whistleblower-compliance
Audit whistleblower systems and draft compliant reporting policies. Use when assessing or building whistleblower programs.
What this skill does
> **⚠️ EXPERIMENTAL** — This skill is provided for educational and informational purposes only. It does NOT constitute legal advice. All responsibility for usage rests with the user. Consult qualified legal professionals before acting on any output. # Whistleblower Compliance Skill ## Overview Production-ready whistleblower compliance toolkit for auditing existing reporting systems and drafting compliant policies. Covers EU Directive 2019/1937, US SOX Section 806, US Dodd-Frank, and UK Public Interest Disclosure Act 1998. Operates in two modes: Mode A (Assessment) runs an 8-phase, 56-checkpoint audit of existing systems; Mode B (Drafting) generates jurisdiction-specific reporting policies. ## Table of Contents - [Tools](#tools) - [Reference Guides](#reference-guides) - [Workflows](#workflows) - [Troubleshooting](#troubleshooting) - [Success Criteria](#success-criteria) - [Scope & Limitations](#scope--limitations) - [Anti-Patterns](#anti-patterns) - [Tool Reference](#tool-reference) ## Tools ### 1. Compliance Checker (`scripts/whistleblower_compliance_checker.py`) Assess an existing whistleblower system against regulatory requirements. Takes organizational parameters and outputs a compliance score with priority-classified gaps. ```bash python scripts/whistleblower_compliance_checker.py \ --jurisdiction EU --headcount 300 --sector financial \ --channels internal,external --has-designated-person \ --has-confidentiality --has-gdpr-measures --has-dissemination python scripts/whistleblower_compliance_checker.py \ --jurisdiction US --headcount 5000 --sector healthcare \ --channels internal --json python scripts/whistleblower_compliance_checker.py \ --jurisdiction UK --headcount 50 --sector technology \ --channels none ``` ### 2. Policy Scaffolder (`scripts/whistleblower_policy_scaffolder.py`) Generate a whistleblower policy skeleton pre-populated with required sections per regulatory framework. ```bash python scripts/whistleblower_policy_scaffolder.py \ --jurisdiction EU --org-type private --headcount 500 \ --org-name "Acme Corp" python scripts/whistleblower_policy_scaffolder.py \ --jurisdiction US --org-type public --headcount 10000 \ --org-name "MegaCorp Inc" --json python scripts/whistleblower_policy_scaffolder.py \ --jurisdiction UK --org-type nonprofit --headcount 100 \ --org-name "CharityOrg" --output policy-draft.md ``` ## Reference Guides | Reference | Purpose | |-----------|---------| | `references/regulatory_framework.md` | Multi-jurisdiction whistleblower regulations, comparison matrix | | `references/assessment_checklist.md` | 8-phase, 56-checkpoint assessment with priority classifications | ## Workflows ### Mode A: Assessment Workflow 1. **Gather Parameters** -- Collect jurisdiction, headcount, sector, and system description 2. **Run Compliance Checker** -- Execute `whistleblower_compliance_checker.py` with parameters 3. **Review Gaps** -- Prioritize CRITICAL gaps first, then IMPORTANT, then IMPROVEMENT 4. **Cross-Reference Checklist** -- Walk through `assessment_checklist.md` for manual verification 5. **Generate Remediation Plan** -- Address gaps by priority, set deadlines per regulatory timelines ### Mode B: Drafting Workflow 1. **Determine Jurisdiction** -- Identify applicable regulations based on headquarters and operations 2. **Generate Scaffold** -- Run `whistleblower_policy_scaffolder.py` with organization details 3. **Customize Sections** -- Replace placeholders with organization-specific information 4. **Legal Review** -- Route draft through legal counsel for jurisdiction-specific validation 5. **Approval & Publication** -- Obtain board/management approval and disseminate to all personnel ### 8-Phase Assessment Framework | Phase | Focus | Checkpoints | |-------|-------|-------------| | 1. Applicability | Regulatory scope determination | 3 | | 2. Reception Channel | Reporting channel adequacy | 5 | | 3. Designated Persons | Personnel and independence | 7 | | 4. Verification/Processing | Investigation procedures | 8 | | 5. Confidentiality | Identity and data protection | 9 | | 6. Dissemination/Information | Awareness and accessibility | 10 | | 7. Data Protection/GDPR | Privacy compliance | 12 | | 8. Sector-Specific | Industry requirements | 6 | | **Total** | | **60** | ### Three Reporting Channels | Channel | When Used | Key Requirements | |---------|-----------|-----------------| | Internal | First preference; report to organization | Acknowledge within 7 days; feedback within 3 months | | External (Regulatory) | When internal fails or is inappropriate | Report to competent authority; same protections apply | | Public Disclosure | Last resort; imminent danger or retaliation | Protected only if internal/external channels exhausted | ### Whistleblower Protections | Protection | Description | |------------|-------------| | Civil immunity | No liability for breach of confidentiality obligations | | Criminal immunity | No criminal liability for acquiring reported information | | Prohibited retaliation | Dismissal, demotion, harassment, blacklisting, discrimination | | Burden of proof reversal | Employer must prove action was not retaliatory | | Interim relief | Provisional protection during investigation | | Legal aid access | Access to legal counsel and support | ### Priority Classification | Priority | Definition | Example | |----------|-----------|---------| | CRITICAL | Legal non-compliance; immediate regulatory risk | No reporting channel exists; no confidentiality measures | | IMPORTANT | Significant gap reducing system effectiveness | Acknowledgment timeline exceeds 7 days; no designated person | | IMPROVEMENT | Enhancement opportunity; not currently non-compliant | Training frequency below best practice; limited channel types | ## Troubleshooting | Problem | Cause | Solution | |---------|-------|----------| | Checker reports all CRITICAL | No system parameters provided | Provide accurate `--channels`, `--has-designated-person`, and other flags | | Wrong jurisdiction requirements | Multi-jurisdiction entity using single jurisdiction | Run checker separately per jurisdiction; use strictest requirements | | Policy scaffold missing sections | Jurisdiction flag incorrect | Verify `--jurisdiction` matches EU, US, or UK | | Headcount threshold confusion | EU directive has different thresholds by entity type | Private sector: 50+ employees; public sector: all municipalities | | Sector-specific gaps not flagged | Generic sector value used | Use specific sector: `financial`, `healthcare`, `defense`, `nuclear` | | GDPR checks fail for US entity | US entities may still need GDPR compliance | If processing EU citizen data, add `--has-gdpr-measures` | | Timeline requirements unclear | Different jurisdictions have different timelines | EU: 7-day ack, 3-month feedback; SOX: 180-day filing deadline | | Policy output too generic | Minimal parameters provided | Add `--org-name`, `--org-type`, and `--headcount` for specificity | ## Success Criteria - **Compliance Coverage**: Assessment covers 100% of applicable regulatory requirements for specified jurisdiction - **Gap Identification**: All CRITICAL and IMPORTANT gaps identified with clear remediation guidance - **Policy Completeness**: Generated policies include all mandatory sections per applicable regulation - **Timeline Compliance**: Policies reflect correct acknowledgment (7 days) and feedback (3 months) timelines - **Audit Readiness**: Assessment output sufficient for regulatory audit preparation and evidence gathering ## Scope & Limitations **This skill covers:** - Compliance assessment against EU Directive 2019/1937, US SOX/Dodd-Frank, UK PIDA - Policy scaffolding with jurisdiction-specific mandatory sections - Gap analysis with priority classification and remediation guidance - Multi-sector considerations (financial, healthcare, defense, nuclear, transport) **This skill does NOT cover:** - Actual whistleblower case management or
Related in Security
mac-ops
IncludedComprehensive macOS workstation operations — diagnose kernel panics, identify failing drives, audit launchd startup items, decode wake reasons, triage TCC permission denials, manage APFS snapshots, recover from no-boot. Use for: Mac is slow, slow bootup, won't boot, kernel panic, kernel_task hot, mds_stores CPU, photoanalysisd, cloudd, login loop, gray screen, sleep wake failure, drive failing, IO errors, APFS snapshots eating space, Time Machine local snapshots, Spotlight indexing, launchd, LaunchAgent, LaunchDaemon, login items, TCC permissions, Full Disk Access, Screen Recording denied, Gatekeeper, quarantine, com.apple.quarantine, app is damaged, helper tool, /Library/PrivilegedHelperTools, pmset, wake reasons, dark wake, sysdiagnose, panic.ips, DiagnosticReports, configuration profile, MDM profile, remote diagnostics over SSH.
a11y-audit
IncludedRun accessibility audits on web projects combining automated scanning (axe-core, Lighthouse) with WCAG 2.1 AA compliance mapping, manual check guidance, and structured reporting. Output is configurable: markdown report only, markdown plus machine-readable JSON, or markdown plus issue tracker integration. Use this skill whenever the user mentions "accessibility audit", "a11y audit", "WCAG audit", "accessibility check", "compliance scan", or asks to check a web project for accessibility issues. Also trigger when the user wants to verify WCAG conformance or map findings to a specific standard (CAN-ASC-6.2, EN 301 549, ADA/AODA).
erpclaw
IncludedAI-native ERP system with self-extending OS. Full accounting, invoicing, inventory, purchasing, tax, billing, HR, payroll, advanced accounting (ASC 606/842, intercompany, consolidation), and financial reporting. 413 actions across 14 domains, 43 expansion modules. Constitutional guardrails, adversarial audit, schema migration. Double-entry GL, immutable audit trail, US GAAP.
assess
IncludedAssesses and rates quality 0-10 across multiple dimensions (correctness, maintainability, security, performance, testability, simplicity) with pros/cons analysis. Compares against project conventions and prior decisions from memory. Produces structured evaluation reports with actionable improvement suggestions. Use when evaluating code, designs, architectures, or comparing alternative approaches.
spring-boot-security-jwt
IncludedProvides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
code-hardcode-audit
IncludedDetect hardcoded values, magic numbers, and leaked secrets. TRIGGERS - hardcode audit, magic numbers, PLR2004, secret scanning.