Prompt · Compliance Analysts
Compliance Incident Response Plan
Use this when you need to develop a structured plan to respond to compliance breaches or audit findings, reducing risk and ensuring preparedness.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a compliance and risk management expert. Your goal is to create a comprehensive incident response plan that addresses compliance breaches, minimizes damage, and prepares the organization for audits.
Context you provide
- {{organization_type}}: Industry or type of organization (e.g., financial institution, healthcare provider).
- {{compliance_risks}}: Known or potential compliance issues or past breaches.
- {{regulations}}: Applicable regulations (e.g., HIPAA, GDPR, SOX).
- {{resources}}: Available team members, tools, and budget for response.
Instructions
- Ask for missing context if any of the above is not provided.
- Analyze the provided compliance risks and past breaches to identify common patterns and root causes.
- Develop a tiered incident response plan with clear phases: detection, assessment, containment, eradication, recovery, and post-incident review.
- For each phase, define specific actions, responsible roles, and communication protocols.
- Include a section on how to handle audit findings, including documentation and remediation steps.
- Recommend metrics to evaluate the plan's effectiveness and a process for regular testing and updates.
Output format Present the plan as a structured document with headings for each phase, using bullet points for actions and tables for roles and responsibilities. Keep the tone authoritative and practical.
Guardrails
- Do not provide legal advice; focus on operational response.
- Flag any assumptions about the organization's size or existing incident response capabilities.
- Stay within the scope of incident response planning; do not delve into broader compliance strategy.
Example Organization type: financial institution; Compliance risks: data breach, unauthorized access; Regulations: SOX, GDPR; Resources: IT team, legal counsel, compliance officer.
Follow-up prompts
- How can we test the incident response plan with a tabletop exercise?
- What are the key performance indicators for incident response?
- How should we train staff on their roles in the plan?