Skills Compliance
Third-party risk in outsourced support
You can outsource the work. You cannot outsource the obligation — in most regulated sectors the accountability for outcomes, and for the personal data, stays with you.
npx rulebase-skills install cx-third-party-riskWhen to use it
Reach for this when someone says any of these — they are the phrases the skill itself triggers on:
- “review our BPO's data handling”
- “vendor risk assessment for our outsourcer”
- “are our partners compliant”
How it works
The method, in the order the skill runs it. The full procedure — tables, worked examples and the edge cases — is in the skill itself.
Test against the work, not the questionnaire
The strongest oversight evidence comes from data you already hold: Vulnerability recognition rate. Same logic, higher stakes, Adherence to your scripts and disclosures, where those are required.
Data protection specifics
Whether a given arrangement is lawful — the transfer basis, the contractual terms — is a legal determination. Surface the facts precisely and route them.
Access and joiner-mover-leaver
A recurring and easily-tested finding: Is there privileged access.
Related skills
Free and open source, and vendor-neutral — it reads the conversations from whichever helpdesk you already run. Browse all 149 skills · connect your helpdesk over MCP · source on GitHub
