Skip to main content
Jeden Skill in Manus ausführen
mit einem Klick
GitHub-Repository

second-line-financial-services

second-line-financial-services enthält 68 gesammelte Skills von anotb, mit Repository-Berufsabdeckung und Skill-Detailseiten auf SkillsMP.

gesammelte Skills
68
Stars
0
aktualisiert
2026-05-09
Forks
0
Berufsabdeckung
6 Berufskategorien · 100% klassifiziert
Repository-Explorer

Skills in diesem Repository

fintech-partner-controls
Compliance-Beauftragter

Drafts the fintech-side controls evidence pack a sponsor bank's third-party risk function expects in its file: control inventory mapped to Reg E error-resolution timing, NACHA Operating Rules obligations the program operator owes upstream, FBO subledger reconciliation, sponsor-bank reporting cadence, customer-facing disclosure adherence (Reg E §1005.7-§1005.11, Reg DD), money-transmitter / MSB BSA posture where applicable, contract-clause adherence evidence under the program agreement, and a 12-month incident-history summary. Output is a Word memo plus an Excel control inventory, review-ready for the fintech's own second line and for production to the sponsor bank's TPRM team or to a state-MTL examiner. Best for: - A fintech, neobank, BaaS program, or wallet operator preparing or refreshing its self-evidence pack for a sponsor-bank annual review, sponsor-bank-led audit, or state-MTL exam. - Compliance has been asked to self-evidence Reg E §1005.11 error-resolution timing (10 / 45 / 90-day clocks), NACHA retu

2026-05-09
agentic-ai-controls
Finanzrisikospezialisten

Reviews and proposes controls for an agentic AI use case (an AI system that selects actions, calls tools, reads or writes systems of record, or operates with autonomy beyond single-turn generation) in a regulated financial-services firm. Output names the agent's scope and authority statement, the architecture and tool inventory with permissions and blast radius, the identity and authorisation posture, the human oversight points with effective oversight evidence, the prompt-injection-via-tool-output and tool-misuse threat assessment, the kill-switch and rollback procedures with drill evidence, the logging and audit posture, the incident response with regulator-notification triggers, the residual risk with accepted owners, and the recommended owner actions. Designed for second-line review of agents that book actions in real systems, not chat-only assistants. Best for: - A first-line owner has built or is building an agentic system that calls tools, reads from systems of record, or executes actions, and second-

2026-05-09
ai-risk-tiering
Finanzrisikospezialisten

Assigns a defensible risk tier (tier-1 through tier-4) to an AI or model use case using a multi-factor rubric, and books the tier alongside the named gates and validation depth it triggers. The tier is the routing decision that drives validation depth, monitoring frequency, committee path, and vendor-diligence depth for the rest of model risk and AI governance. Best for: - An intake record exists and second-line needs to set the tier before sequencing validation, monitoring, or committee work. - A periodic re-tiering exercise on the AI inventory after a change in scope, autonomy, customer exposure, vendor, or supervisory posture. - A sponsor has proposed a tier and second-line needs to challenge or concur with reasoning that an examiner can read. Not the right tool when: - The use case has not been intaked yet. Route to `ai-use-case-intake` first; the tier decision is decided against an intake record version. - The question is whether the use case is high-risk under the EU AI Act specifically. Route to `ai-

2026-05-09
ai-use-case-intake
Compliance-Beauftragter

Turns a first-line AI or model use case description into a structured intake record at the front of the AI governance pipeline. Captures purpose, intended users, data sources, vendor and foundation-model dependencies, autonomy level, decision impact, regulatory exposure flags, proposed review gates, and the open questions a tier reviewer needs answered. The intake is the routing artifact downstream skills consume: ai-risk-tiering reads it to score the rubric, ai-act-triage reads it to scope Annex III overlap, model-card-builder reads it for system and data sections, validation-plan reads it to scope work, and the AI inventory of record consumes the structured object. Best for: - A first-line owner has proposed an AI use case and second-line needs the intake on file before tier, AI Act triage, or any downstream artifact is scoped. - An AI inventory refresh requires consistent intake metadata across in-flight, in-production, and decommissioned use cases. - A vendor-supplied AI tool is moving from POC to limite

2026-05-09
board-ai-risk-pack
Unternehmensberater

Drafts the AI risk committee pack the AI Governance Lead carries into the meeting: AI inventory state with heat map by tier, top AI risks with trajectory, recent AI incidents and near-misses, foundation-model vendor concentration, model performance trends, GenAI program status, AI governance maturity posture, and the decisions the committee owes this cycle. The pack is the firm's standing instrument for AI-specific board oversight, alongside (not inside) the enterprise risk committee pack. Best for: - Standing AI risk committee meeting (often quarterly) where the AI Governance Lead, CRO, and head of model risk need a curated view of AI posture rather than the full inventory dump. - The AI section of a board risk committee at firms without a standalone AI committee, when the board wants AI-specific framing rather than a heat-map row inside the enterprise pack. - Board education session on AI governance: tier mix, top risks, foundation-model exposure, GenAI program status, and the decisions in flight. - Regula

2026-05-09
genai-pre-prod-review
Finanzrisikospezialisten

Pre-production gate review for a GenAI use case before initial release or material expansion. Pulls together the upstream artifacts (intake, tier, model card, validation-plan results, prompt-injection review where applicable, RAG evaluation review where applicable, vendor evidence review where applicable) and produces a recommended decision (go, go-with-conditions, hold, no-go) with reasoning, named blocking and tracking conditions, owners, and source trace. The artifact a senior risk officer or AI risk committee secretary signs into the gate meeting. Best for: - A GenAI use case is at the pre-prod gate and the second-line function needs the gate-review memo with a clear recommendation. - A material expansion of an existing GenAI deployment (new user population, new tool, new corpus, new geography) needs a re-gate. - A regulator pre-meet, examiner request, or supervisory motion is asking for the gate package on a named GenAI use case. - A recurring revalidation cycle has triggered a gate moment and the commi

2026-05-09
llm-vendor-evidence-review
Compliance-Beauftragter

Reviews a foundation-model vendor's published evidence pack (system card, model card, evaluation reports, red-team summaries, security and privacy attestations, responsible-use policies, trust-and-safety pages) against firm criteria for the firm's deployment context. Produces a sufficiency view, named gaps with supplemental evidence requested, residual reliance with caveats, recommended owner actions, and re-review triggers. The artefact a model risk lead, AI risk committee, or vendor-diligence officer uses to decide whether to depend on a foundation model in scope. The model-evidence layer that pairs with vendor-diligence in third-party-operational-resilience for the entity-level wrapper. Best for: - A new foundation-model vendor is being onboarded for one or more in-scope use cases and the model-evidence layer is needed for the deployment-context decision. - A foundation-model provider has published a new system card, model variant, or version and the firm needs the delta review. - A periodic re-attestatio

2026-05-09
model-card-builder
Finanzrisikospezialisten

Drafts a model card for a financial-services AI or model use case, with named sections for intended use, training and reference data, performance, limitations and known failure modes, monitoring plan, controls, change management, and sign-off questions. The card is the firm-side governance artifact that supports model risk committee review, pre-prod gates, the model inventory of record, validator handoff, and regulator response files. Best for: - A first-line owner has proposed an AI use case and second-line needs the model card before a tier decision or pre-prod gate. - A model risk team is refreshing model cards as part of an annual model inventory exercise. - A new vendor model is replacing an existing one and the card needs to be updated to reflect the swap. - A regulator response file or examiner request requires the firm's documented view of an in-scope model. Not the right tool when: - The use case has not been intaked yet (use ai-use-case-intake first). - Validation testing has not run and there are

2026-05-09
prompt-injection-risk
Finanzrisikospezialisten

Reviews the prompt-injection threat surface for a deployed or near-deployed GenAI use case in a regulated financial-services firm. Catalogues the carriers (system prompt, user input, retrieved content, tool output, agent memory, multi-agent message, multimodal input), the trust posture on each, the tested attack classes, the mitigations in place with evidence, the residual risk with likelihood and impact framing, the production monitoring and detection signals, the incident-response classes with regulator-notification triggers, and the recommended owner actions. Output is a second-line-grade memo a CISO function, AI Governance Lead, MRMO, or AI risk committee can act on. Best for: - A GenAI assistant or agent is approaching pre-prod and second-line needs an explicit prompt-injection review before the gate. - An incident or near-miss in a deployed GenAI system has surfaced a prompt-injection vector and the committee needs a refreshed residual-risk view and notification-trigger evaluation. - A pre-exam or pre-

2026-05-09
validation-plan
Finanzrisikospezialisten

Drafts the validator-side scope contract for an AI or model use case before testing starts. Sizes the work to tier, names the conceptual soundness, data review, outcomes analysis, robustness, fairness, and ongoing monitoring scope per pillar, and frames the effective challenge questions the model owner is expected to answer. Output is what the validator and the model owner agree to before validation executes. Best for: - A use case has cleared intake and tiering and validation is the next step before pre-prod or production approval. - An annual revalidation cycle needs a tailored plan rather than a copy-paste of last year's scope. - A vendor or foundation-model swap on an existing use case needs a delta-scoped revalidation plan. - A regulator request lands on a tier-1 or tier-2 model and the firm needs a documented validator scope to point to. Not the right tool when: - Validation has already executed and the work is the validation report write-up. - The use case has not been intaked or tiered (use ai-use-c

2026-05-09
exception-analysis
Compliance-Beauftragter

Classifies the deviations a control test surfaced into design gaps, operating-effectiveness failures, evidence gaps, scope disagreements, data-integrity issues, and anomalies; ranks severity with rationale; names a root-cause hypothesis; sets disposition (elevate to issue, close at exception, re-test, expand sample); and builds the handoff package downstream issue write-up consumes. Output is an exception register that pairs with the testing workpaper and ladders confirmed exceptions into the issue lifecycle. Best for: - A compliance-testing or internal-audit reviewer has finished sample testing and is sitting on a list of deviations that need to be classified before they become findings. - A QA reviewer is challenging a workpaper's exception treatment because the line between evidence gap and control failure was blurred. - A repeat-issue review needs to confirm whether deviations across testing cycles are the same root cause or coincidental. - A second-line lead is preparing a handoff to issue write-up and

2026-05-09
qa-workpaper
Compliance-Beauftragter

Reviews a completed control-test workpaper for QA along named dimensions: scope alignment to the test plan, source-criteria sufficiency, evidence reliability, procedure execution rigor, exception classification, conclusion support, severity calibration, reviewer separation, and remediation handoff. Output is a QA review pack — Excel workbook with QA markup tabs over the workpaper plus a Word QA memo summary — that lists deficiencies by severity, a decision (accept, return for rework, conditional accept), and required rework before workpaper closure. Best for: - A second-line QA function or independent reviewer is performing the standard QA pass over a completed workpaper before issue closure or examiner sharing. - An internal-audit director is rolling up workpaper-quality metrics across a testing cycle and needs structured QA notes per workpaper. - A targeted Federal Reserve, OCC, FDIC, CFPB, NYDFS, or state DOI exam is imminent and the team is doing a self-QA sweep on the workpaper population the examiner w

2026-05-09
fair-lending-test-plan
Compliance-Beauftragter

Drafts a fair-lending test plan covering scope, products, decision points (marketing, underwriting, pricing, steering, servicing, loss mitigation), planned test types (redlining, comparative file review, statistical regression on underwriting and pricing, marketing distribution, steering), demographic-proxy methodology, less-discriminatory-alternative search where AI or ML models drive credit decisions, data and evidence asks, controls hypothesis, owners, and committee approval gate. The plan is the operationalization of the annual fair-lending risk assessment and the artifact a fair-lending committee approves before any test is run. Best for: - Annual fair-lending risk-assessment refresh where the test plan is the operationalization of the assessment. - Pre-exam fair-lending readiness where a regulator has signaled focus on a specific product, MSA, or decision point. - Targeted plan after complaint themes (chain to `complaint-theme-analysis`) or adverse-action review (chain to `adverse-action-review`) surfa

2026-05-09
marketing-claim-review
Compliance-Beauftragter

Drafts a second-line marketing-claim review memo for one creative or one campaign of consumer-financial marketing. Asset-by-asset and claim-by-claim: substantiation status per claim; deception, unfairness, and (where applicable) abusiveness reads on the displayed asset; required disclosures (Reg Z trigger terms, MAPR / APR / fees, FDIC insurance, Reg DD, MLA where in scope, TRID-adjacent where the marketing previews mortgage terms); fair-lending distribution and targeting findings; privacy-claim accuracy; dark-pattern findings against a named taxonomy; AI-generated and AI-personalised content review; and recommended edits with kill-switch candidates. The memo is the input to the marketing-compliance decision forum; it does not approve marketing for launch, take down live assets, or finalize UDAAP, fair-lending, or privacy determinations. Best for: - Pre-launch second-line review of one consumer-financial marketing campaign (deposit, credit card, mortgage, BNPL, personal loan, auto, small business) before the

2026-05-09
cdd-risk-review
Compliance-Beauftragter

Quality-reviews a customer due diligence file (new account, periodic refresh, or event-driven refresh) against the four CDD pillars and named CDD examination expectations. Reads customer identification, beneficial ownership identification and verification, the nature-and-purpose / expected-activity profile, the customer risk rating and its drivers, and the ongoing-monitoring trigger set; produces a second-line review memo with material gaps, evidence-needed items, EDD-trigger posture, and recommended decision checkpoints with named owners. Does not approve onboarding, set or change the customer risk rating, file a SAR, or close or exit the relationship. Best for: - Second-line QA over a sample of new-account CDD files at a bank, broker-dealer, MSB, fintech (sponsor-bank or licensed), or covered-product life insurer. - Periodic CDD refresh review where risk-rating drivers, beneficial-ownership data, or expected activity may have shifted. - Event-driven refresh triggered by negative news, sanctions hit, transa

2026-05-09
negative-news-triage
Compliance-Beauftragter

Triages an adverse-media or negative-news hit set against a specific customer or entity for identity confidence, source reliability, recency, materiality to financial-crime risk, and downstream routing. Produces a triage memo and a structured triage record that downstream artifacts (cdd-risk-review refresh, edd-escalation-pack, sar-decision-qa, sanctions-screening-qa) can consume. Does not change customer ratings, file SARs, exit relationships, or re-tune monitoring scenarios. Best for: - Adverse-media hit triage at onboarding, periodic refresh, or event-driven refresh on a named customer. - Bulk triage over a periodic adverse-media re-scan output where the volume is dominated by common-name false matches. - Pre-EDD triage feeding into an EDD escalation pack. - Pre-SAR-decision triage where adverse media is part of an alert's evidence basis. Not the right tool when: - The work is sanctions-screening match disposition rather than adverse media; use `sanctions-screening-qa`. - The hit is already triaged and t

2026-05-09
sanctions-screening-qa
Compliance-Beauftragter

Quality-reviews a sanctions screening program against named regulatory frames: list-management governance, customer and transaction screening configuration, match-logic and fuzzy-threshold tuning, list-update timeliness, alert disposition documentation, false-positive rationale, escalation paths, 50 Percent Rule and sectoral-sanctions handling, and cyber-evasion exposure. Reads each sampled alert disposition for documented rationale, decision-maker independence, and 50%-rule assessment; produces a second-line QA memo with material findings, evidence-needed items, and recommended decision checkpoints with named owners. Does not approve list configuration, tune match logic, file blocking or rejection reports, close alerts, or make match-or-no-match decisions. Best for: - Periodic sample QA over customer-screening and transaction-screening alert dispositions within a defined review window. - Pre-validation review of screening configuration evidence to scope the next validation cycle. - Pre-exam readiness review

2026-05-09
sar-decision-qa
Compliance-Beauftragter

Quality-reviews a SAR or no-SAR decision file against named SAR rules and the FFIEC SAR examination expectations. Reads the alert chronology, investigation steps, evidence considered, disposition, decision rationale, continuing-activity posture, and confidentiality controls; produces a QA memo with material gaps, reviewer findings, and a routing recommendation to the named decision forum. Does not file, decline to file, amend, or close any SAR; SAR filing is a regulated act reserved to the BSA officer or designee. Best for: - Second-line QA over a sample of closed alerts (filed and unfiled) within a defined lookback window. - Targeted review of high-risk alert types (structuring, trade-based, layering, sanctions-adjacent, fraud typology, cyber-event-related). - Review of continuing-activity posture against the firm's documented SAR program (the 90-day continuing-SAR cadence the industry uses is firm policy, not a BSA-rule requirement; the QA reads adherence to the program the firm has, not a uniform external

2026-05-09
exam-brief
Unternehmensberater

Drafts the engagement playbook a regulatory affairs lead, head of compliance, head of legal, or CRO chief of staff runs during a live regulator engagement. Generic across regulator type and product line. Captures the scope confirmation in writing, the named single-point-of-contact map by topic, the document-handling and privilege posture, the request-list mapping, the interview-prep posture, the supervisory-history that the engagement inherits (open MRA, MRIA, consent-order milestones, self-identified issues), the anticipated reviewer questions tied to current supervisory priorities, the exit-meeting and supervisory-letter response posture, and the post-exam follow-up. The substantive readiness sprint sits in sector-specific exam-readiness skills; this is the engagement-side scaffolding that runs during the exam window. Best for: - An exam window has opened (any regulator, any product line) and the regulatory affairs lead needs the engagement playbook before fieldwork begins. - A supervisory-letter response

2026-05-09
regulatory-impact-assessment
Unternehmensberater

Drafts a second-line impact assessment for a published rule, supervisory letter, FIL, circular, bulletin, industry letter, adopting release, advisory, supervisory speech, or enforcement theme. Carries two lenses in one artifact: an implementation lens (in-scope determination, obligation domains hit, policy and control impact, reporting and disclosure impact, technology and data impact, third-party impact, customer impact, cost-to-comply read, effective-date posture, transition relief) and a regulatory-strategy lens (firm position, regulator-engagement posture, comment-period posture if any, public consultation posture, peer-and-industry alignment, escalation triggers). Audience is regulatory affairs, head of compliance, head of legal, CRO chief of staff, and the head of business affected. Drafts only; attestation external. Best for: - A new final rule, supervisory letter, FIL, circular, bulletin, or industry letter has been published and the regulatory-change function needs a firm-impact and strategic-postur

2026-05-09
control-matrix
Compliance-Beauftragter

Builds the named-row risk-control matrix that maps obligations to control objectives, control activities, owners, frequency, evidence pointers, test methods, last-test results, and open issues. Foundational primitive: compliance-testing samples against it, vendor-diligence and exit-plan reference it, exam-brief reads it, model-card-builder pulls its controls section from it. Risk function and compliance function both consume the same matrix. Best for: - Standing up the matrix for a process, product, or function (lending, vendor lifecycle, model lifecycle, risk-data and risk reporting, cyber-disclosure governance, consumer-compliance management). - Refreshing an existing matrix after a regulatory change, an MRA, an audit finding, an incident, or a process redesign. - Translating a freshly mapped obligation set into the row structure that downstream testing and review will run against. Not the right tool when: - The obligations have not been extracted yet. Run `obligation-mapping` first; the matrix consumes i

2026-05-09
evidence-binder
Compliance-Beauftragter

Assembles the evidence binder index for a regulatory exam, internal audit fieldwork pack, model-validation evidence pack, vendor-review pack, committee evidence pack, or issue-remediation file. One row per artifact, with system-of-record provenance, control and obligation linkage, sufficiency call, and reviewer sign-off. Reconciles a request list against the evidence on hand and surfaces the gaps before the reviewer does. Best for: - A compliance team building the response binder for a regulator exam against the examiner's request list (RFI). - An internal-audit lead assembling the fieldwork evidence pack for a control-test program. - A model-risk validator pulling the evidence pack for a model revalidation cycle under the firm's MRM frame (cadence per the firm's own policy, not assumed annual). - A TPRM team assembling the diligence evidence file for a critical or important vendor review. - A committee secretary compiling the evidence file behind a risk-committee or AI-risk-committee paper, where the commit

2026-05-09
human-review-gates
Unternehmensberater

Builds the named-gate matrix for an artifact, decision, or workflow: gate name, stage in workflow, trigger, required reviewers (with independence), required inputs, decision criteria, stop conditions, escalation path, documentation requirement, frequency, and source anchor. Foundational primitive: every output-builder skill in the repo emits an artifact that runs through one or more of these gates, and the skill exists so the gates themselves get built once and reused. Output is a gate matrix plus a one-page narrative an AI governance committee, vendor onboarding committee, model risk committee, or issue-rating committee can adopt as charter language. Best for: - Standing up a new committee or governance gate (AI use-case approval, vendor onboarding, model release, issue rating, customer-impact action, SAR filing approval, regulator-response sign-off). - Auditing an existing workflow for missing or under-specified human-review gates ahead of an exam, an internal audit, or a Heightened-Standards readiness rev

2026-05-09
issue-writeup
Compliance-Beauftragter

Drafts a single issue write-up using the condition / criteria / cause / effect (CCCE) structure plus severity rationale, remediation, named owner, target date, closure evidence, and evidence-gap flag. Foundational primitive: exception-analysis chains it after a control-test exception, audit findings consume it as the issue artifact, regulator-response files cite it, and the issue log keys off it. The output is a one-issue artifact written in the shape an audit committee, regulator, or issue-tracking system will accept. Best for: - Drafting a finding from internal audit fieldwork, a compliance test exception, a vendor-monitoring exception, a model-validation finding, or a self-identified second-line observation. - Translating an MRA, MRIA, FINRA Letter of Caution, SEC EXAMS deficiency, NYDFS finding, or examiner-issued matter into the firm's internal issue format with traced criteria. - Re-papering a legacy issue whose criteria, cause, or closure evidence does not stand up to current review. Not the right to

2026-05-09
obligation-mapping
Compliance-Beauftragter

Converts any source document (rule text, supervisory guidance, exam manual, exam request list, supervisory letter, regulator speech, internal policy, third-party SLA, contract clause) into a structured obligation register: one row per obligation, traced to source by section, with applicability, control objective, evidence required, owner, status, and open questions. Foundational primitive: control-matrix anchors its rows on this output, policy-gap-review triangulates against it, evidence-binder pulls evidence asks from it, exam-brief reads it, and almost every downstream second-line skill reaches for an obligation register at some point. Best for: - Standing up or refreshing the obligation register for a process, product, function, or regulatory domain. - Converting an exam manual section or an examiner document-request list into an internal obligation set the firm can respond to row by row. - Translating a supervisory letter, regulator speech, or interagency statement into discrete obligations and open ques

2026-05-09
policy-gap-review
Compliance-Beauftragter

Reviews a firm policy or procedure (or a small set of related policy artefacts) against a named, dated benchmark of obligations or supervisory expectations and produces a gap matrix. One row per gap, with classification (missing / partial / weak / inconsistent / outdated), severity with rationale, declarative recommended edit, evidence needed beyond the text, and named owner. Foundational primitive: the gap matrix routes into `issue-writeup` for findings, into `obligation-mapping` when missing obligations surface, and into `control-matrix` when the operational dimension of the gap is a control rather than text. Audience is policy owners, compliance, and internal audit; the artifact is the gap list, not the policy redline. Best for: - Refreshing a policy ahead of a regulator exam, internal audit, post-enforcement uplift, or scheduled triennial review. - Comparing a legacy policy against a newly published rule or refreshed guidance (legacy SR 11-7-anchored MRM policy against the joint April 2026 model-risk gui

2026-05-09
scoping
Projektmanagementspezialisten

Produces a scoping charter and a structured scope record that downstream second-line skills consume. The charter sets institution, engagement, persona, source posture, risk lens, and overlay context so other skills do not reinvent these facts each time they are called. Best for: - An advisory engagement starting up and the lead needs a written scope before review work begins. - An internal review being charted (annual model risk review, periodic third-party risk review, audit support, exam-readiness sprint, regulatory-change implementation, board-pack cycle). - A practitioner joining an engagement mid-flight and needing the context in one place. - A downstream skill called with contested or unclear scope. Not the right tool when: - A current scope is already on file and the downstream skill is scope-aware (pass the existing record). - The work is a one-off question rather than a scoped review. - The institution and persona are already encoded in a `references/firm-overlay.md` the firm has installed.

2026-05-09
attestation-pack
Compliance-Beauftragter

Drafts the periodic management attestation pack a senior officer takes into the certification meeting: scope statement, source criteria, control inventory, evidence index, exceptions with compensating-control narrative, prior-period remediation status, sub-certification chain, reviewer questions, assertion language, and sign-off block. Output is the named-section pack the attesting officer (CEO, CFO, CRO, CCO, CISO, BSA officer, head of internal audit, fund CCO, function head, process owner) and the named reviewers (legal, internal audit, external assessor, regulator) carry into the sign-off conversation. Best for: - Periodic management attestation underpinning a formal certification (SOX 404 process-owner sub-certification; SOC 1 / SOC 2 management assertion package; FFIEC self-assessment; vendor-management annual attestation; BCBS 239 risk-data attestation; fund CCO Rule 38a-1 annual report; BSA officer annual certification; cyber annual certification including NYDFS Form B; privacy annual report under the

2026-05-09
bcbs239-gap-assessment
Finanzrisikospezialisten

Drafts a gap assessment of the firm's risk data aggregation and risk reporting posture against the fourteen BCBS 239 principles, organised by the four BCBS groups (overarching governance and infrastructure, aggregation, reporting, supervisory review). Produces a principle-by-principle matrix with rating, direction, evidence summary, gaps, owners, and target dates that the head of risk data, head of regulatory reporting, CRO office, and internal audit can take to the data-management committee after qualified review. Best for: - Standing up or refreshing a self-assessment ahead of a regulator-driven review (FRB horizontal review on RDARR, ECB SREP thematic, OCC Heightened Standards thematic). - Diagnosing why a risk committee pack carries a non-high data-confidence label; the gap assessment is the upstream artifact. - Refreshing the BCBS 239 posture after a material change (acquisition, system migration, source-of-record consolidation, taxonomy revision). - Pulling the cross-entity gap view across G-SIBs and D

2026-05-09
cyber-disclosure-readiness
Finanzrisikospezialisten

Drafts the second-line readiness pack for SEC cybersecurity disclosure: 8-K Item 1.05 trigger and materiality workpaper for a live or suspected material incident, the 10-K Item 106 risk-management and governance disclosure for the annual filing cycle, and the disclosure controls and procedures (DCP) readiness map. The pack is what a disclosure committee, securities counsel, the CISO, and the CRO take into the materiality call and into the filing decision. Best for: - A material cybersecurity incident has occurred (or is suspected) and the disclosure committee needs the materiality determination, the 4-business-day clock posture, the parallel-regulator clocks, and the Item 1.05 disclosure draft pulled together. - The 10-K Item 106 cyber risk-management and governance disclosure is being refreshed for the upcoming filing cycle and second line is challenging the prior-year text. - The firm is standing up or refreshing its cyber disclosure controls and procedures under Exchange Act Rule 13a-15 and needs the seco

2026-05-09
kri-commentary
Finanzrisikospezialisten

Drafts second-line commentary on KRI / KCI movement and breaches for a periodic risk report. Each per-KRI block carries trend, breach status against the firm's risk appetite statement, named root cause and contributing factors, action taken and action planned with role-level owners and dates, residual-risk view, linked issues and material events, and an explicit second-line challenge note where the second-line view diverges from first-line. Output is a per-KRI commentary block ready to drop into the risk committee pack, the divisional risk pack, the regulator response, or the board memo after qualified review. Best for: - Standing commentary block for each KRI / KCI flagged AMBER or RED in the period, with named root cause and remediation status. - Refreshing commentary on a watch-list KRI that has been at trigger or limit for multiple consecutive periods. - Rewriting first-line draft commentary to second-line standard (challenge, source-anchored, owner-named, evidence-pointed). - Producing the commentary ap

2026-05-09
management-response
Unternehmensberater

Drafts the management response to a regulator finding, an internal-audit finding, or an external-assessor observation: acceptance posture, root-cause acknowledgement, action plan with milestones and owners, interim mitigation, evidence-of-effectiveness plan, reporting cadence to the issuing party, and the linkage to the underlying issue write-up. The response is the load-bearing artifact a head of regulatory affairs, head of compliance, CRO, or general counsel takes back to the regulator or to the audit committee after qualified review. Best for: - Drafting the management response to a supervisory finding from a federal banking agency in the formal-letter format the regulator expects. - Drafting the management response to an internal-audit finding for the audit committee response file. - Drafting the management response to an external-assessor observation (SOC auditor, IIA peer review, third-party regulatory engagement). - Drafting the management response to a consumer-protection or markets-conduct superviso

2026-05-09
risk-committee-pack
Finanzrisikospezialisten

Drafts the enterprise risk committee pack a CRO carries into the meeting: heat map by risk type, top risks, material risk events, KRI movement and breaches against the risk appetite statement, issues and remediation, forward-looking commentary including scenario results, and decision items. The pack is the load-bearing governance instrument the risk committee of the board (or the enterprise risk committee) uses to discharge its oversight under the firm's risk governance framework. Best for: - Standing quarterly or monthly enterprise risk committee pack from upstream KRI feeds, the issue log, the loss-event register, and CRO commentary. - Board-level risk pack ahead of a regulator-attended meeting (FRB horizontal review, OCC Heightened Standards readiness, FRB CCAR cycle review). - A single committee view across credit, market, liquidity, operational, compliance, financial-crime, model, third-party, cyber, climate where in scope, strategic, and reputational risk. - An adviser-firm or insurer enterprise risk c

2026-05-09
contract-gap-review
Compliance-Beauftragter

Reviews a third-party contract or master services agreement against named regulatory clause-coverage expectations and produces a clause-by-clause gap matrix with severity, remediation posture, and the legal-review triggers a control owner needs before signature, renewal, or assignment. Output is the second-line clause-coverage view that sits next to (not in place of) legal redlines. Best for: - A new vendor contract is in negotiation and the firm needs the second-line clause-coverage view before legal redlines land. - Renewal, assignment, or material amendment of an existing contract triggers a refresh against current regulatory expectations. - A digital-operational-resilience preparation cycle requires evidence that critical-or-important-function ICT contracts meet the mandatory-clause set. - A vendor-diligence pack needs the contract-coverage section closed out (chains via `contract_gap_summary`). Not the right tool when: - The criticality tier has not been set (run `criticality-assessment` first; clause

2026-05-09
dora-register-builder
Compliance-Beauftragter

EU-DORA-context build pack and data-quality aid for firms preparing Register of Information entries for ICT third-party arrangements. Helps a US-deep practice with EU-touching engagements populate register fields, surface data-quality gaps, and structure a build-pack narrative for the named approver before the firm's regulatory-reporting pipeline takes over. The skill's local B-table convention is preparation-grade. It is not the official EBA Register of Information template and not submission-grade against the Commission Implementing Regulation (EU) 2024/2956 taxonomy. Best for: - An EU-nexus financial entity scoping the first-cycle register build, where a structured data-quality view and a reviewer-ready build pack matter before the firm's submission tooling formats the official template. - An EU subsidiary of a non-EU group where the parent needs visibility into EU register data quality before the subsidiary files individually to its national competent authority. - A second-line review of an existing regi

2026-05-09
vendor-diligence
Compliance-Beauftragter

Drafts a second-line vendor diligence pack for a single ICT, fintech, cloud, data, or AI service provider. Captures inherent risk, criticality input, due-diligence evidence read against named regulatory criteria, residual risk, exit posture, and the gaps a control owner needs to close before onboarding or recertification. Handles AI vendors via an explicit AI-vendor branch in the same workflow. Best for: - A first-line owner has proposed a new ICT, fintech, cloud, data, or AI vendor and second-line needs the pre-onboarding pack. - A vendor risk team is recertifying an existing critical or important vendor and the prior pack is stale. - An AI vendor (foundation-model API, AI SaaS, embedded-AI feature, agentic system) needs diligence with the second-line lens, not a procurement checklist. - An exit-triggered or post-incident re-review of an existing vendor. Not the right tool when: - The criticality tier has not been set (run `criticality-assessment` first). - The job is portfolio-level concentration across m

2026-05-09
bank-fintech-partnership-review
Compliance-Beauftragter

Produces the bank-side principal-supervisory partnership pack on a US bank-fintech relationship. Carries six named sections (service description and risk classification; risk-based diligence summary; contract gaps; customer-facing controls under Reg O / Reg W / Reg E / Reg DD; termination and wind-down readiness; recommended owner actions) plus a Reg O / Reg W / Reg E / Reg DD applicability summary the bank attests to. Audience is the partnership owner, the chief risk officer, the chief compliance officer, the BSA officer, the head of vendor management, the head of deposit operations, the general counsel, and the OCC / FRB / FDIC supervisory team that examines the relationship as a bank service-provider arrangement. Best for: - A national bank, state-member bank, state non-member bank, or federal savings association is onboarding a fintech relationship (BaaS sponsor program, embedded-lending partner, deposit-program partner, fraud / KYC service partner, payments-processor) and second-line needs the partnersh

2026-05-09
banking-supervision-readiness
Finanzprüfer

Produces the substantive supervision-readiness pack a US bank or bank holding company hands the OCC, FRB, or FDIC examiner-in-charge at the entry meeting and carries through the cycle. Organises preparation around the CAMELS components (or the BHC rated components for a holding-company cycle), the examiner-letter response posture (MRA, MRIA, supervisory recommendation, consent-order article), the MRA / MRIA closure cross-walk with sustained-operation evidence, the Heightened Standards readiness view for covered banks, and the topical examiner-readiness slices (BSA / AML, IT, fair lending, third-party risk) that the cycle scope brings into play. Audience is the head of supervisory affairs, the chief compliance officer, the chief risk officer, the BSA officer, and the examination coordinator. Best for: - A national bank, state-member bank, state non-member bank, or federal savings association is preparing for an OCC, FRB, or FDIC full-scope safety-and-soundness examination and needs the entry-meeting pack with

2026-05-09
credit-risk-governance
Finanzrisikospezialisten

Produces the second-line credit risk governance review pack a US bank's chief credit officer or chief risk officer carries to the credit risk committee or hands the OCC, FRB, or FDIC examiner reviewing credit administration. Organises the artifact around credit policy alignment, underwriting framework, risk-rating discipline, concentration governance, allowance methodology oversight (ACL / CECL), Reg O and Reg W applicability for insider and affiliated credit, second-line challenge of first-line lending decisions, and (for covered banks) the Heightened Standards posture for credit risk. Audience is the chief credit officer, chief risk officer, head of credit risk review, ALLL / ACL governance committee, audit committee, and examiner-in-charge for a credit-administration scope cycle. Best for: - A national bank, state-member bank, state non-member bank, or federal savings association is refreshing its credit policy or credit risk-rating framework and second-line needs to challenge the first-line proposal agai

2026-05-09
deposit-operations-controls
Compliance-Beauftragter

Drafts the second-line deposit-operations control matrix for a US bank: account opening and CIP, beneficial-ownership collection at deposit channels, account-opening and advertising disclosures, EFT and ATM controls under the consumer-EFT regime, funds-availability holds and exception-hold notification, NSF and overdraft fee disclosure under the truth-in-savings regime, garnishments and levies, escheatment and dormant-account governance, deposit-insurance coverage representation under the federal misrepresentation rule, FBO-account ledgering and pass-through deposit-insurance recordkeeping for sponsor-bank fintech programs, exception handling, access controls, and evidence retention. Audience is the deposit-operations director, the bank's compliance officer, the BSA officer, internal audit, and the federal banking examiner reading the matrix line-by-line. Best for: - A bank standing up or refreshing the deposit-operations control framework after a process change, a system migration, an internal-audit finding

2026-05-09
Zeigt die Top 40 von 68 gesammelten Skills in diesem Repository.