Agents address the main substantive code topics but omit specific off-channel communications policy requirements arising from a government enforcement context, phase-specific compliance deadlines for supply chain due diligence directives, employee monitoring consultation requirements in jurisdictions with co-determination rights, and the correct scope of clawback coverage linked to applicable securities law.
Scanned 9/11/2026
Install to Claude Code
npx -y skills add sunyifeisb-art/legalwork --skill draft-updated-code-of-conduct --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Draft Updated Code Of Conduct?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/sunyifeisb-art-draft-updated-code-of-conduct)More formats (shields.io, HTML) on the badges page.
---
name: draft-updated-code-of-conduct
task_id: corporate-governance/draft-updated-code-of-conduct
description: Agents address the main substantive code topics but omit specific off-channel communications policy requirements arising from a government enforcement context, phase-specific compliance deadlines for supply chain due diligence directives, employee monitoring consultation requirements in jurisdictions with co-determination rights, and the correct scope of clawback coverage linked to applicable securities law.
activates_for: [planner, solver, checker]
---
# Skill: Updated Corporate Code of Business Conduct and Ethics
## 2. Failure modes the skill is correcting
- Baseline updates the code at a high level but misses the need to address the specific conduct that triggered prior scrutiny, including any communication channel or record-retention practice implicated by the source documents.
- Baseline treats supply-chain due diligence as a generic ethics topic and omits the company-specific implementation phase, effective date, and supplier rollout sequence required by the governing EU framework.
- Baseline drafts monitoring language as if the company can unilaterally deploy surveillance tools everywhere, without conditioning use on privacy, labor, and co-determination processes where required.
- Baseline describes clawback coverage loosely, creating ambiguity over who is covered under the securities-law listing standard and how the policy maps to executive-officer status.
- Baseline produces recommendations that are directionally right but not operationalized by role, timing, or dependency on external approvals or consultations.
## 3. Legal frameworks / domain conventions that apply
- **Code update after enforcement or self-report:** Where source materials show prior government scrutiny, a self-report, or a compliance commitment tied to the conduct at issue, the updated code should directly address that conduct rather than rely on generalized exhortations. The code should be specific enough to show remediation, retention, supervision, and escalation expectations.
- **SEC clawback rules:** Public-company clawback policies must track the applicable exchange-listing and securities-law framework for the covered executive-officer population. The code should identify the covered population accurately and avoid overbroad wording that suggests all employees are subject to the same recoupment regime.
- **DOJ compliance-program expectations:** An effective code should be tailored to the company’s actual risk profile and should address the misconduct areas surfaced in investigations, reporting, or monitoring. General compliance language is not enough if the source record indicates a known gap.
- **EU CS3D / supply-chain due diligence:** The code should require due diligence on adverse human-rights and environmental impacts across the supply chain, including supplier commitments, escalation, and remedy pathways. The operative deadline and rollout obligations depend on the company’s phase and scope.
- **Whistleblower and complaint-handling frameworks:** The code should align US audit-committee complaint procedures with applicable EU secure-reporting and anti-retaliation obligations where the company operates in both regimes.
- **Employee monitoring limits:** Monitoring of email, devices, and communications is a lawful-compliance tool only when implemented consistently with privacy, labor, and works-council or co-determination requirements where applicable. The code should not imply immediate deployment without required consultation or notice.
- **Controlling authority convention:** Legal propositions should be anchored to the governing statute, regulation, listing rule, or other controlling authority referenced in the source set or otherwise recognized for the issue.
## 4. Analytical scaffolds
- **Source-document gap review:** Read the current code and supporting materials as a package, then identify where the draft fails to translate a source-document risk, commitment, or prior incident into a concrete code obligation.
- **Conduct-specific drafting check:** For each conduct area raised by the source set, verify the code contains a direct rule, an exception if needed, an escalation path, and any retention or approval requirement.
- **Channel-use policy check:** If the source record involves messaging, device use, or off-channel communications, draft the prohibition or controlled-permission rule in operational terms that can be enforced and audited.
- **CS3D implementation check:** Determine from the source documents whether the company is in scope and which implementation phase applies; then align the supplier code language, internal ownership, and external communication sequence to that phase.
- **Monitoring-approval check:** If the draft includes employee monitoring, test it against privacy, labor, and consultation requirements before recommending rollout.
- **Clawback-scope check:** Confirm the policy maps to the covered executive-officer group under the applicable listing rule and does not imply a broader or narrower universe without support.
- **Multi-jurisdiction complaint-handling check:** Where the company operates in both US and EU regimes, ensure the code’s reporting section captures both complaint intake/retention expectations and confidentiality/non-retaliation protections.
## 5. Vertical / structural / temporal relationships
- **Prerequisite sequencing:** Some changes can be drafted immediately, while others depend on board approval, works-council or employee-representative consultation, or completion of regulatory or compliance review. The memo should separate these paths.
- **Rollout dependencies:** Supplier-code language, monitoring protocols, and reporting channels may require internal policy updates, training, and external communication before the revised code is effective for all populations.
- **Temporal alignment:** If the source documents indicate a statutory or phase-based deadline, the code and implementation plan should tie the revised language to that timing rather than a generic “prompt” rollout.
- **Population-specific application:** Distinguish provisions that apply company-wide from those that only apply to executives, monitored jurisdictions, high-risk suppliers, or certain reporting channels.
## 6. Output structure conventions
- **Memorandum to General Counsel:** Write as an advisory memo organized by topic: concise issue framing, gap analysis, drafting recommendations, and implementation guidance.
- **Issue-by-issue treatment:** For each substantive topic, state the gap, explain why it matters under the controlling framework, and give concrete drafting language direction rather than abstract policy advice.
- **Immediate vs contingent actions:** Separate revisions that can be made now from those that depend on external steps, and identify the responsible role and timing anchor for each recommended action.
- **Authority-led drafting:** When discussing a legal requirement, identify the governing authority by name and section or comparable identifier, then tie the recommendation back to the source documents.
- **Operational recommendations:** End with a practical action list that assigns ownership, sequencing, and deadline logic for code revision, approval, publication, training, and rollout.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!