
Subcontract Compliance & Risk Analyzer
Analyze subcontract compliance gaps and identify risks against prime contract obligations.
What You Can Do
This skill analyzes subcontract language for compliance with prime contract obligations, regulatory requirements (DFARS, FAR, industry standards), and identifies protective gaps that could expose your company to customer penalties. You receive a structured risk assessment with specific compliance violations, severity ratings, and actionable remediation strategies tied to both flow-down requirements and protective clauses.
Features
Compares subcontract T&Cs against customer-imposed requirements to ensure flow-down compliance
Flags missing or misaligned clauses required by DFARS, FAR, and industry-specific regulations
Identifies holes in liability protection, indemnification, insurance, and IP terms that expose your company
Analyzes compliance chains when subcontractors have their own subcontractors
Generates specific language fixes and negotiation strategies for each identified risk
Structures findings in audit-ready format with evidence citations and severity classifications
Evaluates new T&Cs in amendments against existing compliance obligations
Creates executive briefings for non-compliance issues requiring management or legal review
Example Output
Compliance Gap: DFARS 252.204-7012 (Safeguarding Controlled Technical Data)
- Finding: Subcontract omits required NIST SP 800-171 cybersecurity controls for unclassified controlled technical data storage
- Severity: HIGH — Customer audit will flag this as prime contract violation
- Current Language: None
- Recommended Fix: Add clause requiring "compliance with NIST SP 800-171 or equivalent for CUI storage and transmission"
- Negotiation Path: Reference prime contract Exhibit C, Section 5.2
Protective Gap: Limitation of Liability
- Finding: Subcontract includes unlimited liability cap; prime contract limits customer claims to 12 months of fees
- Severity: MEDIUM — Subcontractor can claim damages exceeding your prime contract exposure
- Current Language: "Contractor liability for all breaches shall not exceed contract value"
- Recommended Fix: Cap subcontractor liability at 12 months of fees paid, mirroring prime contract terms
- Negotiation Path: Position as standard aerospace/defense practice for multi-tier contracts
What's Included
- SKILL.md instruction file for Claude with complete workflow and analysis framework:
- Prime Contract Compliance Checklist: Master list of DoD/commercial flow-down requirements by contract type
- Subcontract Risk Assessment Template: Structured format for documenting gaps, severity, and remediation
- DFARS/FAR Clause Cross-Reference Matrix: Maps prime contract clauses to required subcontract language
- Remediation Strategy Workbook: Negotiation language, fallback positions, and escalation triggers
Who It's For
- Subcontracts Managers — Managing compliance across subcontractor portfolios in aerospace/defense
- Program Managers — Ensuring subcontractor T&Cs don't create impossible prime contract obligations
- Contracts Compliance Specialists — Conducting pre-execution and audit-stage compliance reviews
- Supply Chain Risk Officers — Identifying and escalating regulatory exposure in multi-tier supply chains
- Procurement Directors — Establishing standardized compliance frameworks for subcontract execution
Best For
- Subcontract review before execution (initial compliance assessment)
- Amendment evaluation when subcontractors propose new T&Cs
- Compliance audit preparation and remediation planning
- Multi-tier subcontract chain analysis
- Risk escalation documentation for management/legal review







