Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Conducting Compliance Risk Assessments

ASecurity

Structures compliance risk assessment with regulatory inventory and inherent/residual risk evaluation. Use when assessing compliance risk, inventorying regulatory obligations, or prioritizing compliance resources.

22 stars
0 votes
0 copies
0 views
Added 9/20/2026
businesstestingdocumentation

Security Analysis

A100/100

Scanned 9/20/2026

Install to Claude Code

$npx -y skills add lev-os/agents --skill conducting-compliance-risk-assessments --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Conducting Compliance Risk Assessments?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Conducting Compliance Risk Assessments
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lev-os-conducting-compliance-risk-assessments/badge)](https://www.skillsdirectory.com/skills/lev-os-conducting-compliance-risk-assessments)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: conducting-compliance-risk-assessments
description: Structures compliance risk assessment with regulatory inventory and inherent/residual risk evaluation. Use when assessing compliance risk, inventorying regulatory obligations, or prioritizing compliance resources.
tags:
  - process
  - financial-compliance
  - compliance
  - regulatory
metadata:
  author: casemark
  practice_areas:
    - Regulatory Compliance
    - Financial Regulation
    - Compliance
  document_types:
    - Process Documentation
  skill_modes:
    - Process Management
---
# Conducting Compliance Risk Assessments

## When To Use

- Performing periodic (annual, quarterly) compliance risk assessments for a regulated entity
- Onboarding a new regulatory obligation and evaluating its risk impact
- Prioritizing compliance resources across multiple regulatory domains (AML/BSA, consumer protection, fair lending, privacy, sanctions)
- Responding to regulatory examination findings, enforcement actions, or audit gaps
- Evaluating compliance risk exposure after organizational changes (new products, market entry, M&A)

## Inputs To Gather

- **Entity profile**: charter type, asset size, business lines, geographic footprint, customer segments
- **Regulatory inventory**: all applicable statutes, regulations, and guidance (federal, state, international) [VERIFY jurisdiction-specific requirements]
- **Prior assessment results**: previous risk ratings, audit findings, exam results, MRAs/MRIAs
- **Control documentation**: policies, procedures, training records, monitoring/testing reports
- **Incident data**: regulatory violations, complaints, SARs filed, enforcement actions, litigation
- **Organizational changes**: new products/services, market expansions, system migrations, staffing changes since last assessment
- **Risk appetite statement**: board-approved risk tolerance thresholds

## Workflow

1. **Define scope and methodology**
   - Identify assessment boundaries (enterprise-wide vs. business-line specific)
   - Select risk rating framework: typically a matrix scoring likelihood (1-5) x impact (1-5)
   - Establish rating definitions — anchor each level to concrete indicators (e.g., "4 = regulatory action within 12 months is probable")
   - Confirm assessment period and reporting timeline

2. **Build the regulatory inventory**
   - Catalog every applicable law, regulation, and regulatory guidance document
   - Map each obligation to responsible business line(s) and compliance owner
   - Flag recently enacted or amended regulations [VERIFY effective dates and transition periods]
   - Note cross-border obligations for entities operating in multiple jurisdictions [VERIFY local registration and licensing requirements]

3. **Assess inherent risk per obligation**
   - For each regulatory obligation, rate inherent risk (risk before controls) across dimensions:
     - **Likelihood**: volume/complexity of covered activity, pace of regulatory change, historical violation frequency
     - **Impact**: potential fines/penalties, reputational harm, operational disruption, customer harm
   - Weight factors by materiality — a high-volume activity under active regulatory scrutiny warrants elevated scoring
   - Document rationale for each rating; avoid unsupported "medium" defaults

4. **Evaluate control effectiveness**
   - For each obligation, assess the design and operating effectiveness of existing controls:
     - Policies and procedures: current, approved, accessible to staff
     - Training: frequency, completion rates, content relevance
     - Monitoring and testing: scope, frequency, deficiency tracking
     - Issue management: timely remediation, root-cause analysis, escalation protocols
   - Rate control strength (strong / satisfactory / weak) with supporting evidence
   - Flag control gaps or untested controls explicitly

5. **Calculate residual risk**
   - Residual risk = inherent risk adjusted for control effectiveness
   - Where controls are strong, residual risk may drop 1-2 levels below inherent; where controls are weak or absent, residual risk remains at or near inherent levels
   - Highlight any obligation where residual risk exceeds the board-approved risk appetite

6. **Prioritize and recommend**
   - Rank obligations by residual risk score to produce a heat map or tiered priority list
   - For high and critical residual risks, draft specific remediation recommendations:
     - Control enhancements (new monitoring, additional testing, policy updates)
     - Resource allocation (staffing, technology, budget)
     - Timeline and accountability (owner, target completion, milestone checkpoints)
   - Identify emerging risks (pending regulations, industry trends) for forward-looking planning

7. **Validate and finalize**
   - Circulate draft assessment to business-line risk owners for challenge and concurrence
   - Incorporate feedback; document material disagreements and resolution
   - Present final assessment to senior management and board/committee for approval

## Output

The final deliverable should include:

- **Executive summary**: overall compliance risk posture, key themes, top residual risks
- **Regulatory inventory table**: obligation, applicable law/rule, business line, compliance owner
- **Risk assessment matrix**: each obligation with inherent risk score, control rating, residual risk score, and rating rationale
- **Heat map or dashboard**: visual representation of residual risk distribution across obligations
- **Remediation plan**: prioritized action items for high/critical risks with owners and deadlines
- **Appendices**: methodology description, rating scale definitions, data sources, prior-period comparison

## Quality Checks

- Every regulatory obligation in the inventory has a corresponding inherent and residual risk rating — no gaps
- Rating rationales are specific and evidence-based, not boilerplate
- Control assessments reference actual testing or monitoring results, not just policy existence
- Residual risk scores logically follow from the inherent risk and control effectiveness pairing
- High residual risks each have a documented remediation recommendation with owner and timeline
- Assessment methodology and rating scales are consistent with prior periods (or changes are explained)
- All jurisdiction-dependent obligations are tagged with [VERIFY] where applicability may vary
- Final output has been reviewed by at least one subject-matter compliance officer before submission

Attribution

lev-oslev-os
View sourceMore from lev-os →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Solution Architect

Designs system architecture, component specifications, and technical integration strategy. Use when: designing solutions, system architecture, technology stack, or integration approaches.

192 votes

Akorchak:Venture Assessment

Generate a comprehensive VC investment assessment report for a company

72 votes

Stock Analysis

Analyze stocks and cryptocurrencies using Yahoo Finance data. Supports portfolio management (create, add, remove assets), crypto analysis (Top 20 by market cap), and periodic performance reports (daily/weekly/monthly/quarterly/yearly). 8 analysis dimensions for stocks, 3 for crypto. Use for stock analysis, portfolio tracking, earnings reactions, or crypto monitoring.

6511 votes

Just Fucking Cancel

Find and cancel unwanted subscriptions by analyzing bank transactions. Detects recurring charges, calculates annual waste, and helps you cancel with direct URLs and browser automation. Use when: 'cancel subscriptions', 'audit subscriptions', 'find recurring charges', 'what am I paying for', 'save money', 'subscription cleanup', 'stop wasting money'. Supports CSV import (Apple Card, Chase, Amex, Citi, Bank of America, Capital One, Mint, Copilot) OR Plaid API for automatic transaction pull. Out...

6511 votes

Telegram Compose

Compose rich, readable Telegram messages using HTML formatting via direct Telegram API. Use when: (1) Sending any Telegram message beyond a simple one-line reply, (2) Creating structured messages with sections, lists, or status updates, (3) Need formatting unavailable via Clawdbot's Markdown conversion (underline, spoilers, expandable blockquotes, user mentions by ID), (4) Sending alerts, reports, summaries, or notifications to Telegram, (5) Want professional, scannable message formatting wit...

6511 votes
View all in business →