This skill validates financial documents, reports, and client-facing communications against applicable regulatory frameworks including FCA conduct rules, SOX internal control requirements, and GDPR data handling obligations. It performs structured checks to identify non-compliant language, missing disclosures, inadequate risk warnings, and data protection failures before content is finalised or distributed.
-
Identify the document type and applicable regulatory scope. Determine whether the document is a financial promotion, client report, engagement letter, regulatory return, or internal control document. Map the document to the relevant regulatory frameworks (FCA Handbook, UK GAAP, IFRS, GDPR, MLR 2017, or SOX where applicable to US-listed entities).
-
Extract all claims, figures, and assertions from the document. Parse the content to identify numerical data, performance claims, forward-looking statements, risk disclosures, fee structures, and any references to past performance. Flag any unsubstantiated claims or figures without source attribution.
-
Check financial promotion rules. If the document is a financial promotion or contains promotional language, verify compliance with FCA COBS 4 requirements: ensure it is fair, clear, and not misleading; confirm past performance disclaimers are present where historical returns are cited; verify that risk warnings are prominent and not obscured by positive messaging.
-
Validate data protection compliance. Scan for personal data references (client names, account numbers, NI numbers, dates of birth). Confirm that any document containing personal data includes appropriate privacy notices, has a stated lawful basis for processing, and does not disclose personal data to unintended recipients.
-
Assess internal control documentation. For SOX-relevant documents, verify that control descriptions include the control objective, frequency, responsible party, evidence of performance, and exception handling procedures. Check that segregation of duties is maintained between preparer, reviewer, and approver roles.
-
Review regulatory disclosure completeness. Cross-reference the document against required disclosures for its type. For financial statements, check that all notes required by FRS 102 or applicable IFRS standards are present. For client agreements, verify that cancellation rights, complaints procedures, and FSCS protection details are included where required.
-
Generate a compliance findings report. Produce a structured report listing each finding with its severity (critical, major, minor, advisory), the specific regulatory reference, a description of the gap, and a recommended remediation action. Order findings by severity.
-
Provide an overall compliance assessment. Assign an overall compliance status of Compliant, Conditionally Compliant (minor issues only), or Non-Compliant (one or more critical or major findings). Include a summary count of findings by severity.