Farhad ChowdhurySpec v1.0 · free
Build spec · no sign-up

A horizon scanner that survives contact with a real week.

The week's regulator output turned into one page. What changed, who owns it, what we do by when. Most firms run this off eleven mailing lists and hope.

Monday · 30 minCollect

Pull the week's primary sources and run the extraction. The machine does this part.

Wednesday · 45 minTier

A human tiers every item, names an owner, writes the action line. The only step that changes behaviour.

Friday · 20 minPublish

One page out. Including the domains where nothing happened.

Under two hours a week. If it is taking longer, your scope is too wide.

What the model does

Gathering

  • Reads the primary source, not a summary of it
  • Extracts only what the document states
  • Quotes the operative wording, never paraphrases it
  • Says NOT STATED rather than filling the gap
What you do

Judgement

  • Assigns the tier
  • Names the owner
  • Writes the action line
  • Confirms every Tier 1 against the source

The full spec

horizon-scanner-spec-v1.md
# Regulatory Horizon Scanner (spec v1.0)

## 1. What it's for

A weekly process that turns regulator output into a single page. What
changed, what it means for us, who owns it, by when.

It isn't a news feed. The output is a decision record.

## 2. Scope, do this first

Scope creep is what kills a scanner.

- Jurisdictions we're licensed or operating in:
- Products in scope:
- Domains: AML/CFT, sanctions, fraud, conduct, data, payments, AI
- Explicitly out of scope:

Anything outside scope is Tier 3, or nothing. Don't widen the scope
because something looks interesting.

## 3. Sources

Primary sources only. Use a law firm briefing to find the rule, then
go and read the rule.

- FATF, Wolfsberg, Egmont
- UK: FCA, HM Treasury, OFSI, UKFIU
- EU: EBA, AMLA, European Commission
- UAE: CBUAE, local FIU, DFSA / FSRA
- US: OFAC, FinCEN.  Canada: FINTRAC
- Africa as applicable: BCEAO, COBAC, national central banks

Sanctions list updates are a separate daily automated feed. Don't put
them in here.

## 4. What you log per item

id, date_published (from the source), source, url, jurisdiction,
domain, instrument type, 3-sentence summary, what it affects, tier,
effective_date, response_due, owner, action, status.

Two of those are human only: tier and action.

## 5. Tiering, fixed criteria

- Tier 1: changes an obligation we're subject to, and has a date.
- Tier 2: shifts supervisory expectations, no deadline.
- Tier 3: directional, awareness only.

If two people disagree, it's the higher tier until the committee says
otherwise.

## 6. The extraction prompt

Paste the primary source text, not a summary of it.

---
You are helping a financial crime compliance team with horizon
scanning. Extract ONLY what the document states. Do not infer,
advise, or assess impact.

Return these and nothing else:

1. issuing_body
2. date_published, as printed
3. instrument_type
4. jurisdictions_named
5. summary, 3 sentences max, plain English
6. obligations_created, each on its own line, quoting the operative
   wording. If none, write NONE.
7. dates_stated, every date and what it applies to
8. entities_in_scope
9. explicitly_excluded
10. uncertainty, anything you could not determine from the text

If the document doesn't state something, write NOT STATED. Never fill
a gap with background knowledge.
---

Fields 9 and 10 matter most. A model that says NOT STATED is useful.
A model that quietly fills gaps is a liability.

## 7. The weekly rhythm

- Monday, 30 min. Collect, run the extraction, log the records.
- Wednesday, 45 min. A human tiers everything, names an owner, writes
  the action line. This is the step you can't automate and the only
  one that really matters.
- Friday, 20 min. Publish the brief.

Under two hours a week. If it's taking longer, your scope is too wide.

## 8. The brief

---
HORIZON BRIEF, week ending [date]

ACTION REQUIRED
[Tier 1: one line each. What changed, owner, due by]

WATCH
[Tier 2: one line each, owner named]

NOTED
[Tier 3: title and link]

NOTHING THIS WEEK IN: [domains with no items]
---

That last line is the one people skip and the one that builds trust.
It's how silence reads as checked rather than forgotten.

## 9. Guardrails

- The AI never assigns a tier and never writes the action line.
- Every Tier 1 item is confirmed by a human against the source.
- No item without a primary source URL and publication date.
- Public documents only. Never paste customer or case data into an
  assistant that isn't approved for it.
- Version the spec. If the tiering criteria change, say so in that
  week's brief.

## 10. What I'd do differently

My first version had eleven domains and four jurisdictions we had no
licence in. It collapsed in six weeks because the Wednesday triage
became a two-hour job nobody wanted. Narrow it until the weekly ritual
sits comfortably under two hours, then widen it only when somebody
complains that something got missed.