By anotb
Regulatory change management skills for impact assessment, obligation extraction, policy diffing, implementation planning, and exam brief preparation.
Decomposes a discrete piece of net-new regulatory rule text into atomic obligations. Input is a named regulator-issued instrument: a Federal Register final rule or adopting release, a CFR codified section, an OCC bulletin, an FRB SR letter, an FDIC FIL, a CFPB circular or bulletin, an NCUA letter to credit unions, an NYDFS industry letter, an EU regulation or implementing technical standard, an FCA handbook chapter, a NAIC model law, a FinCEN advisory, or a published consent order whose remediation requirements the firm should also satisfy. Output is the atomic obligation list as a draft register: each row pinned to a paragraph or subsection, naming the action verb, the party obligated, the condition, the deadline, the exception, and the related obligations. Firm-agnostic and portable across firms; firm-side mapping happens in the next step. Best for: - A new final rule or adopting release has just published in the Federal Register and the firm needs the atomic obligation list before the regulatory-change committee meets. - A supervisory letter, FIL, OCC bulletin, CFPB circular, or NYDFS industry letter has landed and the obligation deltas need extracting against the prior cycle. - A published consent order describes remediation steps the firm should treat as obligations even though the firm is not the named defendant. - An EU regulation or technical standard has entered into force and the firm needs the article-by-article obligation list before the implementation committee scopes work. Not the right tool when: - The source is a firm policy, vendor contract, exam-request list, board minute, or any document other than a regulator-issued rule or guidance instrument; use `risk-compliance-core/obligation-mapping` (it consumes any source and overlays firm context). - The output needed is firm-specific control objectives, named control owners, evidence systems-of-record, and policy mapping; that is `risk-compliance-core/obligation-mapping`. This skill stops at the regulator-side obligation; the next skill in the chain overlays firm context. - Firm impact has not been scoped yet and the question is whether the rule applies at all; run `regulatory-impact-assessment` first. - The question is the delta between the firm's existing policy text and the new rule; run `policy-diff` after this skill produces the obligation list. - The work is sequencing remediation milestones across functions; run `implementation-plan` after this skill.
Drafts the engagement playbook a regulatory affairs lead, head of compliance, head of legal, or CRO chief of staff runs during a live regulator engagement. Generic across regulator type and product line. Captures the scope confirmation in writing, the named single-point-of-contact map by topic, the document-handling and privilege posture, the request-list mapping, the interview-prep posture, the supervisory-history that the engagement inherits (open MRA, MRIA, consent-order milestones, self-identified issues), the anticipated reviewer questions tied to current supervisory priorities, the exit-meeting and supervisory-letter response posture, and the post-exam follow-up. The substantive readiness sprint sits in sector-specific exam-readiness skills; this is the engagement-side scaffolding that runs during the exam window. Best for: - An exam window has opened (any regulator, any product line) and the regulatory affairs lead needs the engagement playbook before fieldwork begins. - A supervisory-letter response or consent-order milestone is in flight and the response posture needs a written engagement record. - A targeted, limited-scope, horizontal, or for-cause review where the generic engagement shape is the operative scaffolding and a sector-specific readiness package is too heavy. - A pre-exam mock or self-assessment exercise where the deliverable should look like the real engagement playbook. Not the right tool when: - The engagement is a full-scope OCC, FRB, or FDIC bank examination at an institution carrying the Heightened Standards. Use `sector-plugins/banking-risk-compliance/banking-supervision-readiness` for the substantive readiness sprint; that skill carries OCC, FRB, and FDIC supervisory framework, capital, liquidity, BSA/AML examination-manual, fair-lending, and CRA scaffolding. The generic exam-brief can still run as a sub-package for an engagement-side slice. - The engagement is an SEC investment-adviser or asset-manager exam. Use `sector-plugins/capital-markets-asset-management-compliance/adviser-exam-readiness`; that skill carries IAA Rule 206(4)-7, custody rule, marketing rule, books-and-records, and Form ADV scaffolding. The generic exam-brief can still cover, for example, a cyber-only slice within a broader adviser exam. - The job is to extract obligations from a published rule (use `rule-to-obligation-extraction`) or to sequence remediation milestones (use `implementation-plan`). - The job is impact assessment of a proposed rule, not engagement with a regulator on an existing rule (use `regulatory-impact-assessment`).
Sequences a regulatory remediation into the workplan a regulatory-change PMO, head of compliance, transformation lead, or business sponsor runs to a mandatory compliance date. Takes an obligation list (from rule-to-obligation-extraction), a policy diff (from policy-diff), and any control-gap output, and produces workstreams, milestones with dependencies, owners by role, evidence-based acceptance criteria, governance cadence (working group, steering, executive, board), implementation risks, resource asks, regulator-readiness checkpoints, and the BAU handoff. Sized for a regulatory-change committee or PMO and structured for tracking against a mandatory compliance date or supervisory-letter deadline. Generic across regulator type and trigger; sector and cross-cutting overlays load from the scope. Best for: - A new final rule has effective dates approaching and the firm needs a sequenced, owner-assigned plan with governance cadence and evidence criteria. - A supervisory letter, MRA, MRIA, or consent order requires a remediation plan with named workstreams, milestones, owners, monitor or independent-consultant integration, and reporting cadence. - A regulatory-change programme needs a refresh after a transition-period change, a regulator FAQ update, or a litigation-driven shift in the effective date. - A self-identified issue or audit finding warrants a programme-level plan with second-line oversight rather than an issue-management ticket. Not the right tool when: - Obligations have not been extracted yet. Use `rule-to-obligation-extraction` first; this skill takes its output as input. - Policy gaps have not been identified. Use `policy-diff` to surface the gaps; combine with control-gap output from compliance-testing where available. - The artifact is for an active examination engagement. Use `exam-brief` for the engagement-side scaffolding; this skill chains downstream from exam-brief when an MRA, MRIA, or supervisory letter is issued. - The objective is to assess whether the firm should comply at all. That is a legal determination and is out of scope for the second line. - The trigger is a single low-risk issue suited to the routine issue-management lifecycle (use `risk-compliance-core/skills/issue-writeup`); this skill is for programme-level remediation.
Compares two versions of a firm policy (or a proposed policy edit against the current approved version) and produces a section-by-section change log with materiality flags, downstream impact, approver routing, and effective date. One row per change. Each row carries the diff (added, removed, reworded, restructured), the section path, the substantive delta, the materiality call, and the downstream consequences (training refresh, control revision, system change, communication, attestation re-up). Used by policy owners during the annual review cycle, by compliance running a redline against an MRA-driven amendment, and by change-management standing up the rollout package after the policy committee approves. Best for: - Annual or scheduled policy review where the second line needs the version-over-version delta before recertification. - Proposed policy amendment where compliance, legal, or the policy owner needs the change log and downstream impacts before the policy committee meets. - Post-MRA or post-issue policy revision where the firm needs to show the regulator exactly what moved between the prior approved version and the remediated version. - Pre-approval review of a draft policy against the live approved version where the question is what changed, what it touches, and who needs to know. Not the right tool when: - The work is comparing a single policy version against external regulatory obligations (use `risk-compliance-core/policy-gap-review`; that skill is policy vs obligation, this skill is policy version A vs version B). - The work is parsing a new rule into atomic obligations before any policy work begins (use `regulatory-change-management/rule-to-obligation-extraction`). - The work is sequencing remediation across business units after the policy is approved (use `regulatory-change-management/implementation-plan`). - The trigger is drafting a new policy from scratch (route to the policy owner; this skill diffs, it does not draft).
Drafts a second-line impact assessment for a published rule, supervisory letter, FIL, circular, bulletin, industry letter, adopting release, advisory, supervisory speech, or enforcement theme. Carries two lenses in one artifact: an implementation lens (in-scope determination, obligation domains hit, policy and control impact, reporting and disclosure impact, technology and data impact, third-party impact, customer impact, cost-to-comply read, effective-date posture, transition relief) and a regulatory-strategy lens (firm position, regulator-engagement posture, comment-period posture if any, public consultation posture, peer-and-industry alignment, escalation triggers). Audience is regulatory affairs, head of compliance, head of legal, CRO chief of staff, and the head of business affected. Drafts only; attestation external. Best for: - A new final rule, supervisory letter, FIL, circular, bulletin, or industry letter has been published and the regulatory-change function needs a firm-impact and strategic-posture read before the issue is logged in the inventory. - A proposed rule is in comment period and the firm needs an impact read to support a comment-letter decision and the workplan that runs if the rule finalises. - A supervisory priorities letter, regulator speech, or interagency statement has shifted examiner posture and the firm needs to assess where current state may not hold up. - An enforcement action or consent order names a peer institution and the firm needs a fast read on whether the same theme applies and what the strategy posture should be. Not the right tool when: - The rule text has already been parsed and the next step is decomposing the rule into discrete obligations (use rule-to-obligation-extraction). - Firm policy text is already drafted and the question is whether it covers the rule (use policy-diff). - Gaps are already documented and the next step is sequencing the remediation (use implementation-plan). - The engagement is a live exam window and the artifact needed is the engagement playbook (use exam-brief).
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Plugins for second-line and 1.5-line financial-services work. Skills cover what risk and compliance teams (and the advisory practitioners who support them) actually produce: scoping a review, mapping obligations, building a control matrix, drafting a model card, writing up an issue, building a vendor-diligence pack, packaging a risk-committee read, working a SAR / no-SAR file, prepping for a supervisory cycle, and so on. Skills are grounded in regulatory and standards material, with sector context (banking, capital markets, insurance, payments / fintech) loaded conditionally from the scoping record.
Built primarily for Claude (and Claude Code), but the skill files follow the open SKILL.md format and can be loaded into other agentic systems that support it: GPT, Gemini, in-house open-weights deployments, or anything else that reads agent skills. The skills are markdown plus optional schemas; the format is the standard, the work product is what travels.
The repo extends Anthropic's published financial-services plugin family. Where Anthropic's plugins cover the cross-industry first-line baseline (financial analysis, banking deal work, equity research, PE, wealth, fund admin, ops), these go deeper into US second-line and 1.5-line work and US supervisory expectations.
Second-line and 1.5-line practitioners inside regulated firms: model-risk leads (MRMO), AI governance leads, third-party risk managers (TPRM), BSA / AML officers, sanctions officers, compliance heads (CCO), fair-lending and UDAAP review teams, controls testing and internal audit teams, risk reporting and CRO-office teams, regulatory-affairs and regulatory-change teams, operational-resilience leads, fund-board secretaries, disclosure committees.
And the advisory and consulting teams running the same work for those firms.
If you work in 1.5L, 2L, or adjacent functions, the skills let Claude (or other agentic systems supporting the SKILL.md format) draft alongside you, like a colleague who knows the work and defers to your judgement on the call.
references/sector-overlays/<sector>.md inside the relevant capability skill, loaded conditionally from the scoping record.references/source-anchors.md with the regulatory and standards citations they lean on. US-deep, with EU as overlay and UK as see-also.The skill set is public-source-derived and anonymous, with no firm-specific policy baked in.
Standalone agent plugins (one-shot reviewers that orchestrate related skills end-to-end) are not in this release. The next iteration adds a maker / checker loop with genuine context-isolated subagent forking, primary-plus-critic two-agent shape, and plugin dependencies in place of bundled-skill copies. See ROADMAP.md for the target shape.
| Plugin | What it covers |
|---|---|
risk-compliance-core | Scoping, obligation mapping, control matrices, evidence binders, issue write-ups, human-review gates, policy-gap reviews. |
regulatory-change-management | Regulatory impact assessment, rule-to-obligation extraction, policy diffs, implementation plans, exam briefs. |
ai-governance-model-risk | AI use-case intake, AI risk tiering, EU AI Act triage, model cards, validation plans, agentic-AI controls, board AI-risk pack, GenAI deep-dive (prompt injection, RAG eval, pre-prod review, LLM vendor evidence). |
third-party-operational-resilience | Vendor diligence, criticality, contract-gap review, exit plans, concentration, DORA register, severe-but-plausible resilience testing. |
compliance-testing | Test plans, control sampling, evidence requests, exception analysis, workpapers, QA review. |
risk-reporting | Risk committee packs, BCBS 239 self-assessment, KRI commentary, SEC cyber-disclosure readiness, attestation packs, management responses to MRA / MRIA / audit findings. |
financial-crime-governance | CDD review, EDD escalation packs, SAR-decision QA, AML model monitoring, sanctions-screening QA, negative-news triage. |
consumer-compliance-fair-lending | Adverse-action review, fair-lending test plans, UDAAP risk review, Section 1071 readiness, complaint-theme analysis, marketing-claim review. |
Analyze RFPs, develop proposals, apply strategic frameworks, and build implementation plans. Create executive deliverables for strategy, operations, and transformation engagements.
AI governance and model risk skills for AI intake, risk tiering, model cards, validation planning, agentic controls, EU AI Act triage, AI vendor review, and board risk packs.
Third-party risk and operational resilience skills for vendor diligence, criticality assessment, DORA registers, contract gaps, exit plans, resilience testing, and concentration risk.
Compliance and controls testing skills for test plans, sampling, evidence requests, workpapers, exception analysis, issue drafting, and QA review.
Core GRC workflow skills for obligation mapping, control matrices, evidence binders, issue write-ups, human-review gates, and policy gap reviews.
npx claudepluginhub anotb/second-line-financial-services --plugin regulatory-change-managementComprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
Permanent coding companion for Claude Code — survives any update. MCP-based terminal pet with ASCII art, stats, reactions, and personality.
UI/UX design intelligence. 67 styles, 161 palettes, 57 font pairings, 25 charts, 15 stacks (React, Next.js, Vue, Svelte, Astro, SwiftUI, React Native, Flutter, Tailwind, shadcn/ui, Nuxt, Jetpack Compose). Actions: plan, build, create, design, implement, review, fix, improve, optimize, enhance, refactor, check UI/UX code. Projects: website, landing page, dashboard, admin panel, e-commerce, SaaS, portfolio, blog, mobile app. Elements: button, modal, navbar, sidebar, card, table, form, chart. Styles: glassmorphism, claymorphism, minimalism, brutalism, neumorphism, bento grid, dark mode, responsive, skeuomorphism, flat design. Topics: color palette, accessibility, animation, layout, typography, font pairing, spacing, hover, shadow, gradient.
This skill should be used when users need to generate ideas, explore creative solutions, or systematically brainstorm approaches to problems. Use when users request help with ideation, content planning, product features, marketing campaigns, strategic planning, creative writing, or any task requiring structured idea generation. The skill provides 30+ research-validated prompt patterns across 14 categories with exact templates, success metrics, and domain-specific applications.
Develop, test, build, and deploy Godot 4.x games with Claude Code. Includes GdUnit4 testing, web/desktop exports, CI/CD pipelines, and deployment to Vercel/GitHub Pages/itch.io.
Upstash Context7 MCP server for up-to-date documentation lookup. Pull version-specific documentation and code examples directly from source repositories into your LLM context.