Legal & Compliance Expert
Comprehensive legal frameworks for governance, contracts, regulatory compliance, and risk management.
Corporate Governance
Board Structure & Responsibilities
BOARD COMPOSITION:
- Independent directors (majority required for NYSE/NASDAQ)
- Lead independent director
- Committee structure
- Board diversity requirements
- Skills matrix
KEY COMMITTEES:
1. Audit Committee (all independent)
2. Compensation Committee (all independent)
3. Nominating/Governance Committee (all independent)
4. Risk Committee (financial institutions)
Fiduciary Duties
| Duty |
Definition |
Key Considerations |
| Duty of Care |
Act with reasonable prudence |
Informed decisions, due diligence |
| Duty of Loyalty |
Act in corporation's best interest |
Avoid conflicts, corporate opportunity |
| Duty of Good Faith |
Act honestly and fairly |
No intentional harm, follow law |
| Duty of Disclosure |
Full and fair disclosure |
Material information, no omissions |
Business Judgment Rule
PROTECTION REQUIREMENTS:
1. Decision made in good faith
2. No personal interest in outcome
3. Reasonably informed decision
4. Rational belief action is in company's best interest
ENHANCED SCRUTINY (Revlon Duties):
- Triggered in change of control
- Duty to maximize shareholder value
- Active market check required
Regulatory Compliance
Sarbanes-Oxley (SOX) Compliance
KEY SECTIONS:
Section 302: CEO/CFO Certifications
- Certify financial statements
- Certify disclosure controls
- Report control deficiencies
Section 404: Internal Control Assessment
- Management assessment required
- External auditor attestation (accelerated filers)
- Material weakness disclosure
Section 906: Criminal Penalties
- Criminal certification of financial reports
- Up to $5M fine / 20 years imprisonment
COMPLIANCE FRAMEWORK:
- COSO Internal Control Framework
- Documentation of key controls
- Testing program (design + operating effectiveness)
- Deficiency evaluation process
- Remediation tracking
GDPR Compliance
| Requirement |
Description |
Penalties |
| Lawful Basis |
Consent, contract, legitimate interest |
Up to 4% global revenue |
| Data Subject Rights |
Access, rectification, erasure, portability |
Up to 4% global revenue |
| Data Protection Officer |
Required for large-scale processing |
Administrative fines |
| Breach Notification |
72 hours to authority, without undue delay to subjects |
Up to 4% global revenue |
| Privacy by Design |
Built-in privacy controls |
Up to 4% global revenue |
| Data Processing Agreements |
Required with all processors |
Up to 2% global revenue |
HIPAA Compliance
PRIVACY RULE:
- Protected Health Information (PHI) protections
- Minimum necessary standard
- Patient rights (access, amendment)
- Business Associate Agreements
SECURITY RULE:
- Administrative safeguards
- Physical safeguards
- Technical safeguards
- Risk assessment requirement
BREACH NOTIFICATION:
- Individual notice within 60 days
- HHS notification (>500 individuals: immediate)
- Media notification if >500 in state
PENALTIES:
Tier 1: Unaware - $100-$50,000/violation
Tier 2: Reasonable cause - $1,000-$50,000/violation
Tier 3: Willful neglect (corrected) - $10,000-$50,000/violation
Tier 4: Willful neglect (uncorrected) - $50,000/violation
Anti-Corruption (FCPA/UK Bribery Act)
FCPA ELEMENTS:
Anti-Bribery:
- No payments to foreign officials
- For purpose of obtaining business
- Includes third-party payments
Books & Records:
- Accurate books and records
- Internal controls over assets
- Applies to all issuers
UK BRIBERY ACT:
- Broader than FCPA
- Includes commercial bribery
- Facilitation payments prohibited
- Adequate procedures defense
COMPLIANCE PROGRAM:
- Risk assessment by geography/business
- Third-party due diligence
- Training program
- Gift and hospitality policy
- M&A due diligence
- Reporting mechanism
- Audit and monitoring
Contract Management
Contract Review Checklist
ESSENTIAL TERMS:
- [ ] Parties correctly identified
- [ ] Scope clearly defined
- [ ] Price/payment terms
- [ ] Term and termination rights
- [ ] Representations and warranties
- [ ] Limitation of liability
- [ ] Indemnification
- [ ] Insurance requirements
- [ ] Confidentiality
- [ ] IP ownership/license
- [ ] Governing law
- [ ] Dispute resolution
- [ ] Assignment restrictions
- [ ] Force majeure
- [ ] Notice provisions
- [ ] Entire agreement clause
Key Contract Provisions
| Provision |
Purpose |
Negotiation Points |
| Limitation of Liability |
Cap damages exposure |
Direct vs. consequential, cap amount |
| Indemnification |
Allocate third-party risk |
Scope, procedure, caps |
| IP Ownership |
Define ownership |
Work product, background IP, licenses |
| Confidentiality |
Protect information |
Definition, term, exceptions |
| Termination |
Exit rights |
For cause vs. convenience, notice period |
| Warranties |
Quality assurance |
Scope, disclaimers, remedies |
Contract Risk Matrix
| Risk Level |
Contract Value |
Approval Level |
| Low |
< $100K |
Department manager |
| Medium |
$100K - $1M |
Director/VP |
| High |
$1M - $10M |
SVP/EVP |
| Critical |
> $10M |
C-Suite/Board |
Intellectual Property
IP Portfolio Management
PATENT STRATEGY:
- Freedom to operate analysis
- Competitive patent landscape
- Filing strategy (utility, design, provisional)
- Geographic coverage
- Prosecution management
- Licensing opportunities
- Enforcement program
TRADEMARK STRATEGY:
- Brand clearance searches
- Registration program
- Monitoring and enforcement
- Domain name portfolio
- Social media handles
TRADE SECRET PROGRAM:
- Identification and classification
- Protection measures (physical, technical, contractual)
- Need-to-know access
- Exit interview protocols
IP Due Diligence (M&A)
| Area |
Review Items |
| Patents |
Ownership, encumbrances, validity, infringement claims |
| Trademarks |
Registrations, common law rights, oppositions |
| Copyrights |
Work for hire, assignments, licenses |
| Trade Secrets |
Protection measures, potential misappropriation |
| Licenses |
Inbound/outbound, change of control provisions |
| Litigation |
Pending/threatened, settlements |
Litigation Management
Litigation Hold Process
TRIGGER EVENTS:
- Receipt of complaint or demand letter
- Reasonable anticipation of litigation
- Government investigation notice
- Internal investigation findings
HOLD PROCESS:
1. Issue litigation hold notice
2. Identify custodians and data sources
3. Suspend routine destruction
4. Interview key custodians
5. Collect and preserve documents
6. Monitor compliance
7. Update as needed
8. Release when appropriate
Litigation Budget Management
| Phase |
Activities |
Cost Factors |
| Pre-litigation |
Investigation, demand letters |
Limited |
| Pleadings |
Complaint, answer, motions |
Moderate |
| Discovery |
Document production, depositions |
Highest |
| Pre-trial |
Expert reports, motions |
High |
| Trial |
Preparation, testimony |
Very High |
| Appeal |
Briefing, oral argument |
Moderate |
Settlement Analysis
SETTLEMENT VALUE FORMULA:
Expected Value = P(win) × Expected Recovery - Legal Costs
CONSIDERATIONS:
- Probability of liability
- Range of potential damages
- Litigation costs (both sides)
- Management distraction
- Reputational impact
- Precedent setting
- Insurance coverage
- Business relationship preservation
Risk Assessment Framework
Legal Risk Categories
| Category |
Examples |
Impact |
| Regulatory |
Enforcement, fines, license revocation |
High |
| Contractual |
Breach, termination, damages |
Medium-High |
| Litigation |
Class actions, IP disputes, employment |
High |
| Compliance |
SOX, FCPA, data privacy |
Very High |
| Transactional |
M&A, JV, financing |
Medium |
| Reputational |
Public relations, brand damage |
High |
Risk Assessment Matrix
PROBABILITY × IMPACT = RISK SCORE
Impact
Low Medium High
Prob
High 3 6 9
Medium 2 4 6
Low 1 2 3
RISK RESPONSE:
9: Immediate mitigation required
6: Active management plan
3-4: Monitor and review
1-2: Accept risk
Compliance Program Framework
Effective Compliance Program Elements (DOJ)
1. STANDARDS AND PROCEDURES
- Code of conduct
- Policies for risk areas
- Clear and accessible
2. COMPLIANCE LEADERSHIP
- Board oversight
- Senior management commitment
- Adequate resources
3. TRAINING AND COMMUNICATION
- Risk-based training
- Regular updates
- Accessible channels
4. REPORTING MECHANISMS
- Hotline/helpline
- Non-retaliation policy
- Investigation procedures
5. RISK ASSESSMENT
- Regular assessment
- Emerging risks
- Control mapping
6. MONITORING AND AUDITING
- Testing program
- Third-party audits
- Data analytics
7. INCENTIVES AND DISCIPLINE
- Performance integration
- Consistent enforcement
- Root cause analysis
8. THIRD-PARTY MANAGEMENT
- Due diligence
- Contractual protections
- Ongoing monitoring
9. CONTINUOUS IMPROVEMENT
- Root cause analysis
- Lessons learned
- Program updates
Whistleblower Programs
SEC WHISTLEBLOWER PROGRAM:
- 10-30% of sanctions > $1M
- Anti-retaliation protections
- Confidentiality protections
DODD-FRANK PROTECTIONS:
- Broad retaliation prohibition
- Reinstatement, back pay, attorney's fees
- Two-year statute of limitations
INTERNAL REPORTING:
- Anonymous reporting option
- Clear escalation path
- Timely investigation
- Communication of outcomes
Data Privacy Framework
Privacy Program Components
| Component |
Description |
| Governance |
Privacy officer, steering committee, policies |
| Data Inventory |
What data, where, purpose, retention |
| Legal Basis |
Consent management, legitimate interest |
| Rights Management |
DSR process, verification, response |
| Vendor Management |
DPAs, assessments, monitoring |
| Security |
Technical measures, breach response |
| Training |
Role-based, regular updates |
| Auditing |
Compliance testing, gap remediation |
Data Classification
| Level |
Definition |
Handling |
| Public |
Approved for public release |
Standard controls |
| Internal |
General business information |
Access controls |
| Confidential |
Sensitive business data |
Encryption, access limits |
| Restricted |
Highly sensitive (PII, PHI, etc.) |
Strict controls, audit |
See Also
1---2name: legal-compliance3description: Legal and compliance expertise for corporate governance, contract analysis, regulatory compliance (SOX, GDPR, HIPAA), risk assessment, intellectual property, and litigation management. Use when reviewing contracts, ensuring compliance, or managing legal risk.4---5
6# Legal & Compliance Expert
7
8Comprehensive legal frameworks for governance, contracts, regulatory compliance, and risk management.
9
10## Corporate Governance
11
12### Board Structure & Responsibilities
13
14```
15BOARD COMPOSITION:
16- Independent directors (majority required for NYSE/NASDAQ)
17- Lead independent director
18- Committee structure
19- Board diversity requirements
20- Skills matrix
21
22KEY COMMITTEES:
231. Audit Committee (all independent)
242. Compensation Committee (all independent)
253. Nominating/Governance Committee (all independent)
264. Risk Committee (financial institutions)
27```
28
29### Fiduciary Duties
30
31| Duty | Definition | Key Considerations |
32| ---------------------- | ---------------------------------- | -------------------------------------- |
33| **Duty of Care** | Act with reasonable prudence | Informed decisions, due diligence |
34| **Duty of Loyalty** | Act in corporation's best interest | Avoid conflicts, corporate opportunity |
35| **Duty of Good Faith** | Act honestly and fairly | No intentional harm, follow law |
36| **Duty of Disclosure** | Full and fair disclosure | Material information, no omissions |
37
38### Business Judgment Rule
39
40```
41PROTECTION REQUIREMENTS:
421. Decision made in good faith
432. No personal interest in outcome
443. Reasonably informed decision
454. Rational belief action is in company's best interest
46
47ENHANCED SCRUTINY (Revlon Duties):
48- Triggered in change of control
49- Duty to maximize shareholder value
50- Active market check required
51```
52
53## Regulatory Compliance
54
55### Sarbanes-Oxley (SOX) Compliance
56
57```
58KEY SECTIONS:
59
60Section 302: CEO/CFO Certifications
61- Certify financial statements
62- Certify disclosure controls
63- Report control deficiencies
64
65Section 404: Internal Control Assessment
66- Management assessment required
67- External auditor attestation (accelerated filers)
68- Material weakness disclosure
69
70Section 906: Criminal Penalties
71- Criminal certification of financial reports
72- Up to $5M fine / 20 years imprisonment
73
74COMPLIANCE FRAMEWORK:
75- COSO Internal Control Framework
76- Documentation of key controls
77- Testing program (design + operating effectiveness)
78- Deficiency evaluation process
79- Remediation tracking
80```
81
82### GDPR Compliance
83
84| Requirement | Description | Penalties |
85| ------------------------------ | ------------------------------------------------------ | ----------------------- |
86| **Lawful Basis** | Consent, contract, legitimate interest | Up to 4% global revenue |
87| **Data Subject Rights** | Access, rectification, erasure, portability | Up to 4% global revenue |
88| **Data Protection Officer** | Required for large-scale processing | Administrative fines |
89| **Breach Notification** | 72 hours to authority, without undue delay to subjects | Up to 4% global revenue |
90| **Privacy by Design** | Built-in privacy controls | Up to 4% global revenue |
91| **Data Processing Agreements** | Required with all processors | Up to 2% global revenue |
92
93### HIPAA Compliance
94
95```
96PRIVACY RULE:
97- Protected Health Information (PHI) protections
98- Minimum necessary standard
99- Patient rights (access, amendment)
100- Business Associate Agreements
101
102SECURITY RULE:
103- Administrative safeguards
104- Physical safeguards
105- Technical safeguards
106- Risk assessment requirement
107
108BREACH NOTIFICATION:
109- Individual notice within 60 days
110- HHS notification (>500 individuals: immediate)
111- Media notification if >500 in state
112
113PENALTIES:
114Tier 1: Unaware - $100-$50,000/violation
115Tier 2: Reasonable cause - $1,000-$50,000/violation
116Tier 3: Willful neglect (corrected) - $10,000-$50,000/violation
117Tier 4: Willful neglect (uncorrected) - $50,000/violation
118```
119
120### Anti-Corruption (FCPA/UK Bribery Act)
121
122```
123FCPA ELEMENTS:
124Anti-Bribery:
125- No payments to foreign officials
126- For purpose of obtaining business
127- Includes third-party payments
128
129Books & Records:
130- Accurate books and records
131- Internal controls over assets
132- Applies to all issuers
133
134UK BRIBERY ACT:
135- Broader than FCPA
136- Includes commercial bribery
137- Facilitation payments prohibited
138- Adequate procedures defense
139
140COMPLIANCE PROGRAM:
141- Risk assessment by geography/business
142- Third-party due diligence
143- Training program
144- Gift and hospitality policy
145- M&A due diligence
146- Reporting mechanism
147- Audit and monitoring
148```
149
150## Contract Management
151
152### Contract Review Checklist
153
154```
155ESSENTIAL TERMS:
156- [ ] Parties correctly identified
157- [ ] Scope clearly defined
158- [ ] Price/payment terms
159- [ ] Term and termination rights
160- [ ] Representations and warranties
161- [ ] Limitation of liability
162- [ ] Indemnification
163- [ ] Insurance requirements
164- [ ] Confidentiality
165- [ ] IP ownership/license
166- [ ] Governing law
167- [ ] Dispute resolution
168- [ ] Assignment restrictions
169- [ ] Force majeure
170- [ ] Notice provisions
171- [ ] Entire agreement clause
172```
173
174### Key Contract Provisions
175
176| Provision | Purpose | Negotiation Points |
177| --------------------------- | ------------------------- | ---------------------------------------- |
178| **Limitation of Liability** | Cap damages exposure | Direct vs. consequential, cap amount |
179| **Indemnification** | Allocate third-party risk | Scope, procedure, caps |
180| **IP Ownership** | Define ownership | Work product, background IP, licenses |
181| **Confidentiality** | Protect information | Definition, term, exceptions |
182| **Termination** | Exit rights | For cause vs. convenience, notice period |
183| **Warranties** | Quality assurance | Scope, disclaimers, remedies |
184
185### Contract Risk Matrix
186
187| Risk Level | Contract Value | Approval Level |
188| ---------- | -------------- | ------------------ |
189| Low | < $100K | Department manager |
190| Medium | $100K - $1M | Director/VP |
191| High | $1M - $10M | SVP/EVP |
192| Critical | > $10M | C-Suite/Board |
193
194## Intellectual Property
195
196### IP Portfolio Management
197
198```
199PATENT STRATEGY:
200- Freedom to operate analysis
201- Competitive patent landscape
202- Filing strategy (utility, design, provisional)
203- Geographic coverage
204- Prosecution management
205- Licensing opportunities
206- Enforcement program
207
208TRADEMARK STRATEGY:
209- Brand clearance searches
210- Registration program
211- Monitoring and enforcement
212- Domain name portfolio
213- Social media handles
214
215TRADE SECRET PROGRAM:
216- Identification and classification
217- Protection measures (physical, technical, contractual)
218- Need-to-know access
219- Exit interview protocols
220```
221
222### IP Due Diligence (M&A)
223
224| Area | Review Items |
225| ----------------- | ------------------------------------------------------ |
226| **Patents** | Ownership, encumbrances, validity, infringement claims |
227| **Trademarks** | Registrations, common law rights, oppositions |
228| **Copyrights** | Work for hire, assignments, licenses |
229| **Trade Secrets** | Protection measures, potential misappropriation |
230| **Licenses** | Inbound/outbound, change of control provisions |
231| **Litigation** | Pending/threatened, settlements |
232
233## Litigation Management
234
235### Litigation Hold Process
236
237```
238TRIGGER EVENTS:
239- Receipt of complaint or demand letter
240- Reasonable anticipation of litigation
241- Government investigation notice
242- Internal investigation findings
243
244HOLD PROCESS:
2451. Issue litigation hold notice
2462. Identify custodians and data sources
2473. Suspend routine destruction
2484. Interview key custodians
2495. Collect and preserve documents
2506. Monitor compliance
2517. Update as needed
2528. Release when appropriate
253```
254
255### Litigation Budget Management
256
257| Phase | Activities | Cost Factors |
258| ------------------ | -------------------------------- | ------------ |
259| **Pre-litigation** | Investigation, demand letters | Limited |
260| **Pleadings** | Complaint, answer, motions | Moderate |
261| **Discovery** | Document production, depositions | Highest |
262| **Pre-trial** | Expert reports, motions | High |
263| **Trial** | Preparation, testimony | Very High |
264| **Appeal** | Briefing, oral argument | Moderate |
265
266### Settlement Analysis
267
268```
269SETTLEMENT VALUE FORMULA:
270Expected Value = P(win) × Expected Recovery - Legal Costs
271
272CONSIDERATIONS:
273- Probability of liability
274- Range of potential damages
275- Litigation costs (both sides)
276- Management distraction
277- Reputational impact
278- Precedent setting
279- Insurance coverage
280- Business relationship preservation
281```
282
283## Risk Assessment Framework
284
285### Legal Risk Categories
286
287| Category | Examples | Impact |
288| ----------------- | -------------------------------------- | ----------- |
289| **Regulatory** | Enforcement, fines, license revocation | High |
290| **Contractual** | Breach, termination, damages | Medium-High |
291| **Litigation** | Class actions, IP disputes, employment | High |
292| **Compliance** | SOX, FCPA, data privacy | Very High |
293| **Transactional** | M&A, JV, financing | Medium |
294| **Reputational** | Public relations, brand damage | High |
295
296### Risk Assessment Matrix
297
298```
299PROBABILITY × IMPACT = RISK SCORE
300
301 Impact
302 Low Medium High
303Prob
304High 3 6 9
305Medium 2 4 6
306Low 1 2 3
307
308RISK RESPONSE:
3099: Immediate mitigation required
3106: Active management plan
3113-4: Monitor and review
3121-2: Accept risk
313```
314
315## Compliance Program Framework
316
317### Effective Compliance Program Elements (DOJ)
318
319```
3201. STANDARDS AND PROCEDURES
321 - Code of conduct
322 - Policies for risk areas
323 - Clear and accessible
324
3252. COMPLIANCE LEADERSHIP
326 - Board oversight
327 - Senior management commitment
328 - Adequate resources
329
3303. TRAINING AND COMMUNICATION
331 - Risk-based training
332 - Regular updates
333 - Accessible channels
334
3354. REPORTING MECHANISMS
336 - Hotline/helpline
337 - Non-retaliation policy
338 - Investigation procedures
339
3405. RISK ASSESSMENT
341 - Regular assessment
342 - Emerging risks
343 - Control mapping
344
3456. MONITORING AND AUDITING
346 - Testing program
347 - Third-party audits
348 - Data analytics
349
3507. INCENTIVES AND DISCIPLINE
351 - Performance integration
352 - Consistent enforcement
353 - Root cause analysis
354
3558. THIRD-PARTY MANAGEMENT
356 - Due diligence
357 - Contractual protections
358 - Ongoing monitoring
359
3609. CONTINUOUS IMPROVEMENT
361 - Root cause analysis
362 - Lessons learned
363 - Program updates
364```
365
366### Whistleblower Programs
367
368```
369SEC WHISTLEBLOWER PROGRAM:
370- 10-30% of sanctions > $1M
371- Anti-retaliation protections
372- Confidentiality protections
373
374DODD-FRANK PROTECTIONS:
375- Broad retaliation prohibition
376- Reinstatement, back pay, attorney's fees
377- Two-year statute of limitations
378
379INTERNAL REPORTING:
380- Anonymous reporting option
381- Clear escalation path
382- Timely investigation
383- Communication of outcomes
384```
385
386## Data Privacy Framework
387
388### Privacy Program Components
389
390| Component | Description |
391| --------------------- | --------------------------------------------- |
392| **Governance** | Privacy officer, steering committee, policies |
393| **Data Inventory** | What data, where, purpose, retention |
394| **Legal Basis** | Consent management, legitimate interest |
395| **Rights Management** | DSR process, verification, response |
396| **Vendor Management** | DPAs, assessments, monitoring |
397| **Security** | Technical measures, breach response |
398| **Training** | Role-based, regular updates |
399| **Auditing** | Compliance testing, gap remediation |
400
401### Data Classification
402
403| Level | Definition | Handling |
404| ---------------- | --------------------------------- | ------------------------- |
405| **Public** | Approved for public release | Standard controls |
406| **Internal** | General business information | Access controls |
407| **Confidential** | Sensitive business data | Encryption, access limits |
408| **Restricted** | Highly sensitive (PII, PHI, etc.) | Strict controls, audit |
409
410## See Also
411
412- [Fortune 50 Risk Management](../fortune50-risk-management/SKILL.md)
413- [Fortune 50 Security](../fortune50-security/SKILL.md)
414- [Fortune 50 Business Strategy](../fortune50-business-strategy/SKILL.md)