Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Managing Compliance Testing

ASecurity

Designs and executes compliance testing programs with sampling methodology and findings documentation. Use when conducting compliance testing, designing test procedures, or documenting testing results.

22 stars
0 votes
0 copies
0 views
Added 9/20/2026
researchgotestingdocumentation

Security Analysis

A100/100

Scanned 9/20/2026

Install to Claude Code

$npx -y skills add lev-os/agents --skill managing-compliance-testing --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Managing Compliance Testing?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Managing Compliance Testing
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lev-os-managing-compliance-testing/badge)](https://www.skillsdirectory.com/skills/lev-os-managing-compliance-testing)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: managing-compliance-testing
description: Designs and executes compliance testing programs with sampling methodology and findings documentation. Use when conducting compliance testing, designing test procedures, or documenting testing results.
tags:
  - management
  - financial-compliance
  - compliance
metadata:
  author: casemark
  practice_areas:
    - Regulatory Compliance
    - Financial Regulation
    - Compliance
  document_types:
    - Management Report
  skill_modes:
    - Management
    - Coordination
---
# Managing Compliance Testing

## When To Use

- Designing a new compliance testing program for a regulatory requirement (AML/BSA, consumer lending, privacy, sanctions screening, etc.)
- Building or refining test procedures and sampling plans for periodic compliance reviews
- Executing a compliance test cycle and documenting findings, exceptions, and remediation items
- Preparing compliance testing reports for management, audit committees, or regulators
- Responding to regulatory examination findings that require enhanced testing protocols

## Inputs To Gather

- **Regulatory scope**: Specific regulations, rules, or internal policies being tested (e.g., Reg E, TILA-RESPA, OFAC, GDPR, SOX controls) [VERIFY applicable jurisdiction and current rule versions]
- **Testing universe**: Total population of transactions, accounts, processes, or controls subject to testing, with date range
- **Risk assessment**: Prior risk ratings, examination findings, audit results, or known deficiency areas that inform scope weighting
- **Sampling parameters**: Confidence level, margin of error, acceptable exception rate; or prescribed sample sizes from regulatory guidance [VERIFY if regulator mandates specific sample sizes]
- **Control documentation**: Existing policies, procedures, process maps, and control matrices for the areas under test
- **Prior test results**: Previous testing cycle findings, remediation status, and trend data
- **Stakeholder requirements**: Reporting audience (compliance committee, board, regulator) and deliverable format expectations

## Workflow

1. **Define testing scope and objectives**
   - Map each regulatory requirement or policy provision to testable control assertions
   - Prioritize testing areas using a risk-based approach — weight toward higher-risk products, channels, or geographies
   - Document scope inclusions, exclusions, and rationale

2. **Design sampling methodology**
   - Determine sampling approach: statistical (random, stratified, systematic) vs. judgmental (targeted, risk-based)
   - For statistical sampling, calculate minimum sample size using population size, confidence level (typically 90-95%), and tolerable error rate (typically 2-10%) [VERIFY against any regulator-prescribed minimums]
   - For judgmental sampling, document selection criteria and basis for sample size
   - Define data extraction procedures and source system(s)

3. **Develop test procedures**
   - Write step-by-step test scripts for each control assertion, specifying: what to inspect, the pass/fail criteria, data fields to capture, and how to document exceptions
   - Include attribute testing (binary pass/fail) and substantive testing (accuracy/completeness checks) as appropriate
   - Build a test workpaper template with columns for: item ID, sample attributes, test result, exception description, root cause category, and evidence reference

4. **Execute testing**
   - Extract sample population and select items per the methodology
   - Perform each test step, recording results contemporaneously in workpapers
   - Classify exceptions by severity: critical (regulatory violation with consumer harm), significant (control failure without immediate harm), minor (procedural deviation, low risk)
   - Escalate critical findings immediately to the Chief Compliance Officer or designated authority — do not wait for report finalization

5. **Analyze results and identify root causes**
   - Calculate exception rates per control area and compare against tolerable thresholds
   - Determine whether exceptions are isolated or systemic (pattern analysis across business units, time periods, or personnel)
   - Assign root cause categories: training gap, system limitation, policy ambiguity, process breakdown, third-party failure, or intentional override
   - Assess whether sample results can be projected to the full population (for statistical samples) or are indicative only (for judgmental samples)

6. **Document findings and remediation**
   - Draft findings with: condition (what was found), criteria (what was required), cause (root cause), effect (actual or potential impact), and recommendation
   - Assign remediation owners, target completion dates, and validation procedures
   - Rate overall compliance health for each tested area: satisfactory, needs improvement, or unsatisfactory

7. **Report and track**
   - Compile the testing report with executive summary, methodology description, detailed findings, and trending data versus prior periods
   - Present to designated governance body (compliance committee, audit committee, or board)
   - Enter remediation items into a tracking system with milestone dates and evidence requirements for closure
   - Schedule validation testing to confirm remediation effectiveness before closing findings

## Output

The deliverable is a **Compliance Testing Report** containing:

- **Executive summary**: Scope, period, overall results, and key themes
- **Methodology section**: Sampling approach, population sizes, sample sizes, confidence parameters, and any limitations
- **Findings detail**: Each finding in condition/criteria/cause/effect/recommendation format, with severity rating
- **Exception rate summary table**: By regulation, control area, and business unit
- **Trend analysis**: Comparison to prior testing cycles with directional indicators
- **Remediation tracker**: Open items with owners, due dates, and status
- **Appendices**: Sample selection log, workpaper references, and data source descriptions

## Quality Checks

- Confirm sample sizes meet or exceed any regulatory or internal audit minimums [VERIFY]
- Verify that test procedures map back to specific regulatory provisions or policy sections — no orphan tests
- Ensure every exception has a documented root cause category and remediation recommendation
- Check that severity ratings are applied consistently using the defined classification criteria
- Validate that exception rate calculations use the correct denominators (items tested, not population size, unless projecting)
- Confirm the report distinguishes between statistical projections and judgmental observations
- Review for completeness: all scope areas appear in findings (even if no exceptions — document "satisfactory" results)
- Verify remediation timelines are realistic and aligned with regulatory expectations [VERIFY any regulator-imposed deadlines]
- Ensure workpapers are retained per the organization's document retention schedule [VERIFY retention period requirements]

Attribution

lev-oslev-os
View sourceMore from lev-os →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Competitor Analysis

This skill provides comprehensive analysis of competitor SEO and GEO strategies, revealing what's working in your market and identifying opportunities to outperform the competition.

1823 votes

Deep Research

Universal deep research agent team. 13-agent pipeline for rigorous academic research on any topic. 7 modes: full research, quick brief, paper review, lit-review, fact-check, Socratic guided research dialogue, and systematic review with optional meta-analysis. Covers research question formulation, Socratic mentoring, methodology design, systematic literature search, source verification, cross-source synthesis, risk of bias assessment, meta-analysis, APA 7.0 report compilation, editorial review...

452202 votes

Paperclip Distill

Use when an operation issue is a Paperclip cursor-window, distill, or backfill — `operationType: "distill"` or `"backfill"` and the body references a Paperclip source bundle for a project or root issue. Turn raw Paperclip activity into a wiki-insightful project page, decisions log, and history note. This skill exists specifically to replace the stiff, datestamp-heavy templated output that the deterministic distiller produces.

805541 votes

Academic Pipeline

Orchestrator for the full academic research pipeline: research -> write -> integrity check -> review -> revise -> re-review -> re-revise -> final integrity check -> finalize. Coordinates deep-research, academic-paper, and academic-paper-reviewer into a seamless 10-stage workflow with mandatory integrity verification, two-stage peer review, and reproducible quality gates. Triggers on: academic pipeline, research to paper, full paper workflow, paper pipeline, end-to-end paper, research-to-publi...

452201 votes

Exa Search

Semantic search, similar content discovery, and structured research using Exa API

304951 votes
View all in research →