Draft a comprehensive compliance policies and procedures manual for a registered investment adviser, addressing deficiencies and gaps identified across source materials such as examination reports, deficiency letters, risk alerts, and internal assessments.
Scanned 9/11/2026
Install to Claude Code
npx -y skills add sunyifeisb-art/legalwork --skill draft-compliance-manual --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Draft Compliance Manual?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/sunyifeisb-art-draft-compliance-manual)More formats (shields.io, HTML) on the badges page.
---
name: draft-compliance-manual
task_id: funds-asset-management/draft-compliance-manual
description: Draft a comprehensive compliance policies and procedures manual for a registered investment adviser, addressing deficiencies and gaps identified across source materials such as examination reports, deficiency letters, risk alerts, and internal assessments.
activates_for: [planner, solver, checker]
---
# Skill: Draft RIA Compliance Manual
## 1. Subject-matter triage
- Read the full source set first: examination reports, deficiency letters, risk alerts, internal assessments, mock exam materials, existing policies, Form ADV disclosures, advisory agreements, code of ethics, client agreements, custody and trading materials, marketing materials, and any board or committee materials.
- Separate findings into: immediate remediation items, policy-drafting items, disclosure alignment items, and open business decisions requiring management input.
- If the adviser has more than one strategy, client type, or regulated activity, identify each separately before drafting so the manual reflects the actual business model rather than a generic program.
## 2. Failure modes the skill is correcting
- Writing a generic manual that does not cure the specific deficiencies and gaps identified in the source materials.
- Omitting entire compliance domains that are material to the adviser’s business.
- Failing to distinguish urgent remediation from policy language that can be implemented in the normal drafting cycle.
- Drafting policies that conflict with Form ADV, advisory agreements, fund documents, or other governing disclosures.
- Addressing controls in abstract terms without stating who owns them, how they are escalated, and how they are reviewed.
- Treating one-off incidents as isolated when they imply a broader program failure needing written procedure.
- Leaving the manual without annual review mechanics, reporting structure, and documentation standards.
- Using boilerplate that does not reflect actual custody, trading, marketing, privacy, valuation, or supervision practices.
- Failing to anchor legal statements in the governing Advisers Act framework and related SEC rules.
## 3. Legal frameworks / domain conventions that apply
- A registered investment adviser must maintain written policies and procedures reasonably designed to prevent violation of the Advisers Act and related rules; the manual should be structured around that standard and the annual review requirement under Advisers Act Rule 206(4)-7.
- The manual should align with Form ADV Part 2A and other governing client disclosures; if the manual describes a practice not disclosed, the disclosure should be flagged for update.
- Portfolio management, trading, and allocation policies should address consistency with disclosed investment mandates, best execution, trade aggregation and allocation, and error handling.
- Personal trading and conflicts policies should reflect fiduciary duty principles and the adviser’s Code of Ethics obligations under Advisers Act Rule 204A-1.
- Advertising and marketing controls should track the SEC marketing rule under Advisers Act Rule 206(4)-1, including testimonials, endorsements, third-party ratings, hypothetical performance, and substantiation/recordkeeping expectations.
- Custody analysis should be grounded in Advisers Act Rule 206(4)-2, including standing instructions, qualified custodian arrangements, surprise examination or audit exceptions, and related notice and reporting obligations.
- Privacy and safeguarding procedures should address Regulation S-P, written privacy notices, and a safeguards program for customer information.
- Political contribution controls should address Advisers Act Rule 206(4)-5 and any de minimis, covered associate, contribution, refund, and cooling-off analysis.
- Soft-dollar and brokerage practices should address Exchange Act Section 28(e) safe-harbor analysis, mixed-use allocation documentation, and trade allocation fairness.
- Valuation procedures should require periodic re-pricing, stale-price escalation, multiple pricing sources for hard-to-value assets, and committee review where necessary.
- If the adviser or any supervised person has access to material non-public information, the manual should include restricted-list, information barrier, escalation, and trading pre-clearance procedures.
- Business continuity procedures should cover succession, systems recovery, alternative premises, communications, and vendor dependence.
- Cybersecurity procedures should address authentication, access control, phishing response, incident escalation, employee training, and data recovery.
- Recordkeeping procedures should map to the adviser’s books-and-records obligations under Advisers Act Rule 204-2 and preserve evidence of supervision, approvals, reviews, and exceptions.
## 4. Analytical scaffolds
- Draft from the source record, not from a template: for each policy area, ask what the adviser actually does, what the source documents criticize, and what procedure must exist to prevent recurrence.
- Where the source materials identify more than one deficiency, enumerate the relevant policy areas and address each one distinctly rather than compressing them into a single general statement.
- For each legal proposition, state the governing authority by name and section or rule citation, and tie the procedure to that authority rather than to a bare conclusion.
- Build each section around four elements: purpose, scope, operative controls, and documentation/escalation.
- Make the CCO’s reporting line explicit: who the CCO reports to, how independence is preserved, and how compliance decisions are reviewed or challenged.
- Include a trade-error workflow: identification, temporary containment, documentation, review, client impact analysis, remediation, and post-incident control changes.
- Where cybersecurity weaknesses appear in the source materials, add concrete controls for MFA, access provisioning, logging, vendor oversight, and incident response.
- Do not write policy language that assumes a control exists unless the manual also specifies the review, evidence, and owner for that control.
- Ensure every section is consistent with the adviser’s actual operations, disclosure set, and client contract framework.
## 5. Vertical / structural / temporal relationships
- Treat Form ADV, advisory agreements, fund documents, and internal procedures as a hierarchy: the manual must not authorize conduct broader than the disclosures or contracts permit.
- Where the source materials identify a current deficiency, separate immediate containment steps from long-term policy revisions and annual review follow-up.
- If the adviser’s business spans multiple client types, strategies, or custody arrangements, the manual should distinguish the controls that apply to each rather than collapsing them into one process.
- If a procedure depends on a periodic event, specify the interval, the trigger, and the escalation point so the control can be tested on a calendar basis.
- When one control depends on another, write the dependency explicitly, such as disclosure review before marketing use, pre-clearance before trading, or custody analysis before standing instructions are implemented.
## 6. Output structure conventions
- Produce a single compliance manual document suitable for `.docx` output.
- Use conventional manual headings rather than a rubric-like checklist structure.
- Begin with an introduction covering purpose, scope, governing authority, applicability, CCO designation, escalation, and annual review.
- Organize the body by functional compliance areas commonly used in adviser manuals, including portfolio management and trading, conflicts, personal trading and ethics, advertising and marketing, custody and asset safeguarding, proxy voting if applicable, brokerage and soft dollars, valuation, privacy, political contributions, information barriers and MNPI, recordkeeping, cybersecurity, business continuity, supervision, and annual review.
- For each section, include: policy statement, procedures, responsible role, monitoring/review, and records maintained.
- If a topic is not applicable, say so expressly and explain the basis briefly; do not leave silent gaps.
- Where the source materials reveal a deficiency, draft the policy to cure it directly rather than merely describing the issue.
- End with a concise implementation and review section that assigns ownership, sequencing, and periodic testing obligations.
- Use clear, operative language suitable for adoption by the adviser’s management and compliance function.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!