skills/ai-governance-reviewer-carl-ditzler/SKILL.md
Use this skill when the user wants an AI governance, legal-risk, privacy, compliance, procurement, or vendor-risk review of an internal AI use case, an AI product feature, an LLM workflow, or a third-party AI vendor. The skill asks intake and clarifying questions first when facts or evidence are missing, identifies required documentation and missing evidence, maps the use case to AI governance frameworks and applicable legal domains, and produces a preliminary or final governance review with scorecards, findings, owners, remediation actions, and follow-up questions.
npx skillsauth add lawvable/awesome-legal-skills ai-governance-reviewer-carl-ditzlerInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill for draft AI governance reviews involving:
This skill supports governance, privacy, security, procurement, and legal preparation. It does not provide legal advice.
LEGAL DISCLAIMER Always include this disclaimer in the response:
This review assists with AI governance processes and does not replace a formal AI Governance, legal review or professional legal representation. This output is a draft and may contain errors or omissions. Verify all conclusions against company policies, primary regulatory sources, and with appropriate internal legal, privacy, security, and compliance teams. This is not legal advice.
references/frameworks.md rather than relying on external URLs.references/frameworks.md.Use sources in this order:
references/official/ legal source filesreferences/working/ legal source filesreferences/frameworks.md, references/responsible-ai-practice.md, and the scenario filesDo not let a lower-priority source override a higher-priority one.
Intake first is mandatory. If key facts or material evidence are missing, the first response must ask questions rather than provide a report.Preliminary Review route after the model has already asked the required intake questions and evidence requests and the user:
Identify the scenario.
Classify the request as Internal AI Use, Product AI Integration, Third-Party AI Vendor, or Hybrid / Multiple. Load the matching scenario reference file.
Run a structured intake before analysis. Start by asking for the core intake facts. If the user has not already provided them clearly, ask for:
When information is missing, the first response should look like this:
Use direct question wording such as:
What is the use case?Who are the intended users?What is your organization's role?What model or vendor is involved?Do not present the first intake as a long prose paragraph or a dense mixed bullet list. Do not ask the user to fill in a form, intake form, markdown table, evidence table, scorecard, matrix, or any other structured layout that requires editing the assistant's message. Every missing item must be asked as an explicit question inside the message so the user can reply directly in plain text.
First-turn sequencing rule:
Core Use Case block.Data and Deployment.Oversight and Testing.Governance Documents and Status.Vendor and Contracting if still relevant.If relevant supporting files already exist, ask for uploads or links in the turn where they become relevant rather than front-loading every document request in the first turn.
See references/example-outputs.md for examples.
The skill should actively question the user and gather information before producing a review. Do not skip this questioning step when material facts are missing. If the use case is incomplete, the next response should be a short question block for the current topic only and nothing more substantial.
Use the following mandatory clarifying topics where relevant:
System Overview
Organization Role
Model Information
Data Sources and Data Types
Deployment
Oversight
Testing and Monitoring
AI Impact Assessment
Privacy and Data Protection
Transparency and User Awareness
Assurance and Operations
Batch questions sensibly:
There is no hard maximum question count. If additional follow-up questions are needed to proceed, then ask them explicitly as questions, rather than dropping them, compressing them into a table, or omitting them.
Topic blocks may include:
Core Use CaseData and DeploymentOversight and TestingGovernance Documents and StatusVendor and ContractingExamples of missing evidence to request before drafting:
When requesting these items, ask the user to provide them by file upload or link and to state whether each item is completed, in progress, not started, or unknown.
Do this in the Governance Documents and Status turn, not in the first intake turn unless the user already asked about document readiness.
If the user cannot provide the evidence after being asked, state that the review will remain preliminary and use Unknown where needed.
Preliminary Review as the first fallback when information is missing.Preliminary Review with Unknown entries instead of a final review.Escalate strongly for legal, privacy, security, or executive review when the use case involves:
references/working/*.md file and a bundled references/official/*.pdf file exist for the same framework, use the working Markdown file for search and drafting efficiency, but treat the official PDF as controlling if there is any mismatch in wording, numbering, or scope.Do not issue a final approval, go-live recommendation, or high-confidence low-risk conclusion unless all of the following are addressed:
Preliminary Review until after the intake-first step has happened and the user cannot or will not provide more information.Final Review only when the output gate is satisfied.Unknown rather than guessing.High confidence when critical facts, testing evidence, approvals, or documentation are missing.development
Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
development
Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DIB). Use this skill whenever a user asks about CMMC 2.0, CMMC Level 1, Level 2, or Level 3, DoD cybersecurity compliance, NIST SP 800-171, CUI (Controlled Unclassified Information) protection, System Security Plan (SSP), Plan of Action & Milestones (POA&M), C3PAO assessments, DIBCAC audits, self-assessment, SPRS score, or any requirement under DFARS 252.204-7012 or 7021. Also trigger for: "CMMC gap analysis", "CMMC readiness", "FCI protection", "CUI scoping", "CMMC practices", "DoD contract cybersecurity", "defense supply chain security", or "prime contractor flow-down requirements".
tools
Build a client instruction schedule — a plain-English, Scott Schedule-style Word table that gathers a struggling client's evidence and instructions issue by issue, with a one-page covering note. Use whenever the user asks for a "client instruction schedule", "instruction schedule", "client questionnaire", "schedule of questions for the client", "get instructions from the client on the papers", or says the client is overwhelmed and needs the case broken into manageable questions. Also trigger when asked to turn case papers into a structured request for client input. Do NOT use for court-facing Scott Schedules, pleadings, witness statements, or advice letters — this skill produces a client-facing working document only. Output is always a .docx draft for solicitor review, never a final document.
tools
Turn complex legal analysis into clear, commercially useful client-facing advice. Use this whenever the user has dense legal material — drafting, internal analysis, counsel notes, research memos, pleadings, a case update, or correspondence — and wants it converted into something a client can actually understand and act on. Trigger on phrases like 'explain this to the client', 'put this in plain English', 'translate this for a non-lawyer', 'turn this into client-facing advice', 'make this client-ready', 'draft a client update', or when the user shares legal analysis and asks 'what does this mean for them'. Also trigger when the user wants a board summary, litigation risk update, or call script derived from legal material. The skill preserves legal nuance, uncertainty, and risk rather than oversimplifying — it makes advice usable, not just simpler.