compliance-escalation-brief

$npx mdskill add Significant-Gravitas/skills-catalog/compliance-escalation-brief

Use this whenever a matter needs a legal or security judgement.

SKILL.md

.github/skills/compliance-escalation-briefView on GitHub ↗
---
name: "compliance-escalation-brief"
description: "Prepare a neutral brief for counsel or the security lead on a matter that needs their judgement."
triggers: ["escalate to counsel", "legal question privacy", "breach question", "compliance escalation", "need a lawyer"]
version: "1"
---

# Compliance escalation brief

Use this whenever a matter needs a legal or security judgement.

## Decide if it must escalate

Escalate to counsel when the matter touches a possible breach or incident,
regulator contact, legal basis, liability or indemnity terms, a request you
cannot scope, or a claim the company cannot back with evidence. Escalate to
the security lead for control failures or unclear technical facts. When in
doubt, escalate.

## Write the brief

Put the decision first:

1. the exact question for counsel or the security lead;
2. the deadline and what depends on it;
3. the facts, with times and sources;
4. the documents involved, with version and section;
5. the company's supplied position or checklist, quoted;
6. what is not yet known;
7. the business owner and who else knows.

Keep facts, claims from others, and open questions apart. Attach the source
rather than a fragment when context matters.

## What you did not decide

State plainly what the brief leaves open: whether the matter is reportable,
whether a clause is acceptable, and what to tell the other side.

Do not give legal advice, say whether the company is compliant, or advise on
breach notice. Return an unsent draft; counsel decides and an authorised
person sends.

More from Significant-Gravitas/skills-catalog

SkillDescription
account-health-and-qbrsUse when a support account wobbles or a quarterly business review looms: read the health signals, run the success plan, and prep the review from evidence.
accounts-receivable-follow-upReview open receivables and draft factual, staged payment follow-ups without inventing status or contacting a customer.
ad-copy-variantsWrite ad variants that each test one idea, within platform limits and supported claims.
alex-getting-startedUse on the first conversation with Alex, or whenever their memory has no product preferences yet: learn what the user is building and who for, where specs, roadmap and numbers live, who decides dates and scope, and get them to a first real product deliverable.
alliance-co-commercializationUse when a strategic alliance needs joint selling governance: operating model, joint targeting, steering prep, and milestone accountability.
anika-getting-startedUse on the first conversation with Anika, or whenever their memory has no partnership preferences yet: learn which partners and alliances the user owns, what motion they run, and get one real partner read on screen in the same session.
assure-partner-led-deliveryUse when partners deliver client work in your name: own the in-flight book, run the weekly delivery review, and rescue engagements before clients feel it.
automate-finance-reportingUse to connect a number source, map an export into the finance ledger, or QA a sheet: the column mapping, the dedupe key, the load summary, and the checks that must pass before a read ships.
billing-refunds-and-exceptionsUse when money is on the table: verify the charge, check the policy, and stage a refund or exception draft that stops at the owner's yes.
board-and-investor-metrics-briefPrepare a concise board or investor metrics brief with definitions, sources, comparisons, drivers, risks, and decisions needed.