uae-grc
FeaturedUnited Arab Emirates Governance, Risk & Compliance advisor — a jurisdiction-first compliance router. In the UAE, WHERE an organization sits determines its law: mainland (Federal PDPL, Decree-Law 45/2021 — executive regulations still pending), DIFC (DP Law No. 5 of 2020 as amended 2025, with a private right of action), ADGM (DP Regulations 2021), CBUAE-licensed financial institutions (consumer-data residency, outsourcing approvals), healthcare (ICT Health Law data localization), and government/CNI (UAE IA Regulation, Cyber Security Council; Dubai ISR, ADHICS). Use for any UAE / Dubai / Abu Dhabi / Emirates compliance question: UAE data protection, DIFC or ADGM privacy, free-zone vs mainland obligations, health-data residency, CBUAE cyber and outsourcing rules, market entry ("expanding to the UAE"), breach notification, gap assessments, and mapping UAE requirements to ISO 27001 / NIST CSF / SOC 2. Trigger for any UAE privacy, cybersecurity, or regulatory question even if no framework is named.
Install
Quality Score: 93/100
Skill Content
Details
- Author
- Sushegaad
- Repository
- Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
- Created
- 5 months ago
- Last Updated
- 5 days ago
- Language
- HTML
- License
- MIT
Similar Skills
Semantically similar based on skill content — not just same category
saudi-arabia-grc
Saudi Arabia Governance, Risk & Compliance advisor — a compliance router that first determines WHICH Saudi regulations apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud Cybersecurity Controls, SAMA Cyber Security Framework, CST cloud framework, DCC/OTCC/TCC), then guides framework-specific compliance. Use for any Saudi Arabia / KSA compliance question: NCA Essential Cybersecurity Controls, SDAIA and the Personal Data Protection Law (نظام حماية البيانات الشخصية), PDPL breach notification and data transfers, SAMA compliance for banks/insurers/fintechs, cloud data residency in the Kingdom, CST CSP registration, government/CNI cybersecurity obligations, market-entry compliance ("expanding to Saudi Arabia"), gap assessments, and mapping Saudi requirements to ISO 27001 / NIST CSF / SOC 2. Trigger for any KSA, Riyadh, Vision 2030 compliance, NCA, SDAIA, SAMA, or Saudi data protection question even if no framework is named.
gcc-market-intelligence
GCC (Saudi Arabia, UAE, Qatar, Bahrain, Kuwait, Oman) market entry intelligence for non-GCC founders of operating or scaling B2B / B2G startups. Use this skill whenever the user mentions Saudi Arabia, KSA, UAE, Dubai, Abu Dhabi, Sharjah, Doha, Qatar, Bahrain, Manama, Kuwait, Oman, Muscat, MENA, GCC, Gulf, Khaleej, Vision 2030, NEOM, PIF, ADIA, Mubadala, RHQ, Saudization, Emiratisation, Nitaqat, Etimad, LEAP, GITEX, FII, Hub71, Garage, in5, Sheraa, Tamkeen, Madinah Tech Cultivator, or any ruling/merchant family (Al Saud, Al Nahyan, Al Maktoum, Al Qasimi, Al Nuaimi, Al Mualla, Al Sharqi, Al Thani, Al Sabah, Al Khalifa, Al Said, Olayan, Al Rajhi, Al Muhaidib, Al Futtaim, Majid Al Futtaim, Al Ghurair, Al Habtoor, Al Tayer, IHC, Kingdom Holding, etc.). Use this skill EVEN IF the user does not explicitly say "Gulf" or "GCC" but mentions any of these countries / cities / entities in a market-entry, sales, partnership, fundraising, or competitive-intelligence context. Also use when the user asks about market sizing,
eu-ai-act
EU AI Act (Regulation (EU) 2024/1689) compliance advisor — risk classification across all four tiers, all 9 prohibited practices (Art. 5, including the nudification/CSAM prohibition from Dec 2, 2026), all 8 Annex III high-risk use case areas, provider and deployer obligations (Arts. 9–17, 26), GPAI model obligations including the July 2025 Code of Practice (Arts. 51–55), conformity assessment and CE marking (Arts. 43–48), EU AI database registration, Art. 50 transparency (chatbots, synthetic media, AI-generated content), governance (AI Office, AI Board), penalties (Art. 99), confirmed phase-in timeline (Digital Omnibus, Reg. (EU) 2026/1744, in force July 27, 2026: Annex III deferred to Dec 2, 2027; Annex I to Aug 2, 2028), and cross-framework mapping to ISO 42001, NIST AI RMF, and GDPR. Use for any EU AI regulation, AI system classification, or AI compliance question. Current as of August 2026. GPAI enforcement powers active since August 2, 2026.