← Compliance Horizon ScannerCONTENT HISTORY

Update to Compliance Horizon Scanner

Snapshot Sep 30, 2026 · 23:16 UTC · version 0.2.0+codex.20260914234654

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "assess-materiality",
  "description": "Assess one named regulatory development in depth against a business's compliance profile — whether it binds them, which provisions engage, what would have to change operationally, and by when. Use when the user names or pastes a specific regulation, rule, directive, statutory instrument, bill, or consultation and asks whether it applies to them, what it means for them, or what they need to do about it. Complements horizon-scan, which finds developments; this one analyses a single development.",
  "included_files": [],
  "skill_md_contents": "---\nname: assess-materiality\ndescription: Assess one named regulatory development in depth against a business's compliance profile — whether it binds them, which provisions engage, what would have to change operationally, and by when. Use when the user names or pastes a specific regulation, rule, directive, statutory instrument, bill, or consultation and asks whether it applies to them, what it means for them, or what they need to do about it. Complements horizon-scan, which finds developments; this one analyses a single development.\n---\n\nRead `../../references/runtime-safety.md` before using this workflow. Resolve relative paths from this skill directory. To use a sibling skill, read its `../<skill-name>/SKILL.md`; no special invocation tool is required.\n\n\nDeep-dive one development. Where `horizon-scan` triages breadth, this goes to depth on a single\ninstrument the user cares about.\n\n**Read `../../references/citation-discipline.md` first. It governs everything below.** The depth\nhere makes provenance more important, not less — a detailed operational analysis built on an\nunsourced threshold is confidently wrong in a way a one-line finding never is.\n\n---\n\n## 1. Identify the instrument precisely\n\nThe user may give you a name, a number, a URL, a pasted extract, or a vague description. Pin it down\nto a specific instrument with an identifier before analysing anything.\n\n- **Resolve it to a primary source and fetch it.** Federal Register document number, CELEX,\n  UK SI `year/number`, or a state instrument identified by state, type, session, and official\n  number. For a named state instrument read `../../references/sources-us-states.md`; an\n  explicit one-off assessment does not change saved recurring state selections. Use `../../references/sources-us-federal.md`, `sources-eu.md`, `sources-uk.md`.\n- **If you cannot find it, say so.** Do not analyse an instrument you could not locate. A\n  plausible-sounding name may be a misremembering, a proposal that was never adopted, a measure\n  under a different number, or nothing at all. The correct response is:\n\n  > I could not locate a primary source for that. Can you share a link or the official number? I\n  > searched <sources> on <date> and found nothing matching.\n\n  Never produce an analysis from recall to be helpful. This is the single most likely way this\n  skill could cause harm.\n- **If several instruments could match, ask which** rather than picking the most likely. Amending\n  instruments, corrigenda, and consolidations often share most of a title.\n\n## 2. Get the profile\n\nAsk for the compliance profile. Without it there is no \"material to whom,\" and the answer collapses\ninto a generic summary the user could get anywhere.\n\nIf they don't have one, you can still analyse the instrument, but say clearly that applicability is\nunassessed and ask the specific facts that decide it — usually jurisdiction, headcount, data types,\nand whether they are consumer-facing.\n\n## 3. Read the instrument and extract, with quotes\n\n- **Scope** — who it binds, in its own words. Quote the scope provision.\n- **Lifecycle stage** — proposed, in consultation, adopted, in force, or applying from a date.\n- **Every date** — comment deadline, entry into force, application, staged milestones, first\n  reporting date. Each quoted separately from the provision that sets it.\n- **Thresholds** — headcount, turnover, data volume, product class. Quoted.\n- **Substantive obligations** — what must actually be done.\n- **Penalties and liability**, including whether any is criminal or personal.\n- **Exemptions and derogations** — often where the answer actually lives, and commonly missed.\n\nWhere the instrument amends another, **read the amended instrument too**. An amending act's text is\noften unintelligible in isolation (\"in Article 4, replace 'six' with 'twelve'\"), and reporting the\namendment without the underlying provision tells the user nothing.\n\n## 4. Assess applicability against the profile\n\nApply `../../references/materiality-rubric.md`. Name the profile field and the threshold that\ndecides it:\n\n> `binds_us` — Article 2(1) applies to \"an employer with 50 or more employees\";\n> `headcount_by_jurisdiction.UK = 120`.\n\nScore `unassessed` and **name the missing facts** when scope cannot be assessed. Use\n`likely` only when affirmative evidence supports probable applicability. Do not resolve\nambiguity toward the more interesting answer, in either direction — neither inflating applicability\nto seem useful nor dismissing it to seem reassuring.\n\n## 5. State what would have to change\n\nThis is the part the user cannot get from reading the instrument, and the reason to run this skill.\nBe concrete and tie each item to the provision that requires it:\n\n- **Policies and documents** — which ones, and what has to change in them\n- **Systems and product** — engineering work, data flows, retention, consent, logging\n- **Contracts** — customer terms, supplier terms, DPAs, flow-down clauses\n- **Governance** — approvals, sign-off, board or committee reporting\n- **Evidence** — what a regulator would ask to see, and what would have to exist to show it\n\nSeparate **what the instrument requires** from **what would be prudent**. Both are useful; conflating\nthem misleads. Label the second as your assessment, not as obligation.\n\n## 6. Output\n\n```\n## <Instrument name> · <official_id>\n`<stage>` · <publisher> · retrieved <date>\n\n**Bottom line.** <Two or three sentences: does it bind them, what is the hardest part, by when.>\n\n**Scope** — <who it binds, quoted> [link]\n\n**Applicability: `binds_us`** — <profile field and threshold, quoted>\n\n**Key dates**\n| What | Date | Source |\n|---|---|---|\n| Comment deadline | <date, or \"none\"> | \"<verbatim quote>\" [link] |\n| Entry into force | <date> <if computed: \"(derived: <arithmetic>)\"> | \"<verbatim quote>\" [link] |\n| Applies from | <date, or \"not specified in the instrument\"> | <quote, or \"—\"> |\n\n**Obligations that engage** — <each with the provision and a quote>\n\n**What would have to change** — <policies / systems / contracts / governance / evidence>\n\n**Penalties** — <quoted, with whether any is criminal or personal>\n\n**Exemptions worth checking** — <any that might apply, with provisions>\n\n**Score** — impact `high` · effort `program_change` · timeline `30-90` · confidence `high`\n**Flag** — <e.g. effort exceeds available lead time>\n\n**Not established from the sources** — <anything you could not source, listed explicitly>\n\n---\nRegulatory intelligence, not legal advice. Verify against the cited primary sources before acting.\n```\n\nThe **\"Not established from the sources\"** section is mandatory and must not be dropped when it\nwould be empty of interesting content — write \"nothing material\" rather than removing the heading.\nIt is where an unpublished effective date, an unresolved threshold, or an unreachable amended\ninstrument gets named. A detailed analysis that quietly omits what it could not establish reads as\nmore complete than it is, which is precisely the failure this heading prevents.\n\n## 7. Self-check\n\nRun the checklist in `citation-discipline.md`. Every date, threshold, and penalty in the output\ntraces to a verbatim quote from a document fetched this session, or it is moved to \"Not established.\"\nThen state the provenance tally.\n\n---\n\n## When the user pushes for a bottom line you cannot source\n\nThey will sometimes want a date, a number, or a yes/no that the sources do not give — often for a\nreal deadline of their own. Give the sourced part, name the gap, and say what would close it:\n\n> The comment deadline is fixed and sourced: 11:59 p.m. Eastern Time on 30 September 2026 (quoted,\n> linked). The instrument sets no effective date, and none is published — that comes with the final\n> rule. I can't give you a date for it. If you need something to plan against, the comment deadline\n> is the one that's certain; I'd re-scan this agency monthly for the final rule rather than plan to\n> an assumed date.\n\nThat is a complete and useful answer. An invented effective date, however well hedged, is not.\n"
}

SHA-256: 5605fc916b976e4629b7ab373955d05ee3932204093c448e9c0a9a35cfadae12