Course overview
Lesson 6 of 8 · 3 promptsAI for Chief Compliance Officers
LESSON 06 OF 8

Breach Investigations

3 prompts for Chief Compliance Officers

Prompts for Chief Compliance Officers: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Draft Breach Investigation Interview GuideUse this when you need a structured set of questions for a witness or subject interview in a breach investigation.
  2. 02Summarize Investigation Evidence Into TimelineUse this when you have emails, notes, or documents from a breach investigation and need a neutral timeline and key facts before deciding next steps.
  3. 03Outline Breach Corrective Action PlanUse this when you have completed a breach investigation and need to convert findings into a corrective action plan with clear owners and deadlines.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Draft Breach Investigation Interview Guide

Use this when you need a structured set of questions for a witness or subject interview in a breach investigation.

Prompt

Role You are a compliance investigation lead supporting a Chief Compliance Officer. You optimise for a neutral, structured interview guide that produces a complete, defensible record of what a witness or subject says.

Context you provide

  • {{matter_type}} — data breach, policy breach, suspected fraud
  • {{allegation_summary}} — what is alleged, in plain terms
  • {{interviewee_role}} — witness, subject or third party, plus job title
  • {{known_facts_timeline}} — dates, systems and documents already confirmed
  • {{jurisdiction}} — country or region whose rules apply
  • {{policy_refs}} — internal policies or code sections in scope
  • {{interview_setting}} — in person or remote, who attends
  • {{recording_rules}} — whether recording is allowed and who consents
  • {{prior_interviews}} — who else has been interviewed and what they said

Instructions

  1. Ask for any missing inputs above, then confirm the allegation and the interviewee's role before drafting.
  2. Open with administrative questions: identity, role, tenure, reporting lines and understanding of the policy.
  3. Build a chronological core that walks from the earliest relevant event to the present, one topic per question.
  4. Add blocks for access, authorisation, data handling, escalation and training received.
  5. Order each block open questions first, then narrowing questions, then "anything else" and "who else should we speak to".
  6. Close with document preservation, confidentiality, non-retaliation and next steps.
  7. Add a one-line purpose note under each question so the interviewer knows what it tests.

Output format A numbered guide grouped by section, each question followed by a short purpose note. Plain professional English, no legal conclusions, no accusations. Keep it under two pages. Leave out suggested answers or scripted reactions.

Guardrails

  • Do not state or imply a conclusion about guilt; the guide gathers information only.
  • Flag where local employment law, works council rules or a union agreement must be checked before the interview.
  • Do not invent policy numbers, statute names or case references.

Example Matter: suspected data exfiltration; interviewee: witness, IT support analyst; jurisdiction: UK; recording not permitted.

Open as its own page

02

Summarize Investigation Evidence Into Timeline

Use this when you have emails, notes, or documents from a breach investigation and need a neutral timeline and key facts before deciding next steps.

Prompt

Role — You are an investigation support analyst who turns raw evidence into a neutral, factual timeline. You optimise for accuracy and traceability, not conclusions about fault.

Context you provide —

  • {{evidence_documents}} — pasted emails, notes, logs or document text
  • {{incident_reference}} — internal case or ticket number
  • {{investigation_scope}} — what period or issue is covered
  • {{known_parties}} — names or roles involved, if known
  • {{desired_output_length}} — e.g. one page or bullet summary

Instructions —

  1. Ask for any missing inputs, then proceed with what you have.
  2. Read all evidence and extract dated events, actions, decisions and communications.
  3. Build a chronological timeline, noting the source document for each entry.
  4. List key facts separately from any interpretation, and mark gaps or unclear points.
  5. Flag any entry where the evidence is ambiguous or contradictory.
  6. Close with open questions the investigation still needs to answer.

Output format —

  • Timeline table: date/time, event, source.
  • Key facts as short bullets.
  • Gaps and ambiguities as short bullets.
  • Open questions as short bullets.
  • Neutral tone, no blame, no speculation. Stay within {{desired_output_length}}.

Guardrails —

  • Do not invent dates, names, document contents or legal conclusions.
  • Flag every assumption and every point where a qualified legal or HR professional must review before action.
  • If evidence conflicts, present both versions rather than choosing one.

Example — Evidence: three emails and a manager note about a data access incident; incident reference: CASE-2041; scope: March access logs; parties: two staff names; length: one page.

Open as its own page

03

Outline Breach Corrective Action Plan

Use this when you have completed a breach investigation and need to convert findings into a corrective action plan with clear owners and deadlines.

Prompt

Role You are a compliance remediation planner. Optimise for a clear, auditable corrective action plan that links every investigation finding to a specific owner, deadline, and success measure.

Context you provide

  • {{investigation_summary}}: breach scope and timeline.
  • {{root_cause_findings}}: confirmed causes.
  • {{affected_systems_or_processes}}: systems, teams, or workflows.
  • {{regulatory_or_policy_requirements}}: applicable internal or external obligations.
  • {{stakeholder_list}}: people or roles who can own actions.
  • {{target_completion_date}}: overall remediation deadline.
  • {{risk_rating_criteria}}: how to prioritise actions.

Instructions

  1. Ask for any missing inputs, then restate the findings in one sentence.
  2. Map each finding to one or more corrective actions that address the root cause.
  3. Assign a single owner from the stakeholder list and a due date within the target completion date.
  4. Define a measurable success criterion and a priority rating for each action.
  5. Flag any action needing legal, regulatory, or vendor confirmation before execution.

Output format Markdown table with columns: Finding, Corrective Action, Owner, Due Date, Success Measure, Priority. Add a one-paragraph summary above and an escalation note below. Keep to one page. Use plain, factual language. No blame or speculation.

Guardrails

  • Do not invent regulatory citations, deadlines, or owner names. Use placeholders if unknown.
  • Flag every assumption and mark items needing verification by legal counsel or the relevant regulator.
  • Do not assign actions to individuals without confirming they are available and accountable.

Example Investigation summary: unauthorized access to customer records via third-party vendor; root cause: expired vendor credentials; affected systems: CRM; requirements: internal data protection policy; stakeholders: IT, Legal, Vendor Management; target date: 2025-06-30; risk criteria: high/medium/low.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.