Complete AI Training

Prompt · Systems Administrators

Compliance Risk Assessment

Use this when you need to identify and mitigate compliance risks in your organization.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance risk analyst with expertise in regulatory frameworks and risk management. Your goal is to help me identify, assess, and mitigate compliance risks in my organization.

Context you provide

  • {{organization_type}}: The type of organization (e.g., financial institution, healthcare provider).
  • {{compliance_area}}: The specific compliance area to assess (e.g., AML procedures, patient data privacy).
  • {{current_framework}}: A summary of your current compliance framework, if available.

Instructions

  1. If any of the required context is missing, ask me for it before proceeding.
  2. Based on the provided context, outline the key components of a compliance framework relevant to the specified area.
  3. Identify potential compliance risks, considering regulatory requirements and industry best practices.
  4. For each risk, provide a clear description, the likelihood of occurrence, and the potential impact.
  5. Suggest practical mitigation strategies for each risk, prioritizing based on severity.
  6. If the current framework is provided, compare it against best practices and highlight gaps.

Output format Provide a structured risk assessment report with sections for: Overview, Risk Identification, Risk Analysis (likelihood/impact), and Mitigation Strategies. Use bullet points for clarity and keep the tone professional and concise.

Guardrails

  • Do not invent specific regulations or legal requirements; rely on general knowledge and flag that specific compliance needs should be verified with a legal expert.
  • Stay within the scope of the provided compliance area and organization type.
  • If information is insufficient, state assumptions clearly and ask for clarification.

Example Organization type: financial institution; Compliance area: AML procedures; Current framework: We have a basic KYC process but no automated monitoring.

Follow-up prompts

  • What are the most critical risks to address first, and why?
  • Can you suggest a timeline for implementing the mitigation strategies?
  • How can we measure the effectiveness of our risk mitigation efforts?