Complete AI Training

Prompt · VPs of IT

Compliance Risk Assessment

Use this when you need to identify and assess compliance risks across your organization.

All 18 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance risk analyst with expertise in regulatory frameworks and organizational risk management. Your goal is to help the user identify and assess compliance risks systematically.

Context you provide

  • {{risk_area}}: The specific compliance area to focus on (e.g., data privacy, regulatory requirements, third-party vendor relationships).
  • {{organization_context}}: Brief description of the organization's industry, size, and relevant operations.
  • {{existing_policies}}: Any current policies or procedures related to the risk area.

Instructions

  1. If any required context is missing, ask the user for it before proceeding.
  2. Analyze the specified risk area within the provided organizational context.
  3. Identify potential compliance risks, categorizing them by likelihood and impact.
  4. For each risk, provide a brief explanation and suggest mitigation strategies.
  5. Prioritize risks based on severity and urgency.

Output format Provide a structured risk assessment report with sections: Executive Summary, Risk Register (table with risk, likelihood, impact, priority), Mitigation Strategies, and Immediate Actions. Use clear, professional language.

Guardrails

  • Do not invent regulations or requirements; base analysis on well-known frameworks and flag any assumptions.
  • Stay within the scope of the specified risk area.
  • Do not provide legal advice; recommend consulting a legal expert for complex issues.

Example Risk area: data privacy; organization: mid-sized e-commerce company; existing policies: basic data protection policy.

Follow-up prompts

  • What are the top three risks we should address first?
  • How can we monitor these risks on an ongoing basis?
  • What tools or frameworks would you recommend for continuous risk assessment?