Skip to main content

Tutorial 13: Regulatory Compliance & Risk Assessment

Master regulatory compliance research, gap assessments, risk matrices, and monitoring systems across multiple jurisdictions with Claude or ChatGPT.

DektClaude: geverifieerdChatGPT / Codex: conceptGrok Bot: concept

Overzicht

Leer hoe u onderzoek naar naleving van regelgeving uitvoert, risicobeoordelingen opstelt, beleidsregels aan regelgeving koppelt en monitoringsystemen bouwt die wetswijzigingen in verschillende jurisdicties volgen.

Wat u vandaag zult voltooien

Deze tutorial begeleidt u door nalevingsworkflows met uw AI-assistent. U volgt één duidelijk stapsgewijs pad — zonder van platform te wisselen in de hoofdflow.

Primaire workflow in Claude: voer de onderstaande prompts uit binnen een matter Project (Tutorial 04), gebruik een Legal plugin command waar dat bestaat (Tutorial 06), en koppel onderzoeksconnectors via MCP (Tutorial 07). Houd escalatieregels expliciet voordat u op een beoordeling vertrouwt.

Officiële Claude-screenshot voor juridische taken met output van een controle op naleving van regelgeving

Officiële Claude-screenshot van Claude Legal Solutions. Nalevingsoutput moet citaten, aannames en markeringen voor onduidelijke richtsnoeren behouden, zodat een jurist deze kan controleren voordat op de analyse wordt vertrouwd.

Leerdoelen

Aan het einde van deze tutorial kunt u:

  • Uitgebreid onderzoek naar naleving van regelgeving uitvoeren over verschillende jurisdicties heen
  • Wettelijke vereisten interpreteren en wetswijzigingen volgen
  • Geautomatiseerde risicomatrices en gap-analyses opstellen
  • Organisatiebeleid koppelen aan regelgevingskaders
  • Wijzigingen in regelgeving monitoren en systemen voor nalevingstracking implementeren
  • SEC-filings analyseren en disclosure-verplichtingen beoordelen
  • Nalevingsworkflows voor financiële diensten ontwikkelen
  • Datagedreven bedrijfsbeleid opstellen op basis van wettelijke vereisten
  • Leveranciersnaleving en risico's van derden evalueren

Gevorderd niveau

Deze tutorial vereist 60 minuten en enig technisch inzicht in regelgevingskaders en nalevingsdocumentatie.


Deel 1: Onderzoeksraamwerk voor naleving van regelgeving

Onderzoeksstrategie voor meerdere jurisdicties

Moderne naleving vereist inzicht in hoe regelgeving werkt in meerdere jurisdicties. De assistent kan helpen dit onderzoek te systematiseren.

Officiële Claude-screenshot van compliance-audit met georganiseerde auditvoorbereiding

Officiële Claude-screenshot van Prep scattered documents for a compliance audit. Gebruik output voor auditorganisatie als checklist voor opvolging door de reviewer, niet als bewijs dat aan een controlevereiste of indieningsverplichting is voldaan.

Kernconcept: Onderzoek naar regelgeving omvat het identificeren van toepasselijke regels, het kruislings vergelijken van vereisten en het in kaart brengen van impact.

Prompt: Uitgebreid nalevingsonderzoek

I need to research data privacy regulations applicable to our operations.

Company Profile:
- Headquarters: California
- Operations: California, New York, Colorado, and EU (subsidiary)
- Industry: SaaS/Cloud Services
- Data Types: Customer personal data, employee data, financial data

Please provide:
1. PRIMARY REGULATIONS - All laws that directly apply
   - List by jurisdiction
   - State effective dates
   - Summary of key requirements

2. SECONDARY REGULATIONS - Related rules affecting compliance
   - Industry standards
   - Contractual requirements
   - Best practices

3. INTERACTION MAP - How regulations work together
   - Conflicts or overlaps
   - Cumulative requirements
   - Most restrictive standard to follow

4. COMPLIANCE GAPS TABLE
   | Regulation | Current Status | Required By | Gap | Priority |
   | --- | --- | --- | --- | --- |

5. IMPLEMENTATION TIMELINE
   - Quick wins (under 30 days)
   - Medium term (30-90 days)
   - Long term (90+ days)
   - Dependencies between items

6. RESOURCE RECOMMENDATIONS
   - External counsel needed?
   - Consulting firm guidance?
   - Technology investments?

Best practices voor jurisdictiespecifiek onderzoek

Jurisdiction TypeKey QuestionsSources
FederalIs there federal legislation? Exceptions for small business?eeoc.gov, sec.gov, ftc.gov
StateDoes state law impose stricter requirements?Attorney General offices
InternationalWhich countries collect data? Which regulations apply?Country-specific AG or ministry sites
IndustryAre there regulatory bodies (banking, healthcare, securities)?Industry-specific regulators

Deel 2: Wettelijke interpretatie en het volgen van wetgeving

Analyse van complexe wetten

Naleving van regelgeving vereist vaak interpretatie van dubbelzinnige wettekst. De assistent kan helpen deze analyse te structureren.

Prompt: Wettelijke interpretatie

I need to understand how the FDCPA applies to our debt collection practices.

Statute: Fair Debt Collection Practices Act (15 U.S.C. § 1692)
Specific Issue: Does our SMS reminder system violate prohibitions on abusive
              collection practices?

Please analyze:

1. STATUTORY TEXT - Relevant sections
   - Quote the exact statutory language
   - Note any defined terms that apply
   - Identify the prohibition or requirement

2. LEGISLATIVE INTENT
   - What problem was Congress trying to solve?
   - Historical context
   - Any legislative history?

3. REGULATORY INTERPRETATION
   - FTC guidance on this provision
   - CFPB interpretations if applicable
   - Regulatory preambles

4. CASE LAW ANALYSIS
   - Leading cases interpreting this section
   - Circuits or jurisdictions with most guidance
   - Conflicting interpretations
   - Recent developments

5. PRACTICAL APPLICATION EXAMPLES
   - Scenario 1: Morning SMS to borrower [COMPLIANT/RISKY/VIOLATION]
   - Scenario 2: SMS at 10 PM [COMPLIANT/RISKY/VIOLATION]
   - Scenario 3: Multiple daily SMS [COMPLIANT/RISKY/VIOLATION]

6. SAFE HARBOR RECOMMENDATIONS
   - Best practices that clearly comply
   - Grey areas requiring additional verification
   - Prohibited practices to avoid

7. COMPLIANCE DOCUMENTATION
   - How to document compliance monitoring
   - What records to maintain
   - Audit procedures

Wetswijzigingen volgen

Regelgevingslandschappen veranderen vaak. Bouw systematische monitoring op.

Prompt: Monitoring van wetswijzigingen

Set up a legislative tracking system for the following regulations:
- Banking Secrecy Act amendments
- Anti-money laundering (AML) updates
- Know Your Customer (KYC) requirements

For each regulation, provide:

1. MONITORING SOURCES
   - Which committees draft these bills?
   - Which agencies interpret them?
   - Where to find proposed rules?

2. TRACKING TRIGGERS
   - What signals new rulemaking (Congress draft, agency notice, etc.)?
   - What signals significant changes?
   - What warrants immediate escalation?

3. NOTIFICATION TIMELINE
   - When are bills typically introduced?
   - How long is comment period?
   - When do rules take effect?
   - Implementation grace periods?

4. IMPACT ASSESSMENT TEMPLATE
   When new legislation is identified:
   - Affected business units
   - Required policy changes
   - Technology investments needed
   - Training requirements
   - Timeline for implementation

5. ESCALATION MATRIX
   - Who needs to know?
   - When to escalate to C-suite?
   - When to engage outside counsel?
   - When to brief board?

Deel 3: Risicomatrixgeneratie en gap-analyse voor naleving

Geautomatiseerde mapping van nalevingsgaps

Breng in kaart wat u hebt versus wat vereist is.

Prompt: Gap-analyse voor naleving

Generate a compliance gap assessment for HIPAA Privacy Rule.

Our Organization:
- Type: Healthcare provider
- Size: 150 employees
- Data: Patient health records, insurance info
- Systems: Electronic health record (Healthlink), email, Paper records
- Current Policies:
  * Data Security Policy (2022)
  * Access Control Policy (2022)
  * Incident Response Plan (2020)
  * Business Associate Agreements (partial)

Please provide:

1. REQUIREMENT INVENTORY
   Create table of all HIPAA Privacy Rule requirements:
   | Requirement | Source | Status | Evidence | Gap |
   | --- | --- | --- | --- | --- |

2. ASSESSMENT METHODOLOGY
   For each requirement, determine if we:
   - Fully Comply (documented evidence)
   - Substantially Comply (minor gaps)
   - Partially Comply (major gaps)
   - Non-Compliant (not implemented)
   - Not Applicable

3. EVIDENCE MAPPING
   For implemented controls, link to:
   - Policy document
   - Procedure document
   - Training records
   - Audit findings

4. RISK MATRIX
   For each gap:
   | Gap | Severity | Likelihood | Risk Score | Remediation | Timeline |
   | --- | --- | --- | --- | --- | --- |

5. REMEDIATION ROADMAP
   Phase 1 (Immediate - 30 days): Critical risks
   Phase 2 (Short-term - 90 days): High risks
   Phase 3 (Medium-term - 6 months): Medium risks
   Phase 4 (Long-term - 12 months): Low risks

6. RESOURCE REQUIREMENTS
   - Personnel hours needed
   - External expertise required
   - Technology investments
   - Budget estimate for each phase

7. METRICS & MONITORING
   - How to track progress on remediation
   - Key performance indicators
   - Audit schedule

Best practice voor risicomatrices

Structureer uw risicobeoordelingen consistent over alle nalevingsgebieden heen om vergelijking en prioritering van herstelmaatregelen mogelijk te maken.


Deel 4: Mapping van beleidsnaleving

Beleidsregels kruislings vergelijken met regelgeving

Maak een centrale koppeling van bedrijfsbeleid aan wettelijke vereisten.

Prompt: Mapping van beleidsnaleving

Map our company policies against GDPR requirements.

Our Current Policies:
1. Data Protection Policy (attached)
2. Privacy by Design Standard (attached)
3. Vendor Management Policy (attached)
4. Data Breach Response Plan (attached)
5. Records Retention Policy (attached)

GDPR Articles to Address: Articles 1-99 (full GDPR)

Please provide:

1. REGULATORY REQUIREMENT MATRIX
   For each GDPR article:
   - Article number and title
   - Specific requirement text
   - Applicable to our organization? (Yes/No)
   - Current coverage in our policies? (Yes/No)

2. POLICY-TO-REGULATION MAPPING
   Create table showing:
   | Policy | Article | Section | Requirement | Coverage Level |
   | --- | --- | --- | --- | --- |

   Coverage Levels:
   - Full: Requirement completely addressed
   - Substantial: Mostly addressed, minor gaps
   - Partial: Partially addressed, major gaps
   - Absent: Not addressed at all

3. GAPS & OVERLAPS
   - Which GDPR articles lack policy coverage?
   - Which policies address multiple articles?
   - Conflicting policy provisions?

4. POLICY DEVELOPMENT NEEDS
   Articles requiring entirely new policies

5. POLICY REVISION PRIORITIES
   Existing policies needing updates ranked by:
   - Risk impact
   - Implementation difficulty
   - Regulatory urgency

6. IMPLEMENTATION CHECKLIST
   For each identified gap:
   - [ ] Draft new policy language
   - [ ] Cross-reference related policies
   - [ ] Obtain compliance review
   - [ ] Board approval (if required)
   - [ ] Employee training materials
   - [ ] Documentation of compliance

Deel 5: Systeem voor monitoring van wijzigingen in regelgeving

Een geautomatiseerde nalevingskalender bouwen

Prompt: Instellen van monitoring voor wijzigingen in regelgeving

Build a regulatory monitoring system for financial services compliance.

Regulations to Monitor:
- Dodd-Frank Act
- Gramm-Leach-Bliley Act (GLBA)
- Anti-money laundering (AML) regulations
- Know Your Customer (KYC) requirements
- CFPB regulations
- State consumer finance laws

Please provide:

1. MONITORING INFRASTRUCTURE
   For each regulation:
   - Official government sources to monitor
   - Industry association resources
   - Law firm alerts to subscribe to
   - Consulting firm research to follow
   - Recommended search alerts

2. CHANGE DETECTION MATRIX
   | Regulation | Source | Check Frequency | Escalation Trigger | Owner |
   | --- | --- | --- | --- | --- |

3. IMPACT ASSESSMENT PLAYBOOK
   When regulatory change detected:
   - Questions to ask about impact
   - Stakeholders to involve
   - Timeline for implementation
   - Resources required
   - Documentation needed

4. REGULATORY CALENDAR
   | Deadline | Regulation | Action | Owner | Status |
   | --- | --- | --- | --- | --- |

5. TREND ANALYSIS
   - What patterns do you see in recent regulatory changes?
   - What industries/topics are getting increased scrutiny?
   - What's coming in next 12 months?
   - How should we adapt our compliance posture?

6. STAKEHOLDER COMMUNICATION PLAN
   - Who needs regulatory updates?
   - Update frequency (weekly/monthly/quarterly)?
   - Communication format?
   - Escalation procedures?

Deel 6: Analyse van SEC-filings en disclosure-verplichtingen

Analyse van risicofactorsecties in 10-K's

Beursgenoteerde ondernemingen moeten materiële risico's openbaar maken. Analyseer wat u openbaar maakt en waarom.

Prompt: Risicoanalyse van SEC-filings

Analyze risk factor disclosures for a technology company.

Company: [Company Name]
Recent 10-K Filing: [Attached or URL]
Fiscal Year: [Year]

Please analyze:

1. RISK FACTOR INVENTORY
   - List all risk factors disclosed
   - Categorize by type (operational, legal, market, etc.)
   - Note which are new or revised from prior year

2. ADEQUACY ASSESSMENT
   For each significant risk:
   - Is disclosure adequate or formulaic?
   - Does it explain specific business impact?
   - Are quantified risks included?
   - Is mitigation strategy disclosed?

3. COMPARABLES ANALYSIS
   Compare risk disclosures to:
   - Competitors in same industry
   - Companies of similar size
   - Prior years of same company

4. LITIGATION RISK ANALYSIS
   Identify:
   - Current litigation disclosed
   - Contingent liability reserves
   - Likelihood of material claims
   - Potential exposure amounts

5. REGULATORY RISK ASSESSMENT
   - New regulations affecting business?
   - Pending regulatory actions?
   - Government investigations?
   - Compliance costs anticipated?

6. MATERIAL WEAKNESS ANALYSIS
   - Are there material weaknesses in internal controls?
   - How are they described in filing?
   - What's the plan to remediate?
   - Timeline for remediation?

7. UPDATE RECOMMENDATIONS
   Based on current events/circumstances:
   - Risk factors needing revision
   - New risks requiring disclosure
   - Risks that can be removed as no longer material
   - Suggested language changes

Deel 7: Nalevingsworkflows voor financiële diensten

Naleving in bank- en financiële diensten

Financiële instellingen hebben te maken met bijzondere regelgevingslasten.

Prompt: AML/KYC-nalevingsworkflow

Design an AML/KYC compliance program for a fintech company.

Company Profile:
- Licensed as Money Services Business
- Operates in 30 US states
- Peer-to-peer payment platform
- 500K+ active customers
- Average transaction: $150
- High-risk geographies: [list]

Please develop:

1. KYC PROGRAM FRAMEWORK
   - Customer identification procedures
   - Risk-based approach to due diligence
   - Ongoing customer monitoring
   - Enhanced due diligence triggers
   - Documentation requirements

2. AML MONITORING PROCEDURES
   - Transaction monitoring thresholds
   - Suspicious activity detection
   - Filing obligations (SARs, CTRs)
   - Record retention requirements
   - Audit procedures

3. RISK ASSESSMENT MATRIX
   | Factor | Risk Level | Mitigation | Monitoring |
   | --- | --- | --- | --- |

   Factors:
   - Customer type (individual vs. business)
   - Geography
   - Transaction amount
   - Transaction frequency
   - Customer profile changes

4. COMPLIANCE CALENDAR
   - Quarterly SAR reviews
   - Annual program effectiveness testing
   - Training schedules
   - Policy review cycles
   - Examination prep

5. TECHNOLOGY REQUIREMENTS
   - Automated transaction monitoring tools
   - Customer risk scoring systems
   - Document verification solutions
   - Reporting platforms
   - Audit trail systems

6. STAFFING & TRAINING
   - Compliance officer responsibilities
   - Staff training requirements
   - Third-party vendor management
   - Escalation procedures
   - Documentation

7. REGULATORY EXAMINATION READINESS
   - Common examination issues
   - Preparation checklist
   - Documentation organization
   - Self-assessment procedures

Complexiteit van financiële diensten

Naleving in financiële diensten is sterk gereguleerd en technisch. Schakel altijd gespecialiseerde juristen in voor implementatie en beoordeling van AML/KYC-programma's.


Deel 8: Beheer van leveranciers- en derdennaleving

Leveranciersrisico evalueren

Derden creëren nalevingsrisico's die u overneemt.

Prompt: Risicobeoordeling van leveranciersnaleving

Create a vendor compliance management program.

Vendor Categories to Assess:
- Cloud service providers
- Payroll processors
- Insurance brokers
- Accounting firms
- IT service providers
- Data disposal companies

Please develop:

1. VENDOR RISK ASSESSMENT FRAMEWORK
   For each vendor, evaluate:
   - Data access level (what data do they handle?)
   - Regulatory applicability (what rules apply?)
   - Security controls (are they adequate?)
   - Financial stability (will they stay in business?)
   - Compliance maturity (have they been audited?)

2. RISK SCORING MATRIX
   | Vendor | Data Risk | Compliance Risk | Security Risk | Financial Risk | Overall Score |
   | --- | --- | --- | --- | --- | --- |

3. DUE DILIGENCE CHECKLIST
   For high-risk vendors:
   - [ ] SOC 2 Type II audit review
   - [ ] Insurance verification
   - [ ] References check
   - [ ] Security documentation review
   - [ ] Financial statements review
   - [ ] Litigation/regulatory history check
   - [ ] Disaster recovery/business continuity plan
   - [ ] Data location and processing review

4. CONTRACTUAL PROTECTIONS
   - Indemnification clauses
   - Data processing agreements
   - Security requirements
   - Audit rights
   - Insurance requirements
   - Breach notification obligations
   - Confidentiality and NDA standards
   - Term and termination rights

5. ONGOING MONITORING PLAN
   | Vendor | Monitoring Mechanism | Frequency | Owner | Escalation |
   | --- | --- | --- | --- | --- |

   Monitoring mechanisms:
   - Annual certification/attestation
   - Periodic on-site audits
   - Continuous security scanning
   - Regulatory news monitoring
   - Financial monitoring
   - Performance metrics tracking

6. REMEDIATION PROCEDURES
   When issues identified:
   - Severity assessment
   - Vendor notification
   - Corrective action timeline
   - Escalation procedures
   - Termination conditions
   - Business continuity during transition

7. COMPLIANCE DOCUMENTATION
   - Vendor registry with all key info
   - Risk assessment dates and results
   - Due diligence work files
   - Current contracts and amendments
   - Audit reports
   - Compliance certifications

Risico van derden

Veel datalekken en nalevingsproblemen ontstaan bij externe leveranciers. Regelmatige leveranciersbeoordelingen zijn cruciaal om de nalevingspositie van uw organisatie te behouden.


Deel 9: Checklist voor kwaliteitscontrole

Volledigheid van het nalevingsprogramma

Gebruik deze checklist om uw programma voor naleving van regelgeving te beoordelen:

QC-checklist voor programma's voor naleving van regelgeving

  • Overzicht van regelgeving volledig - Alle toepasselijke regels geïdentificeerd en gedocumenteerd
  • Jurisdictiemapping actueel - Vereisten voor meerdere staten/internationaal geïdentificeerd
  • Gap-analyse gedocumenteerd - Nalevingsgaps geïdentificeerd en geprioriteerd
  • Beleidsregels opgesteld/bijgewerkt - Alle vereiste beleidsregels aanwezig en actueel
  • Mapping beleid-regelgeving - Elk beleid kruislings gekoppeld aan toepasselijke regelgeving
  • Risicomatrix ontwikkeld - Nalevingsrisico's geïdentificeerd, beoordeeld en geprioriteerd
  • Herstelplan - Actiepunten toegewezen met verantwoordelijken en deadlines
  • Monitoringsysteem ingericht - Wijzigingen in regelgeving systematisch gevolgd
  • Trainingsprogramma actief - Medewerkers getraind in nalevingsverplichtingen
  • Auditschema vastgesteld - Regelmatige nalevingsaudits ingepland
  • Leveranciersbeoordeling voltooid - Nalevingsrisico's van derden beoordeeld
  • Governance gedocumenteerd - Rollen, verantwoordelijkheden en escalatie helder
  • Bewijs verzameld - Documentatie ter onderbouwing van nalevingsclaims
  • Jaarlijkse beoordeling ingepland - Nalevingsprogramma jaarlijks beoordeeld/bijgewerkt
  • Rapportage aan bestuur - Nalevingsstatus gerapporteerd aan bestuur/leiding

Praktische oefeningen

Oefening 1: Bouw uw protocol voor nalevingsonderzoek

Kies een regeling die op uw organisatie van toepassing is. Gebruik de prompt voor onderzoek in meerdere jurisdicties uit Deel 1 om het volgende te onderzoeken en documenteren:

  • Alle toepasselijke jurisdicties
  • Primaire en secundaire regelgeving
  • Samenvatting van belangrijkste vereisten
  • Huidige nalevingsstatus
  • Geïdentificeerde gaps

Oefening 2: Maak een kaart van beleid naar regelgeving

Selecteer één van uw bedrijfsbeleidsregels. Maak een gedetailleerde kaart van:

  • Welke regelgeving deze adresseert
  • Welke vereisten volledig/gedeeltelijk/helemaal niet worden afgedekt
  • Aanbevolen herzieningen
  • Bewijs van implementatie

Oefening 3: Ontwerp een monitoringsysteem

Ontwerp voor een specifiek regelgevingsgebied:

  • Te monitoren informatiebronnen
  • Triggers voor wijzigingsdetectie
  • Procedure voor impactbeoordeling
  • Communicatieplan voor stakeholders
  • Implementatietijdlijn

Oefening 4: Risicobeoordeling van leveranciers

Selecteer een kritieke leverancier. Voer uit:

  • Risicobeoordeling met het raamwerk uit Deel 8
  • Gapanalyse ten opzichte van contractvoorwaarden
  • Ontwikkeling van een monitoringsplan
  • Aanbevelingen voor herstel indien nodig

Vergelijking: Handmatige versus AI-ondersteunde naleving

TaskManual ApproachAI-Assisted
Regulatory ResearchStatuten/regelingen handmatig lezenSnellere gestructureerde eerste analyse (validatie door jurist vereist)
Gap AssessmentTracking via spreadsheets en interviewsChecklist op basis van raamwerk en mapping van bewijs
Policy MappingHandmatige kruisverwijzing, links worden sneller gemistSystematische mapping van vereiste naar beleid
Risk ScoringSubjectieve beoordeling, inconsistentGestructureerde matrix met consistente criteria
MonitoringVaak reactiefProactieve monitoringsworkflows (indien onderhouden)
Vendor Due DiligenceGefragmenteerde documentbeoordelingHerhaalbare workflow voor risicobeoordeling
DocumentationMoeilijker gestandaardiseerd/audit-ready te houdenGeorganiseerde templates en trackingartefacten
Time InvestmentVarieert per scope en volwassenheidMeestal lager na inrichting van de workflow; verifieer met pilotmetrics

Doe dit nu

  • Onderzoek één regeling die op uw organisatie van toepassing is (prompt uit Deel 1)
  • Voltooi één oefening in wettelijke interpretatie of het volgen van wetgeving
  • Voer één gap-analyse voor naleving uit en maak een risicomatrix
  • Koppel één bedrijfsbeleid aan de bijbehorende wettelijke vereisten
  • Ontwerp een monitoringsysteem voor één belangrijke regeling
  • Beoordeel één leverancier met het nalevingsraamwerk
  • Voltooi de QC-checklist voor het programma voor naleving van regelgeving

Huiswerk vóór gevorderde tutorials

  1. Breng uw regelgevingslandschap in kaart - Documenteer alle regelgeving die op uw organisatie van toepassing is

  2. Maak een overzicht van regelgeving - Bouw een centrale spreadsheet van alle toepasselijke vereisten

  3. Voer één gap-analyse uit - Kies één belangrijke regeling en voltooi een gap-analyse

  4. Ontwerp uw monitoringsysteem - Bouw een systeem om wijzigingen in belangrijke regelgeving te volgen

  5. Beoordeel uw leveranciersrisico - Evalueer uw top 3-5 leveranciers met het beoordelingsraamwerk


Bijlage: Bronnen voor regelgevingsmonitoring per sector

Bankwezen en financiële diensten

  • Federal Reserve (federalreserve.gov)
  • CFPB (consumerfinance.gov)
  • OCC (occ.gov)
  • FinCEN (fincen.gov)
  • State attorneys general

Gezondheidszorg

  • CMS (cms.gov)
  • HHS/OCR (hhs.gov)
  • Staatsgezondheidsdiensten
  • State attorneys general
  • DEA (indien van toepassing)

Technologie/data

  • FTC (ftc.gov)
  • State attorneys general
  • EU-gegevensbeschermingsautoriteiten
  • CISA (cisa.gov)
  • Sectorspecifieke instanties

Effecten

  • SEC (sec.gov)
  • FINRA (finra.org)
  • Staatsregulatoren voor effecten
  • SRO-aankondigingen
  • EDGAR-filings

Bronnen

Verdere lectuur


Belangrijkste inzichten

Succesfactoren

  • Systematische aanpak: Gebruik gestructureerde prompts en raamwerken voor consistente nalevingsbeoordelingen
  • Documentatie: Houd uitgebreid bewijs bij van nalevingsinspanningen en beslissingen
  • Monitoring: Bouw proactieve systemen om wijzigingen in regelgeving te volgen voordat ze impact hebben op de bedrijfsvoering
  • Risicogebaseerd: Prioriteer herstelmaatregelen op basis van risicoscores en bedrijfsimpact
  • Leveranciersbeheer: Naleving door derden is uw naleving -- beoordeel en monitor leveranciers regelmatig

Snel overzicht: Nalevingsprompts

# Quick Regulatory Research
"Research [regulation name] in [jurisdiction].
Show: requirements, gaps, timeline, resources needed."

# Quick Gap Assessment
"Compare our [policy name] to [regulation name].
Identify all gaps and priorities."

# Quick Risk Score
"Score compliance risk for [area]:
Rate 1-10 by severity, likelihood, and overall risk."

# Quick Monitoring Setup
"Design monitoring system for [regulation].
Show sources, frequency, triggers, escalation."

Gerelateerd


On this page

1 Overzicht1.1 Wat u vandaag zult voltooien2 Deel 1: Onderzoeksraamwerk voor naleving van regelgeving2.1 Onderzoeksstrategie voor meerdere jurisdicties2.2 Prompt: Uitgebreid nalevingsonderzoek2.3 Best practices voor jurisdictiespecifiek onderzoek3 Deel 2: Wettelijke interpretatie en het volgen van wetgeving3.1 Analyse van complexe wetten3.2 Wetswijzigingen volgen4 Deel 3: Risicomatrixgeneratie en gap-analyse voor naleving4.1 Geautomatiseerde mapping van nalevingsgaps5 Deel 4: Mapping van beleidsnaleving5.1 Beleidsregels kruislings vergelijken met regelgeving6 Deel 5: Systeem voor monitoring van wijzigingen in regelgeving6.1 Een geautomatiseerde nalevingskalender bouwen7 Deel 6: Analyse van SEC-filings en disclosure-verplichtingen7.1 Analyse van risicofactorsecties in 10-K's8 Deel 7: Nalevingsworkflows voor financiële diensten8.1 Naleving in bank- en financiële diensten9 Deel 8: Beheer van leveranciers- en derdennaleving9.1 Leveranciersrisico evalueren10 Deel 9: Checklist voor kwaliteitscontrole10.1 Volledigheid van het nalevingsprogramma11 Praktische oefeningen11.1 Oefening 1: Bouw uw protocol voor nalevingsonderzoek11.2 Oefening 2: Maak een kaart van beleid naar regelgeving11.3 Oefening 3: Ontwerp een monitoringsysteem11.4 Oefening 4: Risicobeoordeling van leveranciers12 Vergelijking: Handmatige versus AI-ondersteunde naleving13 Doe dit nu14 Huiswerk vóór gevorderde tutorials15 Bijlage: Bronnen voor regelgevingsmonitoring per sector15.1 Bankwezen en financiële diensten15.2 Gezondheidszorg15.3 Technologie/data15.4 Effecten16 Bronnen17 Verdere lectuur18 Belangrijkste inzichten19 Snel overzicht: Nalevingsprompts20 Gerelateerd21 Navigatie