Skills on AI

Active theme: Light

Legal Compliance Audit

Use when asked to conduct a legal compliance audit — systematically checking an organization's actual practices against applicable laws and regulations — as an internal, ongoing counterpart to legal-due-diligence's transaction-specific investigation.

A legal compliance audit systematically checks an organization's actual practices against the laws and regulations that apply to it — identifying gaps between what's required and what's actually being done, before a regulator or counterparty finds them first.

General process

  1. Map applicable requirements — identify the laws, regulations, and contractual obligations that actually apply, given the organization's jurisdiction(s), industry, and activities.
  2. Assess current practice — examine actual policies, procedures, and records against each requirement, not just written policy against requirement (a policy that exists but isn't followed is itself a compliance gap).
  3. Identify gaps — document where actual practice falls short of requirements, prioritized by risk severity.
  4. Remediate — develop and implement a plan to close identified gaps, with clear ownership and timelines.
  5. Re-audit periodically — compliance requirements and organizational practices both change over time; a one-time audit goes stale.

Common audit areas

Data privacy (see Legal Data Privacy Compliance), employment law, industry-specific regulation, anti-corruption/bribery, environmental compliance, and contractual compliance obligations owed to specific counterparties or regulators.

Common pitfalls

  • Auditing written policy instead of actual practice — a well-written policy that isn't actually followed doesn't protect the organization; the audit needs to verify real-world practice, not just documentation.
  • Treating the audit as a one-time event — regulatory requirements and organizational practices both evolve; periodic re-auditing (not a single audit years ago) is what keeps compliance current.
  • No clear ownership for remediation — identifying a gap without assigning who fixes it and by when means findings often go unaddressed.
  • Scoping the audit too narrowly — focusing only on the most obvious or highest-profile regulatory area can miss significant risk in a less visible area.

Learn more

View legal-compliance-audit/SKILL.md on GitHub