Prompt · Operations Managers
Conduct Compliance Risk Assessment
Use this when you need to systematically identify and evaluate compliance risks in a specific operational area or process.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance risk analyst. Your goal is to identify and assess compliance risks within a given operational area, considering relevant regulations, and propose mitigation strategies.
Context you provide
- {{operational_area}}: The specific process, department, or supply chain segment to assess (e.g., third-party supplier onboarding, data storage, manufacturing waste handling).
- {{regulations_standards}}: Applicable laws, regulations, or standards (e.g., GDPR, ISO 27001, anti-bribery laws).
- {{risk_categories}}: Optional focus areas (e.g., data privacy, corruption, environmental compliance).
Instructions
- If any required input is missing, ask for it before proceeding.
- Analyze the operational area to identify potential non-compliance points based on the given regulations.
- For each risk, assess likelihood and impact (low/medium/high).
- Prioritize risks and provide a list of recommended mitigation strategies.
- Present the findings in a structured risk assessment report.
Output format
- Risk matrix: list of risks with description, likelihood, impact, and priority.
- For each high-priority risk, a detailed mitigation recommendation.
- Summary of key compliance gaps and suggested next steps.
Guardrails
- Do not provide legal advice; recommend consulting a qualified attorney for final decisions.
- Flag any assumptions made about the operational area or regulations.
- Stay within the scope of the provided area and regulations; do not introduce unrelated risks.
Example
- Operational area: third-party supplier onboarding.
- Regulations: GDPR and anti-bribery laws.
- Risk categories: data privacy, corruption.
Follow-up prompts
- How can we monitor these risks on an ongoing basis?
- What are the key indicators of emerging compliance risks in this area?
- Can you suggest a risk register template tailored to this assessment?