ワンクリックで
grimoire-core
grimoire-core には jeffreytse から収集した 1,231 個の skills があり、リポジトリ単位の職業カバレッジとサイト内 skill 詳細ページを表示します。
このリポジトリの skills
Use when a family-owned business needs governance structures addressing the specific tension between family dynamics and business decision-making — establishing a family council separate from the operating board, a written family charter or constitution, and defined succession criteria, rather than relying on informal family relationships to substitute for genuine governance structure.
Use when an organization wants to assess how mature its overall governance practices are — decision rights, oversight bodies, policy management, accountability mechanisms — against a recognized international governance standard, producing a structured maturity assessment rather than an unstructured, subjective sense of "our governance seems fine."
Use when an organization is forming any standing committee — a risk committee, a compensation committee, an ethics committee, or any other recurring decision-making body — writing a formal charter that defines the committee's scope, authority, and reporting line before it begins operating, rather than letting the committee's mandate remain implicit and subject to later dispute.
Use when an organization needs a standing policy for employees, officers, and board members to disclose personal, financial, or relational interests that could conflict with their organizational duties — requiring proactive, periodic disclosure and a defined recusal process, rather than relying on individuals to voluntarily raise conflicts only when they happen to think of it.
Use when an organization needs a defined governance chain of command for a major corporate crisis — a product safety failure, an executive scandal, a data breach, a natural disaster affecting operations — establishing who has decision authority at each severity level and when the board itself must be activated, rather than discovering the chain of command for the first time while the crisis is already unfolding.
Use when an organization repeatedly experiences slow or contested strategic and operational decisions because it's unclear who has actual authority to decide — explicitly mapping decision types to the specific role or body with final decision authority, distinct from who merely provides input, rather than leaving decision authority ambiguous and re-litigated each time a similar decision arises.
Use when an organization's internal policies accumulate without a defined process for creating, approving, reviewing, and retiring them — establishing a formal policy lifecycle with an accountable owner, a defined review cadence, and a single authoritative repository, rather than letting policies proliferate as scattered documents with no owner and no scheduled review.
Use when a company engages in political spending, lobbying, or trade association dues that fund political activity — establishing board-level oversight of this spending and voluntary transparency about it, rather than treating political activity as an operational decision with no defined governance or disclosure structure behind it.
Use when a task, process, or decision has unclear ownership — multiple people assuming someone else is handling it, or no one being sure who has final authority — mapping every significant activity to exactly one Responsible party, one Accountable party, and explicitly defined Consulted and Informed parties, rather than leaving task ownership implicit and assumed.
Use when an organization is establishing oversight for how it develops, deploys, or uses AI systems — classifying AI use cases by risk level, assigning accountable owners, and applying oversight proportionate to each use case's actual risk, rather than applying either no governance or the same uniform review process to every AI use case regardless of its actual risk level.
Use when an organization needs an ongoing process to verify that users' system and data access remains appropriate over time — running periodic access recertification campaigns where accountable managers explicitly confirm or revoke each user's access, rather than granting access once and never systematically reviewing whether it's still needed.
Use when an organization's data governance policy exists on paper but no specific person is actually accountable for a given data domain's quality, definitions, and appropriate use — assigning named data stewards to specific data domains with clear accountability, rather than leaving data quality and definitional consistency as an unowned, organization-wide responsibility.
Use when an organization's technology investment decisions are made ad hoc by whichever team has the loudest voice or the most urgent request — establishing an IT steering committee with defined authority to prioritize technology investments against business strategy and evaluate major project proposals, rather than letting technology spending decisions happen without a structured, cross-functional decision process.
Use when a public company needs board-level cybersecurity risk governance and disclosure meeting SEC requirements — establishing defined board oversight of cyber risk, a documented incident materiality-assessment process, and required disclosure of both governance practices and material incidents, rather than treating cybersecurity purely as a technical, management-level function with no board accountability structure.
Use when a financial institution or money-services business needs an anti-money-laundering compliance program — building it around the specific pillars required under the Bank Secrecy Act (written policies, a designated compliance officer, ongoing training, independent testing, and customer due diligence), rather than a generic fraud-prevention policy with no BSA-specific structure.
Use when a financial institution or similarly regulated organization relies on quantitative models for decisions with material financial consequences — establishing independent model validation, a model inventory with defined ownership, and ongoing performance monitoring, rather than treating a model as trustworthy simply because it was built by a competent team.
Use when a company's corporate treasury function manages cash, debt, hedging, or counterparty relationships without formal board-level authorization limits — establishing defined authority thresholds for treasury decisions, approved counterparty and instrument lists, and board or committee oversight of treasury risk, rather than leaving treasury decisions to management discretion with no defined governance boundary.
Use when two or more companies are forming a joint venture and need to structure its governance in the JV agreement — defining board or management committee composition, veto rights over major decisions, and a specific deadlock-resolution mechanism, rather than assuming ordinary majority-rule governance will function adequately for a structure with only a small number of equally-invested partners.
Use when a public company is designing executive compensation and preparing for the required periodic shareholder advisory vote on that compensation — structuring pay to demonstrate a genuine link between compensation and company performance, and responding substantively if the advisory vote result is weak, rather than treating the vote as a formality unconnected to actual pay decisions.
Use when a company's board wants to systematically evaluate its own performance — running a structured self-assessment of the full board, individual directors, and committees on a regular cycle, rather than relying on informal impressions of how well the board is functioning.
Use when a company is entering, or reviewing whether it has properly reviewed, a transaction involving a director, officer, significant shareholder, or their close associates — requiring independent-committee review and approval before the transaction proceeds, rather than allowing an interested party to approve or influence approval of a transaction that benefits them.
Use when a company operating internationally needs a compliance program addressing bribery and corruption risk under the FCPA, UK Bribery Act, or similar anti-corruption laws — implementing risk-based third-party due diligence, defined approval thresholds for gifts and hospitality, and a documented program structure prosecutors will actually credit, rather than a generic ethics policy with no anti-corruption-specific rigor.
Use when a company competing in a concentrated market needs a compliance program preventing antitrust and competition law violations — training employees on specific prohibited conduct (price-fixing agreements, market allocation, bid-rigging), restricting improper information exchange with competitors, and documenting the program's operation, rather than a generic ethics statement with no antitrust-specific content.
Use when establishing or reviewing a public company's audit committee — setting the committee's composition requirements (full independence, at least one financial expert), its specific oversight responsibilities over financial reporting and the external auditor, and documenting these in a formal charter, rather than treating audit oversight as an informal extension of general board duties.
Use when a company is setting board composition objectives or preparing required board diversity disclosures — establishing a genuine process for broadening the director candidate pool beyond incumbent networks and disclosing board diversity statistics per applicable exchange requirements, rather than treating diversity as an unstructured aspiration with no defined process behind it.
Use when composing or evaluating a public or pre-IPO company's board of directors — determining what fraction of the board must be independent directors, applying the specific criteria that disqualify a director from independent status, and structuring the independence-review process, rather than treating board composition as a purely informal or founder-controlled decision.
Use when a board wants to establish or evaluate its CEO succession planning process — maintaining both an emergency (sudden departure) succession plan and a longer-term planned-transition process, as a standing board fiduciary responsibility, rather than treating succession as something to address only once a CEO departure is imminent or has already occurred.
Use when a public company is establishing the mandatory policy for recovering erroneously awarded incentive-based executive compensation following an accounting restatement — applying the recovery requirement without regard to individual executive fault, and disclosing the policy and any recovery actions per SEC and exchange listing requirements, rather than treating clawback as a discretionary or fault-based decision.
Use when a company with a dual-class share structure (unequal voting rights between share classes, commonly used to let founders retain control after an IPO) is designing the structure's governance safeguards — including a time- or event-based sunset provision converting to a single class — rather than adopting a perpetual dual-class structure with no mechanism for eventual alignment between voting control and economic ownership.
Use when a board wants to establish a dedicated board-level committee (or full-board process) for overseeing the company's enterprise-wide risk profile — distinct from the audit committee's financial-reporting-specific mandate — integrating risk appetite, major risk categories, and management's risk response into a single board-level oversight function, rather than leaving enterprise risk oversight scattered across committees with no unifying view.
Use when a board is establishing formal board-level oversight of environmental, social, and governance risk and strategy — assigning clear committee ownership (a dedicated ESG/sustainability committee, or explicit allocation across existing committees) rather than leaving ESG oversight as an undefined, informally-shared responsibility with no single accountable body.
Use when a company exports goods, software, or technology internationally and needs a compliance program addressing export control classification, restricted-party screening, and licensing requirements under the EAR or ITAR — building automated screening into transaction workflows rather than relying on manual, case-by-case review that can't scale with transaction volume.
Use when a public company is establishing or reviewing its insider trading compliance policy — defining blackout periods around material non-public information, requiring pre-cleared Rule 10b5-1 trading plans for executives who want to trade on a schedule, and applying restrictions company-wide rather than relying on individual employees' personal judgment about what counts as material information.
Use when a public company is establishing or reviewing its nominating and corporate governance committee — the body responsible for board candidate identification, board composition planning, and oversight of the company's overall governance practices — writing a formal charter that separates this function from the audit and compensation committees rather than leaving governance oversight informally absorbed into another committee's mandate.
Use when establishing or evaluating a nonprofit organization's board governance — applying the specific fiduciary duties (care, loyalty, obedience to mission) and structural practices distinct from for-profit corporate governance, since a nonprofit board answers to its mission and the public interest rather than to shareholders, rather than applying a for-profit governance template unchanged.
Use when a board is considering adopting a shareholder rights plan (poison pill) to defend against an unsolicited takeover attempt or rapid stock accumulation — setting a defensible triggering threshold, a limited duration with a defined expiration, and a genuine, disclosed strategic rationale, rather than adopting an indefinite, low-threshold pill purely to entrench current management against any future challenge.
Use when a company is adopting or amending a proxy access bylaw — the provision allowing qualifying shareholders to nominate director candidates directly on the company's own proxy statement — setting ownership and holding-period thresholds consistent with market-standard private-ordering practice, rather than setting thresholds so restrictive that the provision offers no genuine access in practice.
Use when a company doing business internationally needs a sanctions compliance program addressing OFAC and equivalent restrictions — building the program around the five components OFAC has explicitly defined as essential, including automated screening and periodic testing, rather than an ad hoc process without OFAC's specific structural expectations built in.
Use when a board faces a transaction where a controlling shareholder, director, or officer has a conflicting personal interest — a going-private buyout, a related-party acquisition, a squeeze-out merger — forming an independent special committee with its own advisors and genuine negotiating authority to satisfy the heightened judicial scrutiny these transactions receive, rather than having the full board (including the conflicted party) approve the deal directly.
Use when a public company needs to comply with SEC and CFTC whistleblower bounty program requirements — ensuring internal policies, employment agreements, and settlement terms don't impede an employee's ability to report directly to regulators or receive a bounty award, distinct from designing the company's own internal speak-up culture and reporting channel.