Browse the bible
Foundations
Getting started
Capabilities
Security & governance
Workflows
Prompt library
Rollout playbook
Troubleshooting
Reference
Workflow · Operations

Compliance checklists — required-document audits with Claude Cowork

Claude Cowork workflow for compliance and ops — walk a folder of documents against a checklist, produce status report and gap summary. Conservative bias built in.

Updated 2026-04-25Read 4 min

TL;DR. Walk through a folder of documents, check against a defined compliance checklist, and produce a status report — for vendor onboarding, customer due diligence, ISO/SOC audits, or regulatory filings. Roughly 8 hours per audit saved. Conservative bias is the most important rule: 30% false-positive rate on gaps is fine; 1% false-negative on Compliant is not.

Job to be done#

Walk through a folder of documents, check them against a compliance checklist, and produce a status report with cited evidence.

Who runs it#

Compliance officer, ops lead with compliance responsibility, legal ops.

Inputs (inbox/)#

  • The checklist as a structured Word or Excel doc
  • The document set under review in /inbox/audit-[name]/
  • Any prior reviews for context

Outputs (output/)#

  • compliance-status-[name].xlsx — one row per checklist item with status and evidence reference
  • gaps-[name].docx summarising missing or non-compliant items
  • An evidence/ folder of cited document excerpts

Prompt seed#

Read the checklist in /inbox/checklist.xlsx.
For each item, search /inbox/audit-[name]/ for evidence.
Output /output/compliance-status-[name].xlsx with:
  item, requirement, status (Compliant / Gap / Not applicable),
  evidence file + page, notes.
For any item with status "Gap," write a paragraph in
/output/gaps-[name].docx describing what's missing and the typical fix.
Be conservative — when in doubt, mark as Gap, never as Compliant.

Quality bar#

  • Conservative bias: Cowork should never mark Compliant on inference.
  • Evidence references are specific — filename + page or section.
  • Common trip-up: claiming Compliant because a document mentions the right keyword. Push back; the standard is "satisfies the requirement," not "contains the word."

Time saved (typical)#

About 8 hours of an ops or compliance professional per audit.

Upgrade path#

  • Convert to a vendor-due-diligence skill or iso-prep skill per specific use case.
  • Connector to your GRC tool if you have one — Vanta, Drata, ZenGRC.

Tinkso's take#

Conservative bias is the most important rule. We deliberately tune the prompt to over-report gaps. A 30% false-positive rate on gaps is fine — the human reviewer will down-mark the false positives in a few minutes. A 1% false-negative on Compliant will land you in front of an auditor. Tune accordingly.

Need help applying this?

Book a 30-minute call. We'll ask where you are, what your team needs, and which systems Cowork should touch.

Last reviewed: 25 April 2026 · The Cowork Bible · Tinkso