← Back to library

GRC / Compliance Analyst

Risk registers and control crosswalks, gated.

AvailableFinance, Legal & Compliancev1.0.17

About this persona

Scores risks by likelihood and impact into a register, maps controls across NIST CSF 2.0, ISO 27001, SOC 2, and COSO via verified crosswalks, runs gap analyses, drafts policies and control narratives, and prepares board risk reports. Never renders a compliance determination, those route to counsel, CCO, or DPO.

What it does

  • Likelihood × impact risk registers
  • Control crosswalks: NIST CSF 2.0, ISO 27001, SOC 2, COSO
  • Gap analyses with residual-gap statements
  • Tailored policies and control narratives
  • Board risk reports; publish and filings gated

Commands and examples

Every capability below is a skill in the plugin. Run it directly with its namespaced slash command, or just describe what you want in plain language and the matching skill activates on its own, both work.

Get help and onboarding

Run this any time in Claude Code. It explains the persona and how to run any capability below.

/grc-compliance-analyst:help-grc

Assessing and mapping risk

Scores risks by likelihood and impact into a risk register, maps controls across frameworks like NIST CSF, ISO 27001, and SOC 2 using verified crosswalks, and runs gap analyses.

Run it directly

/grc-compliance-analyst:assessing-and-mapping-risk

Or just describe what you want

Score these risks by likelihood and impact and build a risk register: [paste risk list].

Drafting policies and controls

Writes policies and procedures mapped to control requirements with RACI ownership, authors control narratives tied to evidence, and publishes policies behind a confirmation gate.

Run it directly

/grc-compliance-analyst:drafting-policies-and-controls

Or just describe what you want

Draft an access control policy mapped to our SOC 2 requirements, with RACI ownership: [describe environment].

Reporting and escalating

Drafts executive and board risk reports as assessments, flags legal and regulatory determinations for counsel, and submits attestations or filings behind a confirmation gate.

Run it directly

/grc-compliance-analyst:reporting-and-escalating

Or just describe what you want

Draft a board risk report covering our top risks and gaps from this risk register: [paste risk register].

Install in Claude Code

/plugin marketplace add roleplugin/personas-marketplace
/plugin install grc-compliance-analyst@personas-marketplace

Requires an active subscription. Prefer not to use GitHub? Download the zip from your library instead.

How to use it

Install the persona, then either ask Claude for the kind of work it covers in plain language, or run a capability directly as its namespaced slash command, /grc-compliance-analyst:<skill-name>. Every RolePlugin persona also ships a built-in help guide, /grc-compliance-analyst:help-grc, so you can run it any time to see what the persona can do and how to work with it.