global-grc

Map security controls against mid-2026 regulatory requirements across 14 jurisdictions.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill global-grc
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: global-grc
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/global-grc
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill global-grc

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Most security and compliance tools rely on stale, pre-2020 threat models and framework documentation that fails to address mid-2026 attack patterns like prompt injection, MCP supply chain attacks, and AI-as-C2. Organizations operating across multiple jurisdictions struggle to map their existing controls to global regulatory requirements, leading to critical compliance gaps, unexpected fines, and unaddressed threat coverage.

Core Features & Use Cases

  • Multi-Jurisdiction Framework Mapping: Covers 14 jurisdictions (EU, UK, AU, SG, JP, IN, CA, etc.) and 2 global standards (ISO 27001:2022, CSA CCM v4) with up-to-date mid-2026 regulatory requirements.
  • Universal Control Gap Identification: Surfaces 8+ critical control gaps unaddressed by any national or global framework, including prompt injection as an access control failure, MCP/agent trust boundaries, and AI pipeline integrity requirements.
  • Notification & Compliance Timeline Summaries: Provides side-by-side comparison of incident notification timelines, patch SLAs, and enforcement penalties across all covered jurisdictions.
  • Use Case: A global financial services firm can use this skill to quickly identify that its existing NIST-based compliance program misses NIS2 24-hour early-warning incident notification requirements and EU AI Act Art. 9 risk management obligations for high-risk AI systems.

Quick Start

Use the global-grc skill to map your organization's current security controls against EU NIS2 and DORA requirements to identify all compliance gaps for mid-2026 threat patterns.

Frequently Asked Questions about global-grc

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map existing security controls against global regulatory requirements like EU NIS2 and DORA?▼

To map security controls against global regulatory requirements, align your existing frameworks with mid-2026 threat reality across 14+ jurisdictions. This identifies critical compliance gaps, including missed incident notification timelines and AI risk management obligations for global enterprises.

What compliance frameworks are covered for cross-border regulatory gap analysis?▼

Cross-border regulatory gap analysis covers 14 jurisdictions including EU, UK, AU, SG, JP, IN, and CA, alongside 2 global standards: ISO 27001:2022 and CSA CCM v4. This provides side-by-side comparison of incident notification timelines and enforcement penalties.

How do I identify unaddressed AI threat control gaps like prompt injection in my compliance program?▼

Identify unaddressed AI threat control gaps by surfacing 8+ critical vulnerabilities missing from national or global frameworks. This includes detecting prompt injection access control failures, MCP/agent trust boundary issues, and AI pipeline integrity requirements.

Does this compliance assessment support incident notification timeline comparisons across multiple jurisdictions?▼

Yes, the compliance assessment supports incident notification timeline comparisons. It provides side-by-side summaries of incident notification deadlines, patch SLAs, and enforcement penalties across all 14+ covered global jurisdictions.

Can I use this to check if my NIST-based compliance program misses EU AI Act risk management obligations?▼

Yes, you can use this to check if your NIST-based compliance program misses EU AI Act Article 9 risk management obligations. It maps your current controls against mid-2026 regulatory requirements to quickly identify unaddressed high-risk AI system obligations.

What are the limitations of using pre-2020 threat models for multi-jurisdiction compliance?▼

Pre-2020 threat models fail to address mid-2026 attack patterns like MCP supply chain attacks and AI-as-C2. Relying on stale framework documentation leads to critical compliance gaps and unexpected fines across multi-jurisdiction operations.