1---2name: its-draft-trade-compliance-policy-manual3description: Drafts a comprehensive multi-chapter trade compliance policy manual that converts remediation commitments into binding policy, specifies technology access matrices for the deemed export program, addresses EU general export authorizations and catch-all controls for EU operations, and incorporates privilege protocols for investigation records.4---56# Skill: Draft Comprehensive Trade Compliance Policy Manual78## 1. Subject-matter triage910- Treat the source set as the governing factual record for the manual: the self-disclosure materials define required remediation, the internal investigation identifies root causes and control gaps, the audit or assessment materials identify implementation details, and the existing manual is the baseline to supersede or amend.11- Identify every subsidiary, region, business line, and compliance process that has distinct trade-control exposure, then tailor policy obligations to each rather than repeating a generic parent-company standard.12- If the record contains multiple remediation commitments, control failures, destinations, product lines, or subsidiaries, map them separately before drafting so each is addressed expressly in the manual.1314## 2. Failure modes the skill is correcting1516- Converting remediation commitments into soft aspirations instead of binding policy duties with ownership, timing, and monitoring.17- Drafting abstract trade controls without the operational matrices, escalation steps, and records that make the program implementable.18- Omitting screening-tool governance, including automatic restricted-party list updating, fallback verification, and failure escalation.19- Ignoring EU-specific export-control obligations, including general export authorizations, notice or registration conditions, and catch-all controls.20- Failing to address deemed-export risk through technology-access controls that distinguish among controlled technologies and foreign-national access categories.21- Neglecting privilege and record-segregation protocols for investigation files, causing avoidable waiver risk during government-facing productions.22- Using inconsistent terminology across chapters so that policy obligations, procedures, and recordkeeping duties do not line up.2324## 3. Legal frameworks / domain conventions that apply2526- Convert each remediation commitment into a mandatory policy requirement, with the implementing owner, implementation timeline, and compliance-monitoring mechanism stated in operative terms.27- Build the screening section around restricted-party screening governance: auto-update configuration, periodic integrity checks, manual verification when automation fails, and escalation if updates are delayed or incomplete.28- Use a technology access matrix for deemed-export controls: identify each controlled technology or category, the physical and logical access controls, the foreign-national categories requiring license review, and the approval workflow before access is granted.29- For EU operations, address general export authorizations as an affirmative compliance path only where the authorization applies to the product, destination, and transaction profile, and require any registration, filing, or notice the authorization conditions demand.30- Apply catch-all controls to relevant EU transactions even when the item is not independently controlled, whenever end-use, end-user, diversion, or other red-flag factors trigger review.31- Separate legal advice communications from ordinary business records in investigation matters; mark privileged communications appropriately, limit circulation, and segregate counsel-directed materials from operational files.32- Preserve record-retention and legal-hold obligations across jurisdictions, and state that legal holds override routine destruction schedules until clearance is given.3334## 4. Analytical scaffolds3536- Start from the source documents and extract every discrete compliance commitment, then convert each into a policy clause with: scope, rule, owner, timing, evidence of completion, and monitoring cadence.37- Draft the manual chapter by chapter: governance; screening; licensing; technology control; EU exports; catch-all review; investigations and privilege; records and retention; training and audit; escalation and discipline.38- For each control area, state the trigger, the required decision, the responsible role, the record to be created, and the escalation path for exceptions or suspected breaches.39- When the source set identifies a prior failure mode, write the compensating control directly against that failure mode so the policy cannot be read as optional or aspirational.40- For deemed-export controls, make the matrix operational: define the controlled item, access conditions, review question, license requirement, approval authority, and documentation standard.41- For EU authorizations and catch-all controls, write the decision tree in policy form: eligibility check, transaction screening, authorization verification, documentation, and stop/escalate criteria.42- For privilege and investigations, define three buckets of material: privileged legal communications, non-privileged business records, and mixed files; then specify handling rules for each.43- Where subsidiaries have different risk profiles, use subsidiary-specific annexes or provisions rather than one global rule that obscures local obligations.4445## 5. Vertical / structural / temporal relationships4647- The manual should read as a binding enterprise policy with subordinate procedures and annexes, not as a narrative report.48- Cross-reference remediation provisions to the source commitment they implement, and align each policy rule with the investigation finding or audit gap that necessitated it.49- Make temporal sequencing explicit: immediate interim controls, near-term remediation steps, ongoing monitoring, periodic review, and escalation upon non-compliance.50- State that investigation-related holds, preservation steps, and production protocols apply once a matter is reasonably anticipated or opened, and continue until closure or written release.51- Where one control depends on another, specify the dependency; for example, access approval depends on classification of the technology, and EU authorization reliance depends on destination and end-use screening being complete.5253## 6. Output structure conventions5455- Produce a complete trade compliance policy manual in a polished, multi-chapter form suitable for company adoption.56- Use conventional policy drafting elements in each chapter: purpose, scope, policy statement, procedures, responsibilities, records, exceptions, and review.57- Use defined terms consistently and include an interpretation section if needed to keep policy terms aligned across chapters.58- Include annexes or tables where needed for access matrices, escalation paths, record categories, and subsidiary-specific requirements.59- Write in operative policy language; avoid commentary that merely describes what the policy would do.60- Ensure the final document is self-contained, implementation-ready, and suitable for circulation as the company’s controlling trade compliance policy.