Skills
BACEN Compliance Sentinel
A practice-area skill: it carries legal knowledge — a doctrine, a regime, a review standard — and applies it to your material.
What this skill does
Comprehensive guidance on compliance with Central Bank of Brazil regulations: CMN Resolution No. 4,893/2021 (Cybersecurity Policy), BCB Resolution No. 85/2021 (GRSIC), Open Finance Brazil (BCB Resolutions No. 32/2020 and updates), and other BACEN prudential rules. Covers drafting and reviewing Cybersecurity Policies, Incident Action and Response Plans (PARI), Information and Communication Services Risk Management (GRSIC), consent and data sharing in Open Finance, API requirements, third-party management (outsourcing), and BACEN sanctions. Triggers: Bacen, Central Bank, CMN 4,893, Resolution 4,893, banking cybersecurity, PARI, GRSIC, Open Finance, Open Banking, financial data sharing, Open Finance consent, financial API, banking outsourcing, cyber risk, bank cyber incident, financial LGPD, fintech compliance, financial institution, DICT, Pix security.
- Bacen
- Compliance
- Sentinel
Free, and published by its author - not by HAQQ. The link leaves this site.
Where it runs, and how to install it
Agent Skills are a format, not a product feature: a folder with a SKILL.md and whatever files it needs. Nothing inside one is model-specific.
- Claude
- Drop the skill folder into ~/.claude/skills/, or upload it in Settings → Capabilities. Claude loads it when the description matches what you asked for.
- Claude Code
- Same folder, per-project instead: .claude/skills/ inside the repository, so the skill travels with the work rather than with the machine.
- Any agent that reads SKILL.md
- A skill is a folder with a SKILL.md and whatever files it needs. Nothing in the format is model-specific, so a runtime that reads the file reads the skill.
More from Rafael Mastronardi
Skills that do related work
- AI Governance ReviewerConduct AI governance, legal-risk, privacy, compliance, procurement, or vendor-risk reviews of internal AI use cases, AI product features, LLM workflows, or thi
- DPDPA & GDPR Compliance ReviewPerforms structured compliance review, clause redlining, and drafting suggestions for legal documents (privacy policies, data processing agreements, vendor and
- EU AI Act System ClassifierClassify an AI system under the EU AI Act (Regulation (EU) 2024/1689) and map the compliance obligations that follow. Walks Art. 2 scope exclusions, Art. 3(1) A
- EU Data Act Compliance AssessmentAssess compliance obligations under the EU Data Act (Regulation (EU) 2023/2854) for connected products, IoT devices, data sharing, cloud switching, B2B fairness
- Invoice Review ComplianceReviews outside counsel invoices against billing guidelines, flags non-compliant entries by category, and produces the documents needed to approve, reduce, reje
- LGPD SentinelLGPD guidance for processing operations in Brazil. Covers legal bases (Articles 7 and 11), DPIA, incidents (Articles 48-49), data subject rights (Article 18), a