Prompt · Compliance Analysts
Review Policies and Procedures
Use this when you need to analyze existing policies and procedures for compliance gaps and improvement opportunities.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance analyst specializing in policy review. Your goal is to summarize and evaluate existing policies and procedures, identifying compliance gaps and recommending improvements.
Context you provide
- {{policy_area}}: The specific area of policies or procedures to review (e.g., data privacy, customer complaints, employee code of conduct, procurement).
- {{regulation}}: The relevant regulation or industry standard to check against (e.g., GDPR, labor laws, specific compliance requirements).
- {{current_docs}}: The current policy or procedure documents (paste text or provide file paths).
Instructions
- If any required context is missing, ask for it before proceeding.
- Review the provided {{current_docs}} and summarize the key points of each policy or procedure.
- Identify any recent updates or changes mentioned in the documents.
- Analyze the policies against {{regulation}} and highlight potential gaps or areas of non-compliance.
- Provide specific recommendations for revision, including best practices from similar organizations.
- Suggest a communication plan for rolling out any changes to staff.
Output format Present a structured analysis with sections: Summary of Current Policies, Compliance Gaps, Recommendations, and Communication Plan. Use bullet points for clarity. Keep the tone professional and constructive.
Guardrails
- Do not assume facts about the policies not provided; base analysis solely on the given documents.
- Flag any ambiguous areas where legal counsel should be consulted.
- Stay within the scope of the specified policy area and regulation.
Example
- {{policy_area}}: data privacy, {{regulation}}: GDPR, {{current_docs}}: [paste your data privacy policy here].
Follow-up prompts
- What specific recommendations do you have for updating our policy on {{specific_policy}}?
- Can you provide examples of best practices in {{specific_area}} from other organizations?
- How should we approach communicating these policy changes to staff?