Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,9 @@ This list is intended for **compliance officers**, **risk managers**, **auditors
- [ISO 27017](https://www.iso.org/standard/43757.html) - Cloud-specific security practices (self-declarative).
- [ISO 27018](https://www.iso.org/standard/76559.html) - Cloud privacy controls for protecting PII (self-declarative).
- [ISO 27701](https://www.iso.org/standard/71670.html) - Privacy Information Management System standard (Annual audit).
- [Microsoft SSPA](https://www.microsoft.com/en-us/trust-center/privacy/data-protection-requirements) - Microsoft's Supplier Security & Privacy Assurance (Annual audit).
- [Microsoft SSPA](https://www.microsoft.com/en-us/trust-center/privacy/data-protection-requirements) -
-
- [KYC Analyst](https://github.com/vyayasan/kyc-analyst) - Open-source KYC/AML compliance automation plugin for Claude Cowork, Claude Code, or any Claude client. Features 17 mandatory human-in-the-loop checkpoints, deterministic risk scoring, and free public data sources. Tested in fintech pilot showing 27 min/case processing with zero vendor lock-in. MIT licensed.Microsoft's Supplier Security & Privacy Assurance (Annual audit).
Comment on lines +68 to +70
Copy link

Copilot AI Feb 17, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR description states "Removed duplicate Microsoft SSPA entry" but the diff does not show any duplicate being removed. There is only one Microsoft SSPA entry visible in the changes, and it has been corrupted rather than cleaned up. This indicates a discrepancy between what the PR claims to do and what it actually does.

Copilot uses AI. Check for mistakes.
Copy link

Copilot AI Feb 17, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The KYC Analyst description contains a spelling error. "Claude Cowork" should likely be "Claude for Work" as this appears to reference Anthropic's enterprise product. Additionally, "Claude Code" is not a recognized Anthropic product and may be a typo for "Claude" or another product name.

Suggested change
- [KYC Analyst](https://github.com/vyayasan/kyc-analyst) - Open-source KYC/AML compliance automation plugin for Claude Cowork, Claude Code, or any Claude client. Features 17 mandatory human-in-the-loop checkpoints, deterministic risk scoring, and free public data sources. Tested in fintech pilot showing 27 min/case processing with zero vendor lock-in. MIT licensed.Microsoft's Supplier Security & Privacy Assurance (Annual audit).
- [KYC Analyst](https://github.com/vyayasan/kyc-analyst) - Open-source KYC/AML compliance automation plugin for Claude for Work or any Claude client. Features 17 mandatory human-in-the-loop checkpoints, deterministic risk scoring, and free public data sources. Tested in fintech pilot showing 27 min/case processing with zero vendor lock-in. MIT licensed. Microsoft's Supplier Security & Privacy Assurance (Annual audit).

Copilot uses AI. Check for mistakes.
Comment on lines +68 to +70
Copy link

Copilot AI Feb 17, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Microsoft SSPA entry has been corrupted during editing. Lines 68-70 show a malformed entry where the description is split across multiple lines incorrectly. The entry should be on a single line following the format used by all other entries in this list. The text "Microsoft's Supplier Security & Privacy Assurance (Annual audit)." appears at the end of line 70 instead of being part of the Microsoft SSPA entry on line 68.

Suggested change
- [Microsoft SSPA](https://www.microsoft.com/en-us/trust-center/privacy/data-protection-requirements) -
-
- [KYC Analyst](https://github.com/vyayasan/kyc-analyst) - Open-source KYC/AML compliance automation plugin for Claude Cowork, Claude Code, or any Claude client. Features 17 mandatory human-in-the-loop checkpoints, deterministic risk scoring, and free public data sources. Tested in fintech pilot showing 27 min/case processing with zero vendor lock-in. MIT licensed.Microsoft's Supplier Security & Privacy Assurance (Annual audit).
- [Microsoft SSPA](https://www.microsoft.com/en-us/trust-center/privacy/data-protection-requirements) - Microsoft's Supplier Security & Privacy Assurance (Annual audit).
- [KYC Analyst](https://github.com/vyayasan/kyc-analyst) - Open-source KYC/AML compliance automation plugin for Claude Cowork, Claude Code, or any Claude client. Features 17 mandatory human-in-the-loop checkpoints, deterministic risk scoring, and free public data sources. Tested in fintech pilot showing 27 min/case processing with zero vendor lock-in. MIT licensed.

Copilot uses AI. Check for mistakes.
Comment on lines +68 to +70
Copy link

Copilot AI Feb 17, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Line 69 contains only a list marker "- " with no content, creating an empty list item. This should be removed as it serves no purpose and breaks the consistent formatting of the list.

Suggested change
- [Microsoft SSPA](https://www.microsoft.com/en-us/trust-center/privacy/data-protection-requirements) -
-
- [KYC Analyst](https://github.com/vyayasan/kyc-analyst) - Open-source KYC/AML compliance automation plugin for Claude Cowork, Claude Code, or any Claude client. Features 17 mandatory human-in-the-loop checkpoints, deterministic risk scoring, and free public data sources. Tested in fintech pilot showing 27 min/case processing with zero vendor lock-in. MIT licensed.Microsoft's Supplier Security & Privacy Assurance (Annual audit).
- [Microsoft SSPA](https://www.microsoft.com/en-us/trust-center/privacy/data-protection-requirements) - Microsoft's Supplier Security & Privacy Assurance (Annual audit).
- [KYC Analyst](https://github.com/vyayasan/kyc-analyst) - Open-source KYC/AML compliance automation plugin for Claude Cowork, Claude Code, or any Claude client. Features 17 mandatory human-in-the-loop checkpoints, deterministic risk scoring, and free public data sources. Tested in fintech pilot showing 27 min/case processing with zero vendor lock-in. MIT licensed.

Copilot uses AI. Check for mistakes.
Comment on lines +68 to +70
Copy link

Copilot AI Feb 17, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The KYC Analyst entry does not follow the established convention for this section. Looking at all other entries in the "Security, privacy & data protection" section (lines 55-76), each entry follows the pattern: framework/standard name, brief description (typically 3-10 words), and compliance frequency in parentheses. The KYC Analyst entry contains a promotional 50+ word description including technical details, performance metrics, and feature lists. This entry should either be moved to the "Tools & softwares" section (where detailed tool descriptions are more appropriate, as seen on lines 82-85), or significantly condensed to match the format of other framework entries in this section.

Suggested change
- [Microsoft SSPA](https://www.microsoft.com/en-us/trust-center/privacy/data-protection-requirements) -
-
- [KYC Analyst](https://github.com/vyayasan/kyc-analyst) - Open-source KYC/AML compliance automation plugin for Claude Cowork, Claude Code, or any Claude client. Features 17 mandatory human-in-the-loop checkpoints, deterministic risk scoring, and free public data sources. Tested in fintech pilot showing 27 min/case processing with zero vendor lock-in. MIT licensed.Microsoft's Supplier Security & Privacy Assurance (Annual audit).
- [Microsoft SSPA](https://www.microsoft.com/en-us/trust-center/privacy/data-protection-requirements) - Microsoft Supplier Security & Privacy Assurance (Annual audit).
- [KYC Analyst](https://github.com/vyayasan/kyc-analyst) - KYC/AML compliance automation toolkit (self-declarative).

Copilot uses AI. Check for mistakes.
- [NIST AI RMF](https://www.nist.gov/itl/ai-risk-management-framework) - Risk management framework for AI governance (self-declarative).
- [PIPEDA](https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/) - Personal Information Protection and Electronic Documents Act (self-declarative).
- [SOC 1](https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-1) - Reporting on internal financial controls (Annual audit).
Expand Down
Loading