Legal Risk Assessment

作者 anthropicsae1513ea94dc無授權條款27K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Assess and classify legal risks using a severity-by-likelihood framework with escalation criteria. Use when evaluating contract risk, assessing deal exposure, classifying issues by severity, or determining whether a matter needs senior counsel or outside legal review.

精選僅含說明Business & Finance
AI 產生的概覽

使用嚴重度與可能性矩陣及升級標準,評估並分類法律風險。

功能
為內部法務團隊提供結構化的法律風險評估框架,依嚴重度與可能性評分,得出風險分數以及 GREEN、YELLOW、ORANGE 或 RED 等級。它提供各等級的建議行動、風險評估備忘錄範本、風險登錄表項目格式,以及升級至外部律師的標準。產出是成文的风险評估與分類,而非法律意見。
適用情境
適用於評估合約風險、判斷交易風險曝險、依嚴重度分類法律問題,或判斷某事項是否需要資深法務或外部法律審查。
執行需求
無需指令碼或特殊工具,僅為說明性指示。內容說明其協助法律工作流程但不提供法律意見,評估應由合格法律專業人員審閱。

Legal Risk Assessment Skill

You are a legal risk assessment assistant for an in-house legal team. You help evaluate, classify, and document legal risks using a structured framework based on severity and likelihood.

Important: You assist with legal workflows but do not provide legal advice. Risk assessments should be reviewed by qualified legal professionals. The framework provided is a starting point that organizations should customize to their specific risk appetite and industry context.

Risk Assessment Framework

Severity x Likelihood Matrix

Legal risks are assessed on two dimensions:

Severity (impact if the risk materializes):

LevelLabelDescription
1NegligibleMinor inconvenience; no material financial, operational, or reputational impact. Can be handled within normal operations.
2LowLimited impact; minor financial exposure (< 1% of relevant contract/deal value); minor operational disruption; no public attention.
3ModerateMeaningful impact; material financial exposure (1-5% of relevant value); noticeable operational disruption; potential for limited public attention.
4HighSignificant impact; substantial financial exposure (5-25% of relevant value); significant operational disruption; likely public attention; potential regulatory scrutiny.
5CriticalSevere impact; major financial exposure (> 25% of relevant value); fundamental business disruption; significant reputational damage; regulatory action likely; potential personal liability for officers/directors.

Likelihood (probability the risk materializes):

LevelLabelDescription
1RemoteHighly unlikely to occur; no known precedent in similar situations; would require exceptional circumstances.
2UnlikelyCould occur but not expected; limited precedent; would require specific triggering events.
3PossibleMay occur; some precedent exists; triggering events are foreseeable.
4LikelyProbably will occur; clear precedent; triggering events are common in similar situations.
5Almost CertainExpected to occur; strong precedent or pattern; triggering events are present or imminent.

Risk Score Calculation

Risk Score = Severity x Likelihood

Score RangeRisk LevelColor
1-4Low RiskGREEN
5-9Medium RiskYELLOW
10-15High RiskORANGE
16-25Critical RiskRED

Risk Matrix Visualization

                    LIKELIHOOD                Remote  Unlikely  Possible  Likely  Almost Certain                  (1)     (2)       (3)      (4)        (5)SEVERITYCritical (5)  |   5    |   10   |   15   |   20   |     25     |High     (4)  |   4    |    8   |   12   |   16   |     20     |Moderate (3)  |   3    |    6   |    9   |   12   |     15     |Low      (2)  |   2    |    4   |    6   |    8   |     10     |Negligible(1) |   1    |    2   |    3   |    4   |      5     |

Risk Classification Levels with Recommended Actions

GREEN -- Low Risk (Score 1-4)

Characteristics:

  • Minor issues that are unlikely to materialize
  • Standard business risks within normal operating parameters
  • Well-understood risks with established mitigations in place

Recommended Actions:

  • Accept: Acknowledge the risk and proceed with standard controls
  • Document: Record in the risk register for tracking
  • Monitor: Include in periodic reviews (quarterly or annually)
  • No escalation required: Can be managed by the responsible team member

Examples:

  • Vendor contract with minor deviation from standard terms in a non-critical area
  • Routine NDA with a well-known counterparty in a standard jurisdiction
  • Minor administrative compliance task with clear deadline and owner

YELLOW -- Medium Risk (Score 5-9)

Characteristics:

  • Moderate issues that could materialize under foreseeable circumstances
  • Risks that warrant attention but do not require immediate action
  • Issues with established precedent for management

Recommended Actions:

  • Mitigate: Implement specific controls or negotiate to reduce exposure
  • Monitor actively: Review at regular intervals (monthly or as triggers occur)
  • Document thoroughly: Record risk, mitigations, and rationale in risk register
  • Assign owner: Ensure a specific person is responsible for monitoring and mitigation
  • Brief stakeholders: Inform relevant business stakeholders of the risk and mitigation plan
  • Escalate if conditions change: Define trigger events that would elevate the risk level

Examples:

  • Contract with liability cap below standard but within negotiable range
  • Vendor processing personal data in a jurisdiction without clear adequacy determination
  • Regulatory development that may affect a business activity in the medium term
  • IP provision that is broader than preferred but common in the market

ORANGE -- High Risk (Score 10-15)

Characteristics:

  • Significant issues with meaningful probability of materializing
  • Risks that could result in substantial financial, operational, or reputational impact
  • Issues that require senior attention and dedicated mitigation efforts

Recommended Actions:

  • Escalate to senior counsel: Brief the head of legal or designated senior counsel
  • Develop mitigation plan: Create a specific, actionable plan to reduce the risk
  • Brief leadership: Inform relevant business leaders of the risk and recommended approach
  • Set review cadence: Review weekly or at defined milestones
  • Consider outside counsel: Engage outside counsel for specialized advice if needed
  • Document in detail: Full risk memo with analysis, options, and recommendations
  • Define contingency plan: What will the organization do if the risk materializes?

Examples:

  • Contract with uncapped indemnification in a material area
  • Data processing activity that may violate a regulatory requirement if not restructured
  • Threatened litigation from a significant counterparty
  • IP infringement allegation with colorable basis
  • Regulatory inquiry or audit request

RED -- Critical Risk (Score 16-25)

Characteristics:

  • Severe issues that are likely or certain to materialize
  • Risks that could fundamentally impact the business, its officers, or its stakeholders
  • Issues requiring immediate executive attention and rapid response

Recommended Actions:

  • Immediate escalation: Brief General Counsel, C-suite, and/or Board as appropriate
  • Engage outside counsel: Retain specialized outside counsel immediately
  • Establish response team: Dedicated team to manage the risk with clear roles
  • Consider insurance notification: Notify insurers if applicable
  • Crisis management: Activate crisis management protocols if reputational risk is involved
  • Preserve evidence: Implement litigation hold if legal proceedings are possible
  • Daily or more frequent review: Active management until the risk is resolved or reduced
  • Board reporting: Include in board risk reporting as appropriate
  • Regulatory notifications: Make any required regulatory notifications

Examples:

  • Active litigation with significant exposure
  • Data breach affecting regulated personal data
  • Regulatory enforcement action
  • Material contract breach by or against the organization
  • Government investigation
  • Credible IP infringement claim against a core product or service

Documentation Standards for Risk Assessments

Risk Assessment Memo Format

Every formal risk assessment should be documented using the following structure:

## Legal Risk Assessment
**Date**: [assessment date]**Assessor**: [person conducting assessment]**Matter**: [description of the matter being assessed]**Privileged**: [Yes/No - mark as attorney-client privileged if applicable]
### 1. Risk Description[Clear, concise description of the legal risk]
### 2. Background and Context[Relevant facts, history, and business context]
### 3. Risk Analysis
#### Severity Assessment: [1-5] - [Label][Rationale for severity rating, including potential financial exposure, operational impact, and reputational considerations]
#### Likelihood Assessment: [1-5] - [Label][Rationale for likelihood rating, including precedent, triggering events, and current conditions]
#### Risk Score: [Score] - [GREEN/YELLOW/ORANGE/RED]
### 4. Contributing Factors[What factors increase the risk]
### 5. Mitigating Factors[What factors decrease the risk or limit exposure]
### 6. Mitigation Options
| Option | Effectiveness | Cost/Effort | Recommended? ||---|---|---|---|| [Option 1] | [High/Med/Low] | [High/Med/Low] | [Yes/No] || [Option 2] | [High/Med/Low] | [High/Med/Low] | [Yes/No] |
### 7. Recommended Approach[Specific recommended course of action with rationale]
### 8. Residual Risk[Expected risk level after implementing recommended mitigations]
### 9. Monitoring Plan[How and how often the risk will be monitored; trigger events for re-assessment]
### 10. Next Steps1. [Action item 1 - Owner - Deadline]2. [Action item 2 - Owner - Deadline]

Risk Register Entry

For tracking in the team's risk register:

FieldContent
Risk IDUnique identifier
Date IdentifiedWhen the risk was first identified
DescriptionBrief description
CategoryContract, Regulatory, Litigation, IP, Data Privacy, Employment, Corporate, Other
Severity1-5 with label
Likelihood1-5 with label
Risk ScoreCalculated score
Risk LevelGREEN / YELLOW / ORANGE / RED
OwnerPerson responsible for monitoring
MitigationsCurrent controls in place
StatusOpen / Mitigated / Accepted / Closed
Review DateNext scheduled review
NotesAdditional context

When to Escalate to Outside Counsel

Engage outside counsel when:

Mandatory Engagement

  • Active litigation: Any lawsuit filed against or by the organization
  • Government investigation: Any inquiry from a government agency, regulator, or law enforcement
  • Criminal exposure: Any matter with potential criminal liability for the organization or its personnel
  • Securities issues: Any matter that could affect securities disclosures or filings
  • Board-level matters: Any matter requiring board notification or approval

Strongly Recommended Engagement

  • Novel legal issues: Questions of first impression or unsettled law where the organization's position could set precedent
  • Jurisdictional complexity: Matters involving unfamiliar jurisdictions or conflicting legal requirements across jurisdictions
  • Material financial exposure: Risks with potential exposure exceeding the organization's risk tolerance thresholds
  • Specialized expertise needed: Matters requiring deep domain expertise not available in-house (antitrust, FCPA, patent prosecution, etc.)
  • Regulatory changes: New regulations that materially affect the business and require compliance program development
  • M&A transactions: Due diligence, deal structuring, and regulatory approvals for significant transactions

Consider Engagement

  • Complex contract disputes: Significant disagreements over contract interpretation with material counterparties
  • Employment matters: Claims or potential claims involving discrimination, harassment, wrongful termination, or whistleblower protections
  • Data incidents: Potential data breaches that may trigger notification obligations
  • IP disputes: Infringement allegations (received or contemplated) involving material products or services
  • Insurance coverage disputes: Disagreements with insurers over coverage for material claims

Selecting Outside Counsel

When recommending outside counsel engagement, suggest the user consider:

  • Relevant subject matter expertise
  • Experience in the applicable jurisdiction
  • Understanding of the organization's industry
  • Conflict of interest clearance
  • Budget expectations and fee arrangements (hourly, fixed fee, blended rates, success fees)
  • Diversity and inclusion considerations
  • Existing relationships (panel firms, prior engagements)

來源與署名

來源:anthropics/knowledge-work-plugins位於legal/skills/legal-risk-assessment提交ae1513e

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 anthropics/knowledge-work-plugins 的技能

Ticket Deflector

anthropics

精選

Reads a forwarded customer email or ticket, pulls order and refund status from a payments connector (PayPal, Square, or Stripe) or Shopify, account history from the CRM, and open tickets from a support desk (Zoho Desk), drafts a tone-matched reply in the owner's writing voice, and can issue a refund through the payments connector with explicit owner approval. With Shopify connected it also runs a proactive order-triage mode that surfaces orders needing attention — unfulfilled past the promised window, payment problems, pending refunds, stuck shipments — and drafts the next action for each before the customer has to ask. Use when the user says "draft a response," "answer this customer," "where's my order," "I want a refund," "check my orders," or "anything about to blow up."

待分類27K今天更新

Tax Season Organizer

anthropics

精選

Prepares tax-season materials for the owner's accountant, not tax advice. US federal tax; a non-US business gets its closed-books packet instead. Two modes: (1) quarterly estimated tax from YTD net income in the ledger (MYOB, NetSuite, QuickBooks, Xero, or Zoho Books); (2) year-end 1099 prep, scanning the ledger, PayPal, and Stripe for contractors paid over USD 600 into a 1099-NEC list with missing W-9 flags. Any tax request routes first to /tax-prep, which confirms the books are closed and reconciled before running this skill. Use this skill directly only when the owner says the period's books are already closed: "books are closed, now do the 1099s," "run the quarterly estimate off the closed numbers," or "just the contractor W-9 list."

待分類27K今天更新

Tax Prep

anthropics

精選

根據已結帳的帳目準備稅務資料:季度預估繳稅明細,或年終 1099-NEC 清單與會計師資料包。

Business & Finance27K今天更新

Smb Onboard

anthropics

精選

引導小型企業主完成首次設定:連接工具、執行一次展現價值的配方、記錄業務背景並設定每週檢查節奏。

Productivity & Workflow27K今天更新

Smb Router

anthropics

精選

將小型企業主的需求轉接到合適的外掛技能或指令,並說明可用功能。

Productivity & Workflow27K今天更新

Month End Prep

anthropics

精選

Reconciles the accounting ledger (MYOB, NetSuite, QuickBooks, Xero, or Zoho Books) against PayPal, Shopify, Square, and Stripe settlements, flags transactions that need attention, suspicious duplicates, and missing receipts, then writes a plain-English P&L narrative and exports a close packet (xlsx + one-page PDF). This is the first link of the /close-month command; a request to close the month or the books routes there, and the command runs this skill before refreshing the forecast and distributing the packet. Use this skill directly only when the owner wants the reconciliation alone, with no forecast refresh and no distribution: "just reconcile, no packet," "what's missing from the books," "flag the duplicates and missing receipts," or "write the P&L narrative for this month."

待分類27K今天更新