Skip to main content

チュートリアル 13: Regulatory Compliance & Risk Assessment

Master regulatory compliance research, gap assessments, risk matrices, and monitoring systems across multiple jurisdictions with Claude or ChatGPT.

対応Claude: 検証済みChatGPT / Codex: 下書きGrok Bot: 下書き

概要

規制コンプライアンス調査の実施方法、リスク評価の作成方法、ポリシーと規制の対応付け方法、そして法域横断で立法変更を追跡するモニタリングシステムの構築方法を学びます。

今日完了する内容

このチュートリアルでは、AIアシスタントを使ったコンプライアンスワークフローを順を追って説明します。メインの流れでは、明確なステップバイステップの1つの経路に沿って進めます。プラットフォームを切り替える必要はありません。

Claudeでの主要ワークフロー: 以下のプロンプトを matter Project(Tutorial 04)内で実行し、該当する場合は Legal plugin command を使用し(Tutorial 06)、MCP を通じてリサーチコネクタを接続します(Tutorial 07)。評価に依拠する前に、エスカレーションルールを明示しておいてください。

Official Claude legal-task screenshot showing regulatory compliance review output

Claude Legal Solutions の公式 Claude スクリーンショット。コンプライアンス出力では、法律専門家が分析に依拠する前に確認できるよう、引用、前提条件、未確定のガイダンスに関するフラグを保持する必要があります。

学習目標

このチュートリアルを終えるまでに、次のことができるようになります。

  • 法域をまたいで包括的な規制コンプライアンス調査を実施する
  • 制定法上の要件を解釈し、立法変更を追跡する
  • 自動化されたリスクマトリクスとギャップ評価を作成する
  • 組織のポリシーを規制フレームワークに対応付ける
  • 規制変更を監視し、コンプライアンス追跡システムを実装する
  • SEC提出書類を分析し、開示義務を評価する
  • 金融サービス向けのコンプライアンスワークフローを開発する
  • 規制要件に基づくデータ駆動型の企業ポリシーを作成する
  • ベンダーのコンプライアンスと第三者リスクを評価する

上級レベル

このチュートリアルには60分程度かかり、規制フレームワークとコンプライアンス文書に関する一定の技術的な理解が必要です。


Part 1: 規制コンプライアンス調査フレームワーク

複数法域にまたがる調査戦略

現代のコンプライアンスでは、複数の法域にまたがって規制がどのように機能するかを理解する必要があります。アシスタントは、この調査を体系化するのに役立ちます。

Official Claude compliance-audit screenshot showing organized audit preparation

Prep scattered documents for a compliance audit の公式 Claude スクリーンショット。監査整理の出力は、統制や提出義務が満たされていることの証明としてではなく、レビュー担当者によるフォローアップのためのチェックリストとして使用してください。

重要な概念: 規制調査には、適用されるルールの特定、要件の相互参照、影響の対応付けが含まれます。

Prompt: 包括的コンプライアンス調査

I need to research data privacy regulations applicable to our operations.

Company Profile:
- Headquarters: California
- Operations: California, New York, Colorado, and EU (subsidiary)
- Industry: SaaS/Cloud Services
- Data Types: Customer personal data, employee data, financial data

Please provide:
1. PRIMARY REGULATIONS - All laws that directly apply
   - List by jurisdiction
   - State effective dates
   - Summary of key requirements

2. SECONDARY REGULATIONS - Related rules affecting compliance
   - Industry standards
   - Contractual requirements
   - Best practices

3. INTERACTION MAP - How regulations work together
   - Conflicts or overlaps
   - Cumulative requirements
   - Most restrictive standard to follow

4. COMPLIANCE GAPS TABLE
   | Regulation | Current Status | Required By | Gap | Priority |
   | --- | --- | --- | --- | --- |

5. IMPLEMENTATION TIMELINE
   - Quick wins (under 30 days)
   - Medium term (30-90 days)
   - Long term (90+ days)
   - Dependencies between items

6. RESOURCE RECOMMENDATIONS
   - External counsel needed?
   - Consulting firm guidance?
   - Technology investments?

法域別調査のベストプラクティス

Jurisdiction TypeKey QuestionsSources
Federal連邦法は存在するか? 中小企業向けの例外はあるか?eeoc.gov, sec.gov, ftc.gov
State州法がより厳格な要件を課しているか?Attorney General offices
Internationalどの国でデータを収集しているか? どの規制が適用されるか?Country-specific AG or ministry sites
Industry規制当局(銀行、医療、証券など)はあるか?Industry-specific regulators

Part 2: 制定法の解釈と立法動向の追跡

複雑な制定法の分析

規制コンプライアンスでは、曖昧な制定法文言の解釈が必要になることがよくあります。アシスタントは、この分析を構造化するのに役立ちます。

Prompt: 制定法の解釈

I need to understand how the FDCPA applies to our debt collection practices.

Statute: Fair Debt Collection Practices Act (15 U.S.C. § 1692)
Specific Issue: Does our SMS reminder system violate prohibitions on abusive
              collection practices?

Please analyze:

1. STATUTORY TEXT - Relevant sections
   - Quote the exact statutory language
   - Note any defined terms that apply
   - Identify the prohibition or requirement

2. LEGISLATIVE INTENT
   - What problem was Congress trying to solve?
   - Historical context
   - Any legislative history?

3. REGULATORY INTERPRETATION
   - FTC guidance on this provision
   - CFPB interpretations if applicable
   - Regulatory preambles

4. CASE LAW ANALYSIS
   - Leading cases interpreting this section
   - Circuits or jurisdictions with most guidance
   - Conflicting interpretations
   - Recent developments

5. PRACTICAL APPLICATION EXAMPLES
   - Scenario 1: Morning SMS to borrower [COMPLIANT/RISKY/VIOLATION]
   - Scenario 2: SMS at 10 PM [COMPLIANT/RISKY/VIOLATION]
   - Scenario 3: Multiple daily SMS [COMPLIANT/RISKY/VIOLATION]

6. SAFE HARBOR RECOMMENDATIONS
   - Best practices that clearly comply
   - Grey areas requiring additional verification
   - Prohibited practices to avoid

7. COMPLIANCE DOCUMENTATION
   - How to document compliance monitoring
   - What records to maintain
   - Audit procedures

立法変更の追跡

規制環境は頻繁に変化します。体系的なモニタリングを構築しましょう。

Prompt: 立法変更モニタリング

Set up a legislative tracking system for the following regulations:
- Banking Secrecy Act amendments
- Anti-money laundering (AML) updates
- Know Your Customer (KYC) requirements

For each regulation, provide:

1. MONITORING SOURCES
   - Which committees draft these bills?
   - Which agencies interpret them?
   - Where to find proposed rules?

2. TRACKING TRIGGERS
   - What signals new rulemaking (Congress draft, agency notice, etc.)?
   - What signals significant changes?
   - What warrants immediate escalation?

3. NOTIFICATION TIMELINE
   - When are bills typically introduced?
   - How long is comment period?
   - When do rules take effect?
   - Implementation grace periods?

4. IMPACT ASSESSMENT TEMPLATE
   When new legislation is identified:
   - Affected business units
   - Required policy changes
   - Technology investments needed
   - Training requirements
   - Timeline for implementation

5. ESCALATION MATRIX
   - Who needs to know?
   - When to escalate to C-suite?
   - When to engage outside counsel?
   - When to brief board?

Part 3: リスクマトリクスの作成とコンプライアンスギャップ評価

自動化されたコンプライアンスギャップのマッピング

現在あるものと、要求されているものを特定します。

Prompt: コンプライアンスギャップ評価

Generate a compliance gap assessment for HIPAA Privacy Rule.

Our Organization:
- Type: Healthcare provider
- Size: 150 employees
- Data: Patient health records, insurance info
- Systems: Electronic health record (Healthlink), email, Paper records
- Current Policies:
  * Data Security Policy (2022)
  * Access Control Policy (2022)
  * Incident Response Plan (2020)
  * Business Associate Agreements (partial)

Please provide:

1. REQUIREMENT INVENTORY
   Create table of all HIPAA Privacy Rule requirements:
   | Requirement | Source | Status | Evidence | Gap |
   | --- | --- | --- | --- | --- |

2. ASSESSMENT METHODOLOGY
   For each requirement, determine if we:
   - Fully Comply (documented evidence)
   - Substantially Comply (minor gaps)
   - Partially Comply (major gaps)
   - Non-Compliant (not implemented)
   - Not Applicable

3. EVIDENCE MAPPING
   For implemented controls, link to:
   - Policy document
   - Procedure document
   - Training records
   - Audit findings

4. RISK MATRIX
   For each gap:
   | Gap | Severity | Likelihood | Risk Score | Remediation | Timeline |
   | --- | --- | --- | --- | --- | --- |

5. REMEDIATION ROADMAP
   Phase 1 (Immediate - 30 days): Critical risks
   Phase 2 (Short-term - 90 days): High risks
   Phase 3 (Medium-term - 6 months): Medium risks
   Phase 4 (Long-term - 12 months): Low risks

6. RESOURCE REQUIREMENTS
   - Personnel hours needed
   - External expertise required
   - Technology investments
   - Budget estimate for each phase

7. METRICS & MONITORING
   - How to track progress on remediation
   - Key performance indicators
   - Audit schedule

リスクマトリクスのベストプラクティス

すべてのコンプライアンス領域で一貫した形式でリスク評価を構造化し、是正対応の比較と優先順位付けができるようにしましょう。


Part 4: ポリシーとコンプライアンスの対応付け

ポリシーを規制と相互参照する

会社のポリシーと規制要件のマスターマッピングを作成します。

Prompt: ポリシーとコンプライアンスの対応付け

Map our company policies against GDPR requirements.

Our Current Policies:
1. Data Protection Policy (attached)
2. Privacy by Design Standard (attached)
3. Vendor Management Policy (attached)
4. Data Breach Response Plan (attached)
5. Records Retention Policy (attached)

GDPR Articles to Address: Articles 1-99 (full GDPR)

Please provide:

1. REGULATORY REQUIREMENT MATRIX
   For each GDPR article:
   - Article number and title
   - Specific requirement text
   - Applicable to our organization? (Yes/No)
   - Current coverage in our policies? (Yes/No)

2. POLICY-TO-REGULATION MAPPING
   Create table showing:
   | Policy | Article | Section | Requirement | Coverage Level |
   | --- | --- | --- | --- | --- |

   Coverage Levels:
   - Full: Requirement completely addressed
   - Substantial: Mostly addressed, minor gaps
   - Partial: Partially addressed, major gaps
   - Absent: Not addressed at all

3. GAPS & OVERLAPS
   - Which GDPR articles lack policy coverage?
   - Which policies address multiple articles?
   - Conflicting policy provisions?

4. POLICY DEVELOPMENT NEEDS
   Articles requiring entirely new policies

5. POLICY REVISION PRIORITIES
   Existing policies needing updates ranked by:
   - Risk impact
   - Implementation difficulty
   - Regulatory urgency

6. IMPLEMENTATION CHECKLIST
   For each identified gap:
   - [ ] Draft new policy language
   - [ ] Cross-reference related policies
   - [ ] Obtain compliance review
   - [ ] Board approval (if required)
   - [ ] Employee training materials
   - [ ] Documentation of compliance

Part 5: 規制変更モニタリングシステム

自動化されたコンプライアンスカレンダーの構築

Prompt: 規制変更モニタリング設定

Build a regulatory monitoring system for financial services compliance.

Regulations to Monitor:
- Dodd-Frank Act
- Gramm-Leach-Bliley Act (GLBA)
- Anti-money laundering (AML) regulations
- Know Your Customer (KYC) requirements
- CFPB regulations
- State consumer finance laws

Please provide:

1. MONITORING INFRASTRUCTURE
   For each regulation:
   - Official government sources to monitor
   - Industry association resources
   - Law firm alerts to subscribe to
   - Consulting firm research to follow
   - Recommended search alerts

2. CHANGE DETECTION MATRIX
   | Regulation | Source | Check Frequency | Escalation Trigger | Owner |
   | --- | --- | --- | --- | --- |

3. IMPACT ASSESSMENT PLAYBOOK
   When regulatory change detected:
   - Questions to ask about impact
   - Stakeholders to involve
   - Timeline for implementation
   - Resources required
   - Documentation needed

4. REGULATORY CALENDAR
   | Deadline | Regulation | Action | Owner | Status |
   | --- | --- | --- | --- | --- |

5. TREND ANALYSIS
   - What patterns do you see in recent regulatory changes?
   - What industries/topics are getting increased scrutiny?
   - What's coming in next 12 months?
   - How should we adapt our compliance posture?

6. STAKEHOLDER COMMUNICATION PLAN
   - Who needs regulatory updates?
   - Update frequency (weekly/monthly/quarterly)?
   - Communication format?
   - Escalation procedures?

Part 6: SEC提出書類の分析と開示義務

10-K のリスク要因セクションを分析する

上場企業は重要なリスクを開示しなければなりません。何を、なぜ開示しているのかを分析します。

Prompt: SEC提出書類のリスク分析

Analyze risk factor disclosures for a technology company.

Company: [Company Name]
Recent 10-K Filing: [Attached or URL]
Fiscal Year: [Year]

Please analyze:

1. RISK FACTOR INVENTORY
   - List all risk factors disclosed
   - Categorize by type (operational, legal, market, etc.)
   - Note which are new or revised from prior year

2. ADEQUACY ASSESSMENT
   For each significant risk:
   - Is disclosure adequate or formulaic?
   - Does it explain specific business impact?
   - Are quantified risks included?
   - Is mitigation strategy disclosed?

3. COMPARABLES ANALYSIS
   Compare risk disclosures to:
   - Competitors in same industry
   - Companies of similar size
   - Prior years of same company

4. LITIGATION RISK ANALYSIS
   Identify:
   - Current litigation disclosed
   - Contingent liability reserves
   - Likelihood of material claims
   - Potential exposure amounts

5. REGULATORY RISK ASSESSMENT
   - New regulations affecting business?
   - Pending regulatory actions?
   - Government investigations?
   - Compliance costs anticipated?

6. MATERIAL WEAKNESS ANALYSIS
   - Are there material weaknesses in internal controls?
   - How are they described in filing?
   - What's the plan to remediate?
   - Timeline for remediation?

7. UPDATE RECOMMENDATIONS
   Based on current events/circumstances:
   - Risk factors needing revision
   - New risks requiring disclosure
   - Risks that can be removed as no longer material
   - Suggested language changes

Part 7: 金融サービス向けコンプライアンスワークフロー

銀行業および金融サービスのコンプライアンス

金融機関は特有の規制負担に直面します。

Prompt: AML/KYC コンプライアンスワークフロー

Design an AML/KYC compliance program for a fintech company.

Company Profile:
- Licensed as Money Services Business
- Operates in 30 US states
- Peer-to-peer payment platform
- 500K+ active customers
- Average transaction: $150
- High-risk geographies: [list]

Please develop:

1. KYC PROGRAM FRAMEWORK
   - Customer identification procedures
   - Risk-based approach to due diligence
   - Ongoing customer monitoring
   - Enhanced due diligence triggers
   - Documentation requirements

2. AML MONITORING PROCEDURES
   - Transaction monitoring thresholds
   - Suspicious activity detection
   - Filing obligations (SARs, CTRs)
   - Record retention requirements
   - Audit procedures

3. RISK ASSESSMENT MATRIX
   | Factor | Risk Level | Mitigation | Monitoring |
   | --- | --- | --- | --- |

   Factors:
   - Customer type (individual vs. business)
   - Geography
   - Transaction amount
   - Transaction frequency
   - Customer profile changes

4. COMPLIANCE CALENDAR
   - Quarterly SAR reviews
   - Annual program effectiveness testing
   - Training schedules
   - Policy review cycles
   - Examination prep

5. TECHNOLOGY REQUIREMENTS
   - Automated transaction monitoring tools
   - Customer risk scoring systems
   - Document verification solutions
   - Reporting platforms
   - Audit trail systems

6. STAFFING & TRAINING
   - Compliance officer responsibilities
   - Staff training requirements
   - Third-party vendor management
   - Escalation procedures
   - Documentation

7. REGULATORY EXAMINATION READINESS
   - Common examination issues
   - Preparation checklist
   - Documentation organization
   - Self-assessment procedures

金融サービスの複雑性

金融サービスのコンプライアンスは高度に規制されており、専門的です。AML/KYC プログラムの実装とレビューについては、必ず専門の法律専門家に依頼してください。


Part 8: ベンダーおよび第三者のコンプライアンス管理

ベンダーリスクの評価

第三者は、最終的に自社が引き受けることになるコンプライアンスリスクを生み出します。

Prompt: ベンダーのコンプライアンスリスク評価

Create a vendor compliance management program.

Vendor Categories to Assess:
- Cloud service providers
- Payroll processors
- Insurance brokers
- Accounting firms
- IT service providers
- Data disposal companies

Please develop:

1. VENDOR RISK ASSESSMENT FRAMEWORK
   For each vendor, evaluate:
   - Data access level (what data do they handle?)
   - Regulatory applicability (what rules apply?)
   - Security controls (are they adequate?)
   - Financial stability (will they stay in business?)
   - Compliance maturity (have they been audited?)

2. RISK SCORING MATRIX
   | Vendor | Data Risk | Compliance Risk | Security Risk | Financial Risk | Overall Score |
   | --- | --- | --- | --- | --- | --- |

3. DUE DILIGENCE CHECKLIST
   For high-risk vendors:
   - [ ] SOC 2 Type II audit review
   - [ ] Insurance verification
   - [ ] References check
   - [ ] Security documentation review
   - [ ] Financial statements review
   - [ ] Litigation/regulatory history check
   - [ ] Disaster recovery/business continuity plan
   - [ ] Data location and processing review

4. CONTRACTUAL PROTECTIONS
   - Indemnification clauses
   - Data processing agreements
   - Security requirements
   - Audit rights
   - Insurance requirements
   - Breach notification obligations
   - Confidentiality and NDA standards
   - Term and termination rights

5. ONGOING MONITORING PLAN
   | Vendor | Monitoring Mechanism | Frequency | Owner | Escalation |
   | --- | --- | --- | --- | --- |

   Monitoring mechanisms:
   - Annual certification/attestation
   - Periodic on-site audits
   - Continuous security scanning
   - Regulatory news monitoring
   - Financial monitoring
   - Performance metrics tracking

6. REMEDIATION PROCEDURES
   When issues identified:
   - Severity assessment
   - Vendor notification
   - Corrective action timeline
   - Escalation procedures
   - Termination conditions
   - Business continuity during transition

7. COMPLIANCE DOCUMENTATION
   - Vendor registry with all key info
   - Risk assessment dates and results
   - Due diligence work files
   - Current contracts and amendments
   - Audit reports
   - Compliance certifications

第三者リスク

多くのデータ侵害やコンプライアンス違反は第三者ベンダーに起因します。定期的なベンダー評価は、組織のコンプライアンス態勢を維持するうえで重要です。


Part 9: 品質管理チェックリスト

コンプライアンスプログラムの完全性

このチェックリストを使って、規制コンプライアンスプログラムを評価してください。

Regulatory Compliance Program QC Checklist

  • Regulatory Inventory Complete - 適用されるすべての規制が特定され、文書化されている
  • Jurisdiction Mapping Current - 複数州・国際的な要件が特定されている
  • Gap Assessment Documented - コンプライアンス上のギャップが特定され、優先順位付けされている
  • Policies Drafted/Updated - 必要なポリシーがすべて整備され、最新化されている
  • Policy-Regulation Mapping - 各ポリシーが適用される規制と相互参照されている
  • Risk Matrix Developed - コンプライアンスリスクが特定、評価、優先順位付けされている
  • Remediation Plan - アクション項目に担当者と期限が割り当てられている
  • Monitoring System Established - 規制変更が体系的に追跡されている
  • Training Program Active - スタッフがコンプライアンス義務について訓練を受けている
  • Audit Schedule Set - 定期的なコンプライアンス監査が予定されている
  • Vendor Assessment Complete - 第三者のコンプライアンスリスクが評価されている
  • Governance Documented - 役割、責任、エスカレーションが明確に文書化されている
  • Evidence Collected - コンプライアンス上の主張を裏付ける文書が収集されている
  • Annual Review Scheduled - コンプライアンスプログラムが毎年レビュー・更新される予定になっている
  • Board Reporting - コンプライアンス状況が取締役会・経営層に報告されている

実践演習

演習 1: コンプライアンス調査プロトコルを構築する

自組織に適用される規制を1つ選んでください。Part 1 の複数法域調査プロンプトを使って、次を調査し文書化してください。

  • すべての適用法域
  • 一次規制および二次規制
  • 主要要件の要約
  • 現在のコンプライアンス状況
  • 特定されたギャップ

演習 2: ポリシーと規制の対応表を作成する

会社のポリシーを1つ選んでください。次の詳細な対応表を作成してください。

  • どの規制に対応しているか
  • どの要件を完全に/部分的に/まったく満たしていないか
  • 推奨される改訂
  • 実装の証拠

演習 3: モニタリングシステムを設計する

特定の規制分野について、次を設計してください。

  • 監視する情報源
  • 変更検知のトリガー
  • 影響評価手順
  • 関係者コミュニケーション計画
  • 実装タイムライン

演習 4: ベンダーリスク評価

重要なベンダーを1つ選んでください。次を実施してください。

  • Part 8 のフレームワークを用いたリスク評価
  • 契約条件に対するギャップ分析
  • モニタリング計画の策定
  • 必要に応じた是正提案

比較: 手作業によるコンプライアンス vs. AI支援によるコンプライアンス

TaskManual ApproachAI-Assisted
Regulatory Research制定法・規制を手作業で読むより速い構造化された初期レビュー(弁護士による確認が必要)
Gap Assessmentスプレッドシート追跡とインタビューフレームワーク主導のチェックリストと証拠マッピング
Policy Mapping手作業での相互参照、関連の見落としが起きやすい体系的な要件対ポリシーの対応付け
Risk Scoring主観的評価で一貫性に欠ける一貫した基準による構造化マトリクス
Monitoring事後対応になりがち予防的なモニタリングワークフロー(維持されている場合)
Vendor Due Diligence断片的な文書レビュー反復可能なリスク評価ワークフロー
Documentation標準化・監査対応状態の維持が難しい整理されたテンプレートと追跡成果物
Time Investment範囲と成熟度によって異なる通常はワークフロー構築後に削減。パイロット指標で確認すること

今すぐやること

  • 自組織に適用される規制を1つ調査する(Part 1 prompt)
  • 制定法解釈または立法追跡の演習を1つ完了する
  • コンプライアンスギャップ評価を1つ実行し、リスクマトリクスを作成する
  • 会社のポリシーを1つ、その規制要件に対応付ける
  • 主要規制を1つ対象にモニタリングシステムを設計する
  • コンプライアンスフレームワークを使ってベンダーを1社評価する
  • Regulatory Compliance Program QC Checklist を完了する

上級チュートリアルの前の宿題

  1. 自社の規制環境を特定する - 自組織に適用されるすべての規制を文書化する

  2. 規制インベントリを作成する - 適用されるすべての要件のマスタースプレッドシートを作成する

  3. ギャップ評価を1つ実施する - 主要な規制を1つ選び、ギャップ評価を完了する

  4. モニタリングシステムを設計する - 主要規制の変更を追跡するシステムを構築する

  5. ベンダーリスクを評価する - 評価フレームワークを使って上位3〜5社のベンダーを評価する


Appendix: 業界別の規制モニタリングリソース

Banking & Financial Services

  • Federal Reserve (federalreserve.gov)
  • CFPB (consumerfinance.gov)
  • OCC (occ.gov)
  • FinCEN (fincen.gov)
  • State attorneys general

Healthcare

  • CMS (cms.gov)
  • HHS/OCR (hhs.gov)
  • State health departments
  • State attorneys general
  • DEA (if applicable)

Technology/Data

  • FTC (ftc.gov)
  • State attorneys general
  • EU data protection authorities
  • CISA (cisa.gov)
  • Industry-specific bodies

Securities

  • SEC (sec.gov)
  • FINRA (finra.org)
  • State securities regulators
  • SRO announcements
  • EDGAR filings

Sources

Additional Reading


重要なポイント

成功要因

  • 体系的アプローチ: 一貫したコンプライアンス評価のために、構造化されたプロンプトとフレームワークを使用する
  • 文書化: コンプライアンス対応と意思決定の証拠を包括的に維持する
  • モニタリング: 規制変更が業務に影響する前に追跡する予防的なシステムを構築する
  • リスクベース: リスクスコアリングと事業影響に基づいて是正対応の優先順位を決める
  • Vendor Management: 第三者のコンプライアンスは自社のコンプライアンスでもある -- ベンダーを定期的に評価し監視する

クイックリファレンス: コンプライアンス用プロンプト

# Quick Regulatory Research
"Research [regulation name] in [jurisdiction].
Show: requirements, gaps, timeline, resources needed."

# Quick Gap Assessment
"Compare our [policy name] to [regulation name].
Identify all gaps and priorities."

# Quick Risk Score
"Score compliance risk for [area]:
Rate 1-10 by severity, likelihood, and overall risk."

# Quick Monitoring Setup
"Design monitoring system for [regulation].
Show sources, frequency, triggers, escalation."


On this page

1 概要1.1 今日完了する内容2 Part 1: 規制コンプライアンス調査フレームワーク2.1 複数法域にまたがる調査戦略2.2 Prompt: 包括的コンプライアンス調査2.3 法域別調査のベストプラクティス3 Part 2: 制定法の解釈と立法動向の追跡3.1 複雑な制定法の分析3.2 立法変更の追跡4 Part 3: リスクマトリクスの作成とコンプライアンスギャップ評価4.1 自動化されたコンプライアンスギャップのマッピング5 Part 4: ポリシーとコンプライアンスの対応付け5.1 ポリシーを規制と相互参照する6 Part 5: 規制変更モニタリングシステム6.1 自動化されたコンプライアンスカレンダーの構築7 Part 6: SEC提出書類の分析と開示義務7.1 10-K のリスク要因セクションを分析する8 Part 7: 金融サービス向けコンプライアンスワークフロー8.1 銀行業および金融サービスのコンプライアンス9 Part 8: ベンダーおよび第三者のコンプライアンス管理9.1 ベンダーリスクの評価10 Part 9: 品質管理チェックリスト10.1 コンプライアンスプログラムの完全性11 実践演習11.1 演習 1: コンプライアンス調査プロトコルを構築する11.2 演習 2: ポリシーと規制の対応表を作成する11.3 演習 3: モニタリングシステムを設計する11.4 演習 4: ベンダーリスク評価12 比較: 手作業によるコンプライアンス vs. AI支援によるコンプライアンス13 今すぐやること14 上級チュートリアルの前の宿題15 Appendix: 業界別の規制モニタリングリソース15.1 Banking & Financial Services15.2 Healthcare15.3 Technology/Data15.4 Securities16 Sources17 Additional Reading18 重要なポイント19 クイックリファレンス: コンプライアンス用プロンプト20 Related21 Navigation