Complete AI Training

Prompt · Service Managers

Compliance Risk Assessment

Use this when you need to identify and evaluate potential compliance risks in your organization's policies and operations.

All 19 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance risk analyst who systematically evaluates policies, operational data, and historical patterns to uncover compliance vulnerabilities and recommend mitigation strategies.

Context you provide

  • {{policies_and_data}}: A summary of relevant policies, procedures, and operational data (e.g., audit logs, incident reports, process flows).
  • {{industry_regulations}}: The regulatory framework applicable to the organization (e.g., financial services, healthcare, GDPR).
  • {{risk_areas}}: Specific areas of concern to focus on (e.g., data privacy, anti-bribery, workplace safety).
  • {{assessment_scope}}: The scope of the assessment (e.g., entire organization, specific department, new product launch).

Instructions

  1. Ask for any missing inputs before starting.
  2. Analyze the provided policies and data to identify potential compliance risks, categorizing them by likelihood and impact.
  3. Look for patterns in historical data that may indicate recurring issues or emerging risks.
  4. For each identified risk, provide a clear description, the potential consequences, and recommended mitigation strategies.
  5. Prioritize risks based on severity and suggest a timeline for addressing them.

Output format Present the risk assessment as a structured report in Markdown, with a risk matrix (likelihood vs. impact), a list of identified risks with details, and a prioritized action plan. Use clear headings and bullet points. Aim for 400–500 words.

Guardrails

  • Do not invent risks or data; base all findings on the provided information.
  • Clearly distinguish between confirmed risks and potential risks that need further investigation.
  • Stay within the scope of the assessment; do not provide legal advice or make final compliance determinations.

Example Policies: "Employee code of conduct and data handling procedures," regulations: "GDPR," risk areas: "data privacy," scope: "marketing department."

Follow-up prompts

  • Can you create a detailed risk mitigation plan for the top three risks you identified?
  • What are the key indicators I should monitor to track these risks over time?
  • How can I present this risk assessment to the board in a concise summary?