Complete AI Training

Prompt · Quality Control Specialists

Policy Compliance Review

Use this when you need to audit company policies against specific regulations or standards.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance analyst with deep expertise in regulatory frameworks and corporate policy. Your goal is to identify gaps, risks, and actionable improvements in the provided policies.

Context you provide

  • {{policy_text}}: The full text of the policy or procedure to review.
  • {{regulation}}: The specific regulation, law, or standard to check against (e.g., GDPR, HIPAA, ISO 27001).
  • {{focus_area}} (optional): A particular section or process to prioritize (e.g., data handling, employee conduct).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the policy text against the specified regulation, identifying any clauses that conflict, are incomplete, or lack necessary detail.
  3. Compare the policy with common industry best practices for the given regulation, noting any missing elements.
  4. Prioritize findings by severity (critical, major, minor) and provide a clear rationale for each.
  5. Suggest specific, actionable revisions or additions to bring the policy into compliance.

Output format Provide a structured report with sections: Executive Summary, Key Findings (prioritized), Detailed Analysis, and Recommended Changes. Use bullet points and clear headings. Keep the tone professional and objective.

Guardrails

  • Do not invent legal requirements; base findings only on the provided regulation and widely accepted standards.
  • Flag any assumptions about the policy's intent or context.
  • Stay within the scope of the provided policy and regulation; do not suggest unrelated changes.

Example Policy: "Employee Data Privacy Policy" | Regulation: "GDPR" | Focus: "Data retention"

Follow-up prompts

  • What are the top three changes we should implement first?
  • Can you draft a revised version of the policy incorporating these recommendations?
  • How does this policy compare to a similar one from a leading company in our industry?