CAT E Compliance
# Category E — Compliance & Security Artifacts `[COMP]`
**Audience**: Compliance / Security. **Mandate**: `04-mandates\/MANDATE_compliance.md`.
**Adoption time per module**: 1–2 hours by 1 Compliance Officer.
**Writing standard**: Auditor-facing, with traceable evidence.
## The 4 Compliance Artifacts
> **Agent ownership** (who *generates* each artifact): A16 owns E.1, E.2, E.3;
> A17 owns E.4. A06 feeds technical evidence via handoff (A16 → A06) when a
> control needs it; A16 remains the emitting owner.
### Group E.P0 — Must-have (3 artifacts)
| # | Title | Output |
|---|---|---|
| E.1 | Control Mapping | Per COMP-NNN: control → implementation (`file:line`) → test evidence → gaps |
| E.3 | Data-Flow & PII Map | Per PRV-NNN: data collected, storage, retention, erasure, lawful basis |
| E.4 | Risk Register Entries | Per security / compliance risk: severity, mitigation, owner |
### Group E.P1 — Should-have (1 artifact)
| # | Title | Output |
|---|---|---|
| E.2 | Audit Evidence Index | What to show an auditor and where it lives |
## E.1 Control Mapping Formatwhen to use it
Community prompt sourced from the open-source GitHub repo Harery/Praetor (NOASSERTION). A "CAT E Compliance" style prompt — adapt the placeholders and specifics to your task. Imported as-is and not independently retested here, so check the output before relying on it.
tags
productivitycommunitydeveloper
source
Harery/Praetor · NOASSERTION
more in Productivity
Productivity✓ tested
Summarize a doc into decisions & actions
chief of staff who extracts what to DO, not just what was said
Productivity✓ tested
Draft a reply to a hard email
calm, direct communicator who de-escalates without caving
Productivity✓ tested
Turn a brain-dump into a weekly plan
planning coach who protects your focus, not just your calendar