compliance-investigation-design

compliance-investigation-design is a skill for Claude Code, Codex from guoliang1114-boop/AriaAI. It costs 45 tokens per session (2,540 once invoked), scanned A, original, MIT.

A framework for designing an internal compliance investigation after a report, warning sign, regulatory concern, or suspected breach.

In plain words
What is it for?
Use it for investigations involving bribery laws, money laundering, privacy, third parties, gifts, donations, accounting records, or internal controls.
Why use it?
It provides a structured way to define the scope, preserve electronic and paper evidence, conduct interviews, protect legal privilege, and document findings.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Use it for investigations involving bribery laws, money laundering, privacy, third parties, gifts, donations, accounting records, or internal controls.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/guoliang1114-boop/ariaai/compliance-investigation-design
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add guoliang1114-boop/AriaAI --skill compliance-investigation-design
Clone the repo
git clone --depth 1 https://github.com/guoliang1114-boop/AriaAI

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for compliance-investigation-design

README.md
[![agentmods](https://agentmods.dev/badge/skills/guoliang1114-boop/ariaai/compliance-investigation-design/github.svg)](https://agentmods.dev/skills/guoliang1114-boop/ariaai/compliance-investigation-design)
Your own site
<a href="https://agentmods.dev/skills/guoliang1114-boop/ariaai/compliance-investigation-design"><img src="https://agentmods.dev/badge/skills/guoliang1114-boop/ariaai/compliance-investigation-design/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for compliance-investigation-design

Your own site · 80×15
<a href="https://agentmods.dev/skills/guoliang1114-boop/ariaai/compliance-investigation-design"><img src="https://agentmods.dev/badge/skills/guoliang1114-boop/ariaai/compliance-investigation-design.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 45 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,540 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector pass 7 Sept 2026
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00045 $0.02540
Opus 5 $0.00023 $0.01270
Sonnet 5 $0.00009 $0.00508
Haiku 4.5 $0.00005 $0.00254

Measured 12d ago against content hash 1bd46fee7cdc, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

compliance-investigation-design scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/compliance-investigation-design/SKILL.md · 282 lines

How it starts

The opening of the file, as written. The whole thing — 282 lines — stays where its author put it; the contents beside it link to each section on GitHub.

合规内部调查方案设计

When To Use

  • 收到内部举报或外部线索,需要启动正式调查
  • 监管机构调查前的内部自查
  • 并购后发现目标公司存在合规问题
  • 年度合规审计中发现异常需要深入调查
  • FCPA/UK Bribery Act/反洗钱违规的内部调查

Tools

  • 调查计划模板(调查范围、时间表、资源)
  • 证据保全清单(电子/纸质)
  • 访谈提纲模板
  • 特权日志(Privilege Log)
  • 调查报告模板

Framework

Anti-Corruption (FCPA / UK Bribery Act)

US Foreign Corrupt Practices Act (FCPA)

  • Anti-Bribery Provisions:禁止向外国政府官员支付款项以获取/保留业务
  • Books & Records Provisions:准确、完整地记录所有交易
  • Internal Controls Provisions:建立充分的内部会计控制
  • 调查重点:第三方代理商、礼品/招待、慈善捐赠、政治捐款

UK Bribery Act 2010

  • 比FCPA更严格:禁止私营部门间的行贿
  • "Associated Person"范围更广
  • "Adequate Procedures"抗辩
  • 无Facilitating Payment例外

Anti-Money Laundering (AML)

  • FATF 40项建议
  • 中国《反洗钱法》
  • 五级可疑交易报告体系
  • 调查重点:客户尽职调查(CDD/EDD)、交易监控、STR报告

Data Privacy in Investigations

  • 中国《个人信息保护法》
  • EU GDPR(跨境数据传输限制)
  • 调查中的数据收集边界
  • 员工隐私权与调查权的平衡

Investigation Methodology

Phase 1: Scoping & Planning(范围界定与计划)

  • 确定调查范围和目标
  • 识别潜在违规行为
  • 组建调查团队(内部/外部律师、法务会计师)
  • 法律特权保护策略
  • 资源和时间表

Phase 2: Evidence Preservation(证据保全)

  • 电子证据保全(邮件、即时通讯、ERP数据)
  • 纸质证据保全
  • 镜像备份(Forensic Image)
  • 证据链(Chain of Custody)维护
  • 数据跨境传输合规

Phase 3: Document Review(文件审阅)

  • 关键词搜索策略
  • 优先级排序(热文档/一般文档)
  • 特权审查
  • 时间线建立
  • 关键发现记录

Phase 4: Interviews(访谈)

  • 访谈顺序设计(外围→核心)
  • 访谈提纲准备
  • Upjohn警告(公司律师特权告知)
  • 访谈记录方式
  • 后续跟进

Phase 5: Analysis & Reporting(分析与报告)

  • 事实认定
  • 违规行为定性
  • 根本原因分析
  • 改进建议
  • 监管报告决策

Workflow

1. 调查启动
   ├─ 线索来源及初步评估
   ├─ 调查范围界定
   ├─ 调查团队组建
   ├─ 法律特权保护安排
   └─ 调查计划制定

2. 证据保全
   ├─ 电子数据保全通知(Litigation Hold)
   ├─ 关键人员电脑/手机镜像
   ├─ ERP/财务系统数据导出
   ├─ 纸质文件收集
   └─ 证据链记录

3. 文件审阅
   ├─ 第一轮关键词搜索
   ├─ 优先级文档深度审阅
   ├─ 时间线建立
   ├─ 关键发现汇总
   └─ 特权文件标识

4. 访谈执行
   ├─ 访谈顺序规划
   ├─ 外围人员访谈(了解流程)
   ├─ 关键人员访谈
   ├─ 被调查人访谈
   └─ 访谈记录整理

5. 分析与报告
   ├─ 事实梳理与认定
   ├─ 违规定性分析
   ├─ 根本原因分析
   ├─ 损失评估
   ├─ 改进建议
   └─ 监管报告评估

6. 后续行动
   ├─ 纪律处分建议
   ├─ 合规体系改进
   ├─ 监管沟通
   └─ 民事/刑事追偿评估

Output Format

# 合规内部调查方案

## 一、调查概要
| 项目 | 内容 |
|------|------|
| 调查编号 | |
| 线索来源 | 内部举报/监管通知/审计发现/媒体报告 |
| 涉嫌违规行为 | |
| 调查范围 | |
| 涉及人员 | |
| 涉及期间 | |
| 调查团队 | |
| 预计时间 | |

## 二、调查范围
### 包含
- ____(具体行为/交易/人员/期间)

### 不包含
- ____(明确排除的范围)

## 三、法律风险评估
| 法规 | 适用性 | 违规风险等级 | 潜在后果 |
|------|--------|-------------|----------|
| FCPA | | | |
| UK Bribery Act | | | |
| 中国反洗钱法 | | | |
| 个人信息保护法 | | | |
| 刑法(行贿/受贿) | | | |

## 四、证据保全计划
### 电子证据
| 类型 | 来源 | 保全方式 | 责任人 |
|------|------|----------|--------|
| 邮件 | | | |
| 即时通讯 | | | |
| ERP数据 | | | |
| 文档服务器 | | | |

### 纸质证据
| 类型 | 存放地点 | 保全方式 | 责任人 |
|------|----------|----------|--------|
| 合同原件 | | | |
| 付款审批单 | | | |
| 会议纪要 | | | |

## 五、访谈计划
| 序号 | 访谈对象 | 角色 | 访谈重点 | 预计时间 | 访谈人 |
|------|----------|------|----------|----------|--------|
| 1 | | 外围 | 了解流程 | | |
| 2 | | 外围 | 了解流程 | | |
| 3 | | 关键证人 | | | |
| 4 | | 被调查人 | | | |

### 访谈原则
- Upjohn警告:告知律师代表公司而非个人
- 保密义务提醒
- 不承诺不追责
- 如实记录

## 六、时间表
| 阶段 | 时间 | 关键里程碑 |
|------|------|------------|
| 调查启动 | | |
| 证据保全 | | |
| 文件审阅 | | |
| 访谈执行 | | |
| 分析报告 | | |
| 后续行动 | | |

## 七、报告机制
| 阶段 | 报告对象 | 频率 | 形式 |
|------|----------|------|------|
| 进展汇报 | 审计委员会 | 双周 | 书面+会议 |
| 重大发现 | 董事会 | 即时 | 会议 |
| 最终报告 | 审计委员会+外部律师 | 完成后 | 书面报告 |

## 八、特权保护
- 调查由外部律师主导/监督
- 所有调查文件标注"Attorney-Client Privilege"
- 维护特权日志
- 非特权文件与特权文件分离

Read the full file on GitHub · 282 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 282 lines · 45 tokens per session scan A 1bd46fee7cdc

Subscribe to this mod's changes

compliance-investigation-design is a skill published in the GitHub repository guoliang1114-boop/AriaAI (37 stars, last pushed today), licensed MIT. It adds 45 tokens to every session and 2,540 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.