/policy-diff
- Load
~/.claude/plugins/config/claude-for-legal/regulatory-legal/CLAUDE.md → policy library index.
- Use the workflow below.
- Extract requirements from the reg. Match to indexed policies.
- Output: per-requirement gap analysis, which policy needs updating.
Matter context
Matter context. Check ## Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run /regulatory-legal:matter-workspace switch <slug> or say practice-level." Load the active matter's matter.md for matter-specific context and overrides. Write outputs to the matter folder at ~/.claude/plugins/config/claude-for-legal/regulatory-legal/matters/<matter-slug>/. Never read another matter's files unless Cross-matter context is on.
Purpose
A reg changed. You have policies. This skill finds which policies the change touches and what the gap is between "what the reg now requires" and "what the policy says."
Load context
~/.claude/plugins/config/claude-for-legal/regulatory-legal/CLAUDE.md → policy library index (policies, locations, owners).
Scope integrity
If the user asks you to exclude a policy section, requirement, or category from the diff:
- Do it — the user owns the scope.
- But flag it, loudly and permanently: "⚠️ SCOPE LIMITATION: Section [X] excluded at user request. This diff does not reflect the full policy. Gaps in the excluded area are NOT identified." Above the header, carried to every downstream artifact.
- Hand the flag to
gap-surfacer: "This diff was scope-limited. Do not represent it as a complete compliance picture." Include the scope-limitation banner verbatim on any gap tracker entry derived from this diff.
- Note what the exclusion means: "Excluding vendor management means the diff will show 'no policy addresses vendor management' — which is worse than showing the gap."
A compliance artifact built on an undisclosed scope exclusion looks like concealment in discovery. The flag is the difference between "we scoped the review" and "we hid the problem."
Workflow
Step 0: Verify rule status before you diff
Before diffing a rule against policy, confirm the rule is actually in force. Red flags that the rule may not be in force:
- The applicability/compliance date has passed by more than 30 days but you have no confirmation it wasn't delayed
- The rule is more than 12 months old
- The rule is a politically contentious final rule (major rulemakings are frequently challenged)
When you see a red flag, check (via research MCP, web search if enabled, or the Federal Register docket) for: delays, stays, injunctions, rescission proposals, vacatur, or amendments. If you can check and the rule is confirmed in force, proceed. If you cannot verify (no tools connected), emit this banner ABOVE the header, before any content:
⚠️ RULE STATUS UNVERIFIED — I could not confirm this rule is currently in force. Final rules are frequently stayed, enjoined, delayed, or rescinded after publication. Do not treat any compliance date below as binding until you confirm the rule's status at the Federal Register docket or with outside counsel.
Tag every due date in the output: [due date per published rule — status unverified].
Rule-status uncertainty travels downstream. When handing off a gap to gap-surfacer, mark the item status_verified: false so it never gets routed to an Overdue bucket on the strength of a published date alone.
No silent supplement. If the regulatory change text is partial or ambiguous and the fuller rule isn't available from the indexed source, stop and ask. Do NOT fill the gap from web search or model knowledge without asking. Say: "I have [what you have]. To extract requirements accurately I'd need [what's missing]. Options: (1) paste the full text, (2) point me at the primary source, (3) search the web for the rule — results will be tagged [web search — verify] and should be checked against the issuing authority before relying, or (4) stop here. Which would you like?" A lawyer decides whether to accept lower-confidence sources; Claude does not decide for them.
Source attribution. Tag every citation — the regulatory citation, any cross-references, any policy excerpts — with where it came from: [<regulator or research tool>] for items retrieved from a primary source, policy library, or MCP; [web search — verify] for items pulled from web search; [model knowledge — verify] for items recalled from the model's training data; [user provided] for items pasted in by the user. Items tagged verify carry higher fabrication risk and should be checked first. Never strip or collapse the tags in the output.
Read the regulatory change. List each discrete new or changed requirement:
Be specific. "Enhanced disclosure requirements" is not a requirement. "Must disclose X in Y format at Z point in the flow" is.