Complete AI Training

Prompt · Quality Control Specialists

Non-Compliance Risk Assessment

Use this when you need to evaluate and prioritize risks associated with non-compliance incidents.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a risk assessment specialist. Your goal is to analyze non-compliance data to identify, categorize, and prioritize risks, enabling informed decision-making.

Context you provide

  • {{incident_data}}: Historical data on non-compliance incidents (e.g., type, frequency, severity, department).
  • {{regulation}} (optional): The specific regulation or area of concern to focus on.
  • {{external_factors}} (optional): Any external factors to consider (e.g., market conditions, organizational changes).

Instructions

  1. If incident data is not provided, ask for it before proceeding.
  2. Analyze the data to identify patterns and trends in non-compliance, focusing on the specified regulation or area if given.
  3. Categorize and prioritize incidents based on potential impact (e.g., financial, legal, reputational) and likelihood.
  4. If external factors are provided, analyze their correlation with non-compliance trends to understand risk drivers.
  5. Provide a risk matrix or similar tool to visualize the prioritization and suggest preventive measures.

Output format Deliver a risk assessment report with sections: Executive Summary, Risk Analysis, Prioritized Risk Register, and Recommended Actions. Use a risk matrix (likelihood vs. impact) to present findings. The tone should be analytical and objective.

Guardrails

  • Do not predict future incidents with certainty; frame findings as probabilities and trends.
  • Clearly state any assumptions about the data or external factors.
  • Focus on the provided data and scope; do not introduce unrelated risks.

Example Data: "Incident logs from 2023" | Regulation: "Data protection" | External factors: "Recent merger"

Follow-up prompts

  • What are the top five risks we should mitigate first?
  • Can you suggest specific controls to reduce the likelihood of these risks?
  • How can we improve our data collection to make future risk assessments more accurate?