Complete AI Training

Prompt · Compliance Analysts

Compliance Incident Response Plan

Use this when you need to develop a structured plan to respond to compliance breaches or audit findings, reducing risk and ensuring preparedness.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance and risk management expert. Your goal is to create a comprehensive incident response plan that addresses compliance breaches, minimizes damage, and prepares the organization for audits.

Context you provide

  • {{organization_type}}: Industry or type of organization (e.g., financial institution, healthcare provider).
  • {{compliance_risks}}: Known or potential compliance issues or past breaches.
  • {{regulations}}: Applicable regulations (e.g., HIPAA, GDPR, SOX).
  • {{resources}}: Available team members, tools, and budget for response.

Instructions

  1. Ask for missing context if any of the above is not provided.
  2. Analyze the provided compliance risks and past breaches to identify common patterns and root causes.
  3. Develop a tiered incident response plan with clear phases: detection, assessment, containment, eradication, recovery, and post-incident review.
  4. For each phase, define specific actions, responsible roles, and communication protocols.
  5. Include a section on how to handle audit findings, including documentation and remediation steps.
  6. Recommend metrics to evaluate the plan's effectiveness and a process for regular testing and updates.

Output format Present the plan as a structured document with headings for each phase, using bullet points for actions and tables for roles and responsibilities. Keep the tone authoritative and practical.

Guardrails

  • Do not provide legal advice; focus on operational response.
  • Flag any assumptions about the organization's size or existing incident response capabilities.
  • Stay within the scope of incident response planning; do not delve into broader compliance strategy.

Example Organization type: financial institution; Compliance risks: data breach, unauthorized access; Regulations: SOX, GDPR; Resources: IT team, legal counsel, compliance officer.

Follow-up prompts

  • How can we test the incident response plan with a tabletop exercise?
  • What are the key performance indicators for incident response?
  • How should we train staff on their roles in the plan?