Reviewing a draft master services agreement against a contracting playbook, vendor management policy, and due diligence materials to produce a structured deviation report covering regulatory compliance and commercial risk.
Scanned 9/11/2026
Install to Claude Code
npx -y skills add sunyifeisb-art/legalwork --skill review-master-services-agreement-for-regulatory-compliance --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Review Master Services Agreement For Regulatory Compliance?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/sunyifeisb-art-review-master-services-agreement-for-regulatory-co)More formats (shields.io, HTML) on the badges page.
---
name: review-msa-regulatory-compliance
task_id: intellectual-property/review-master-services-agreement-for-regulatory-compliance
description: Reviewing a draft master services agreement against a contracting playbook, vendor management policy, and due diligence materials to produce a structured deviation report covering regulatory compliance and commercial risk.
activates_for: [planner, solver, checker]
---
# Skill: Review Master Services Agreement for Regulatory Compliance
## 1. Subject-matter triage (only if applicable)
- Treat the contract draft, playbook, vendor management policy, due diligence materials, and internal deal context as separate source layers and reconcile them in that order.
- If the sources identify multiple vendor categories, service lines, entities, jurisdictions, or time periods, enumerate them first and analyze each against the same framework rather than blending them into one pass.
- If the materials point to a single vendor, service scope, or regulatory regime, say so explicitly and proceed on that basis.
## 2. Failure modes the skill is correcting
- Reviewing the agreement for commercial risk without also testing the regulatory compliance obligations embedded in the vendor management policy and diligence record.
- Failing to cross-check diligence findings against representations, warranties, covenants, certifications, and notice obligations in the draft.
- Missing where the draft complies with the playbook in substance but still conflicts with policy-mandated controls, verification steps, or escalation requirements.
- Collapsing distinct issues into a generic “needs review” note instead of isolating the exact deviation, source, and consequence.
- Treating internal deal context as background only, rather than using it to calibrate risk severity where the documents show known issues or sensitivities.
- Stating that a provision is “noncompliant” or “insufficient” without identifying the governing rule, policy requirement, or authority that supports the conclusion.
- Failing to distinguish a missing clause from an inadequate clause, or a drafting deviation from a diligence mismatch.
- Producing commentary without a clear remediation path tied to the right business or legal owner.
## 3. Legal frameworks / domain conventions that apply
- The playbook is the primary drafting baseline; deviations should be measured against its preferred wording, fallback positions, and any mandatory points.
- Vendor management policies commonly require controls for regulatory compliance, information security, incident notice, audit/inspection access, records retention, business continuity, subcontractor control, and insurance verification.
- Diligence findings are not standalone background; they should be used to test whether draft representations, warranties, and covenants are accurate, complete, and proportionate to the risk profile.
- Regulatory compliance language in an MSA should usually require the vendor to comply with applicable law, maintain required approvals or registrations, report material enforcement actions or investigations, and cooperate with audits or remediation.
- Insurance review should compare the draft’s coverages, limits, exclusions, certificates, and notice mechanics to the policy minimums for the vendor category, not just to market custom.
- Internal emails or deal communications may evidence known operational, security, or regulatory issues; those facts should adjust the severity and recommended cure even if they are not themselves contractual text.
- Where a legal conclusion depends on a rule or authority, cite the controlling authority by name and section or other specific identifier recognized in the source materials or standard practice.
## 4. Analytical scaffolds
1. Build a source map: identify each governing document, the clause families it controls, and any hierarchy or conflict rule among them.
2. Read the draft clause by clause and compare each provision to the playbook position, noting whether the issue is omission, dilution, overreach, or inconsistency.
3. Compare the draft against the vendor management policy and identify any required protections that are absent, under-specified, or not verifiable.
4. Cross-reference diligence findings against the draft’s representations, warranties, covenants, disclosures, and termination rights to find mismatches.
5. Assess insurance, audit, security, incident response, data handling, subcontracting, continuity, and compliance-monitoring provisions against the policy baseline and diligence record.
6. Use internal deal context to grade severity, especially where the record shows prior incidents, unresolved concerns, time pressure, or heightened sensitivity.
7. For each issue, state: what the clause says, what the source material requires, why that matters for compliance or risk, and what language or action would cure it.
8. Separate true deviations from optional drafting preferences so the report stays focused on material compliance gaps and meaningful commercial exposure.
## 5. Vertical / structural / temporal relationships (only if applicable)
- Test whether the draft’s compliance obligations flow down to subcontractors, affiliates, and permitted delegates where the policy or diligence record expects that reach.
- Check whether notice, audit, certification, reporting, cure, and termination rights are aligned across the body of the agreement, schedules, exhibits, and any referenced policies.
- If the materials contain staged obligations, pre-signing conditions, post-signing certifications, periodic renewals, or renewal-triggered updates, track them in temporal order and flag any gap in timing.
- Identify whether a broad clause in one section is narrowed or contradicted by a later exception, disclaimer, limitation, or exhibit-specific carveout.
- Where a duty depends on a threshold event, confirm the trigger, the recipient, and the deadline are all stated with enough precision to be operational.
## 6. Output structure conventions
- Produce a structured deviation report, not a narrative memo.
- Begin with a short severity legend using an ordinal scale, and apply that same scale to every entry.
- Group findings by conventional compliance categories such as commercial terms, regulatory compliance, vendor-management controls, and representation accuracy.
- For each entry, include the clause reference, source material relied on, severity, the deviation or mismatch, the controlling rule or policy point, and the recommended fix.
- Where a finding depends on a legal or policy proposition, cite the governing authority or source by name and section or other specific identifier.
- Close each issue with the practical consequence to the client, including compliance, operational, litigation, transactional, or financial impact as appropriate.
- End with a concise Recommended Actions block that assigns each next step to the relevant role and a timing anchor tied to signing, redraft, diligence follow-up, or regulatory milestone.
- If the draft is being reviewed alongside a final output file, ensure the primary deliverable is the deviation report itself and that it is complete, non-empty, and usable without additional explanation.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!