RA/QM & Compliance Skills
27 skills with 50+ Python tools covering 18 compliance frameworks including medical device regulation, privacy, security, AI governance, and financial resilience. Includes 6 audit-prep playbooks (ra-qm-team/audit-prep/) for short-runway audit preparation: SOC 2, GDPR, FDA QSR, EU AI Act, ISO 42001 AIMS, multi-framework readiness.
Frameworks covered
SOC 2, ISO 27001, ISO 13485, ISO 14971, ISO 42001, GDPR/DSGVO, HIPAA, CCPA/CPRA, EU AI Act, EU MDR, FDA (510(k)/PMA), NIS2, DORA, NIST CSF 2.0, PCI-DSS v4.0, 21 CFR Part 11, IEC 62304, IEC 62443.
Medical Device & Healthcare
| Skill |
Description |
Tools |
| mdr-745-specialist |
EU MDR 2017/745 classification, technical docs, clinical evidence, post-market surveillance |
1 |
| fda-consultant-specialist |
510(k)/PMA/De Novo pathways, QSR (21 CFR 820), HIPAA, device cybersecurity |
3 |
| regulatory-affairs-head |
Regulatory strategy, FDA submissions, EU MDR CE marking coordination |
1 |
| risk-management-specialist |
ISO 14971 risk management -- analysis, evaluation, control, FMEA |
1 |
Quality Management
| Skill |
Description |
Tools |
| quality-manager-qms-iso13485 |
ISO 13485 QMS implementation, documentation control, internal auditing |
1 |
| quality-manager-qmr |
Management reviews, quality objectives, KPI tracking, quality culture |
1 |
| quality-documentation-manager |
Document control, version management, 21 CFR Part 11 compliance |
1 |
| qms-audit-expert |
ISO 13485 internal audit planning, execution, nonconformity classification |
1 |
| capa-officer |
Root cause analysis, corrective action planning, 5-Why, fishbone, FMEA |
1 |
| Skill |
Description |
Tools |
| soc2-compliance-expert |
SOC 2 Type I/II readiness, Trust Services Criteria gap analysis, evidence collection |
3 |
| information-security-manager-iso27001 |
ISO 27001 ISMS implementation, security risk assessment, control implementation |
2 |
| isms-audit-expert |
ISO 27001 audit planning, execution, and certification support |
1 |
| infrastructure-compliance-auditor |
Cloud, DNS, TLS, endpoint, network, container, CI/CD, secrets, and logging audits |
3 |
| nist-csf-specialist |
NIST CSF 2.0 implementation, maturity assessment, risk management |
2 |
| pci-dss-specialist |
PCI DSS v4.0 compliance, tokenization, cardholder data protection |
2 |
Privacy
| Skill |
Description |
Tools |
| gdpr-dsgvo-expert |
GDPR/DSGVO codebase scanning, DPIA generation, data subject rights tracking |
3 |
| ccpa-cpra-privacy-expert |
CCPA/CPRA audit, personal information flow mapping, consumer rights readiness |
2 |
AI Governance & Emerging Regulation