| name | regulatory-compliance |
| title | Regulatory Compliance |
| description | Multi-sector regulatory compliance skill for industry-specific regulations. Use when the user needs assistance with regulatory frameworks, compliance programs, regulatory investigations, or industry-specific requirements across sectors. Triggers on keywords like "regulatory", "compliance program", "regulated industry", "agency", "enforcement", "regulatory investigation", "consent decree", "compliance audit", "regulatory risk". |
| author | judicialmind |
| author_url | https://github.com/judicialmind/legal-skills/tree/main/skills/regulatory-compliance |
| license | MIT |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | regulatory |
| language | en |
Regulatory Compliance
This skill provides expert guidance for navigating regulatory frameworks across multiple industries and jurisdictions.
Core Capabilities
1. Compliance Programs
- Program design
- Policy development
- Risk assessment
- Monitoring and testing
2. Regulatory Strategy
- Agency engagement
- Comment letters
- Rulemaking participation
- Regulatory advocacy
3. Investigations
- Investigation response
- Self-disclosure
- Settlement negotiation
- Remediation
4. Industry-Specific
- Financial services
- Healthcare
- Energy
- Technology
Compliance Program Framework
Essential Elements (DOJ/SEC Framework)
EFFECTIVE COMPLIANCE PROGRAM ELEMENTS
1. COMMITMENT FROM SENIOR MANAGEMENT
- Tone at the top
- Resource allocation
- Accountability
2. AUTONOMY AND RESOURCES
- Chief Compliance Officer
- Reporting structure
- Budget and staff
3. POLICIES AND PROCEDURES
- Clear standards
- Tailored guidance
- Regular updates
4. RISK ASSESSMENT
- Enterprise risk assessment
- Control environment review
- Third-party risk
5. TRAINING AND COMMUNICATION
- Role-based training
- Annual certifications
- Ongoing awareness
6. REPORTING MECHANISMS
- Hotline/helpline
- Non-retaliation
- Investigation protocol
7. INCENTIVES AND DISCIPLINE
- Compliance in performance
- Consistent enforcement
- Documented actions
8. CONTINUOUS IMPROVEMENT
- Testing and monitoring
- Remediation
- Lessons learned
9. THIRD-PARTY MANAGEMENT
- Due diligence
- Contract requirements
- Monitoring
10. M&A DUE DILIGENCE
- Pre-acquisition review
- Integration planning
- Post-acquisition remediation
Risk Assessment Process
┌─────────────────────────────────────────────────┐
│ 1. IDENTIFY RISKS │
│ - Regulatory requirements │
│ - Industry-specific risks │
│ - Geographic considerations │
│ - Business activities │
└─────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────┐
│ 2. ASSESS INHERENT RISK │
│ - Likelihood of occurrence │
│ - Potential impact │
│ - Regulatory scrutiny │
└─────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────┐
│ 3. EVALUATE CONTROLS │
│ - Preventive controls │
│ - Detective controls │
│ - Control effectiveness │
└─────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────┐
│ 4. DETERMINE RESIDUAL RISK │
│ - Risk after controls │
│ - Risk tolerance │
│ - Action required │
└─────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────┐
│ 5. PRIORITIZE AND REMEDIATE │
│ - High-risk areas first │
│ - Resource allocation │
│ - Timeline and milestones │
└─────────────────────────────────────────────────┘