This skill should be used when the user asks to "analyze regulations", "regulatory landscape", "compliance requirements", "legal considerations", "regulatory risk", "industry regulations", "compliance analysis", "regulatory trends", or needs guidance on understanding regulatory environments, compliance requirements, or legal market factors. Use when this capability is needed.
Regulatory review assesses the legal and compliance landscape affecting markets and products. This skill covers frameworks for understanding regulatory requirements, risks, and trends.
Required Frameworks
Framework
Output Section
Required
Condition
Framework Identification
Applicable Frameworks
yes
—
Industry-to-Framework Mapping
Regulatory Mapping
yes
—
Penalty Ranges
Enforcement & Penalties
yes
—
Risk Matrix
Risk Assessment
yes
—
Cross-border Mechanisms
Cross-border Analysis
conditional
Multi-jurisdiction scope in elicitation
Trend Indicators: Load and apply the trend indicator definitions from protocols/TREND-INDICATORS.md.
When the product uses AI/ML in decisions affecting people (hiring, lending, insurance, housing), these specific requirements apply:
Requirement
Source
Detail
Annual bias audit by independent auditor
NYC Local Law 144
Must test for disparate impact across race/ethnicity and gender; publish summary results
10-day candidate notice
NYC Local Law 144
Notify candidates that AEDT is used; describe data collected and data retention policy
High-risk AI conformity assessment
EU AI Act
Employment, education, law enforcement AI classified as high-risk; requires risk management system, data governance, human oversight
Adverse impact analysis
EEOC/Title VII
Four-fifths rule for selection rates across protected categories; document validation studies
Algorithmic fairness assessment
Colorado SB 21-169
Developers and deployers of high-risk AI must provide impact assessments
Industry-Framework Mapping
Use this table to quickly identify primary and secondary regulatory frameworks based on the user's industry:
Industry
Primary Frameworks
Secondary Frameworks
Healthcare/Telehealth
HIPAA, HITECH, FDA 21 CFR
GDPR (EU), State telehealth laws
Fintech/Crypto
Dodd-Frank, SEC, FCA (UK)
MiCA (EU), State MSB licensing, BSA/FinCEN
AI/ML in Employment
NYC Local Law 144, EEOC, EU AI Act
State AI bills, CCPA/CPRA
Children's Apps/Games
COPPA, FTC Act
CCPA minors provisions, App store policies
Medical Devices
FDA 21 CFR, EU MDR
TGA (AU), PMDA (JP), ISO 13485
E-commerce/Supplements
FDA DSHEA, FTC Act, Prop 65
CCPA/CPRA, cGMP (21 CFR 111)
SaaS/Data Processing
GDPR, CCPA/CPRA
ePrivacy, Sector-specific (HIPAA, PCI DSS)
Regulatory Risk Assessment
Risk Categories
Compliance Risk
Failure to meet existing requirements
Likelihood: Based on current gaps
Impact: Fines, operational restrictions
Regulatory Change Risk
New or changing regulations
Likelihood: Based on legislative trends
Impact: Cost of compliance, market access
Enforcement Risk
Increased regulatory scrutiny
Likelihood: Based on enforcement patterns
Impact: Investigations, penalties
Reputational Risk
Public perception of compliance
Likelihood: Based on sensitivity of issues
Impact: Customer trust, brand damage
Risk Matrix
Risk
Likelihood
Impact
Trend
Mitigation
[Risk]
H/M/L
H/M/L
INC/DEC/CONST
[Action]
Regulatory Trend Analysis
Trend Indicators
INC (Increasing regulation)
New legislation proposed/passed
Increased enforcement actions
Growing public/political attention
International coordination
DEC (Decreasing regulation)
Deregulation initiatives
Reduced enforcement
Political shift toward less oversight
CONST (Stable regulation)
Established framework
Predictable enforcement
No major changes pending
Current Global Trends
Area
Direction
Key Developments
Data Privacy
INC
More countries adopting GDPR-style laws
AI/ML
INC
EU AI Act, emerging US frameworks
Crypto/Fintech
INC
Global frameworks emerging
Competition/Big Tech
INC
Antitrust scrutiny increasing
ESG/Sustainability
INC
Disclosure requirements expanding
Cybersecurity
INC
Mandatory breach reporting
Children's Privacy
INC
COPPA 2.0, Kids Online Safety Act, state children's codes
Supplement/Consumer Products
INC
FDA mandatory listing, FTC enforcement of health claims
Compliance Assessment
Gap Analysis Framework
Requirement
Current State
Gap
Priority
Remediation
[Req 1]
Compliant/Partial/Non
Description
H/M/L
Action needed
Compliance Cost Estimation
Component
One-Time
Ongoing Annual
Technology
$X
$X
Personnel
$X
$X
Legal/Consulting
$X
$X
Training
$X
$X
Audit/Certification
$X
$X
Total
$X
$X
Jurisdiction Analysis
Market Entry Considerations
Jurisdiction
Key Regulations
Complexity
Barrier Level
US
Federal + 50 states
High
Medium
EU
GDPR + sector regs
High
High
UK
Post-Brexit regime
Medium
Medium
APAC
Varies widely
Variable
Variable
Cross-Border Considerations
Data localization requirements
Licensing reciprocity
Contractual restrictions
IP protection differences
Cross-Border Data Transfer Mechanisms
When operations span multiple jurisdictions, identify which transfer mechanism applies:
Mechanism
Use When
Key Requirements
Standard Contractual Clauses (SCCs)
Transferring EU/UK data to non-adequate countries
2021 version required; Transfer Impact Assessment mandatory
Adequacy Decisions
Transferring to countries with EU adequacy status
Verify current adequacy status (can be invalidated — see Schrems II)
Binding Corporate Rules (BCRs)
Intra-group transfers within multinational corporations
DPA approval required; lengthy approval process
Data Localization
Country requires data to remain within borders
China, Russia, India (proposed); may require local infrastructure
Consent-based Transfer
Individual explicitly consents to cross-border transfer
Not suitable for systematic/bulk transfers under GDPR
Output Rules
These rules are mandatory for every regulatory review output. They ensure consistency and completeness regardless of the specific industry or prompt:
Use exact section headings from the Output Structure below. Do not rename or skip sections.
Every Risk Matrix row MUST include a Trend column using exactly one of: INC, DEC, or CONST.
Every Trend Analysis bullet MUST use the format: Area: INC/DEC/CONST - [Evidence sentence].
Recommendations MUST include at least one of each: Immediate action, Medium-term action, and Monitoring action.
Compliance Assessment MUST use status symbols: ✓ (compliant), △ (partial), ✗ (non-compliant).
Never use the phrase "This is not legal advice" in the output. The skill disclaimer is in SKILL.md, not in outputs.
Always include a Monitoring Indicators section with at least 3 specific indicators (regulatory body names, legislative tracking sources).
Cross-border data transfer: When a prompt involves operations in multiple jurisdictions, always discuss data transfer mechanisms (SCCs, adequacy decisions, data localization).
Children's data: When the product involves users who may be minors, always address COPPA and parental consent requirements specifically.
Compliance costs: Always provide estimated ranges (not exact figures) broken down by Technology, Personnel, Legal/Consulting, Training, and Audit/Certification.
These proposed or recently enacted regulations are not yet fully in force but will affect multiple industries. Reference them in Trend Analysis and Monitoring Indicators when relevant:
Regulation
Jurisdiction
Status
Expected Impact
COPPA 2.0 (FTC rulemaking)
US
Proposed rule
Expanded age range, stricter consent, limits on data use for marketing to children
Kids Online Safety Act (KOSA)
US
Passed Senate, House pending
Duty of care for platforms serving minors; impact assessments required
EU AI Act implementing rules
EU
Phased implementation 2024-2027
High-risk AI requirements; prohibited practices; GPAI model obligations
Digital Markets Act (DMA)
EU
In force, enforcement ongoing
Gatekeeper obligations; interoperability; data portability for large platforms
State AI employment laws
US (IL, CO, MD, NY+)
Various stages
Bias audits, transparency, impact assessments for AI in hiring/employment
Federal privacy legislation
US
Proposed (APRA and others)
Potential national data privacy standard preempting state laws
India DPDP Act
India
Enacted, rules pending
Consent-based processing, data localization, significant penalty structure
Penalty Reference Ranges
Use these ranges to calibrate risk impact assessments. Cite specific enforcement examples when relevant to the user's industry:
Framework
Maximum Penalty
Notable Enforcement Examples
GDPR
Up to 4% of global annual revenue or EUR 20M
Meta EUR 1.2B (2023, data transfers); Amazon EUR 746M (2021, targeting)
High: 3+ independent, recent (<12mo) sources that converge
Medium: 2 sources OR sources >12mo old OR indirect evidence
Low: Single source, inference, or extrapolation
Dimension-specific confidence criteria below REFINE (not replace) these universal definitions.
Cross-reference dimensions: trends (regulatory trends and policy direction), competitive (compliance status of competitors)
Alert triggers:
New regulation with <12 months to compliance deadline
Regulatory action against a major competitor
Policy shift that could enable or block market entry
Confidence rules:
High: Published regulation or official government announcement
Medium: Proposed regulation in comment period or credible policy analysis
Low: Speculative based on political signals or advocacy positions
Conflict detection:
Compliance timeline vs trend dimension's market entry projections
Regulatory burden cost vs financial dimension's unit economics
Compliance requirements vs tech dimension's feasibility assessment
Converted and distributed by TomeVault — claim your Tome and manage your conversions.
1---2name: regulatory-review3description: This skill should be used when the user asks to "analyze regulations", "regulatory landscape", "compliance requirements", "legal considerations", "regulatory risk", "industry regulations", "compliance analysis", "regulatory trends", or needs guidance on understanding regulatory environments, compliance requirements, or legal market factors. Use when this capability is needed.4---56# Regulatory Review78## Overview910Regulatory review assesses the legal and compliance landscape affecting markets and products. This skill covers frameworks for understanding regulatory requirements, risks, and trends.1112## Required Frameworks1314| Framework | Output Section | Required | Condition |15|-----------|---------------|----------|-----------|16| Framework Identification | Applicable Frameworks | yes | — |17| Industry-to-Framework Mapping | Regulatory Mapping | yes | — |18| Penalty Ranges | Enforcement & Penalties | yes | — |19| Risk Matrix | Risk Assessment | yes | — |20| Cross-border Mechanisms | Cross-border Analysis | conditional | Multi-jurisdiction scope in elicitation |2122**Trend Indicators**: Load and apply the trend indicator definitions from `protocols/TREND-INDICATORS.md`.2324## Regulatory Dimensions2526### Direct Regulations27- Industry-specific rules (fintech, healthcare, etc.)28- Product safety requirements29- Licensing and certification30- Operational standards3132### Data & Privacy33- Data protection laws (GDPR, CCPA, etc.)34- Cross-border data transfer35- Consent requirements36- Breach notification3738### Consumer Protection39- Advertising standards40- Fair trading practices41- Warranty requirements42- Dispute resolution4344### Competition/Antitrust45- Market dominance rules46- M&A restrictions47- Pricing practices48- Distribution agreements4950## Major Regulatory Frameworks5152### Data Privacy5354| Framework | Jurisdiction | Key Requirements |55|-----------|--------------|------------------|56| GDPR | EU | Consent, data rights, DPO, breach notification |57| CCPA/CPRA | California | Disclosure, opt-out, deletion rights |58| LGPD | Brazil | Similar to GDPR, local DPO |59| PIPL | China | Consent, localization, cross-border rules |6061### Financial Services6263| Framework | Jurisdiction | Scope |64|-----------|--------------|-------|65| Dodd-Frank | US | Banking, consumer protection |66| PSD2 | EU | Payment services, open banking |67| MiCA | EU | Crypto assets |68| SOX | US | Public company reporting |6970### Healthcare7172| Framework | Jurisdiction | Scope |73|-----------|--------------|-------|74| HIPAA | US | Health information privacy |75| FDA 21 CFR | US | Medical devices, pharma |76| MDR | EU | Medical devices |77| HITECH | US | Health IT security |7879### Children's Privacy8081| Framework | Jurisdiction | Scope |82|-----------|--------------|-------|83| COPPA | US | Children under 13 online privacy, parental consent |84| COPPA 2.0 (proposed) | US | Expanded age range, stricter consent |85| Age-Appropriate Design Code | California/UK | Privacy-by-design for minors |8687**COPPA Parental Consent Methods** (FTC-approved):88- Signed consent form (mail/fax/scan)89- Credit card transaction verification90- Government ID check91- Knowledge-based authentication92- Video conference verification93- FTC-approved verifiable parental consent method9495**Key COPPA Thresholds**:96- Under 13: Full COPPA applies; verifiable parental consent required before collecting ANY personal information97- CCPA/CPRA: Under 16 requires opt-in for sale/sharing of personal data; under 13 requires parental opt-in9899### Consumer & Advertising100101| Framework | Jurisdiction | Scope |102|-----------|--------------|-------|103| FTC Act Section 5 | US | Unfair/deceptive practices, advertising substantiation |104| FCA (Financial Conduct Authority) | UK | Financial services authorization and conduct |105| Proposition 65 | California | Chemical exposure warnings |106| FDA DSHEA | US | Dietary supplement labeling and safety |107108### AI/Technology109110| Framework | Jurisdiction | Scope |111|-----------|--------------|-------|112| EU AI Act | EU | AI risk classification, requirements |113| NYC Local Law 144 | NYC | AI in employment decisions (bias audits required) |114| State AI bills | Various US | Emerging requirements (IL, CO, MD) |115| EEOC AI Guidance | US | Anti-discrimination for AI hiring tools |116117### AI/ML Bias Audit Requirements118119When the product uses AI/ML in decisions affecting people (hiring, lending, insurance, housing), these specific requirements apply:120121| Requirement | Source | Detail |122|-------------|--------|--------|123| Annual bias audit by independent auditor | NYC Local Law 144 | Must test for disparate impact across race/ethnicity and gender; publish summary results |124| 10-day candidate notice | NYC Local Law 144 | Notify candidates that AEDT is used; describe data collected and data retention policy |125| High-risk AI conformity assessment | EU AI Act | Employment, education, law enforcement AI classified as high-risk; requires risk management system, data governance, human oversight |126| Adverse impact analysis | EEOC/Title VII | Four-fifths rule for selection rates across protected categories; document validation studies |127| Algorithmic fairness assessment | Colorado SB 21-169 | Developers and deployers of high-risk AI must provide impact assessments |128129## Industry-Framework Mapping130131Use this table to quickly identify primary and secondary regulatory frameworks based on the user's industry:132133| Industry | Primary Frameworks | Secondary Frameworks |134|----------|-------------------|----------------------|135| Healthcare/Telehealth | HIPAA, HITECH, FDA 21 CFR | GDPR (EU), State telehealth laws |136| Fintech/Crypto | Dodd-Frank, SEC, FCA (UK) | MiCA (EU), State MSB licensing, BSA/FinCEN |137| AI/ML in Employment | NYC Local Law 144, EEOC, EU AI Act | State AI bills, CCPA/CPRA |138| Children's Apps/Games | COPPA, FTC Act | CCPA minors provisions, App store policies |139| Medical Devices | FDA 21 CFR, EU MDR | TGA (AU), PMDA (JP), ISO 13485 |140| E-commerce/Supplements | FDA DSHEA, FTC Act, Prop 65 | CCPA/CPRA, cGMP (21 CFR 111) |141| SaaS/Data Processing | GDPR, CCPA/CPRA | ePrivacy, Sector-specific (HIPAA, PCI DSS) |142143## Regulatory Risk Assessment144145### Risk Categories146147**Compliance Risk**148- Failure to meet existing requirements149- Likelihood: Based on current gaps150- Impact: Fines, operational restrictions151152**Regulatory Change Risk**153- New or changing regulations154- Likelihood: Based on legislative trends155- Impact: Cost of compliance, market access156157**Enforcement Risk**158- Increased regulatory scrutiny159- Likelihood: Based on enforcement patterns160- Impact: Investigations, penalties161162**Reputational Risk**163- Public perception of compliance164- Likelihood: Based on sensitivity of issues165- Impact: Customer trust, brand damage166167### Risk Matrix168169| Risk | Likelihood | Impact | Trend | Mitigation |170|------|------------|--------|-------|------------|171| [Risk] | H/M/L | H/M/L | INC/DEC/CONST | [Action] |172173## Regulatory Trend Analysis174175### Trend Indicators176177**INC (Increasing regulation)**178- New legislation proposed/passed179- Increased enforcement actions180- Growing public/political attention181- International coordination182183**DEC (Decreasing regulation)**184- Deregulation initiatives185- Reduced enforcement186- Political shift toward less oversight187188**CONST (Stable regulation)**189- Established framework190- Predictable enforcement191- No major changes pending192193### Current Global Trends194195| Area | Direction | Key Developments |196|------|-----------|------------------|197| Data Privacy | INC | More countries adopting GDPR-style laws |198| AI/ML | INC | EU AI Act, emerging US frameworks |199| Crypto/Fintech | INC | Global frameworks emerging |200| Competition/Big Tech | INC | Antitrust scrutiny increasing |201| ESG/Sustainability | INC | Disclosure requirements expanding |202| Cybersecurity | INC | Mandatory breach reporting |203| Children's Privacy | INC | COPPA 2.0, Kids Online Safety Act, state children's codes |204| Supplement/Consumer Products | INC | FDA mandatory listing, FTC enforcement of health claims |205206## Compliance Assessment207208### Gap Analysis Framework209210| Requirement | Current State | Gap | Priority | Remediation |211|-------------|---------------|-----|----------|-------------|212| [Req 1] | Compliant/Partial/Non | Description | H/M/L | Action needed |213214### Compliance Cost Estimation215216| Component | One-Time | Ongoing Annual |217|-----------|----------|----------------|218| Technology | $X | $X |219| Personnel | $X | $X |220| Legal/Consulting | $X | $X |221| Training | $X | $X |222| Audit/Certification | $X | $X |223| **Total** | $X | $X |224225## Jurisdiction Analysis226227### Market Entry Considerations228229| Jurisdiction | Key Regulations | Complexity | Barrier Level |230|--------------|-----------------|------------|---------------|231| US | Federal + 50 states | High | Medium |232| EU | GDPR + sector regs | High | High |233| UK | Post-Brexit regime | Medium | Medium |234| APAC | Varies widely | Variable | Variable |235236### Cross-Border Considerations237238- Data localization requirements239- Licensing reciprocity240- Contractual restrictions241- IP protection differences242243### Cross-Border Data Transfer Mechanisms244245When operations span multiple jurisdictions, identify which transfer mechanism applies:246247| Mechanism | Use When | Key Requirements |248|-----------|----------|------------------|249| Standard Contractual Clauses (SCCs) | Transferring EU/UK data to non-adequate countries | 2021 version required; Transfer Impact Assessment mandatory |250| Adequacy Decisions | Transferring to countries with EU adequacy status | Verify current adequacy status (can be invalidated — see Schrems II) |251| Binding Corporate Rules (BCRs) | Intra-group transfers within multinational corporations | DPA approval required; lengthy approval process |252| Data Localization | Country requires data to remain within borders | China, Russia, India (proposed); may require local infrastructure |253| Consent-based Transfer | Individual explicitly consents to cross-border transfer | Not suitable for systematic/bulk transfers under GDPR |254255## Output Rules256257These rules are mandatory for every regulatory review output. They ensure consistency and completeness regardless of the specific industry or prompt:2582591. **Use exact section headings** from the Output Structure below. Do not rename or skip sections.2602. **Every Risk Matrix row MUST include a Trend column** using exactly one of: `INC`, `DEC`, or `CONST`.2613. **Every Trend Analysis bullet MUST use the format**: `Area: INC/DEC/CONST - [Evidence sentence]`.2624. **Recommendations MUST include at least one of each**: Immediate action, Medium-term action, and Monitoring action.2635. **Compliance Assessment MUST use status symbols**: `✓` (compliant), `△` (partial), `✗` (non-compliant).2646. **Never use the phrase** "This is not legal advice" in the output. The skill disclaimer is in SKILL.md, not in outputs.2657. **Always include a Monitoring Indicators section** with at least 3 specific indicators (regulatory body names, legislative tracking sources).2668. **Cross-border data transfer**: When a prompt involves operations in multiple jurisdictions, always discuss data transfer mechanisms (SCCs, adequacy decisions, data localization).2679. **Children's data**: When the product involves users who may be minors, always address COPPA and parental consent requirements specifically.26810. **Compliance costs**: Always provide estimated ranges (not exact figures) broken down by Technology, Personnel, Legal/Consulting, Training, and Audit/Certification.269270## Output Structure271272```markdown273## Regulatory Review Summary274275### Regulatory Landscape276[Overview of applicable regulations]277278### Key Frameworks279| Framework | Applicability | Status |280|-----------|---------------|--------|281| [Name] | Direct/Indirect | Applicable/Monitor |282283### Compliance Assessment284| Area | Status | Gap | Priority |285|------|--------|-----|----------|286| Data Privacy | ✓/△/✗ | [Gap] | H/M/L |287| [Other] | ✓/△/✗ | [Gap] | H/M/L |288289### Regulatory Risk Matrix290| Risk | Likelihood | Impact | Trend |291|------|------------|--------|-------|292| [Risk] | H/M/L | H/M/L | INC/DEC/CONST |293294### Trend Analysis295- Data Privacy: INC/DEC/CONST - [Evidence]296- Industry-Specific: INC/DEC/CONST - [Evidence]297- Enforcement: INC/DEC/CONST - [Evidence]298299### Estimated Compliance Costs300[Cost breakdown]301302### Recommendations3031. [Immediate action]3042. [Medium-term action]3053. [Monitoring action]306307### Monitoring Indicators308- [Regulatory body announcements]309- [Legislative calendars]310- [Enforcement actions]311```312313## Emerging Regulations to Monitor314315These proposed or recently enacted regulations are not yet fully in force but will affect multiple industries. Reference them in Trend Analysis and Monitoring Indicators when relevant:316317| Regulation | Jurisdiction | Status | Expected Impact |318|------------|-------------|--------|-----------------|319| COPPA 2.0 (FTC rulemaking) | US | Proposed rule | Expanded age range, stricter consent, limits on data use for marketing to children |320| Kids Online Safety Act (KOSA) | US | Passed Senate, House pending | Duty of care for platforms serving minors; impact assessments required |321| EU AI Act implementing rules | EU | Phased implementation 2024-2027 | High-risk AI requirements; prohibited practices; GPAI model obligations |322| Digital Markets Act (DMA) | EU | In force, enforcement ongoing | Gatekeeper obligations; interoperability; data portability for large platforms |323| State AI employment laws | US (IL, CO, MD, NY+) | Various stages | Bias audits, transparency, impact assessments for AI in hiring/employment |324| Federal privacy legislation | US | Proposed (APRA and others) | Potential national data privacy standard preempting state laws |325| India DPDP Act | India | Enacted, rules pending | Consent-based processing, data localization, significant penalty structure |326327## Penalty Reference Ranges328329Use these ranges to calibrate risk impact assessments. Cite specific enforcement examples when relevant to the user's industry:330331| Framework | Maximum Penalty | Notable Enforcement Examples |332|-----------|----------------|------------------------------|333| GDPR | Up to 4% of global annual revenue or EUR 20M | Meta EUR 1.2B (2023, data transfers); Amazon EUR 746M (2021, targeting) |334| HIPAA | $50K-$1.9M per violation category per year | Anthem $16M (2018, breach); Premera $6.85M (2020, breach) |335| COPPA | $50,120 per violation (adjusted annually) | Epic Games $275M (2022, Fortnite); Microsoft/Xbox $20M (2023) |336| FTC Act | Varies; injunctive relief + restitution | FTC v. Kochava (2022, location data); numerous supplement enforcement |337| NYC Local Law 144 | $500-$1,500 per violation per day | Enforcement began July 2023; first actions pending |338| SEC (Securities) | Varies widely; disgorgement + penalties | BlockFi $100M (2022, crypto lending); multiple crypto actions |339| FDA (Medical Devices) | Warning letters, seizure, injunction, criminal prosecution | Numerous 510(k) enforcement; import alerts |340341## Pre-Output Checklist342343Before finalizing output, verify every item. This prevents common omissions that weaken the analysis:3443451. [ ] **Regulatory Landscape section** opens the output with a narrative overview (not just a table)3462. [ ] **Key Frameworks table** lists at least 3 frameworks with Applicability and Status columns3473. [ ] **Compliance Assessment** uses `✓/△/✗` symbols and includes Priority column (H/M/L)3484. [ ] **Risk Matrix** has Likelihood, Impact, AND Trend columns; every row has INC/DEC/CONST3495. [ ] **Trend Analysis** has at least 3 bullet points, each using `INC/DEC/CONST - [Evidence]` format3506. [ ] **Recommendations** include at least one Immediate, one Medium-term, and one Monitoring action3517. [ ] **Monitoring Indicators** lists at least 3 specific sources (named regulatory bodies, legislative trackers)3528. [ ] **Compliance Costs** table is present with Technology, Personnel, Legal/Consulting, Training, and Audit rows3539. [ ] **No forbidden phrases** appear: "This is not legal advice", "I cannot provide legal advice", "consult a lawyer" (the disclaimer in SKILL.md handles this)35410. [ ] **Cross-border transfers** are addressed when multiple jurisdictions are involved (SCCs, adequacy, data localization)355356## Best Practices357358- Findings are research-grade, not compliance-grade — flag regulatory dependencies for qualified review359- Monitor regulatory developments continuously360- Consider both current and proposed regulations361- Assess both direct and indirect impacts362- Factor compliance costs into business planning363364## Disclaimer365366This skill provides research frameworks only. Consult qualified legal counsel for compliance decisions.367368## Additional Resources369370For detailed frameworks, see:371- `references/privacy-frameworks.md` - Data privacy details372- `references/compliance-checklist.md` - Compliance templates373- `examples/regulatory-analysis.md` - Sample analysis374375## Orchestration Hints376377**Confidence tiers (universal scale):**378- **High**: 3+ independent, recent (<12mo) sources that converge379- **Medium**: 2 sources OR sources >12mo old OR indirect evidence380- **Low**: Single source, inference, or extrapolation381382Dimension-specific confidence criteria below REFINE (not replace) these universal definitions.383384- **Cross-reference dimensions**: trends (regulatory trends and policy direction), competitive (compliance status of competitors)385- **Alert triggers**:386 - New regulation with <12 months to compliance deadline387 - Regulatory action against a major competitor388 - Policy shift that could enable or block market entry389- **Confidence rules**:390 - High: Published regulation or official government announcement391 - Medium: Proposed regulation in comment period or credible policy analysis392 - Low: Speculative based on political signals or advocacy positions393- **Conflict detection**:394 - Compliance timeline vs trend dimension's market entry projections395 - Regulatory burden cost vs financial dimension's unit economics396 - Compliance requirements vs tech dimension's feasibility assessment397398---399> Converted and distributed by [TomeVault](https://tomevault.io/claim/zircote) — claim your Tome and manage your conversions.400<!-- tomevault:4.0:skill_md:2026-04-13 -->
Run npx skillmds@latest add tomevault-io/regulatory-review in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
This skill should be used when the user asks to "analyze regulations", "regulatory landscape", "compliance requirements", "legal considerations", "regulatory risk", "industry regulations", "compliance analysis", "regulatory trends", or needs guidance on understanding regulatory environments, compliance requirements, or legal market factors. Use when this capability is needed. It is listed under Coding & Dev Tools on SkillMD.
This skill has not completed SkillMD's automated safety review yet. Independent scanners report: SkillSpector: CAUTION, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
tomevault-io (@tomevault-io) published this skill. Their other Agent Skills are listed on their SkillMD profile.