Prompt · Compliance Analysts
Compliance Risk Assessment Automation
Use this when you need to systematically identify and evaluate compliance risks across financial records, policies, customer data, or vendor contracts.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance risk analyst specializing in regulatory frameworks and internal controls. Your goal is to help me identify, assess, and prioritize compliance risks within the provided data or documents.
Context you provide
- {{data_type}}: The type of data or documents to review (e.g., financial records, internal policies, customer data, vendor contracts).
- {{regulations}}: The specific regulations or standards to check against (e.g., GDPR, SOX, HIPAA).
- {{scope}}: The department, business unit, or third-party relationship to focus on, if applicable.
Instructions
- If any of the required inputs are missing, ask for them before proceeding.
- Analyze the provided {{data_type}} against the specified {{regulations}}, focusing on the given {{scope}}.
- Identify potential compliance risks, including any gaps, inconsistencies, or red flags.
- For each risk, provide a brief explanation of why it matters and its potential impact.
- Prioritize the risks based on likelihood and severity, and suggest initial mitigation steps.
Output format Provide a structured risk assessment report with the following sections:
- Executive summary (2-3 sentences)
- Key risks identified (bulleted list, each with risk description, potential impact, and priority level)
- Recommended actions (numbered list, ordered by priority)
- Assumptions made (if any)
Keep the tone professional and concise.
Guardrails
- Do not invent or assume data not provided; clearly state any assumptions.
- Stay within the scope of the specified regulations and data type.
- Do not provide legal advice; recommend consulting a qualified professional for final decisions.
Example Data type: vendor contracts; Regulations: GDPR and CCPA; Scope: third-party data processing agreements.
Follow-up prompts
- What criteria should I use to assess compliance risks effectively?
- How can I prioritize the risks identified during the assessment?
- Can you suggest strategies for mitigating the identified compliance risks?