputs

  • named framework, regulation, or internal control standard
  • current policies, procedures, forms, or evidence
  • scope: business unit, process, customer segment, or geography
  • known incidents, findings, or deadlines

Procedure

  1. Define the exact framework and scope before evaluating anything.
  2. Break the framework into control requirements or evidence expectations.
  3. Compare current evidence against each requirement.
  4. Rate each gap by severity, exposure, and remediation effort.
  5. Separate high-risk gaps from documentation-only gaps.
  6. Build a practical 30/60/90-day remediation sequence and evidence request list.
  7. Escalate areas that need specialist legal or regulatory review.

Output

  • control or requirement matrix
  • current-state evidence summary
  • gap list with severity and rationale
  • remediation plan with owners and priorities
  • evidence request list for unresolved areas

Definition of done

  • The target framework is explicit.
  • Gaps are mapped to concrete requirements, not vague opinions.
  • The output shows what to fix first and what evidence is still missing.

Examples

  • "Compare our onboarding process to AML and KYC expectations and tell me the top gaps."
  • "Assess our privacy operating procedures against our internal control checklist."

Quality Criteria

  • Every finding is tied to a specific evidence source (log, test, metric)
  • Pass/fail criteria are binary and measurable — no subjective judgments
  • Severity levels are assigned with clear thresholds
  • Remediation steps are provided for all critical and high findings

Verification (4C)

CheckQuestion
CorrectnessAre all pass/fail criteria applied against the correct standard or rule?
CompletenessWere all required dimensions or checklist items evaluated?
Context-fitDoes the verification scope match the actual risk level of the deliverable?
ConsequenceIf this passed verification but had a hidden flaw, what is the worst-case impact?

Edge Cases

  • Incomplete data for full assessment — Document which checks were limited and flag for re-verification when data becomes available.
  • Ambiguous pass/fail criteria — Request clarification from the standard owner before scoring. Mark as 'Needs Review'.
  • Multiple overlapping standards — Identify the governing standard and note where others diverge.

Changelog

  • v1.0.0 — Initial release

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Design rigorous A/B test plans with hypothesis, sample size calculation, Minimum Detectable Effect (MDE), randomization strategy, and decision rules. Includes guardrail metrics and rollout playbook. Use when planning product experiments, conversion optimization, or data-driven feature decisions.

日本語の概要は準備中です。原文の説明を表示しています。

hoavdc/CodexKit252026年10月11日 更新

Review REST and GraphQL API designs for consistency, usability, and best practices. Covers naming conventions, versioning strategy, error format, pagination, authentication patterns, and breaking change detection. Use when reviewing API specs, designing new APIs, or auditing existing endpoints.

日本語の概要は準備中です。原文の説明を表示しています。

hoavdc/CodexKit252026年10月11日 更新

Write Architecture Decision Records (ADRs) following the Michael Nygard format. Captures context, options considered, decision rationale, and consequences. Use when making technology choices, framework selections, or any architectural decision that future developers need to understand.

日本語の概要は準備中です。原文の説明を表示しています。

hoavdc/CodexKit252026年10月11日 更新

Assess organizational readiness for financial audits (internal or external). Map assertions to account balances, check evidence completeness, score readiness using a Red/Amber/Green framework, and generate a remediation timeline. Aligned with SOX, IFRS, and GAAP audit standards. Use before scheduled audits or when preparing for first-time compliance.

日本語の概要は準備中です。原文の説明を表示しています。

hoavdc/CodexKit252026年10月11日 更新

Design safe recurring Codex automations with clear prompts, outputs, schedules, and gating rules.

日本語の概要は準備中です。原文の説明を表示しています。

hoavdc/CodexKit252026年10月11日 更新

Refine Product Backlog Items to meet INVEST criteria. Write User Stories with Acceptance Criteria in Given/When/Then format, estimate with Story Points, and flag dependencies. Use before sprint planning when backlog items need grooming. Do not use to prioritize the backlog — that is the Product Owner's decision.

日本語の概要は準備中です。原文の説明を表示しています。

hoavdc/CodexKit252026年10月11日 更新

hoavdc のスキルをすべて見る

このスキルの問題を報告する