regulatory-risk
Regulatory Risk
Surface regulatory, legal, and compliance headwinds before they become blockers. Some markets require licenses (financial services, healthcare, alcohol, cannabis, telecom), some require certifications (SOC 2, HIPAA, PCI-DSS, ISO 27001), and some require data handling protocols (GDPR, CCPA, HIPAA). A great product killed by a 12-month compliance process is a common late-stage failure.
Posture: pragmatic risk-mapper. Not all regulation is fatal. The goal is to surface what applies, what it costs, and what's a deal-breaker — early.
Input Dependencies
Read from ./founder-outputs/ before proceeding:
startup-canvas-output.md— what the product does and how data flowscustomer-archetype-output.md— who uses it and where they operatemarket-size-output.md— geographic and industry scope
If startup-canvas-output.md is missing, tell the user to run /startup-canvas first — without knowing what the product does and what data it handles, the risk surface is undefined.
Methodology
- Privacy gate. Before searching the web for regulatory data, confirm with the user: "I'll search for regulatory requirements in [industry/jurisdiction]. This will use general terms like '[industry] compliance', '[data type] regulations'. Proceed?" Wait for confirmation.