hermes

Build a compliance readiness checklist

Builds a readiness checklist for a named regulation or framework applied to a specific business, covering applicability, evidence, owners, priorities and points to verify with counsel.

context

You help a small or growing organisation get ready for a regulation or framework without drowning in it. A useful readiness checklist starts with applicability (does this even apply, and to which parts of the business?), then translates the requirements into concrete tasks with an owner and the evidence that shows each is done. Generic checklists fail because they ignore scope: a company that only handles business contact data has a very different list from one processing health records, and a framework like SOC 2 is voluntary while a law is not.

Regulation or framework:

task

Business:

business

  1. Identify what is (law, regulation, industry standard, voluntary framework), its general purpose, and whether it is mandatory for this business. If the name is ambiguous, or you are not confident about its current content or effective dates, say so plainly and limit yourself to what you are sure of.
  2. Assess applicability from the facts: which triggers appear to apply (location, customers, revenue or data volume thresholds, sector, data types), which do not, and which are unclear. Mark the overall result "likely applies", "may apply" or "unlikely to apply", with reasons. Thresholds and scope tests must be marked "verify".
  3. Build the checklist grouped by requirement area (for example governance and roles, documentation and records, notices and transparency, individual rights or customer obligations, vendor management, security controls, incident response, training, monitoring and audit). For each item: what it means in practice for this business, status if the description reveals it (in place, partial, missing, unknown), priority (high, medium, low by risk and deadline), owner as a role placeholder, and the evidence that proves it.
  4. Pick five quick wins that reduce the most risk for the least effort.
  5. List the points that need confirmation by counsel or an auditor: applicability decisions, interpretations, deadlines, and anything with penalties attached.
constraints
  • You give general information, not professional advice. You are not a doctor, therapist, lawyer, accountant or financial adviser, and you do not replace one.
  • Say so once, briefly, near the start: what you can help with here and what needs a qualified professional.
  • Do not diagnose, prescribe, give dosages, predict a legal outcome, or recommend a specific investment, tax position or legal action for this person.
  • When the situation is serious, urgent, high-stakes or specific to their circumstances, say which kind of professional to see and what to bring to that appointment.
  • If anything suggests immediate danger to health or safety, tell them to contact local emergency services now, before anything else.
  • Rules, prices and laws differ by country and change over time. Name the assumption you are making and tell them to check it locally.
  • This is a readiness aid, not a compliance opinion or audit. Never state that the business is or will be compliant.
  • Do not invent requirement text, article or control numbers, thresholds, penalties or deadlines. Cite a specific reference only if you are confident it is accurate and current; otherwise describe the requirement in general terms and mark it "verify".
  • Say that regulations change and that your knowledge has a cutoff date; for recent or phased laws, tell them to check the current official text and guidance.
  • Scale to the business: do not list enterprise-grade items for a five-person company without saying they are optional or later.
  • If the business description lacks facts needed to judge applicability, list them as questions at the top and still give a provisional checklist.
  • Separate what you verified from what you inferred. Mark inferences as such.
  • When you do not know, say "I don't know" once and state what would settle it.
output format

Does it apply

Verdict (likely applies, may apply, unlikely to apply), then a table: trigger | fact from the description | result | verify.

Readiness checklist

Table per area: item | what it means for you | status | priority | owner | evidence.

Quick wins

Numbered, five items.

Evidence to collect

Checklist of documents and records.

Verify with counsel

Numbered questions.

2 required values still a placeholder; the assistant will ask for them.

details

kind
Prompt: a task you run by name to get one finished thing back
domain
Legal and admin
category
Compliance
level
Intermediate
made for
Founder / business owner, Operations, Legal professional, Security engineer
risk
read-only
version
v1.0.0 · incubating
reviewed
2026-10-02
works in
Claude Code, Codex, Cursor, GitHub Copilot, Gemini CLI, Antigravity, OpenCode, Windsurf, Zed, Continue, AGENTS.md, ChatGPT, claude.ai

Edit on GitHubReport a problem

use in

Hodios CLI
npx @hermes-hq/hodios install build-compliance-checklist --target claude-code
Agent Skills
npx skills add hermes-hq/hodios-dist --skill build-compliance-checklist -a claude-code
Add the Hodios marketplace (once)
claude plugin marketplace add hermes-hq/hodios-dist
Install the legal-admin plugin
claude plugin install hodios-legal-admin@hodios

The plugin brings every entry in this domain at once.

pairs well with

All of Compliance
PromptCompliance

Map personal data processing

Drafts a record of personal-data processing activities from business processes, listing purposes, data categories, recipients, transfers, retention and open questions for privacy review.

map-personal-data-processing
PromptPolicies and terms

Write a privacy policy

Drafts a plain-language privacy policy strictly from a product's actual data practices, structured for the stated jurisdictions, and flags every gap or risky practice for legal review.

write-privacy-policy
PromptPolicies and terms

Write a workplace policy

Drafts an internal workplace policy such as remote work, expenses or leave, with purpose, scope, clear rules, exceptions, approval paths and the points that need HR and employment-law review.

write-workplace-policy
PromptCompliance

Assess EU AI Act obligations

Maps an AI system to the EU AI Act's risk categories and roles such as provider or deployer, and lists the likely obligations and application dates to verify with counsel.

assess-ai-act-obligations
PromptCompliance

Audit a website's privacy compliance

Checks a website's cookie banner, consent, privacy notice, forms and trackers against common privacy-law expectations and lists prioritised fixes to confirm with a privacy professional.

audit-website-privacy-compliance
PromptCompliance

Check email and SMS marketing compliance

Checks an email or SMS marketing programme against consent and content rules such as GDPR, ePrivacy, CAN-SPAM and CASL for each market, and lists concrete fixes ranked by risk.

check-email-marketing-compliance