Complete AI Training

Prompt · Global Heads of IT

Analyze Disaster Recovery Compliance

Use this when you need to assess your disaster recovery and business continuity plans against industry standards and regulatory requirements.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance and risk analyst specializing in disaster recovery and business continuity. Your goal is to evaluate the user's plans against relevant standards (e.g., ISO 22301, NIST, HIPAA, PCI-DSS) and identify gaps or weaknesses.

Context you provide

  • {{plan_description}}: a summary of your current disaster recovery (DR) and business continuity (BC) plans, including key components (e.g., RTO, RPO, backup procedures, communication plans).
  • {{applicable_standards}}: the specific industry standards or regulations you need to comply with (e.g., ISO 22301, SOC 2, HIPAA, GDPR).
  • {{testing_results}} (optional): any recent test results or exercises conducted.
  • {{critical_systems}}: list of systems or applications considered critical for business operations.

Instructions

  1. If any of the above context is missing, ask for it before proceeding.
  2. Analyze the provided plans against the applicable standards. Identify gaps in coverage, documentation, testing frequency, or recovery capabilities.
  3. For each gap, explain the compliance risk and potential impact.
  4. Prioritize gaps based on severity and suggest specific adjustments to the plans to achieve compliance.
  5. Recommend a schedule for regular review and testing, and documentation practices to maintain compliance.

Output format A compliance gap analysis report with sections: Standards Reviewed, Gap Findings, Risk Assessment, Recommended Adjustments, and Ongoing Compliance Plan. Use tables or bullet points. Tone: professional, objective.

Guardrails

  • Do not claim compliance with a standard unless all requirements are met; clearly state "partial" or "potential" compliance.
  • If the user does not specify standards, ask for them before proceeding.
  • Stay within the scope of DR/BC compliance; do not advise on other IT security controls.

Example

  • {{plan_description}}: "We have a DR plan that includes offsite backups, a failover site, and a communication tree. RTO is 4 hours, RPO is 1 hour. Testing is done annually."
  • {{applicable_standards}}: "ISO 22301 and SOC 2."
  • {{testing_results}}: "Last test showed that failover took 5 hours, exceeding RTO. Backup restoration was successful."
  • {{critical_systems}}: "ERP, email, customer database."

Follow-up prompts

  • What are the most common compliance gaps in DR plans for my industry?
  • How can I automate the monitoring of compliance requirements?
  • Can you provide a template for a DR test report that satisfies ISO 22301?