anotb
- 86 skills
- 0 followers
- 6 hours ago last updated
- ▌ Open Market Data · anotbQuery read-only stock, company financial, SEC filing, crypto, and macroeconomic data with provenance. Use when an agent needs current market data, public economic data, source comparison, provider diagnostics, or a compact company research snapshot.
- ▌ PPTX Masters · anotb bundleExtract PptxGenJS slide masters from corporate .pptx/.potx templates. Converts OOXML theme colors, fonts, placeholders, backgrounds, slide numbers, and static shapes into ready-to-use defineSlideMaster() JavaScript code. Use when building presentations programmatically with PptxGenJS and the user has a corporate PowerPoint template they want to replicate.
- ▌ Org Design · anotb bundleDesign organizational structures, operating models, role architectures, and transitions that support strategy. Use for reporting lines, spans and layers, centralization, decision rights, job families, and reorganizations.
- ▌ Due Diligence · anotb bundleInvestigate commercial, operational, financial, strategic, and technology claims for acquisition, investment, partnership, or vendor decisions. Use for data-room analysis, quality of earnings, customer concentration, working capital, synergies, and diligence recommendations.
- ▌ Writing Style · anotbWrite and edit consulting analysis, recommendations, reports, decks, and client communications with direct language, proportional detail, and explicit evidence. Use to adapt a consulting deliverable to its audience and remove generic or unsupported claims.
- ▌ Engagement Setup · anotb bundleLaunch a consulting engagement with a focused kickoff, discovery plan, stakeholder assessment, and working arrangements. Use after award or when resetting an engagement that lacks shared scope, access, or decision authority.
- ▌ Project Closeout · anotb bundleClose or transition a consulting engagement through acceptance, handover, knowledge transfer, benefits ownership, financial reconciliation, and lessons learned. Use for successful completion, early termination, suspension, or transition to business-as-usual.
- ▌ Change Management · anotb bundleDiagnose adoption barriers and design organizational change, stakeholder engagement, communications, training, and reinforcement. Use for system rollouts, new operating models, integration, culture change, and adoption measurement.
- ▌ Engagement Pricing · anotb bundlePrice consulting engagements and evaluate delivery economics. Use for fee models, rate cards, margin floors, realization, retainers, discounts, payment schedules, and the commercial section of a proposal or SOW.
- ▌ Financial Modeling · anotb bundleBuild auditable financial models and business cases for investment, valuation, cost-benefit, and build-versus-buy decisions. Use for cash-flow projections, NPV, IRR, ROI, payback, TCO, break-even, and sensitivity analysis.
- ▌ Process Excellence · anotb bundleDiagnose and improve business processes using evidence, flow analysis, Lean, and appropriate statistical methods. Use for bottlenecks, cycle time, defects, cost, process mining, DMAIC plans, and control design.
- ▌ Project Governance · anotb bundleDesign and operate consulting engagement governance: decision rights, steering committees, RACI, risk and issue registers, status reports, escalation, and stage gates. Use for oversight of delivery; use implementation-planning when available for the execution plan itself.
- ▌ Strategic Analysis · anotb bundleStructure an ambiguous business decision, test competing explanations, and recommend a course using evidence. Use for growth, market entry, competitive positioning, business models, and portfolio choices. For execution of an approved direction, use implementation-planning when available.
- ▌ Thought Leadership · anotb bundleDevelop evidence-backed points of view, white papers, case studies, industry briefs, and research reports for a consulting audience. Use to turn research or permitted engagement experience into a useful, defensible argument.
- ▌ Client Deliverables · anotb bundleCreate and refine consulting reports, decision memos, and executive presentations, including storylines, exhibits, visual design, and artifact review. Use for board readouts, investment committee memos, steering updates, and final reports. For sales proposals and pitch decks, use proposal-development when available.
- ▌ Proposal Development · anotb bundleDevelop consulting pursuits, RFP responses, proposals, statements of work, value propositions, and pitch decks. Use for winning and scoping an engagement; use client-deliverables when available for reports and presentations during delivery.
- ▌ Workshop Facilitation · anotb bundleDesign and facilitate consulting workshops, strategy offsites, discovery sessions, prioritization, and design sprints. Use for agendas, participant activities, facilitation guides, pre-work, and follow-through for in-person, virtual, or hybrid groups.
- ▌ Implementation Planning · anotb bundleTurn an agreed recommendation into a feasible roadmap and implementation plan. Use for sequencing, workstreams, dependencies, resources, rollout gates, recovery plans, and the business case needed to fund execution.
- ▌ Scoping · anotb bundleProduces a scoping charter and a structured scope record that downstream second-line skills consume. The charter sets institution, engagement, persona, source posture, risk lens, and overlay context so other skills do not reinvent these facts each time they are called. Best for: - An advisory engagement starting up and the lead needs a written scope before review work begins. - An internal review being charted (annual model risk review, periodic third-party risk review, audit support, exam-readiness sprint, regulatory-change implementation, board-pack cycle). - A practitioner joining an engagement mid-flight and needing the context in one place. - A downstream skill called with contested or unclear scope. Not the right tool when: - A current scope is already on file and the downstream skill is scope-aware (pass the existing record). - The work is a one-off question rather than a scoped review. - The institution and persona are already encoded in a `references/firm-overlay.md` the firm has installed.
- ▌ Kri Commentary · anotb bundleDrafts second-line commentary on KRI / KCI movement and breaches for a periodic risk report. Each per-KRI block carries trend, breach status against the firm's risk appetite statement, named root cause and contributing factors, action taken and action planned with role-level owners and dates, residual-risk view, linked issues and material events, and an explicit second-line challenge note where the second-line view diverges from first-line. Output is a per-KRI commentary block ready to drop into the risk committee pack, the divisional risk pack, the regulator response, or the board memo after qualified review. Best for: - Standing commentary block for each KRI / KCI flagged AMBER or RED in the period, with named root cause and remediation status. - Refreshing commentary on a watch-list KRI that has been at trigger or limit for multiple consecutive periods. - Rewriting first-line draft commentary to second-line standard (challenge, source-anchored, owner-named, evidence-pointed). - Producing the commentary app
- ▌ QA Workpaper · anotb bundleReviews a completed control-test workpaper for QA along named dimensions: scope alignment to the test plan, source-criteria sufficiency, evidence reliability, procedure execution rigor, exception classification, conclusion support, severity calibration, reviewer separation, and remediation handoff. Output is a QA review pack — Excel workbook with QA markup tabs over the workpaper plus a Word QA memo summary — that lists deficiencies by severity, a decision (accept, return for rework, conditional accept), and required rework before workpaper closure. Best for: - A second-line QA function or independent reviewer is performing the standard QA pass over a completed workpaper before issue closure or examiner sharing. - An internal-audit director is rolling up workpaper-quality metrics across a testing cycle and needs structured QA notes per workpaper. - A targeted Federal Reserve, OCC, FDIC, CFPB, NYDFS, or state DOI exam is imminent and the team is doing a self-QA sweep on the workpaper population the examiner wi
- ▌ Attestation Pack · anotb bundleDrafts the periodic management attestation pack a senior officer takes into the certification meeting: scope statement, source criteria, control inventory, evidence index, exceptions with compensating-control narrative, prior-period remediation status, sub-certification chain, reviewer questions, assertion language, and sign-off block. Output is the named-section pack the attesting officer (CEO, CFO, CRO, CCO, CISO, BSA officer, head of internal audit, fund CCO, function head, process owner) and the named reviewers (legal, internal audit, external assessor, regulator) carry into the sign-off conversation. Best for: - Periodic management attestation underpinning a formal certification (SOX 404 process-owner sub-certification; SOC 1 / SOC 2 management assertion package; FFIEC self-assessment; vendor-management annual attestation; BCBS 239 risk-data attestation; fund CCO Rule 38a-1 annual report; BSA officer annual certification; cyber annual certification including NYDFS Form B; privacy annual report under the
- ▌ Issue Writeup · anotb bundleDrafts a single issue write-up using the condition / criteria / cause / effect (CCCE) structure plus severity rationale, remediation, named owner, target date, closure evidence, and evidence-gap flag. Foundational primitive: exception-analysis chains it after a control-test exception, audit findings consume it as the issue artifact, regulator-response files cite it, and the issue log keys off it. The output is a one-issue artifact written in the shape an audit committee, regulator, or issue-tracking system will accept. Best for: - Drafting a finding from internal audit fieldwork, a compliance test exception, a vendor-monitoring exception, a model-validation finding, or a self-identified second-line observation. - Translating an MRA, MRIA, FINRA Letter of Caution, SEC EXAMS deficiency, NYDFS finding, or examiner-issued matter into the firm's internal issue format with traced criteria. - Re-papering a legacy issue whose criteria, cause, or closure evidence does not stand up to current review. Not the right tool
- ▌ Management Response · anotb bundleDrafts the management response to a regulator finding, an internal-audit finding, or an external-assessor observation: acceptance posture, root-cause acknowledgement, action plan with milestones and owners, interim mitigation, evidence-of-effectiveness plan, reporting cadence to the issuing party, and the linkage to the underlying issue write-up. The response is the load-bearing artifact a head of regulatory affairs, head of compliance, CRO, or general counsel takes back to the regulator or to the audit committee after qualified review. Best for: - Drafting the management response to a supervisory finding from a federal banking agency in the formal-letter format the regulator expects. - Drafting the management response to an internal-audit finding for the audit committee response file. - Drafting the management response to an external-assessor observation (SOC auditor, IIA peer review, third-party regulatory engagement). - Drafting the management response to a consumer-protection or markets-conduct supervisor
- ▌ Risk Committee Pack · anotb bundleDrafts the enterprise risk committee pack a CRO carries into the meeting: heat map by risk type, top risks, material risk events, KRI movement and breaches against the risk appetite statement, issues and remediation, forward-looking commentary including scenario results, and decision items. The pack is the load-bearing governance instrument the risk committee of the board (or the enterprise risk committee) uses to discharge its oversight under the firm's risk governance framework. Best for: - Standing quarterly or monthly enterprise risk committee pack from upstream KRI feeds, the issue log, the loss-event register, and CRO commentary. - Board-level risk pack ahead of a regulator-attended meeting (FRB horizontal review, OCC Heightened Standards readiness, FRB CCAR cycle review). - A single committee view across credit, market, liquidity, operational, compliance, financial-crime, model, third-party, cyber, climate where in scope, strategic, and reputational risk. - An adviser-firm or insurer enterprise risk co
- ▌ Control Sampling · anotb bundleDesigns the sample for a control test before fieldwork starts. Defines the testable population, picks a sampling method (statistical or judgmental), sizes the sample, sets a tolerable deviation rate, names the selection technique, and documents the rationale a reviewer can defend in front of an examiner. Output is a sampling memo that drops into the test plan or workpaper as a referenceable artifact. Best for: - A second-line testing pod or internal-audit team is scoping a control test and needs a defensible sample method, size, and rationale before pulling evidence. - A reviewer is challenging a first-line control owner's self-attested testing because the sampling rationale is missing or thin and the sample needs to be redesigned. - A walkthrough has confirmed control design and the next step is sizing operating-effectiveness testing across a defined population. - A prior-cycle workpaper failed QA on sample-design grounds and the redraft starts at the sampling memo. Not the right tool when: - The control or
- ▌ Control Matrix · anotb bundleBuilds the named-row risk-control matrix that maps obligations to control objectives, control activities, owners, frequency, evidence pointers, test methods, last-test results, and open issues. Foundational primitive: compliance-testing samples against it, vendor-diligence and exit-plan reference it, exam-brief reads it, model-card-builder pulls its controls section from it. Risk function and compliance function both consume the same matrix. Best for: - Standing up the matrix for a process, product, or function (lending, vendor lifecycle, model lifecycle, risk-data and risk reporting, cyber-disclosure governance, consumer-compliance management). - Refreshing an existing matrix after a regulatory change, an MRA, an audit finding, an incident, or a process redesign. - Translating a freshly mapped obligation set into the row structure that downstream testing and review will run against. Not the right tool when: - The obligations have not been extracted yet. Run `obligation-mapping` first; the matrix consumes its
- ▌ Test Plan Builder · anotb bundleDrafts the pre-fieldwork test plan for a single control test cycle: scope, control objective, named source criteria, period, population, sampling reference, walkthrough plan, design-effectiveness procedures, operating-effectiveness procedures, evidence-request reference, pass and fail criteria, limitations, downstream consumers, and reviewer sign-off block. Output is the planning artifact that gets reviewer sign-off before evidence pulls and fieldwork begin; it is the contract the workpaper is written against. Best for: - A compliance-testing or internal-audit team is scoping an annual test plan or a one-off targeted review and needs the pre-fieldwork planning workpaper before evidence pulls and fieldwork. - A second-line reviewer is responding to a regulatory-change-management trigger (a new rule, an updated examiner priority, a new exam letter) by standing up a fresh test against an updated control set. - An audit lead is rebuilding a test program after a prior issue, restating control objectives and proced
- ▌ Workpaper Drafter · anotb bundleDrafts the testing workpaper for a single control test cycle once evidence has been inspected and procedures executed. Captures source criteria, walkthrough, evidence inspected, procedures performed, sample-level results, exception aggregation, and a separate design and operating effectiveness conclusion. Output is the standard testing workpaper a QA reviewer, internal audit reviewer, or examiner expects, formatted so each conclusion ties back to evidence. Best for: - A compliance-testing or internal-audit team has finished evidence inspection and procedure execution and needs the workpaper drafted from those results. - A second-line reviewer is documenting a targeted, off-cycle review (regulatory-change triggered, incident-triggered, examiner request) and the workpaper is the artifact. - A QA reviewer is rebuilding a workpaper that failed prior QA, working from the same evidence and exception register. Not the right tool when: - Testing has not been done. Pre-fieldwork scoping is `test-plan-builder`; sample
- ▌ Evidence Binder · anotb bundleAssembles the evidence binder index for a regulatory exam, internal audit fieldwork pack, model-validation evidence pack, vendor-review pack, committee evidence pack, or issue-remediation file. One row per artifact, with system-of-record provenance, control and obligation linkage, sufficiency call, and reviewer sign-off. Reconciles a request list against the evidence on hand and surfaces the gaps before the reviewer does. Best for: - A compliance team building the response binder for a regulator exam against the examiner's request list (RFI). - An internal-audit lead assembling the fieldwork evidence pack for a control-test program. - A model-risk validator pulling the evidence pack for a model revalidation cycle under the firm's MRM frame (cadence per the firm's own policy, not assumed annual). - A TPRM team assembling the diligence evidence file for a critical or important vendor review. - A committee secretary compiling the evidence file behind a risk-committee or AI-risk-committee paper, where the committ
- ▌ Exception Analysis · anotb bundleClassifies the deviations a control test surfaced into design gaps, operating-effectiveness failures, evidence gaps, scope disagreements, data-integrity issues, and anomalies; ranks severity with rationale; names a root-cause hypothesis; sets disposition (elevate to issue, close at exception, re-test, expand sample); and builds the handoff package downstream issue write-up consumes. Output is an exception register that pairs with the testing workpaper and ladders confirmed exceptions into the issue lifecycle. Best for: - A compliance-testing or internal-audit reviewer has finished sample testing and is sitting on a list of deviations that need to be classified before they become findings. - A QA reviewer is challenging a workpaper's exception treatment because the line between evidence gap and control failure was blurred. - A repeat-issue review needs to confirm whether deviations across testing cycles are the same root cause or coincidental. - A second-line lead is preparing a handoff to issue write-up and w
- ▌ Bcbs239 Gap Assessment · anotb bundleDrafts a gap assessment of the firm's risk data aggregation and risk reporting posture against the fourteen BCBS 239 principles, organised by the four BCBS groups (overarching governance and infrastructure, aggregation, reporting, supervisory review). Produces a principle-by-principle matrix with rating, direction, evidence summary, gaps, owners, and target dates that the head of risk data, head of regulatory reporting, CRO office, and internal audit can take to the data-management committee after qualified review. Best for: - Standing up or refreshing a self-assessment ahead of a regulator-driven review (FRB horizontal review on RDARR, ECB SREP thematic, OCC Heightened Standards thematic). - Diagnosing why a risk committee pack carries a non-high data-confidence label; the gap assessment is the upstream artifact. - Refreshing the BCBS 239 posture after a material change (acquisition, system migration, source-of-record consolidation, taxonomy revision). - Pulling the cross-entity gap view across G-SIBs and D-
- ▌ AI Act Triage · anotb bundleClassifies an AI use case under the EU AI Act (Regulation (EU) 2024/1689) and produces the obligations the firm picks up at the resulting classification. Walks Article 5 prohibited practices, Article 6 high-risk via Annex I product safety legislation or Annex III listed use cases, Article 50 transparency, GPAI Articles 51 to 55, and the operator role determination (provider, deployer, importer, distributor, authorised representative). Output is a draft triage decision plus an obligations checklist, stopped at the legal/compliance review gate. Best for: - A use case has any EU touch-point (EU users, EU establishment, EU data subjects, market placement) and second-line needs an AI Act classification before pre-prod or before market. - A vendor-supplied GenAI assistant is being deployed inside the firm and the firm needs the deployer-versus-provider boundary written down before signing. - An AI inventory sweep is checking which use cases are in scope as Article 113 phasing dates land. - Legal or compliance is ch
- ▌ Policy Gap Review · anotb bundleReviews a firm policy or procedure (or a small set of related policy artefacts) against a named, dated benchmark of obligations or supervisory expectations and produces a gap matrix. One row per gap, with classification (missing / partial / weak / inconsistent / outdated), severity with rationale, declarative recommended edit, evidence needed beyond the text, and named owner. Foundational primitive: the gap matrix routes into `issue-writeup` for findings, into `obligation-mapping` when missing obligations surface, and into `control-matrix` when the operational dimension of the gap is a control rather than text. Audience is policy owners, compliance, and internal audit; the artifact is the gap list, not the policy redline. Best for: - Refreshing a policy ahead of a regulator exam, internal audit, post-enforcement uplift, or scheduled triennial review. - Comparing a legacy policy against a newly published rule or refreshed guidance (legacy SR 11-7-anchored MRM policy against the joint April 2026 model-risk guid
- ▌ Exam Brief · anotb bundleDrafts the engagement playbook a regulatory affairs lead, head of compliance, head of legal, or CRO chief of staff runs during a live regulator engagement. Generic across regulator type and product line. Captures the scope confirmation in writing, the named single-point-of-contact map by topic, the document-handling and privilege posture, the request-list mapping, the interview-prep posture, the supervisory-history that the engagement inherits (open MRA, MRIA, consent-order milestones, self-identified issues), the anticipated reviewer questions tied to current supervisory priorities, the exit-meeting and supervisory-letter response posture, and the post-exam follow-up. The substantive readiness sprint sits in sector-specific exam-readiness skills; this is the engagement-side scaffolding that runs during the exam window. Best for: - An exam window has opened (any regulator, any product line) and the regulatory affairs lead needs the engagement playbook before fieldwork begins. - A supervisory-letter response o
- ▌ Human Review Gates · anotb bundleBuilds the named-gate matrix for an artifact, decision, or workflow: gate name, stage in workflow, trigger, required reviewers (with independence), required inputs, decision criteria, stop conditions, escalation path, documentation requirement, frequency, and source anchor. Foundational primitive: every output-builder skill in the repo emits an artifact that runs through one or more of these gates, and the skill exists so the gates themselves get built once and reused. Output is a gate matrix plus a one-page narrative an AI governance committee, vendor onboarding committee, model risk committee, or issue-rating committee can adopt as charter language. Best for: - Standing up a new committee or governance gate (AI use-case approval, vendor onboarding, model release, issue rating, customer-impact action, SAR filing approval, regulator-response sign-off). - Auditing an existing workflow for missing or under-specified human-review gates ahead of an exam, an internal audit, or a Heightened-Standards readiness revi
- ▌ Obligation Mapping · anotb bundleConverts any source document (rule text, supervisory guidance, exam manual, exam request list, supervisory letter, regulator speech, internal policy, third-party SLA, contract clause) into a structured obligation register: one row per obligation, traced to source by section, with applicability, control objective, evidence required, owner, status, and open questions. Foundational primitive: control-matrix anchors its rows on this output, policy-gap-review triangulates against it, evidence-binder pulls evidence asks from it, exam-brief reads it, and almost every downstream second-line skill reaches for an obligation register at some point. Best for: - Standing up or refreshing the obligation register for a process, product, function, or regulatory domain. - Converting an exam manual section or an examiner document-request list into an internal obligation set the firm can respond to row by row. - Translating a supervisory letter, regulator speech, or interagency statement into discrete obligations and open quest
- ▌ AI Risk Tiering · anotb bundleAssigns a defensible risk tier (tier-1 through tier-4) to an AI or model use case using a multi-factor rubric, and books the tier alongside the named gates and validation depth it triggers. The tier is the routing decision that drives validation depth, monitoring frequency, committee path, and vendor-diligence depth for the rest of model risk and AI governance. Best for: - An intake record exists and second-line needs to set the tier before sequencing validation, monitoring, or committee work. - A periodic re-tiering exercise on the AI inventory after a change in scope, autonomy, customer exposure, vendor, or supervisory posture. - A sponsor has proposed a tier and second-line needs to challenge or concur with reasoning that an examiner can read. Not the right tool when: - The use case has not been intaked yet. Route to `ai-use-case-intake` first; the tier decision is decided against an intake record version. - The question is whether the use case is high-risk under the EU AI Act specifically. Route to `ai-ac
- ▌ Validation Plan · anotb bundleDrafts the validator-side scope contract for an AI or model use case before testing starts. Sizes the work to tier, names the conceptual soundness, data review, outcomes analysis, robustness, fairness, and ongoing monitoring scope per pillar, and frames the effective challenge questions the model owner is expected to answer. Output is what the validator and the model owner agree to before validation executes. Best for: - A use case has cleared intake and tiering and validation is the next step before pre-prod or production approval. - An annual revalidation cycle needs a tailored plan rather than a copy-paste of last year's scope. - A vendor or foundation-model swap on an existing use case needs a delta-scoped revalidation plan. - A regulator request lands on a tier-1 or tier-2 model and the firm needs a documented validator scope to point to. Not the right tool when: - Validation has already executed and the work is the validation report write-up. - The use case has not been intaked or tiered (use ai-use-cas
- ▌ Policy Diff · anotb bundleCompares two versions of a firm policy (or a proposed policy edit against the current approved version) and produces a section-by-section change log with materiality flags, downstream impact, approver routing, and effective date. One row per change. Each row carries the diff (added, removed, reworded, restructured), the section path, the substantive delta, the materiality call, and the downstream consequences (training refresh, control revision, system change, communication, attestation re-up). Used by policy owners during the annual review cycle, by compliance running a redline against an MRA-driven amendment, and by change-management standing up the rollout package after the policy committee approves. Best for: - Annual or scheduled policy review where the second line needs the version-over-version delta before recertification. - Proposed policy amendment where compliance, legal, or the policy owner needs the change log and downstream impacts before the policy committee meets. - Post-MRA or post-issue polic
- ▌ Cyber Disclosure Readiness · anotb bundleDrafts the second-line readiness pack for SEC cybersecurity disclosure: 8-K Item 1.05 trigger and materiality workpaper for a live or suspected material incident, the 10-K Item 106 risk-management and governance disclosure for the annual filing cycle, and the disclosure controls and procedures (DCP) readiness map. The pack is what a disclosure committee, securities counsel, the CISO, and the CRO take into the materiality call and into the filing decision. Best for: - A material cybersecurity incident has occurred (or is suspected) and the disclosure committee needs the materiality determination, the 4-business-day clock posture, the parallel-regulator clocks, and the Item 1.05 disclosure draft pulled together. - The 10-K Item 106 cyber risk-management and governance disclosure is being refreshed for the upcoming filing cycle and second line is challenging the prior-year text. - The firm is standing up or refreshing its cyber disclosure controls and procedures under Exchange Act Rule 13a-15 and needs the secon
- ▌ Cdd Risk Review · anotb bundleQuality-reviews a customer due diligence file (new account, periodic refresh, or event-driven refresh) against the four CDD pillars and named CDD examination expectations. Reads customer identification, beneficial ownership identification and verification, the nature-and-purpose / expected-activity profile, the customer risk rating and its drivers, and the ongoing-monitoring trigger set; produces a second-line review memo with material gaps, evidence-needed items, EDD-trigger posture, and recommended decision checkpoints with named owners. Does not approve onboarding, set or change the customer risk rating, file a SAR, or close or exit the relationship. Best for: - Second-line QA over a sample of new-account CDD files at a bank, broker-dealer, MSB, fintech (sponsor-bank or licensed), or covered-product life insurer. - Periodic CDD refresh review where risk-rating drivers, beneficial-ownership data, or expected activity may have shifted. - Event-driven refresh triggered by negative news, sanctions hit, transac
- ▌ Sar Decision QA · anotb bundleQuality-reviews a SAR or no-SAR decision file against named SAR rules and the FFIEC SAR examination expectations. Reads the alert chronology, investigation steps, evidence considered, disposition, decision rationale, continuing-activity posture, and confidentiality controls; produces a QA memo with material gaps, reviewer findings, and a routing recommendation to the named decision forum. Does not file, decline to file, amend, or close any SAR; SAR filing is a regulated act reserved to the BSA officer or designee. Best for: - Second-line QA over a sample of closed alerts (filed and unfiled) within a defined lookback window. - Targeted review of high-risk alert types (structuring, trade-based, layering, sanctions-adjacent, fraud typology, cyber-event-related). - Review of continuing-activity posture against the firm's documented SAR program (the 90-day continuing-SAR cadence the industry uses is firm policy, not a BSA-rule requirement; the QA reads adherence to the program the firm has, not a uniform external
- ▌ Credit Risk Governance · anotb bundleProduces the second-line credit risk governance review pack a US bank's chief credit officer or chief risk officer carries to the credit risk committee or hands the OCC, FRB, or FDIC examiner reviewing credit administration. Organises the artifact around credit policy alignment, underwriting framework, risk-rating discipline, concentration governance, allowance methodology oversight (ACL / CECL), Reg O and Reg W applicability for insider and affiliated credit, second-line challenge of first-line lending decisions, and (for covered banks) the Heightened Standards posture for credit risk. Audience is the chief credit officer, chief risk officer, head of credit risk review, ALLL / ACL governance committee, audit committee, and examiner-in-charge for a credit-administration scope cycle. Best for: - A national bank, state-member bank, state non-member bank, or federal savings association is refreshing its credit policy or credit risk-rating framework and second-line needs to challenge the first-line proposal again
- ▌ AI Use Case Intake · anotb bundleTurns a first-line AI or model use case description into a structured intake record at the front of the AI governance pipeline. Captures purpose, intended users, data sources, vendor and foundation-model dependencies, autonomy level, decision impact, regulatory exposure flags, proposed review gates, and the open questions a tier reviewer needs answered. The intake is the routing artifact downstream skills consume: ai-risk-tiering reads it to score the rubric, ai-act-triage reads it to scope Annex III overlap, model-card-builder reads it for system and data sections, validation-plan reads it to scope work, and the AI inventory of record consumes the structured object. Best for: - A first-line owner has proposed an AI use case and second-line needs the intake on file before tier, AI Act triage, or any downstream artifact is scoped. - An AI inventory refresh requires consistent intake metadata across in-flight, in-production, and decommissioned use cases. - A vendor-supplied AI tool is moving from POC to limited
- ▌ Board AI Risk Pack · anotb bundleDrafts the AI risk committee pack the AI Governance Lead carries into the meeting: AI inventory state with heat map by tier, top AI risks with trajectory, recent AI incidents and near-misses, foundation-model vendor concentration, model performance trends, GenAI program status, AI governance maturity posture, and the decisions the committee owes this cycle. The pack is the firm's standing instrument for AI-specific board oversight, alongside (not inside) the enterprise risk committee pack. Best for: - Standing AI risk committee meeting (often quarterly) where the AI Governance Lead, CRO, and head of model risk need a curated view of AI posture rather than the full inventory dump. - The AI section of a board risk committee at firms without a standalone AI committee, when the board wants AI-specific framing rather than a heat-map row inside the enterprise pack. - Board education session on AI governance: tier mix, top risks, foundation-model exposure, GenAI program status, and the decisions in flight. - Regulat
- ▌ Model Card Builder · anotb bundleDrafts a model card for a financial-services AI or model use case, with named sections for intended use, training and reference data, performance, limitations and known failure modes, monitoring plan, controls, change management, and sign-off questions. The card is the firm-side governance artifact that supports model risk committee review, pre-prod gates, the model inventory of record, validator handoff, and regulator response files. Best for: - A first-line owner has proposed an AI use case and second-line needs the model card before a tier decision or pre-prod gate. - A model risk team is refreshing model cards as part of an annual model inventory exercise. - A new vendor model is replacing an existing one and the card needs to be updated to reflect the swap. - A regulator response file or examiner request requires the firm's documented view of an in-scope model. Not the right tool when: - The use case has not been intaked yet (use ai-use-case-intake first). - Validation testing has not run and there are n
- ▌ Evidence Request Builder · anotb bundleDrafts the provided-by-client (PBC) evidence request list for a single control test cycle: one numbered row per ask, each carrying the control objective tested, criterion source, artifact requested, format, system of record, owner role, due date, population reference, reliance classification, and status. Produced before fieldwork begins; tracked through fieldwork; closed when every row resolves to received-or-not-applicable. The deliverable is an Excel workbook rendered via the `xlsx` skill in `document-skills`. Downstream, the workpaper consumes the request_id per evidence row and the closure binder consumes the closed list as the index of what was produced. Best for: - A compliance-testing or internal-audit pod has a signed test plan and is preparing the evidence ask before fieldwork begins. - A second-line reviewer is preparing for an upcoming examination and needs to pre-anticipate the regulator's evidence asks against current control coverage. - A QA reviewer is building a re-perform request list to redo
- ▌ Agentic AI Controls · anotb bundleReviews and proposes controls for an agentic AI use case (an AI system that selects actions, calls tools, reads or writes systems of record, or operates with autonomy beyond single-turn generation) in a regulated financial-services firm. Output names the agent's scope and authority statement, the architecture and tool inventory with permissions and blast radius, the identity and authorisation posture, the human oversight points with effective oversight evidence, the prompt-injection-via-tool-output and tool-misuse threat assessment, the kill-switch and rollback procedures with drill evidence, the logging and audit posture, the incident response with regulator-notification triggers, the residual risk with accepted owners, and the recommended owner actions. Designed for second-line review of agents that book actions in real systems, not chat-only assistants. Best for: - A first-line owner has built or is building an agentic system that calls tools, reads from systems of record, or executes actions, and second-l
- ▌ Exit Plan · anotb bundleDrafts the second-line exit plan for a critical or important third-party arrangement. Covers trigger events across vendor, firm, regulator, and market drivers; transition target options scored against impact tolerance; data return-and-destruction choreography; contract-termination mechanics; customer- and regulator-notice posture; supervisory readiness through a multi-month transition; testing cadence; named approver. Consumes the vendor-diligence record (criticality, subcontractors, data_access, residual_risk, exit_plan_status). Handles AI vendors via an explicit AI-vendor branch covering prompt-template portability, RAG migration, model-version pin handling, and agent-tool offboarding. Best for: - A new critical or important arrangement is being onboarded and the exit plan is required as part of pre-onboarding evidence. - Annual recertification of an existing critical or important vendor where the prior plan is stale, untested, or absent. - DORA preparation for critical-or-important-function arrangements wh
- ▌ Genai Pre Prod Review · anotb bundlePre-production gate review for a GenAI use case before initial release or material expansion. Pulls together the upstream artifacts (intake, tier, model card, validation-plan results, prompt-injection review where applicable, RAG evaluation review where applicable, vendor evidence review where applicable) and produces a recommended decision (go, go-with-conditions, hold, no-go) with reasoning, named blocking and tracking conditions, owners, and source trace. The artifact a senior risk officer or AI risk committee secretary signs into the gate meeting. Best for: - A GenAI use case is at the pre-prod gate and the second-line function needs the gate-review memo with a clear recommendation. - A material expansion of an existing GenAI deployment (new user population, new tool, new corpus, new geography) needs a re-gate. - A regulator pre-meet, examiner request, or supervisory motion is asking for the gate package on a named GenAI use case. - A recurring revalidation cycle has triggered a gate moment and the commit
- ▌ Prompt Injection Risk · anotb bundleReviews the prompt-injection threat surface for a deployed or near-deployed GenAI use case in a regulated financial-services firm. Catalogues the carriers (system prompt, user input, retrieved content, tool output, agent memory, multi-agent message, multimodal input), the trust posture on each, the tested attack classes, the mitigations in place with evidence, the residual risk with likelihood and impact framing, the production monitoring and detection signals, the incident-response classes with regulator-notification triggers, and the recommended owner actions. Output is a second-line-grade memo a CISO function, AI Governance Lead, MRMO, or AI risk committee can act on. Best for: - A GenAI assistant or agent is approaching pre-prod and second-line needs an explicit prompt-injection review before the gate. - An incident or near-miss in a deployed GenAI system has surfaced a prompt-injection vector and the committee needs a refreshed residual-risk view and notification-trigger evaluation. - A pre-exam or pre-c
- ▌ RAG Evaluation Review · anotb bundleReviews the retrieval and grounding evaluation for a RAG-based GenAI use case in a regulated financial-services firm. Confirms the corpus is fit for the intended purpose, retrieval quality is measured with named methods on a labelled set, grounding (faithfulness, citation precision, refusal on out-of-scope queries) is tested with documented metric semantics, failure modes are catalogued, mitigations are evidenced, and ongoing monitoring runs against a real ground-truth pipeline. Output is a second-line memo on whether the RAG implementation can be relied on for the use case's intended purpose, with named gaps, residual-risk framing, and owner actions. Best for: - A first-line owner has built a RAG system and second-line needs an evaluation review before pre-prod, expansion, or annual revalidation. - A foundation-model swap or a retrieval-stack change has happened and the grounding evaluation needs to be re-confirmed. - An incident on hallucination, off-corpus answer, or cross-scope leakage has surfaced and th
- ▌ Edd Escalation Pack · anotb bundleDrafts an enhanced due diligence escalation pack for a higher-risk customer profile (PEP, private banking, foreign correspondent, cash-intensive business, complex ownership, MSB-affiliated, sanctions-adjacent, high-risk jurisdiction nexus, or event-driven trigger). The pack assembles beneficial-ownership chain, derogatory information, source of wealth and source of funds, customer rationale, expected versus actual activity, sanctions-screening posture, conduct-risk indicators, ongoing-monitoring plan, and decision options for the EDD committee. Produces a review artifact only; the EDD committee or designated approver makes the relationship decision. Best for: - A baseline CDD review has flagged EDD escalation and the next artifact is the pack the EDD committee will review. - Periodic refresh on an existing high-risk customer where ownership, activity, derogatory information, or jurisdictional posture may have shifted. - Event-driven refresh triggered by adverse media, sanctions exposure, ownership change, or
- ▌ Aml Model Monitoring · anotb bundleReviews ongoing-monitoring evidence for an AML transaction-monitoring system, scoping which components of the stack sit inside the model-risk perimeter under the joint interagency model-risk supervisory guidance and which are deterministic rules outside it. Reads data quality, customer segmentation drift, scenario inventory and tuning evidence, below-the-line testing, alert volume and productivity trends, threshold-change governance, and validation evidence; produces a second-line monitoring memo that opens with a model-scoping read and a program-level review, carries the monitoring evidence in named structured sections, and closes with material findings, evidence-needed items, and recommended decision checkpoints with named owners. Does not approve scenario changes, set thresholds, sign off on validation conclusions, or QA individual SAR decisions. Best for: - Annual or quarterly second-line monitoring memo on a production AML transaction-monitoring system. - Pre-validation review scoping what the next valid
- ▌ Negative News Triage · anotb bundleTriages an adverse-media or negative-news hit set against a specific customer or entity for identity confidence, source reliability, recency, materiality to financial-crime risk, and downstream routing. Produces a triage memo and a structured triage record that downstream artifacts (cdd-risk-review refresh, edd-escalation-pack, sar-decision-qa, sanctions-screening-qa) can consume. Does not change customer ratings, file SARs, exit relationships, or re-tune monitoring scenarios. Best for: - Adverse-media hit triage at onboarding, periodic refresh, or event-driven refresh on a named customer. - Bulk triage over a periodic adverse-media re-scan output where the volume is dominated by common-name false matches. - Pre-EDD triage feeding into an EDD escalation pack. - Pre-SAR-decision triage where adverse media is part of an alert's evidence basis. Not the right tool when: - The work is sanctions-screening match disposition rather than adverse media; use `sanctions-screening-qa`. - The hit is already triaged and the
- ▌ Deposit Operations Controls · anotb bundleDrafts the second-line deposit-operations control matrix for a US bank: account opening and CIP, beneficial-ownership collection at deposit channels, account-opening and advertising disclosures, EFT and ATM controls under the consumer-EFT regime, funds-availability holds and exception-hold notification, NSF and overdraft fee disclosure under the truth-in-savings regime, garnishments and levies, escheatment and dormant-account governance, deposit-insurance coverage representation under the federal misrepresentation rule, FBO-account ledgering and pass-through deposit-insurance recordkeeping for sponsor-bank fintech programs, exception handling, access controls, and evidence retention. Audience is the deposit-operations director, the bank's compliance officer, the BSA officer, internal audit, and the federal banking examiner reading the matrix line-by-line. Best for: - A bank standing up or refreshing the deposit-operations control framework after a process change, a system migration, an internal-audit finding,
- ▌ Implementation Plan · anotb bundleSequences a regulatory remediation into the workplan a regulatory-change PMO, head of compliance, transformation lead, or business sponsor runs to a mandatory compliance date. Takes an obligation list (from rule-to-obligation-extraction), a policy diff (from policy-diff), and any control-gap output, and produces workstreams, milestones with dependencies, owners by role, evidence-based acceptance criteria, governance cadence (working group, steering, executive, board), implementation risks, resource asks, regulator-readiness checkpoints, and the BAU handoff. Sized for a regulatory-change committee or PMO and structured for tracking against a mandatory compliance date or supervisory-letter deadline. Generic across regulator type and trigger; sector and cross-cutting overlays load from the scope. Best for: - A new final rule has effective dates approaching and the firm needs a sequenced, owner-assigned plan with governance cadence and evidence criteria. - A supervisory letter, MRA, MRIA, or consent order require
- ▌ Fintech Partner Controls · anotb bundleDrafts the fintech-side controls evidence pack a sponsor bank's third-party risk function expects in its file: control inventory mapped to Reg E error-resolution timing, NACHA Operating Rules obligations the program operator owes upstream, FBO subledger reconciliation, sponsor-bank reporting cadence, customer-facing disclosure adherence (Reg E §1005.7-§1005.11, Reg DD), money-transmitter / MSB BSA posture where applicable, contract-clause adherence evidence under the program agreement, and a 12-month incident-history summary. Output is a Word memo plus an Excel control inventory, review-ready for the fintech's own second line and for production to the sponsor bank's TPRM team or to a state-MTL examiner. Best for: - A fintech, neobank, BaaS program, or wallet operator preparing or refreshing its self-evidence pack for a sponsor-bank annual review, sponsor-bank-led audit, or state-MTL exam. - Compliance has been asked to self-evidence Reg E §1005.11 error-resolution timing (10 / 45 / 90-day clocks), NACHA retur
- ▌ Payments Risk Assessment · anotb bundleDrafts a payments risk assessment for a fintech, money transmitter, BaaS platform, neobank, wallet, or sponsor-bank program: a matrix-shaped artifact denominated by rail (ACH, Same Day ACH, wire, card debit / credit, FedNow, RTP, P2P, check, cross-border correspondent, virtual-currency on-ramp), by customer segment (consumer, SMB, payroll-on-demand, gig, BNPL, cross-border remittance, high-risk vertical), and by US-state and corridor geography. Carries fraud, BSA / AML, sanctions, operational resilience, third-party / sponsor-bank dependence, customer-harm / UDAAP, and reporting-control views, with concentration sub-tables for sponsor-bank, processor, and BIN-sponsor exposure. Output suits a sponsor-bank annual review, a state MTL exam preparation file, an internal audit kickoff, or an enterprise risk committee read-out. Best for: - A program operator, sponsor-bank program-management team, or money transmitter is running its annual or semi-annual payments risk assessment and second-line is owning the artifact
- ▌ Sanctions Screening QA · anotb bundleQuality-reviews a sanctions screening program against named regulatory frames: list-management governance, customer and transaction screening configuration, match-logic and fuzzy-threshold tuning, list-update timeliness, alert disposition documentation, false-positive rationale, escalation paths, 50 Percent Rule and sectoral-sanctions handling, and cyber-evasion exposure. Reads each sampled alert disposition for documented rationale, decision-maker independence, and 50%-rule assessment; produces a second-line QA memo with material findings, evidence-needed items, and recommended decision checkpoints with named owners. Does not approve list configuration, tune match logic, file blocking or rejection reports, close alerts, or make match-or-no-match decisions. Best for: - Periodic sample QA over customer-screening and transaction-screening alert dispositions within a defined review window. - Pre-validation review of screening configuration evidence to scope the next validation cycle. - Pre-exam readiness review
- ▌ Banking Supervision Readiness · anotb bundleProduces the substantive supervision-readiness pack a US bank or bank holding company hands the OCC, FRB, or FDIC examiner-in-charge at the entry meeting and carries through the cycle. Organises preparation around the CAMELS components (or the BHC rated components for a holding-company cycle), the examiner-letter response posture (MRA, MRIA, supervisory recommendation, consent-order article), the MRA / MRIA closure cross-walk with sustained-operation evidence, the Heightened Standards readiness view for covered banks, and the topical examiner-readiness slices (BSA / AML, IT, fair lending, third-party risk) that the cycle scope brings into play. Audience is the head of supervisory affairs, the chief compliance officer, the chief risk officer, the BSA officer, and the examination coordinator. Best for: - A national bank, state-member bank, state non-member bank, or federal savings association is preparing for an OCC, FRB, or FDIC full-scope safety-and-soundness examination and needs the entry-meeting pack with
- ▌ Udaap Risk Review · anotb bundleDrafts a second-line UDAAP review memo for a product, feature, fee, disclosure or customer-experience flow, marketing motion, complaint pattern, or enforcement theme. Element-by-element analysis under Dodd-Frank §1031 (unfairness, deception, abusiveness) and §1036; consumer-harm hypothesis with population and magnitude; AI / algorithmic-discrimination tie-in where automated systems are in path; severity rating with rubric; conduct-risk implications; recommended remediation; cross-references to complaint, marketing, adverse-action, and fair-lending review. The memo surfaces UDAAP risk for human decision; it does not finalize a UDAAP determination, take down a live product, execute consumer redress, or issue any customer-facing action. Best for: - Pre-launch UDAAP review of a new product, feature, fee structure, or disclosure flow before a product or risk committee approves launch. - Targeted review after a complaint cluster (chain to `complaint-theme-analysis`), a regulator inquiry, or a peer enforcement actio
- ▌ Insurance Outsourcing Review · anotb bundleDrafts a second-line oversight pack for an insurance outsourcing or delegated-authority arrangement (MGA, MGU, TPA, claims administrator, underwriting bureau, IT or actuarial outsourcer) read against the NAIC outsourcing and holding-company family and the NAIC Insurance Data Security Model Law. The pack carries the holding-company status, producer-licensing posture, contractual-control review, third-party-service-provider clauses, claims-handling oversight, premium-handling posture, vendor-AI exposure, ORSA fit, named gaps with citations, and a recommended supervisor disposition. The audience is state-DOI exam-grade. Best for: - A US insurer or reinsurer is onboarding, renewing, or remediating an MGA, MGU, TPA, or claims-administrator arrangement and second-line needs the pre-decision review. - A market-conduct exam, ORSA cycle, or internal audit has flagged outsourced-function oversight and the team is preparing the response file. - A reinsurer is reviewing a cedent's delegated-underwriting authority arrange
- ▌ Open Banking Data Controls · anotb bundleDrafts a controls inventory and self-evidence pack for consumer-permissioned data sharing under the named US personal-financial-data-rights frame. The pack covers data-provider duties (covered-data scope, developer-interface availability and security, consumer authorisation, scope and duration limits, revocation propagation, third-party screening) and data-recipient duties (consumer authorisation, collection and use limits, retention, deletion-on-revocation, reauthorisation, downstream sharing). The artifact aligns to industry-standard tokenised data-sharing patterns and to the migration off credential-based screen scraping. Audience is the data-provider fintech, the data-recipient fintech (account aggregator, PFM, lender, BNPL, payroll-on-demand), or the sponsor-bank programme acting as either, plus the second-line or advisory team supporting them. Best for: - A data-provider fintech (or its sponsor bank's programme) is preparing for an implementation-tier milestone, an examiner data request, or a sponsor-ba
- ▌ LLM Vendor Evidence Review · anotb bundleReviews a foundation-model vendor's published evidence pack (system card, model card, evaluation reports, red-team summaries, security and privacy attestations, responsible-use policies, trust-and-safety pages) against firm criteria for the firm's deployment context. Produces a sufficiency view, named gaps with supplemental evidence requested, residual reliance with caveats, recommended owner actions, and re-review triggers. The artefact a model risk lead, AI risk committee, or vendor-diligence officer uses to decide whether to depend on a foundation model in scope. The model-evidence layer that pairs with vendor-diligence in third-party-operational-resilience for the entity-level wrapper. Best for: - A new foundation-model vendor is being onboarded for one or more in-scope use cases and the model-evidence layer is needed for the deployment-context decision. - A foundation-model provider has published a new system card, model variant, or version and the firm needs the delta review. - A periodic re-attestation
- ▌ Vendor Diligence · anotb bundleDrafts a second-line vendor diligence pack for a single ICT, fintech, cloud, data, or AI service provider. Captures inherent risk, criticality input, due-diligence evidence read against named regulatory criteria, residual risk, exit posture, and the gaps a control owner needs to close before onboarding or recertification. Handles AI vendors via an explicit AI-vendor branch in the same workflow. Best for: - A first-line owner has proposed a new ICT, fintech, cloud, data, or AI vendor and second-line needs the pre-onboarding pack. - A vendor risk team is recertifying an existing critical or important vendor and the prior pack is stale. - An AI vendor (foundation-model API, AI SaaS, embedded-AI feature, agentic system) needs diligence with the second-line lens, not a procurement checklist. - An exit-triggered or post-incident re-review of an existing vendor. Not the right tool when: - The criticality tier has not been set (run `criticality-assessment` first). - The job is portfolio-level concentration across man
- ▌ Bank Fintech Partnership Review · anotb bundleProduces the bank-side principal-supervisory partnership pack on a US bank-fintech relationship. Carries six named sections (service description and risk classification; risk-based diligence summary; contract gaps; customer-facing controls under Reg O / Reg W / Reg E / Reg DD; termination and wind-down readiness; recommended owner actions) plus a Reg O / Reg W / Reg E / Reg DD applicability summary the bank attests to. Audience is the partnership owner, the chief risk officer, the chief compliance officer, the BSA officer, the head of vendor management, the head of deposit operations, the general counsel, and the OCC / FRB / FDIC supervisory team that examines the relationship as a bank service-provider arrangement. Best for: - A national bank, state-member bank, state non-member bank, or federal savings association is onboarding a fintech relationship (BaaS sponsor program, embedded-lending partner, deposit-program partner, fraud / KYC service partner, payments-processor) and second-line needs the partnershi
- ▌ Life Health Pricing Governance · anotb bundleDrafts a second-line pricing-governance review of a US life or health rating change (new rate filing, refile, accelerated-underwriting model, rating-plan refresh, ML-driven rating factor, post-issue underwriting model) for a state DOI rate analyst's audience. The artifact carries a rate-filing summary, a rating-factor map, an unfair-discrimination analysis under NAIC Model #880, disparate-impact red flags under state DOI bulletins, AIS Program coverage against the NAIC AI Bulletin (December 2023), and documentation completeness against SR 11-7-equivalent expectations. The deliverable shape is a Word memo plus an Excel rating-factor map; SERFF-track and AU-track engagements use the same spine. Best for: - A life or health insurer is preparing or refreshing a rate filing and second-line wants the pricing-governance file before SERFF submission. - An accelerated-underwriting model or ML-driven rating factor has gone through development and second-line needs the unfair-discrimination and disparate-impact review b
- ▌ Adverse Action Review · anotb bundleReviews a population of adverse-action notices and the underlying credit decisions field-by-field — timing, content, specificity of cited reasons, traceability of those reasons back to the model and data, FCRA risk-score disclosure overlay, and disparate-impact red flags. Produces a Word memo for the consumer compliance second-line, the fair-lending lead, model risk, and counsel; flags non-compliant notices and AI / complex-model accuracy gaps; recommends action without finalizing any customer-facing change. Best for: - Consumer compliance second-line sampling adverse-action notices on a credit product, testing the population against the notification rule's timing and content obligations. - Model risk or fair-lending review of a credit decision model (including AI / ML scorecards) where adverse-action reasons are produced from feature contributions and the reviewer needs to test that the cited reasons are the principal reasons supported by the model. - Triage of consent-order remediation or supervisory findin
- ▌ Section1071 Readiness · anotb bundleDrafts a Section 1071 small-business lending data readiness assessment under the CFPB's revised final rule (May 1, 2026; effective June 30, 2026; compliance date January 1, 2028). Covers covered-financial-institution determination against the 1,000-covered-transactions threshold, covered-application and covered-credit-transaction scoping, the 12 CFR 1002.107 data-point inventory, applicant-demographic data-collection mechanics, the 12 CFR 1002.108 firewall design, recordkeeping under 12 CFR 1002.110, and reporting-and-filing readiness against the CFPB Filing Instructions Guide. Produces a readiness matrix per data point and a narrative gap memo for the named accountable executive. Best for: - Pre-compliance-date readiness check for a covered financial institution against the January 1, 2028 compliance date (now a single compliance date for all CFIs at or above the 1,000-transaction threshold; the prior tier-based schedule is superseded). - Threshold-determination work for a firm sitting at or near the 1,000 c
- ▌ Contract Gap Review · anotb bundleReviews a third-party contract or master services agreement against named regulatory clause-coverage expectations and produces a clause-by-clause gap matrix with severity, remediation posture, and the legal-review triggers a control owner needs before signature, renewal, or assignment. Output is the second-line clause-coverage view that sits next to (not in place of) legal redlines. Best for: - A new vendor contract is in negotiation and the firm needs the second-line clause-coverage view before legal redlines land. - Renewal, assignment, or material amendment of an existing contract triggers a refresh against current regulatory expectations. - A digital-operational-resilience preparation cycle requires evidence that critical-or-important-function ICT contracts meet the mandatory-clause set. - A vendor-diligence pack needs the contract-coverage section closed out (chains via `contract_gap_summary`). Not the right tool when: - The criticality tier has not been set (run `criticality-assessment` first; clause de
- ▌ Fair Lending Test Plan · anotb bundleDrafts a fair-lending test plan covering scope, products, decision points (marketing, underwriting, pricing, steering, servicing, loss mitigation), planned test types (redlining, comparative file review, statistical regression on underwriting and pricing, marketing distribution, steering), demographic-proxy methodology, less-discriminatory-alternative search where AI or ML models drive credit decisions, data and evidence asks, controls hypothesis, owners, and committee approval gate. The plan is the operationalization of the annual fair-lending risk assessment and the artifact a fair-lending committee approves before any test is run. Best for: - Annual fair-lending risk-assessment refresh where the test plan is the operationalization of the assessment. - Pre-exam fair-lending readiness where a regulator has signaled focus on a specific product, MSA, or decision point. - Targeted plan after complaint themes (chain to `complaint-theme-analysis`) or adverse-action review (chain to `adverse-action-review`) surfac
- ▌ Marketing Claim Review · anotb bundleDrafts a second-line marketing-claim review memo for one creative or one campaign of consumer-financial marketing. Asset-by-asset and claim-by-claim: substantiation status per claim; deception, unfairness, and (where applicable) abusiveness reads on the displayed asset; required disclosures (Reg Z trigger terms, MAPR / APR / fees, FDIC insurance, Reg DD, MLA where in scope, TRID-adjacent where the marketing previews mortgage terms); fair-lending distribution and targeting findings; privacy-claim accuracy; dark-pattern findings against a named taxonomy; AI-generated and AI-personalised content review; and recommended edits with kill-switch candidates. The memo is the input to the marketing-compliance decision forum; it does not approve marketing for launch, take down live assets, or finalize UDAAP, fair-lending, or privacy determinations. Best for: - Pre-launch second-line review of one consumer-financial marketing campaign (deposit, credit card, mortgage, BNPL, personal loan, auto, small business) before the
- ▌ Dora Register Builder · anotb bundleEU-DORA-context build pack and data-quality aid for firms preparing Register of Information entries for ICT third-party arrangements. Helps a US-deep practice with EU-touching engagements populate register fields, surface data-quality gaps, and structure a build-pack narrative for the named approver before the firm's regulatory-reporting pipeline takes over. The skill's local B-table convention is preparation-grade. It is not the official EBA Register of Information template and not submission-grade against the Commission Implementing Regulation (EU) 2024/2956 taxonomy. Best for: - An EU-nexus financial entity scoping the first-cycle register build, where a structured data-quality view and a reviewer-ready build pack matter before the firm's submission tooling formats the official template. - An EU subsidiary of a non-EU group where the parent needs visibility into EU register data quality before the subsidiary files individually to its national competent authority. - A second-line review of an existing regis
- ▌ Complaint Theme Analysis · anotb bundleAggregates and themes a population of consumer complaints (CFPB Complaint Database extracts, internal complaint-management records, app-store reviews, social signals, state-AG referrals, employee escalations) into named themes with severity, root-cause hypotheses, regulatory exposure mapping, and trended movements. Produces two artifacts: an Excel theme-aggregation matrix and a Word memo with the narrative analysis. Themes (not individual complaints) are the unit of analysis. The skill surfaces signal for the consumer compliance committee, the conduct committee, and the cross-skill chain into UDAAP, fair-lending, and adverse-action review; it does not finalise UDAAP determinations, fair-lending findings, or actions on individual complaints. Best for: - Quarterly or monthly complaint-themes pack to the consumer compliance committee, conduct committee, or risk committee. - Pre-exam preparation: re-running the firm's last 12 to 24 months of CFPB Complaint Database public data (and the firm-internal channels) aga
- ▌ Regulatory Impact Assessment · anotb bundleDrafts a second-line impact assessment for a published rule, supervisory letter, FIL, circular, bulletin, industry letter, adopting release, advisory, supervisory speech, or enforcement theme. Carries two lenses in one artifact: an implementation lens (in-scope determination, obligation domains hit, policy and control impact, reporting and disclosure impact, technology and data impact, third-party impact, customer impact, cost-to-comply read, effective-date posture, transition relief) and a regulatory-strategy lens (firm position, regulator-engagement posture, comment-period posture if any, public consultation posture, peer-and-industry alignment, escalation triggers). Audience is regulatory affairs, head of compliance, head of legal, CRO chief of staff, and the head of business affected. Drafts only; attestation external. Best for: - A new final rule, supervisory letter, FIL, circular, bulletin, or industry letter has been published and the regulatory-change function needs a firm-impact and strategic-posture
- ▌ Criticality Assessment · anotb bundleSets the criticality tier of a single third-party arrangement and ties it to the firm's important business service, recovery time and recovery point objectives, customer impact, regulatory impact, operational substitutability, and concentration considerations. Produces the upstream record that vendor-diligence, contract-gap-review, exit-plan, concentration-risk-review, and dora-register-builder consume. Audience: head of TPRM, head of operational resilience, business owner. Best for: - A new arrangement is being proposed and the firm needs the tier set before kicking off vendor-diligence. - An annual third-party portfolio review where tiers are stale or inconsistently applied. - A DORA preparation cycle that requires a critical-or-important-function flag for every ICT arrangement. - A material change to the service or to the firm's important-business-service map triggers a re-tier. Not the right tool when: - The firm has not yet defined the important business service the arrangement supports (the criticality
- ▌ Rule To Obligation Extraction · anotb bundleDecomposes a discrete piece of net-new regulatory rule text into atomic obligations. Input is a named regulator-issued instrument: a Federal Register final rule or adopting release, a CFR codified section, an OCC bulletin, an FRB SR letter, an FDIC FIL, a CFPB circular or bulletin, an NCUA letter to credit unions, an NYDFS industry letter, an EU regulation or implementing technical standard, an FCA handbook chapter, a NAIC model law, a FinCEN advisory, or a published consent order whose remediation requirements the firm should also satisfy. Output is the atomic obligation list as a draft register: each row pinned to a paragraph or subsection, naming the action verb, the party obligated, the condition, the deadline, the exception, and the related obligations. Firm-agnostic and portable across firms; firm-side mapping happens in the next step. Best for: - A new final rule or adopting release has just published in the Federal Register and the firm needs the atomic obligation list before the regulatory-change com
- ▌ Resilience Testing Pack · anotb bundleDrafts a second-line resilience-testing pack for an important business service or for a critical-or-important third-party arrangement. Captures the mapping under test, the firm's impact tolerance as the pass/fail line, the severe-but-plausible scenario set, the test-design choices per scenario (tabletop, walkthrough, partial simulation, full live exercise, data-extraction rehearsal, shadow cutover), success criteria, the evidence-collection and observation plan, the locked read-out template, the lessons-learned-and-findings flow into issue management, the post-test remediation set, and the named approver. Consumes the IBS map, vendor-diligence records, and exit-plan records. Surfaces an explicit AI branch when an AI dependency sits on the chain under test, and a TLPT-scoping line where advanced testing is in scope. Best for: - Annual or quarterly resilience-testing cycle planning for an important business service. - A critical or important third-party arrangement where the diligence pack flagged untested exit
- ▌ Payment Operations Incident Review · anotb bundleDrafts the incident-review pack for a payments-operations event at a fintech program operator, BaaS platform, money transmitter, neobank, wallet, BIN sponsor, or payments processor. The pack carries an incident summary, customer-impact population, named-rail and sponsor-bank notification triggers, root cause, affected transaction population by rail, remediation actions, sponsor-bank reporting, and the regulator-facing artifact list. Output is review-ready for the program operator's second line and for production to the sponsor bank, the named payment-rail authorities (where applicable), and the regulator-facing incident file. Best for: - An ACH return spike, mis-posted batch, double-debit, stuck FedNow / RTP transfer, faulty Reg E claim queue, card-network fraud-rate or chargeback program escalation, or processor-side outage has happened and second line owns the review pack. - A sponsor-bank annual review, internal audit, or examiner data request includes incident retrospectives and the team needs the structu
- ▌ Concentration Risk Review · anotb bundleDrafts a portfolio-level concentration view across the firm's third-party arrangements. Reads single-vendor concentration, sub-contractor (fourth-party) concentration, geographic and jurisdictional concentration, technology-stack concentration (hyperscaler region, foundation-model vendor, shared utility), and sponsor-bank or BaaS concentration against named supervisory thresholds and substitutability tests. Output is a concentration matrix, the concerning concentrations flagged for committee, and a substitutability-grounded recommendation set. The skill stops at the recommendation; the head of TPRM, head of operational resilience, and CRO office decide. Best for: - An annual third-party portfolio review where leadership wants the concentration picture across vendors and fourth parties. - An ICT third-party preliminary concentration assessment cycle in an EU-nexus regime where the firm must form a view before contracting or recontracting a critical-or-important function. - A specific arrangement diligence pack
- ▌ Fund Board Reporting · anotb bundleAssembles the periodic compliance and risk pack delivered to the board of a registered investment company (mutual fund, ETF, closed-end fund, BDC) and its independent trustees. The pack covers the chief compliance officer's annual written report on the fund and service-provider compliance programs, the advisory contract approval and renewal package built on the §15(c) factor analysis, the standing compliance and risk reporting cadence (material compliance matters, valuation oversight, liquidity program reporting, derivatives risk reporting, affiliated-transactions and soft-dollar / brokerage disclosures), and the per-service-provider compliance program assessment for the adviser, sub-advisers, transfer agent, custodian, fund accountant, distributor, principal underwriter, valuation designee, and pricing services. The deliverable is a board-presentation deck plus a Word annex carrying the §15(c) and Rule 38a-1 written content the board minutes record consumes. Best for: - A fund chief compliance officer is pre
- ▌ Adviser Exam Readiness · anotb bundleProduces the substantive readiness pack an SEC-registered investment adviser, broker-dealer, dual registrant, fund adviser, or private-fund adviser carries through an SEC Division of Examinations or FINRA examination cycle. Walks the firm through Form ADV / Form CRS / Form BD cross-check, the Rule 206(4)-7 written compliance program, the Rule 204A-1 code of ethics lane, the Rule 206(4)-2 custody lane, the Rule 206(4)-1 Marketing Rule lane, Rule 204-2 books-and-records, Form PF (Rule 204(b)-1) where applicable, Reg BI and Form CRS for BDs and dual registrants, FINRA 3110 / 3120 / 3130 / 3310 supervision, and the cyber / Reg S-P slice that EXAMS now reaches for routinely. Audience is the chief compliance officer, the chief executive officer, general counsel, the designated FINRA supervisor for a BD or dual registrant, the BSA officer where AML is in scope, and the firm's external counsel. Best for: - An adviser, BD, or dual registrant has been notified of an SEC EXAMS routine, focused, for-cause, or sweep exami
- ▌ Marketing Rule Evidence · anotb bundleBuilds a Marketing Rule evidence and substantiation pack for one piece of SEC-registered investment-adviser advertising. Per-advertisement, per-claim review: classify the statement (advertisement, performance presentation, hypothetical, predecessor, related, extracted, model, testimonial, endorsement, third-party rating); map required disclosures by statement type; record the substantiation file claim by claim; run the testimonial / endorsement and third-party-rating compliance checklists; apply the hypothetical-performance pre-conditions; assemble the books-and-records evidence index. The pack is the input to the CCO or designated reviewer's pre-dissemination sign-off; it does not approve dissemination, finalize antifraud determinations, or replace counsel review. Best for: - Pre-dissemination review of one piece of adviser marketing (pitch deck, fact sheet, website page, RFP response, social post, recorded webinar, podcast script) before the CCO or designated reviewer signs off. - Periodic look-back on advi
- ▌ Best Execution Surveillance · anotb bundleDrafts the periodic best-execution surveillance review for an investment adviser, broker-dealer, dual registrant, or fund adviser. Carries trade-by-trade exception sampling, aggregate venue and counterparty execution-quality metrics, factor analysis under the applicable rule lattice, Rule 605 / 606 reconciliation where applicable, conflict-as-input review (PFOF, principal trades, agency crosses, affiliated brokerage, soft dollars, commission-sharing arrangements), and the best-execution committee escalation pack. Output is the reviewable artifact a best-ex committee, a CCO, a fund board's §15(c) materials, or a SEC IM / FINRA exam file consumes. Best for: - A registered investment adviser is performing its quarterly or annual best-execution review and the second line owns the artifact. - A broker-dealer is performing its FINRA Rule 5310 regular-and-rigorous review of execution quality across venues for retail or institutional flow. - A fund's adviser is preparing the brokerage and best-execution section of th