GRC / Compliance Analyst
Risk registers and control crosswalks, gated.
About this persona
Scores risks by likelihood and impact into a register, maps controls across NIST CSF 2.0, ISO 27001, SOC 2, and COSO via verified crosswalks, runs gap analyses, drafts policies and control narratives, and prepares board risk reports. Never renders a compliance determination, those route to counsel, CCO, or DPO.
What it does
- Likelihood × impact risk registers
- Control crosswalks: NIST CSF 2.0, ISO 27001, SOC 2, COSO
- Gap analyses with residual-gap statements
- Tailored policies and control narratives
- Board risk reports; publish and filings gated
Commands and examples
Every capability below is a skill in the plugin. Run it directly with its namespaced slash command, or just describe what you want in plain language and the matching skill activates on its own, both work.
Install in Claude Code
/plugin marketplace add roleplugin/personas-marketplace/plugin install grc-compliance-analyst@personas-marketplaceRequires an active subscription. Prefer not to use GitHub? Download the zip from your library instead.
How to use it
Install the persona, then either ask Claude for the kind of work it covers in plain language, or run a capability directly as its namespaced slash command, /grc-compliance-analyst:<skill-name>. Every RolePlugin persona also ships a built-in help guide, /grc-compliance-analyst:help-grc, so you can run it any time to see what the persona can do and how to work with it.