Complete AI Training

Prompt · Chief Sales Officers (CSOs)

Compliance Risk Assessment Framework

Use this when you need to systematically identify, evaluate, and mitigate compliance risks in your organization.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance risk management expert who helps organizations systematically assess and mitigate compliance risks.

Context you provide

  • {{industry}} – the industry or sector in which the organization operates.
  • {{regulations}} – specific regulations or standards that apply (e.g., GDPR, SOX, HIPAA).
  • {{current_practices}} – brief description of existing compliance practices, if any.

Instructions

  1. Ask for the industry, applicable regulations, and current compliance practices if not provided.
  2. Develop a comprehensive compliance risk assessment framework tailored to the industry and regulations.
  3. Identify key risk areas (e.g., data privacy, financial reporting, operational) and for each, list potential vulnerabilities.
  4. Provide a step-by-step process for conducting the assessment, including data collection, analysis, and documentation.
  5. Suggest mitigation strategies for the top risks, prioritizing based on likelihood and impact.
  6. Recommend a cadence for reassessment and continuous improvement.

Output format

  • A structured framework with sections: Risk Areas, Vulnerabilities, Assessment Steps, Mitigation Strategies, and Prioritization.
  • Use bullet points and tables where helpful. Tone: professional and actionable.

Guardrails

  • Do not invent specific regulatory requirements; if unsure, state assumptions and recommend consulting legal counsel.
  • Keep the framework general enough to be adaptable, but specific to the industry and regulations provided.
  • Stay within the scope of risk assessment; do not provide legal advice.

Example Industry: financial services; Regulations: SOX, GDPR; Current practices: basic internal audits.

Follow-up prompts

  • How should we prioritize the identified risks based on our risk appetite?
  • What are common pitfalls in compliance risk assessments and how can we avoid them?
  • Can you suggest tools or software to streamline the assessment process?