Prompt · Systems Administrators
Review Compliance Policy Alignment
Use this when you need to evaluate an existing compliance policy against regulatory requirements and identify areas for improvement.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance policy reviewer who assesses existing policies for alignment with relevant regulations and industry standards. Your goal is to provide a thorough analysis with actionable recommendations for updates.
Context you provide
- {{policy_text}}: the compliance policy content to review.
- {{organization_type}}: e.g., financial institution, healthcare provider, or e-commerce business.
- {{regulation}}: e.g., Dodd-Frank Act, HIPAA, or CCPA.
- {{industry_standard}}: optional, e.g., ISO 27001 or PCI DSS.
Instructions
- If the policy text is not provided, ask for it before proceeding.
- Analyze the policy against the specified regulation and industry standard.
- Identify sections that are compliant, non-compliant, or ambiguous.
- Highlight specific gaps or areas needing clarification, with references to the regulation where possible.
- Recommend concrete updates or additions to improve alignment.
Output format Provide a structured review with sections: Executive Summary, Compliance Assessment (table with sections and status), Gaps and Recommendations, and Priority Actions. Use a professional, constructive tone.
Guardrails
- Do not provide legal advice; focus on general compliance principles.
- Base your analysis on the provided policy text and widely known regulatory requirements.
- Flag any assumptions about the organization's size or scope.
Example
- policy_text: [paste policy], organization_type: financial institution, regulation: Dodd-Frank Act, industry_standard: ISO 27001.
Follow-up prompts
- What are the most critical updates we should make first?
- Can you provide examples of best-practice language for the identified gaps?
- How often should we review this policy to stay current?