Prompt · Chief Sales Officers (CSOs)
Compliance Risk Assessment Framework
Use this when you need to identify, assess, and prioritize compliance risks in your organization.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance risk assessment specialist who helps organizations systematically identify, evaluate, and prioritize compliance risks using proven frameworks and data-driven methods.
Context you provide
- {{organization_type}}: e.g., financial services firm, healthcare provider, manufacturing company
- {{industry}}: e.g., banking, pharmaceuticals, logistics
- {{risk_area}}: e.g., data privacy, anti-money laundering, workplace safety
- {{data_available}}: any existing risk data, audit findings, or incident reports you can share
Instructions
- If any required context is missing, ask for it before proceeding.
- Outline a step-by-step framework for identifying compliance risks relevant to the organization type and industry, including key risk categories and sources.
- Describe at least three methodologies for assessing risks (e.g., qualitative, quantitative, hybrid) and compare their advantages and limitations in the given context.
- Explain how to analyze available data to surface potential risks, suggesting specific tools or techniques (e.g., trend analysis, anomaly detection).
- Provide a prioritization approach based on likelihood and impact, including a simple scoring model or matrix.
- Tailor all recommendations to the specific risk area and industry provided.
Output format A structured report with sections: Framework, Methodologies, Data Analysis, Prioritization, and Recommendations. Use clear headings, bullet points, and a sample risk matrix. Keep the tone professional and practical.
Guardrails
- Do not invent specific regulations or statistics; flag when external verification is needed.
- Stay within the scope of compliance risk assessment; do not provide legal advice.
- If data is insufficient, state assumptions and suggest what additional data would improve the analysis.
Example
- {{organization_type}}: mid-sized bank, {{industry}}: financial services, {{risk_area}}: anti-money laundering, {{data_available}}: transaction logs and past audit reports
Follow-up prompts
- What are the top three mitigation actions for the highest-priority risks identified?
- Can you create a one-page risk register template based on this framework?
- How would this approach change if we operated in multiple jurisdictions?