compliance-check

compliance-check is a command for coding agents from brainbytes-dev/everything-claude-finance. It costs 7 tokens per session (1,222 once invoked), scanned A, original, MIT.

A financial-regulation review tool that checks an organisation’s controls and activities against rules such as AML/KYC, SOX, Basel, MiFID II, MaRisk, and GDPR for financial data. It identifies gaps, rates their risk, and suggests corrective work.

In plain words
What is it for?
Use it for routine compliance reviews, preparation for regulatory examinations, new-product assessments, post-acquisition integration, regulatory-change analysis, and board reporting.
Why use it?
It helps teams organise compliance checks and see which regulatory problems are most serious and need attention first.

Command

Part of the everything-claude-finance plugin — 13 skills, 22 commands, 20 agents shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/brainbytes-dev/everything-claude-finance/compliance-check
Clone the repo
git clone --depth 1 https://github.com/brainbytes-dev/everything-claude-finance

Or install everything-claude-finance, the plugin that ships this one along with the rest of its 13 skills, 22 commands, 20 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for compliance-check

README.md
[![agentmods](https://agentmods.dev/badge/commands/brainbytes-dev/everything-claude-finance/compliance-check.svg)](https://agentmods.dev/commands/brainbytes-dev/everything-claude-finance/compliance-check)
Your own site
<a href="https://agentmods.dev/commands/brainbytes-dev/everything-claude-finance/compliance-check"><img src="https://agentmods.dev/badge/commands/brainbytes-dev/everything-claude-finance/compliance-check.svg" alt="Measured on agentmods" height="20"></a>
Per session 7 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,222 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00007 $0.01222
Opus 5 $0.00003 $0.00611
Sonnet 5 $0.00001 $0.00244
Haiku 4.5 $0.00001 $0.00122

Measured 4d ago against content hash 48b19325434f, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

compliance-check scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

commands/compliance-check.md · 125 lines

How it starts

The opening of the file, as written. The whole thing — 125 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/compliance-check — Compliance Review

What This Command Does

Conducts a structured regulatory compliance review against applicable financial regulations. Identifies gaps, assesses risk exposure, and provides remediation recommendations with priority rankings. Covers AML/KYC, SOX, Basel III/IV, MiFID II, MaRisk, GDPR (financial data), and sector-specific regulations.

When to Use

  • Periodic compliance health checks
  • Pre-regulatory examination preparation
  • New product or service compliance assessment
  • Post-acquisition compliance integration
  • Regulatory change impact analysis
  • Board compliance reporting

How It Works

  1. Regulatory Mapping: Identifies all applicable regulations based on entity type, activities, and jurisdiction
  2. Control Assessment: Evaluates existing controls against regulatory requirements
  3. Gap Analysis: Identifies compliance gaps with severity classification
  4. Risk Scoring: Assigns likelihood and impact scores to each gap
  5. Remediation Plan: Proposes corrective actions with timelines and resource estimates
  6. Monitoring Framework: Defines ongoing compliance monitoring KPIs

Example Usage

Input:

/compliance-check entity:"Alpine Capital Partners" regulation:aml-kyc jurisdiction:EU

Output:

# Compliance Review — Alpine Capital Partners
## Focus: AML/KYC | Jurisdiction: EU (AMLD6) | Date: 2026-03-14

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
## Regulatory Framework
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Applicable regulations:
- EU 6th Anti-Money Laundering Directive (AMLD6)
- EU Regulation 2024/1624 (AML Regulation — AMLR)
- National implementation (varies by member state)
- FATF Recommendations (global standard)
- EBA Guidelines on AML/CFT (EBA/GL/2021/02)

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
## Compliance Assessment
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

| Requirement                    | Status     | Gap Description              |
|--------------------------------|------------|------------------------------|
| AML/CFT risk assessment        | ⚠ Partial  | Last updated 18 months ago   |
| Customer due diligence (CDD)   | ✓ Adequate | Procedures documented        |
| Enhanced due diligence (EDD)   | ⚠ Partial  | PEP screening gaps           |
| Ongoing monitoring             | 🔴 Gap     | No automated transaction monitoring |
| Suspicious activity reporting  | ✓ Adequate | SAR procedures in place      |
| Record keeping                 | ✓ Adequate | 5-year retention confirmed   |
| Staff training                 | ⚠ Partial  | Training not annual          |
| Beneficial ownership           | ⚠ Partial  | UBO verification incomplete for 12% |
| Sanctions screening            | ✓ Adequate | Real-time screening active   |
| MLRO appointment               | ✓ Adequate | Designated officer in place  |

Overall Score: 62/100 — NEEDS IMPROVEMENT

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
## Critical Gaps
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

### GAP-001: No Automated Transaction Monitoring (CRITICAL)
- Requirement: AMLD6 Art. 11 — ongoing monitoring of business relationships
- Current state: Manual review of transactions > EUR 15K only
- Risk: Failure to detect structured transactions below threshold
- Regulatory consequence: Potential fine up to EUR 5M or 10% of turnover
- Remediation: Implement automated TM system (est. EUR 150K, 4 months)

### GAP-002: Stale Risk Assessment (HIGH)
- Requirement: AMLD6 Art. 8 — risk assessment must be current
- Current state: Last formal assessment dated September 2024
- Risk: Risk appetite not aligned to current threat landscape
- Remediation: Commission updated firm-wide risk assessment (6 weeks)

### GAP-003: PEP Screening Incomplete (HIGH)
- Requirement: AMLD6 Art. 20-24 — enhanced measures for PEPs
- Current state: Initial screening only — no ongoing re-screening
- Risk: Existing clients acquiring PEP status go undetected
- Remediation: Enable continuous PEP monitoring in screening tool (2 weeks)

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
## Remediation Roadmap
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

| Priority | Action                    | Owner | Deadline   | Cost Est. |
|----------|---------------------------|-------|------------|-----------|
| 1        | Update risk assessment    | MLRO  | 2026-04-30 | EUR 25K   |
| 2        | Enable PEP re-screening   | Ops   | 2026-04-15 | EUR 5K    |
| 3        | Implement TM system       | IT    | 2026-07-31 | EUR 150K  |
| 4        | Annual training program   | HR    | 2026-05-31 | EUR 10K   |
| 5        | UBO verification cleanup  | Ops   | 2026-05-15 | EUR 8K    |

Total remediation investment: EUR 198K

Read the full file on GitHub · 125 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 125 lines · 7 tokens per session scan A 48b19325434f

Subscribe to this mod's changes

compliance-check is a command published in the GitHub repository brainbytes-dev/everything-claude-finance (5 stars, last pushed 5mo ago), licensed MIT. It adds 7 tokens to every session and 1,222 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.