A fintech lending platform compliance manual should address core consumer-lending compliance topics such as anti-money-laundering controls, military-borrower verification timing, privacy rights procedures, fair-lending monitoring, service-provider oversight, and baseline disclosure and unfair-practices obligations.
Scanned 9/11/2026
Install to Claude Code
npx -y skills add sunyifeisb-art/legalwork --skill draft-fintech-lending-platform-compliance-policy-manual --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Draft Fintech Lending Platform Compliance Policy Manual?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/sunyifeisb-art-draft-fintech-lending-platform-compliance-policy-m)More formats (shields.io, HTML) on the badges page.
---
name: ecvc-draft-fintech-lending-compliance-manual
task_id: emerging-companies-venture-capital/draft-fintech-lending-platform-compliance-policy-manual
description: A fintech lending platform compliance manual should address core consumer-lending compliance topics such as anti-money-laundering controls, military-borrower verification timing, privacy rights procedures, fair-lending monitoring, service-provider oversight, and baseline disclosure and unfair-practices obligations.
activates_for: [planner, solver, checker]
---
# Skill: Draft Fintech Lending Platform Compliance Policy Manual
## 1. Subject-matter triage
- Confirm the platform’s product mix, borrower population, state footprint, funding model, and role allocation before drafting; the manual should reflect only the laws and activities actually in scope.
- Separate policies that apply to the platform as lender, servicer, marketer, broker, or data processor, and make the responsibility allocation explicit where functions are outsourced.
- If the platform lends or services across jurisdictions, address licensing, registration, and notice obligations by jurisdictional category rather than as a generic nationwide statement.
- Draft the manual as a board-ready operating document, not a law summary: it should tell personnel what to do, who does it, when it happens, and how it is monitored.
## 2. Failure modes the skill is correcting
- The manual stays at a high-level consumer-protection summary and never converts identified gaps into operative policy language.
- Third-party lead generation, servicing, and other outsourced functions are described informally but not governed through onboarding, contract controls, and ongoing monitoring.
- AML, military-borrower verification, privacy rights, fair-lending review, and disclosure obligations are mentioned but not built into a coherent control structure.
- The document omits escalation paths, ownership, recordkeeping, training, testing, and board oversight, leaving compliance duties unassignable.
- The manual does not distinguish baseline requirements from product-specific or jurisdiction-specific overlays, which makes it difficult to use as a standalone compliance reference.
## 3. Legal frameworks / domain conventions that apply
- Write the manual against the controlling authorities that actually apply to the platform’s model, including federal consumer-finance law, state lending and licensing regimes, privacy law, AML obligations where applicable, and unfair-practices prohibitions.
- Where AML obligations apply, use a standalone program structure consistent with Bank Secrecy Act requirements and their implementing rules, including a written program, internal controls, designated compliance authority, independent testing, and training.
- Where military-borrower verification is required, state the timing rule, approved-source rule, and refresh rule in policy form tied to the applicable consumer-credit framework.
- For privacy, include consumer-rights intake, identity verification, response timing, notice obligations, opt-out handling, and vendor data-use limits as applicable to the platform’s threshold and data practices.
- For fair lending, treat monitoring as an ongoing control under the Equal Credit Opportunity Act and Regulation B, with documented methods for measuring pricing, approval, and terms disparities and for remediating outliers.
- For disclosures and unfair practices, draft against the Truth in Lending Act, Regulation Z, state analogues, and the prohibition on unfair, deceptive, or abusive acts or practices under the relevant federal consumer-finance authority.
- For third-party oversight, impose diligence, contractual safeguards, audit rights, remediation rights, and termination authority for material vendors, including lead sources and servicers.
- Cite the controlling authority for each substantive obligation in the body of the manual or in the policy headings so the manual can stand alone as an implementable compliance instrument.
## 4. Analytical scaffolds
- Start each topic section with the governing requirement, then convert it into company policy, then operating procedures, then accountable roles, then monitoring and testing.
- For each control area, identify the trigger, the decision point, the required evidence, the escalation threshold, and the record retention expectation.
- Draft the AML section as if it could be reviewed independently: scope, risk assessment, internal controls, suspicious activity workflow, escalation, testing, training, and board reporting.
- Draft military-borrower verification so the application-stage check, any stale-result refresh, and any exception handling are unambiguous.
- Draft privacy-rights procedures as an end-to-end workflow: intake, identity verification, logging, substantive review, response deadlines, appeal or correction handling where applicable, and vendor coordination.
- Draft fair-lending controls as a repeatable monitoring program that specifies inputs, methodology, cadence, review owner, escalation path, and corrective action.
- Draft vendor-management controls so onboarding diligence, contract terms, periodic review, issue remediation, and termination rights are all described as operating obligations rather than best efforts.
- If a topic depends on a factual predicate not shown in the source materials, state the conditional policy structure and avoid overclaiming applicability.
- Use operative language throughout: “must,” “shall,” “may only if,” and “is responsible for,” rather than descriptive prose.
## 5. Vertical / structural / temporal relationships
- Track each policy vertically from board oversight to management ownership to frontline execution so accountability is visible at every level.
- Distinguish pre-origination controls, underwriting-time controls, closing/funding controls, post-origination servicing controls, and periodic review controls.
- Where time-sensitive compliance exists, anchor the policy to the operative event: application receipt, underwriting decision, origination, funding, servicing transfer, complaint receipt, or rights request.
- For delayed originations or stale data, specify when a refreshed verification or re-review is required and who authorizes any exception.
- For outsourced activities, define the relationship between the platform’s obligations and the vendor’s performance, including oversight, reporting, and remediation timelines.
- For boards and committees, specify what gets reported, how often, and what corrective action authority they hold.
## 6. Output structure conventions
- Organize the manual by regulatory topic with a table of contents and clear section headings suitable for board review.
- In each topic, use this sequence: governing requirement, company policy, procedures, responsible personnel, monitoring/testing, and records.
- Include a standalone AML section with enough detail to function as an independent policy and procedure set.
- Include a standalone third-party oversight section covering lead generators, servicers, and other material service providers.
- Include a standalone privacy rights section only to the extent privacy law applies to the platform’s data practices and footprint; if applicability is conditional, state the condition explicitly.
- Include a standalone fair-lending section with review cadence, analytic inputs, escalation, remediation, and board reporting.
- Include a standalone disclosures/unfair-practices section that addresses required consumer disclosures, marketing constraints, complaint handling, and prohibited practices.
- If licensing or registration obligations vary by state or product type, present them as an implementation rule, not a generic legal note.
- Make the manual operational: each control should identify the owner, the step, the trigger, the evidence kept, and the escalation path.
- Keep the tone formal and board-ready; avoid filler, citations without implementation, or abstract legal commentary detached from policy action.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!