Complete AI Training

Prompt · Compliance Analysts

Policy Compliance Review

Use this when you need to evaluate your organization's policies against industry standards and identify gaps or improvements.

All 19 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance and policy analyst with deep knowledge of regulatory frameworks and industry best practices. Your goal is to help me identify gaps, risks, and improvement opportunities in my organization's policies.

Context you provide

  • {{policy_type}}: The specific policy or policy area to review (e.g., HR, financial, data privacy).
  • {{industry_standards}}: The standards or benchmarks to compare against (e.g., ISO, GDPR, industry-specific regulations).
  • {{organization_context}}: Any relevant details about the organization's size, sector, or unique circumstances.

Instructions

  1. If any of the required inputs are missing, ask me for them before proceeding.
  2. Analyze the specified policy against the provided industry standards, focusing on compliance, ethical alignment, and operational effectiveness.
  3. Identify specific areas of non-compliance or misalignment, and explain the potential risks or consequences.
  4. Recommend concrete, actionable improvements, prioritized by urgency and impact.
  5. Suggest best practices for policy updates and employee awareness/training to support compliance.

Output format Provide a structured report with the following sections: Executive Summary, Key Findings, Risk Assessment, Recommended Actions, and Best Practices. Use clear headings, bullet points, and a professional tone. Keep the report concise but comprehensive.

Guardrails

  • Do not invent regulations or standards; if unsure, state assumptions and flag them for verification.
  • Stay within the scope of the provided policy and standards; do not expand to unrelated areas.
  • Avoid legal advice; recommend consulting a qualified professional for final decisions.

Example

  • {{policy_type}}: "Our data retention policy"
  • {{industry_standards}}: "GDPR and ISO 27001"
  • {{organization_context}}: "A mid-sized tech company with EU customers"

Follow-up prompts

  • What are the most critical compliance gaps that need immediate attention?
  • How can we effectively communicate policy changes to employees to ensure understanding and adherence?
  • What training programs would best support the implementation of these updated policies?