skills/legal/compliance-summaries/SKILL.md
Generates structured compliance summaries assessing regulatory posture, identifying gaps, and producing prioritized remediation roadmaps across finance (SEC, FINRA), healthcare (HIPAA, FDA), environmental (EPA), and data privacy (GDPR, CCPA) sectors. Use when drafting regulatory compliance reports, audit readiness assessments, or governance documents for executives, boards, or regulators. For sector-specific depth, defer to dedicated sibling skills (environmental-regulation-summaries, hipaa-privacy-notice, fcpa-compliance-policy, etc.).
npx skillsauth add casemark/skills compliance-summariesInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Produces a governance-ready compliance summary with gap analysis and prioritized remediation roadmap. Outputs target dual audiences: board-level oversight and operational compliance teams.
This skill produces cross-sector compliance summaries. For sector-specific depth, defer to:
environmental-regulation-summaries (CAA / CWA / RCRA / CERCLA / NEPA / ESA / TSCA), phase-i-esa (Phase I ESA), consent-decree-epa (federal enforcement settlements), nov-response (regulatory NOVs).hipaa-privacy-notice, hipaa-baa, hipaa-release, cpom-compliance, stark-law-aks-compliance.bsa-risk-assessment, aml-compliance-program, cip-policy, reg-bi-policy, fcpa-compliance-policy.ccpa-policy, gdpr-data-processing-addendum, data-retention-and-destruction-policy, breach-notification, wisp.c-tpat-security-profile, dd-form-254, oci-mitigation-plan, subcontracting-plan.Before drafting, confirm:
| Field | Content | |---|---| | Overall Posture | Compliant / Substantially Compliant / Non-Compliant / Under Active Regulatory Scrutiny | | Top 3 Risks | Ranked by severity and regulatory exposure | | Immediate Action Items | Items requiring executive or board attention now | | Review Period | Date range covered |
Write accessibly for non-lawyers. Detailed sections may use technical regulatory terminology.
For each applicable requirement, organize by regulatory domain (e.g., SEC/FINRA, HIPAA/FDA, EPA, CCPA/GDPR) or by business unit:
| Requirement | Citation | Obligation | Responsible Party | Deadline/Frequency | Penalty Exposure | |---|---|---|---|---|---|
For each requirement in the matrix:
Evaluate whether the organization has:
Track upcoming deadlines in a table covering: license/cert renewals, pending audits/exams, and upcoming regulatory changes requiring program modification. Include item, type, deadline, owner, and status.
Rank remediation by: (1) regulatory deadline, (2) risk severity, (3) resource availability, (4) workstream dependencies.
| Priority | Action | Owner | Target Date | Success Metric | |---|---|---|---|---|
[VERIFY][VERIFY as of YYYY-MM-DD] marker and recommend re-verification within 90 days.development
name: automated-contract-summary language: en description: Generates structured executive summaries of contracts using ML — captures key terms, party obligations, risk allocations, and compliance requirements in a standardized format. Optimized for high-volume review where speed and consistency matter. tags: - summarization - agreement - corporate --- # Automated Contract Summarization Produces standardized executive summaries of contracts using machine learning, capturing essential term
tools
Extracts regulatory obligations from dense regulations across jurisdictions. Breaks down multi-level regulations into clear article-level obligations, classifies applicability to a business, and prioritizes by risk level. Use when translating regulations into actionable compliance requirements.
development
Continuously monitors regulatory landscapes for changes relevant to a specific business. Ingests global regulatory updates, filters by relevance, summarizes impact, and produces an actionable change advisory. Use when tracking regulatory developments affecting a particular product or market.
testing
Compares an organization's existing compliance controls, policies, and procedures against extracted regulatory obligations to identify coverage gaps. Produces a remediation plan with prioritized actions. Use when assessing compliance maturity or preparing for regulatory audits.