Loops for Legal and Compliance
A standing-order loop for legal watches clause sources, policy changes, and incoming files — then escalates to a person. It is not the collaborative clause-review room, and it must not guess.
Legal and compliance already watch incoming paper and policy changes — or they mean to. Customer paper lands in a folder. A playbook PDF is replaced. A regulator feed publishes. Sales learns “legal is comfortable” from a retrieval snippet. Incoming MSAs sit until someone remembers. The failure mode is fluency treated as review, and a watch that guesses which version applies instead of escalating. The EU Artificial Intelligence Act (Regulation (EU) 2024/1689, 2024) is not a clause playbook; it is a reminder that automated systems carry duties chat etiquette does not satisfy.
This page is unattended standing-order work, not the shared collaborative room where legal, sales, and compliance quote a clause, pin a playbook version, and a named lawyer refuses or signs. The standing order watches a clause source, a policy repository, or an incoming file queue. It quotes or hashes what changed, compares it to the version on the job, and escalates. It does not approve send. It does not paraphrase the clause into “legal OK.” For that room, read collaborative AI for legal and compliance review.
Three nouns, as vocabulary:
- Eval loop — a completion sensor. Did the sent message match the signed payload hash? See eval loops for enterprise agent harnesses.
- Standing-order loop — a compiled watch that admits a run when a trigger fires. See what is loop engineering and the standing-order loop definition.
- Agentic workflow — open-ended replan, such as “review this contract” with no quote, version, or rejector. See what is an agentic workflow.
A watch that logs what it saw is more useful than a bot that guesses comfort. Escalate. Do not guess.
What a legal and compliance standing-order loop is
Three common starts, from six things that start a loop:
- When the policy changes — playbook PDF updated, wiki revision, grid effective date crossed.
- When the file lands — customer paper in the intake folder, vendor MSA upload, RFP attachment.
- When the clause source moves — standard terms URL changed, registry filing published, regulator update feed.
The job is narrow: detect the start, quote or hash what changed, compare to the version pinned on the job, and escalate — open a collaborative matter or notify the named lawyer roster. It does not approve send. A loop is not an agent: the standing order does not bind the company.
Do not let the watch guess which playbook applies when three PDFs share a title. Escalate with the diff and let the lawyer pick the version on the collaborative job. Retrieval that prefers an obsolete doc because it ranked well is a harness failure, not a legal skill issue. What is harness engineering covers pinning versions on the job.
Skip when the file is a duplicate of an open matter, or when the policy diff is empty. That skip is a first-class outcome. A watch that always opens a matter trains lawyers to ignore it. A watch that writes “skipped: hash matches open matter” is evidence you are not paging people for theatre.
Why legal should care
Because fluency is not review, and watching is not signing.
Legal is often late because nobody routed the matter — not because the model cannot summarise. A standing order fixes routing: file landed, policy delta detected, matter opened with sources attached. The collaborative room fixes substance: quote, version, named rejector, send gate.
In February 2024 Air Canada was held to chatbot-invented fare terms — CBC News, decision Moffatt v. Air Canada. A watch would not have saved that alone; a send gate on customer-facing claims would. Standing orders and collaborative review are complementary: detect and route fast; refuse and sign in the room.
NIST’s AI Risk Management Framework (2023) maps govern-measure-manage for AI systems. A watch that logs triggers and skips is a measure input. It is not a substitute for a named rejector on Tuesday’s concession. In June 2023 a New York federal judge sanctioned two lawyers who filed a brief citing cases ChatGPT had invented. Fiction had been written into a court record. The analogue here is “legal OK” written into a CRM field because a summary ranked well.
You should care if:
- policy changes already arrive as email attachments and sales learns from a snippet
- incoming MSAs sit in a folder until someone remembers
- three playbook PDFs share a title and retrieval picks the obsolete one
- customer-facing claims leave the building without a send gate
What is write-back governance stays on customer messages, contract repositories, and CRM terms fields. What is AI governance is the wider map.
Words you will hear
- Quote. The clause as written, extracted — not a paraphrase.
- Pinned playbook version. The version the watch diffs against. Not “the legal PDF.”
- Diff. What changed between pinned version and new source, as an artefact.
- Escalate. Open a collaborative matter or notify the named roster. Do not guess.
- Skip. Duplicate hash or empty diff, recorded with a reason.
- Eval loop. After send, did the message match the signed payload?
- Agentic workflow. “Handle contracts” with no saved escalation path.
Regulators and general counsel reconstruct matters, not token traces. Your watch should produce: file hash, quoted sections, playbook version pinned, diff summary, skip log, matter id opened. Engineers may need traces for debugging; the company needs the matter record.
How to compile one legal standing order
Start from intake people already perform badly when busy.
Example: Incoming customer paper
Trigger: file lands in the legal-intake folder with extension pdf or docx.
Preconditions: job pinned to current playbook version; roster includes the duty lawyer.
Steps:
- Hash file; if duplicate of open matter, skip and log.
- Extract quoted limitation-of-liability and data-processing sections — not summary-only.
- Compare keywords against pinned playbook sections; flag deltas as questions, not approvals.
- Open a collaborative matter with quote, file, playbook version, and flag list.
- Notify the named roster. Disable send on any draft until a lawyer joins the matter.
Explicit non-goals: no customer email; no CRM “legal approved” field; no auto-redline send.
When policy changes:
Trigger: playbook repository commit or effective date.
Steps: diff old vs new pinned version; list clauses affected; open matters for templates that reference changed sections; skip if diff empty.
Write-back — customer messages, contract repositories, CRM terms fields — stays on the collaborative path with write-back governance.
How to evaluate loop engineering applies to watch loops too: can you replay why a matter opened, or why it skipped?
What “done” looks like
A good legal standing-order week:
- Every new file either opened a matter with quotes or logged a skip with reason.
- Policy-change runs produced a diff artefact, not a chat summary.
- No customer send from the standing-order path.
- A later reader can reconstruct intake without asking who “checked the bot.”
The signed review still lives on the collaborative job: quoted text, playbook version, rejector, send log. The standing order is the doorbell, not the judge.
RBAC for enterprise AI applies: outside counsel may see the matter, not every connector. Retention should match how long you must explain the language.
Website and support bots need the same escalation split: a watch may detect that public terms changed; the send of customer-facing language still routes to collaborative AI for customer support or the legal review room with a signer class. Moffatt v. Air Canada is the reminder that the message can be the write.
How to start with one watch
Pick file lands for one intake folder you already have — or policy change if version chaos is the pain.
Four weeks:
- One folder or one playbook repo path.
- Quote extraction plus diff against a pinned version — no approval language.
- Automatic open of a collaborative matter with sources attached.
- Zero sends from the standing order.
Measure: time from upload to lawyer on the matter; count of “legal OK” messages in side chat. If side chat wins, you built notification, not routing.
Loops for finance and planning and loops for revenue operations cover packs and pipeline triggers. If you are still choosing the discipline, start with what is loop engineering and score a vendor with how to evaluate loop engineering before you let a watch open matters on its own. A loop is not an agent is the rule that keeps the watch from drafting a customer email at 3am.
Watch faithfully. Escalate honestly. Leave the signature to the room where a lawyer can refuse.
How this shows up in Nimbus
Nimbus workstreams can host the watch and the review room: file hash, quoted clauses, pinned playbook, run page, and a collaborative matter the named lawyer can refuse. Governance is the send gate — not a prompt that says “ask legal.”
What is a Nimbus Loop is the product noun for the standing order. Score it with how to evaluate loop engineering before you let a watch look like review.
Watchers vs the review room
Is a standing-order loop the same as shared legal review?
No. Review is collaborative AI — quoted clause, playbook version, named lawyer who can refuse. A standing-order loop watches for change or arrival and routes a matter; it does not approve language. It is the doorbell, not the judge. If you collapse the two, you get a watch that writes legal OK into chat, or a review room that never sees the file because nobody routed it. Detect and route fast. Refuse and sign in the room.
Can the loop rewrite the clause if the policy changed?
No. Escalate to a person with the quote, the new policy version, and the diff. Drafting without a named rejector is how obsolete PDFs win because they ranked well. Do not let the loop guess which playbook applies when three PDFs share a title. Pin a version on the job and let the lawyer pick. Retrieval that prefers an obsolete doc is a harness failure, not a legal skill issue. The standing order quotes and flags. It does not bind the company.
What is the difference between a standing-order loop and an eval loop?
A standing-order loop is a watch that admits a run when a file lands or a policy changes. An eval loop is a harness sensor — for example, did the sent message match the signed payload — not a watch on incoming contracts. An agentic workflow is the third noun: review this contract with no quote, version, or rejector. Score the watch on whether you can replay why a matter opened or skipped. Score the send on whether the message matched the signed text.
Can the loop send a customer email if the flags look clean?
No. Disable send on any draft until a named lawyer joins the matter. Clean flags are questions, not approvals. Air Canada was held to chatbot-invented fare terms with no CRM write. A watch would not have saved that alone; a send gate on customer-facing claims would. The standing order may open the matter with quotes attached. The collaborative room still refuses or signs. Zero sends from the loop path.
See what governed AI looks like on your stack.
Connect your tools, run a workstream, and keep every decision on your ledger. Start on Free.