compliance-summaries

Generates structured compliance summaries assessing regulatory posture, identifying gaps, and producing prioritized remediation roadmaps across finance (SEC, FINRA), healthcare (HIPAA, FDA), environmental (EPA), and data privacy (GDPR, CCPA) sectors. Use when drafting regulatory compliance reports, audit readiness assessments, or governance documents for executives, boards, or regulators. For sector-specific depth, defer to dedicated sibling skills (environmental-regulation-summaries, hipaa-privacy-notice, fcpa-compliance-policy, etc.).

11 stars

Best use case

compliance-summaries is best used when you need a repeatable AI agent workflow instead of a one-off prompt.

Generates structured compliance summaries assessing regulatory posture, identifying gaps, and producing prioritized remediation roadmaps across finance (SEC, FINRA), healthcare (HIPAA, FDA), environmental (EPA), and data privacy (GDPR, CCPA) sectors. Use when drafting regulatory compliance reports, audit readiness assessments, or governance documents for executives, boards, or regulators. For sector-specific depth, defer to dedicated sibling skills (environmental-regulation-summaries, hipaa-privacy-notice, fcpa-compliance-policy, etc.).

Teams using compliance-summaries should expect a more consistent output, faster repeated execution, less prompt rewriting.

When to use this skill

  • You want a reusable workflow that can be run more than once with consistent structure.

When not to use this skill

  • You only need a quick one-off answer and do not need a reusable workflow.
  • You cannot install or maintain the underlying files, dependencies, or repository context.

Installation

Claude Code / Cursor / Codex

$curl -o ~/.claude/skills/compliance-summaries/SKILL.md --create-dirs "https://raw.githubusercontent.com/CaseMark/skills/main/skills/legal/compliance-summaries/SKILL.md"

Manual Installation

  1. Download SKILL.md from GitHub
  2. Place it in .claude/skills/compliance-summaries/SKILL.md inside your project
  3. Restart your AI agent — it will auto-discover the skill

How compliance-summaries Compares

Feature / Agentcompliance-summariesStandard Approach
Platform SupportNot specifiedLimited / Varies
Context Awareness High Baseline
Installation ComplexityUnknownN/A

Frequently Asked Questions

What does this skill do?

Generates structured compliance summaries assessing regulatory posture, identifying gaps, and producing prioritized remediation roadmaps across finance (SEC, FINRA), healthcare (HIPAA, FDA), environmental (EPA), and data privacy (GDPR, CCPA) sectors. Use when drafting regulatory compliance reports, audit readiness assessments, or governance documents for executives, boards, or regulators. For sector-specific depth, defer to dedicated sibling skills (environmental-regulation-summaries, hipaa-privacy-notice, fcpa-compliance-policy, etc.).

Where can I find the source code?

You can find the source code on GitHub using the link provided at the top of the page.

SKILL.md Source

# Compliance Summary

Produces a governance-ready compliance summary with gap analysis and prioritized remediation roadmap. Outputs target dual audiences: board-level oversight and operational compliance teams.

---

## Related skills

This skill produces cross-sector compliance summaries. For sector-specific depth, defer to:

- **Environmental** — `environmental-regulation-summaries` (CAA / CWA / RCRA / CERCLA / NEPA / ESA / TSCA), `phase-i-esa` (Phase I ESA), `consent-decree-epa` (federal enforcement settlements), `nov-response` (regulatory NOVs).
- **Healthcare** — `hipaa-privacy-notice`, `hipaa-baa`, `hipaa-release`, `cpom-compliance`, `stark-law-aks-compliance`.
- **Financial services** — `bsa-risk-assessment`, `aml-compliance-program`, `cip-policy`, `reg-bi-policy`, `fcpa-compliance-policy`.
- **Data privacy** — `ccpa-policy`, `gdpr-data-processing-addendum`, `data-retention-and-destruction-policy`, `breach-notification`, `wisp`.
- **Government contracts** — `c-tpat-security-profile`, `dd-form-254`, `oci-mitigation-plan`, `subcontracting-plan`.

## Prerequisites

Before drafting, confirm:

1. **Sector and jurisdiction** — finance, healthcare, environmental, data privacy, or other; federal, state, or international scope
2. **Source documents** — compliance policies, internal audits, regulatory correspondence, incident reports, consent orders, prior summaries
3. **Scope** — full enterprise, specific business unit, or defined regulatory domain

## Output Structure

### 1. Executive Summary

| Field | Content |
|---|---|
| Overall Posture | Compliant / Substantially Compliant / Non-Compliant / Under Active Regulatory Scrutiny |
| Top 3 Risks | Ranked by severity and regulatory exposure |
| Immediate Action Items | Items requiring executive or board attention now |
| Review Period | Date range covered |

Write accessibly for non-lawyers. Detailed sections may use technical regulatory terminology.

### 2. Regulatory Requirements Matrix

For each applicable requirement, organize by regulatory domain (e.g., SEC/FINRA, HIPAA/FDA, EPA, CCPA/GDPR) or by business unit:

| Requirement | Citation | Obligation | Responsible Party | Deadline/Frequency | Penalty Exposure |
|---|---|---|---|---|---|

### 3. Compliance Status Assessment

For each requirement in the matrix:

- **Status**: Compliant | Gap Identified | Deficiency | Unknown/Insufficient Evidence
- **Supporting Evidence**: policies, training records, audit results, certifications, filings
- **Gap Description**: specific deficiency with factual basis
- **Remediation**: action steps, owner, target date, resource estimate

### 4. Compliance Infrastructure Assessment

Evaluate whether the organization has:

- Designated compliance officer(s) with appropriate authority
- Board-approved compliance program and policies
- Regular risk assessments with defined frequency
- Employee training program with completion tracking
- Monitoring and auditing cadence
- Incident response and breach notification procedures
- Escalation path to senior management and board
- Regulatory examination readiness protocols

### 5. Temporal Compliance Calendar

Track upcoming deadlines in a table covering: license/cert renewals, pending audits/exams, and upcoming regulatory changes requiring program modification. Include item, type, deadline, owner, and status.

### 6. Prioritized Action Plan

Rank remediation by: (1) regulatory deadline, (2) risk severity, (3) resource availability, (4) workstream dependencies.

| Priority | Action | Owner | Target Date | Success Metric |
|---|---|---|---|---|

## Checks

- **Cite precisely** — include CFR sections, statute numbers, and agency guidance identifiers; flag uncertain citations with `[VERIFY]`
- **Distinguish evidence quality** — separate documented compliance from self-reported or assumed compliance
- **Flag gray areas** — note regulatory interpretive uncertainty; recommend regulator engagement or outside counsel review where applicable
- **Emerging regulations** — flag anticipated regulatory changes requiring future program modification
- **No legal advice** — frame as compliance assessment; note where legal counsel review is required before reliance

---

## Troubleshooting

- **Multi-sector target.** When the entity operates across multiple regulated sectors, build the matrix sector-by-sector (one block per sector) rather than collapsing into a single matrix. Sector-specific terminology and citation conventions matter; mixing them produces an unauditable summary.
- **Privileged audit findings cited as evidence.** Privileged internal-audit reports cited verbatim may waive privilege. Use neutral re-statements ("internal review identified...") and cite the underlying factual record. Flag the privilege question in a footnote.
- **Rapidly-changing regulatory environment.** For domains in active rulemaking (e.g., AI / data privacy state laws, environmental disclosure rules, SEC climate disclosure), use a `[VERIFY as of YYYY-MM-DD]` marker and recommend re-verification within 90 days.
- **Cite to non-binding guidance.** Distinguish statutes (binding) from regulations (binding when properly promulgated) from agency guidance (often non-binding). Misrepresenting guidance as binding is a common error in compliance summaries.
- **Overlapping federal and state regimes.** State analogs may exceed federal minimums (e.g., CCPA vs. federal privacy patchwork). Always check the state floor; do not treat federal compliance as a safe harbor.

Related Skills

preparing-transfer-summaries

11
from CaseMark/skills

Creates comprehensive transfer documentation for ICU-to-floor or facility-to-facility transitions. Use when transferring patients between units, preparing transfer notes, or coordinating level-of-care changes.

managing-telehealth-compliance

11
from CaseMark/skills

Evaluates telehealth program compliance with state licensing, prescribing, and reimbursement requirements. Use when assessing telehealth compliance, reviewing licensure requirements, or managing virtual care regulations.

managing-state-regulatory-compliance

11
from CaseMark/skills

Monitors state-specific healthcare regulatory requirements including licensing, reporting, and scope of practice. Use when tracking state regulations, managing licensure requirements, or monitoring regulatory changes.

managing-research-compliance

11
from CaseMark/skills

Monitors research compliance with federal regulations (21 CFR, 45 CFR 46) and institutional policies. Use when ensuring research compliance, managing regulatory requirements, or conducting compliance reviews.

managing-medical-records-compliance

11
from CaseMark/skills

Evaluates medical records practices against retention, access, and amendment requirements. Use when auditing medical records, managing record retention, or processing amendment requests.

managing-informed-consent-compliance

11
from CaseMark/skills

Evaluates informed consent practices against state law requirements and institutional policies. Use when auditing consent processes, reviewing consent form adequacy, or managing consent compliance.

managing-emtala-compliance

11
from CaseMark/skills

Evaluates emergency department practices against EMTALA requirements with documentation checklists. Use when assessing EMTALA compliance, reviewing MSE requirements, or documenting transfer obligations.

managing-compliance-programs

11
from CaseMark/skills

Structures OIG-model compliance program elements with effectiveness measurement and reporting. Use when building compliance programs, implementing OIG guidance, or measuring program effectiveness.

managing-compliance-audits

11
from CaseMark/skills

Structures coding compliance audit programs with sampling methodology and corrective action plans. Use when conducting compliance audits, designing audit samples, or implementing corrective actions.

managing-clinical-trial-compliance

11
from CaseMark/skills

Evaluates clinical trial regulatory compliance with FDA/IRB requirements and audit readiness. Use when auditing trial compliance, preparing for FDA inspections, or managing regulatory requirements.

managing-billing-compliance

11
from CaseMark/skills

Structures billing compliance programs with audit methodology and corrective action protocols. Use when auditing billing practices, managing compliance programs, or implementing corrective actions.

managing-accreditation-compliance

11
from CaseMark/skills

Tracks Joint Commission/HFAP/DNV accreditation standards compliance with survey preparation. Use when preparing for accreditation, tracking standards compliance, or managing survey readiness.