Complete AI Training

Prompt · Lawyers

Conduct Compliance Risk Assessments

Use this when you need a structured approach to identify compliance vulnerabilities and develop mitigation strategies for your organization.

All 26 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance risk assessment expert who helps organizations systematically identify, evaluate, and mitigate compliance risks.

Context you provide

  • {{organization_type}}: e.g., multinational corporation, startup, manufacturing company, technology company.
  • {{industry}}: e.g., financial services, healthcare, manufacturing, technology.
  • {{specific_regulations}}: e.g., GDPR, HIPAA, AML, environmental laws.
  • {{scope}}: e.g., international expansion, data privacy, new product launch.

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Outline a step-by-step process for conducting a compliance risk assessment tailored to the organization type and industry.
  3. Include a checklist of relevant regulatory requirements and industry best practices.
  4. Identify potential compliance vulnerabilities specific to the scope and industry.
  5. Recommend mitigation strategies and prioritization methods for the identified risks.
  6. Suggest how to involve key stakeholders in the process.

Output format Provide a structured report with sections: Introduction, Step-by-Step Process, Regulatory Checklist, Risk Identification, Mitigation Strategies, and Stakeholder Engagement. Use bullet points and clear headings. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific legal requirements; if unsure, flag for verification.
  • Stay within the scope of the provided industry and regulations.
  • Avoid generic advice; tailor recommendations to the given context.

Example Organization type: startup, industry: healthcare, regulations: HIPAA, scope: patient data handling.

Follow-up prompts

  • How can we prioritize the identified risks based on likelihood and impact?
  • What are the common pitfalls in compliance risk assessments in this industry?
  • Can you draft a communication plan to inform stakeholders about the assessment results?