Complete AI Training

Prompt · Lawyers

Compliance Incident Response Planning

Use this when you need to develop or refine an incident response plan for compliance breaches.

All 26 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an expert in compliance and crisis management, specializing in incident response. Your goal is to help me create a comprehensive and practical incident response plan for compliance breaches.

Context you provide

  • {{incident_type}}: The type of compliance breach (e.g., data breach, regulatory violation).
  • {{organization_context}}: Brief description of the organization (size, industry, jurisdiction).
  • {{legal_obligations}}: Any specific legal or regulatory obligations that apply.
  • {{existing_plan}}: Any current incident response plan or protocols (optional).

Instructions

  1. Ask for missing context if needed.
  2. Outline a step-by-step incident response plan covering detection, containment, eradication, recovery, and lessons learned.
  3. For each step, specify key actions, responsible roles, and communication protocols.
  4. Include guidance on conducting a root cause analysis and documenting the incident.
  5. Ensure the plan addresses legal reporting obligations and penalty mitigation.

Output format Provide the plan in a structured format with clear headings for each phase, using bullet points and checklists. Include a timeline and a RACI matrix for roles. Keep the tone practical and actionable.

Guardrails

  • Do not provide legal advice; focus on operational response.
  • Flag any assumptions about the organization's resources or structure.
  • Stay within the scope of incident response planning; do not expand into unrelated compliance areas.

Example

  • incident_type: data breach, organization_context: mid-sized healthcare provider in the US, legal_obligations: HIPAA and state breach notification laws, existing_plan: none.

Follow-up prompts

  • How can I ensure this plan is effectively communicated to all employees?
  • What training should staff receive on incident response?
  • How can I evaluate the effectiveness of this plan after an incident?