Pick a depth. Each prompt opens in your AI pre-loaded with the lesson. Click a row to preview the prompt.
A financial product in the US touches: SOC 2 (auditor-attested operational controls), PCI-DSS (if it handles cards), GLBA (if it holds consumer financial data), FFIEC (banking guidance), NYDFS DFS-500 (NY-licensed companies), state money-transmitter licences, SEC for securities, plus state-by-state KYC/AML rules. Internationally: GDPR (EU), PCI Council, MAS (Singapore), etc. Knowing which apply is half the compliance work.
Recommendation: build a compliance matrix as a spreadsheet on Day 1. Rows = applicable regulations + standards. Columns = controls + evidence + owner + audit deadline. Owned by Legal+CISO, reviewed quarterly. Without it, you'll re-discover requirements during an audit (expensive) or after an incident (existential).