Playbooks

Run compliance with AI

Compliance is mostly recurring work: collecting evidence, updating policies, running reviews, chasing tasks. These step-by-step playbooks show how to put that work on AI and automation, and keep humans on the decisions. Each one ships with copy-paste skill files and markdown templates you can use immediately.

7 min · 7 steps · 1 skill file

How to Manage Compliance Controls with AI

A step-by-step playbook for running your controls with AI and automation: map them once, collect evidence automatically, and stay continuously compliant.

7 min · 6 steps · 2 skill files

How to Write and Maintain Compliance Policies with AI

Use AI to draft, tailor, review, and keep your ISO 27001 and PCI DSS policies current, without the blank-page problem or the annual scramble.

8 min · 6 steps · 1 skill file

The Compliance Operating Rhythm (a Calendar You Can Run)

Compliance is a cadence, not a project. Here is the daily-to-annual operating rhythm for ISO 27001 and PCI DSS, and how AI keeps it running.

6 min · 6 steps · 1 skill file

Reminders and Task Management for Compliance with AI

Turn controls into owned, time-bound tasks, and let AI and automation create, assign, chase, and report on them so nothing slips.

7 min · 6 steps · 2 skill files

How to Automate Compliance Evidence Collection with AI

Evidence is the heaviest lift in any audit. A step-by-step playbook for collecting, organising, and sanity-checking evidence with AI and integrations.

7 min · 6 steps · 1 skill file

How to Run an Internal Audit with AI

ISO 27001 requires internal audits and most teams dread them. Here is how AI compresses planning, fieldwork prep, and reporting, with the audit skill included.

7 min · 6 steps · 2 skill files

How to Run a Risk Assessment with AI

The risk assessment drives everything in ISO 27001 and the targeted risk analyses in PCI DSS v4. Here is the AI-assisted way to run one that auditors respect.

6 min · 6 steps · 2 skill files

How to Run Vendor Security Reviews with AI

Third-party risk is a whole ISO control family and PCI requirement 12.8. Here is the AI-assisted vendor review process, with the questionnaire and skill included.

7 min · 6 steps · 2 skill files

How to Use AI in Incident Response (Without Making It Worse)

ISO A.5.24 to A.5.28 and PCI DSS 12.10 both demand a tested incident response capability. Here is where AI genuinely helps during an incident, and where it must not be trusted.

// Signal, not noise

The AI compliance playbook, by email

Practical steps for running ISO 27001 and PCI DSS with AI. No spam.