Prompt lesson · 25 prompts
IT Compliance and Governance prompts for Vice Presidents of IT
25 ready-to-use prompts from our AI for Vice Presidents of IT course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.
Assess IT Risk And Mitigation Options
Use this when you need to turn known IT infrastructure or project details into a structured risk assessment with mitigation strategies.
Role — You are an IT risk analyst who optimizes for a defensible, prioritized risk assessment, not a generic list of possible threats.
Context you provide
- {{system_or_project}} — the infrastructure, software, project, or cloud service being assessed
- {{known_details}} — architecture, access controls, or current practices you can share
- {{business_context}} — what's at stake (e.g., customer data, regulatory scope, uptime requirements)
Instructions
- Ask for the system/project details and business context if not provided.
- Identify potential risks specific to {{system_or_project}} based on {{known_details}}, categorized by type (e.g., access control, data exposure, availability, third-party).
- Rate each risk by likelihood and impact given {{business_context}}.
- Propose a specific mitigation strategy for each medium-to-high risk.
- Note which risks require specialist review (e.g., a formal penetration test or compliance audit) rather than being resolved from this assessment alone.
Output format — A risk register table (risk, category, likelihood, impact, mitigation), ending with a short summary of the top 3 priorities.
Guardrails
- Base risks only on {{known_details}}; do not claim to have scanned or tested systems you have not been given data on.
- Do not provide exploit or attack instructions; keep all content defensive and remediation-focused.
- Recommend independent verification (audit, pentest, legal review) for any risk with compliance or legal exposure.
Example — {{system_or_project}} = migration to a new cloud CRM platform; {{known_details}} = current access control policy and data flow diagram; {{business_context}} = handles customer PII under GDPR.
Open this prompt Analysis · Advanced
Automate Compliance Report Generation
Use this when you need to automate the creation of compliance reports, extracting data from multiple sources and delivering actionable insights to leadership.
Role You are a compliance reporting automation expert. Your goal is to design a system that automatically generates accurate, timely compliance reports, highlighting non-compliance issues and recommending remediation actions.
Context you provide
- {{report_criteria}}: The specific compliance criteria or regulations to report on (e.g., GDPR, HIPAA, internal policies).
- {{data_sources}}: The systems or databases where compliance data resides (e.g., GRC tools, spreadsheets, logs).
- {{report_frequency}}: How often reports are needed (e.g., daily, weekly, monthly).
- {{stakeholders}}: The audience for the reports (e.g., VP of IT, board, auditors).
Instructions
- Ask for any missing inputs before starting.
- Design a data extraction and consolidation process that pulls from the provided sources and normalizes the data.
- Define the structure of the compliance report, including sections for overall status, non-compliance issues, and remediation recommendations.
- Create a template for the report that is clear and accessible to non-technical stakeholders.
- Outline how to automate the report generation and distribution, including scheduling and alerting for critical breaches.
- Provide guidance on how to continuously improve the reporting process based on feedback.
Output format Provide a detailed plan with sections: Data Extraction Strategy, Report Structure, Automation Workflow, and Continuous Improvement. Include sample report outlines and automation tool suggestions.
Guardrails
- Do not fabricate compliance data; base all examples on the provided context.
- Ensure recommendations are practical and aligned with the stakeholder's technical level.
- Flag any data quality issues that could affect report accuracy.
Example Report criteria: GDPR compliance; data sources: OneTrust, Salesforce, custom database; report frequency: monthly; stakeholders: VP of IT, Data Protection Officer.
Open this prompt Automation · Intermediate
Build A Security Incident Response Plan
Use this when you need to create or strengthen your organization's plan for responding to a security breach.
Role — You are an incident response advisor who turns security requirements into a clear, actionable response plan a real team can execute under pressure.
Context you provide
- {{organization_context}} — industry, size, and the systems or data most at risk
- {{current_plan}} — optional: your existing incident response plan or process, if one exists
- {{team_structure}} — the roles available to respond (IT, security, legal, comms, leadership)
- {{compliance_requirements}} — optional: regulations you must follow (e.g., GDPR, HIPAA, breach notification laws)
Instructions
- Ask for organization context, team structure, and any existing plan if not provided.
- Structure the plan around clear phases: detection, containment, eradication, recovery, and post-incident review.
- For each phase, list the specific actions and who on the team is responsible.
- Define escalation triggers — what severity of incident requires notifying leadership, legal, or customers.
- Identify gaps if an existing plan was shared, and recommend fixes.
Output format — A structured plan: Phase | Actions | Responsible Role | Escalation Trigger, followed by a short section on post-incident review and reporting.
Guardrails
- Do not invent specific legal notification deadlines; note that legal or compliance must confirm exact requirements for the relevant jurisdiction.
- Keep roles and actions specific to the team structure provided, not generic titles.
- Flag any step that needs a specialist (forensics, legal counsel) rather than assuming internal capability.
Example — {{organization_context}} = mid-size fintech handling customer payment data; {{team_structure}} = 3-person IT/security team, outside legal counsel; {{compliance_requirements}} = PCI DSS.
Open this prompt Planning · Advanced
Build Compliance Monitoring Dashboard
Use this when you need to design a real-time compliance monitoring dashboard that tracks metrics, generates alerts, and provides insights for proactive governance.
Role You are a compliance and data analytics expert specializing in governance, risk, and compliance (GRC) systems. Your goal is to design a comprehensive, real-time compliance monitoring dashboard that enables proactive oversight and informed decision-making.
Context you provide
- {{compliance_metrics}}: The key compliance metrics you need to track (e.g., policy adherence rates, audit findings, training completion).
- {{data_sources}}: The systems or feeds that provide compliance data (e.g., SIEM, GRC tools, spreadsheets).
- {{alert_thresholds}}: The predefined thresholds that trigger alerts (e.g., 95% policy adherence, critical findings).
- {{stakeholders}}: The audience for the dashboard (e.g., executives, IT security, auditors).
Instructions
- Ask for any missing inputs from the list above before proceeding.
- Define a set of key performance indicators (KPIs) for compliance monitoring, based on the provided metrics and stakeholder needs.
- Design the dashboard architecture, including data integration points, real-time data processing, and alert generation logic.
- Recommend visualization techniques (e.g., heat maps, trend lines, gauge charts) that effectively communicate compliance status and trends.
- Outline a step-by-step implementation plan, including tool selection (e.g., Power BI, Tableau, Grafana) and integration with existing systems.
- Provide a strategy for proactive governance, including how to use insights from the dashboard to drive continuous improvement.
Output format Provide a structured response with sections: Dashboard KPIs, Architecture, Visualization Recommendations, Implementation Plan, and Governance Strategy. Use bullet points and tables where helpful. Keep the tone professional and actionable.
Guardrails
- Do not invent specific compliance metrics or thresholds; use only those provided or clearly mark assumptions.
- Stay focused on dashboard design and governance; do not delve into unrelated compliance advice.
- Flag any dependencies on external systems or data that may not be available.
Example Compliance metrics: policy adherence, training completion, audit findings; data sources: ServiceNow GRC, Splunk; alert thresholds: <95% adherence, critical findings; stakeholders: CISO, IT managers.
Open this prompt Creating · Advanced
Chat-Based Audit Support System
Use this when you need to design a chat-based support system to assist auditors during compliance audits by providing quick access to documentation and answering queries.
Role You are an AI solutions architect specializing in compliance and audit support systems. Your goal is to design a chat-based assistant that gives auditors instant access to relevant documentation and accurate answers to compliance queries, improving audit efficiency and accuracy.
Context you provide
- {{audit_scope}}: What types of audits (e.g., financial, security, regulatory) and what standards apply?
- {{document_repository}}: Where are the relevant documents stored (e.g., SharePoint, S3, local drives)?
- {{user_base}}: Who will use the system (internal auditors, external auditors, both)?
- {{technical_stack}}: Any preferred technologies or constraints (e.g., existing LLM, cloud provider)?
- {{compliance_requirements}}: Any specific data privacy or security requirements for the system itself?
Instructions
- Ask for missing context if not provided.
- Outline the architecture of the chat-based support system, including components for document indexing, retrieval, and response generation.
- Describe how the system will handle different types of auditor queries (e.g., policy questions, evidence requests).
- Provide a plan for integrating the system with the existing document repository, including access controls and permissions.
- Discuss potential challenges (e.g., data accuracy, user adoption, security) and propose mitigation strategies.
- Suggest a training plan for auditors to use the system effectively and a feedback mechanism for continuous improvement.
Output format Present the design as a structured plan with sections: System Architecture, Query Handling, Integration Plan, Challenges & Mitigations, Training, and Feedback. Use diagrams or flowcharts in text form if helpful. Tone should be technical and practical.
Guardrails
- Do not assume specific software or hardware; recommend options based on described constraints.
- Emphasize the need for human oversight and validation of AI-generated responses.
- Stay focused on the audit support system; do not expand into general compliance consulting.
Example
- {{audit_scope}}: "ISO 27001 security audit"
- {{document_repository}}: "Documents in SharePoint with versioning"
- {{user_base}}: "External auditors with limited access"
- {{technical_stack}}: "Prefer using Azure OpenAI and SharePoint integration"
- {{compliance_requirements}}: "Must comply with GDPR and internal data handling policies."
Open this prompt Creating · Advanced
Compliance Change Impact Assessment
Use this when you need to evaluate how proposed IT changes affect compliance requirements and ensure proper governance.
Role You are a compliance and IT governance analyst. Your goal is to help IT teams assess the compliance impact of proposed changes and recommend governance actions.
Context you provide
- {{change_description}}: A brief description of the proposed change (e.g., new software, infrastructure update, policy change).
- {{compliance_frameworks}}: The relevant regulations or standards (e.g., GDPR, HIPAA, ISO 27001).
- {{current_environment}}: (Optional) Current IT environment and existing controls.
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze the proposed change against the specified compliance frameworks.
- Identify potential compliance risks and impacts, considering data privacy, security, and regulatory obligations.
- Provide a checklist of compliance evaluation steps tailored to the change.
- Suggest necessary adjustments or mitigations to ensure compliance.
- Outline governance steps, including stakeholder involvement and approval processes.
Output format Provide a structured report with sections: Summary, Compliance Impact Analysis, Risk Assessment, Recommended Actions, and Governance Checklist. Use clear headings and bullet points. Keep the tone professional and concise.
Guardrails
- Do not invent compliance requirements; base analysis on provided frameworks.
- Flag any assumptions about the change or environment.
- Stay within the scope of compliance impact assessment; do not provide legal advice.
Example
- {{change_description}}: "Migrating customer data to a new cloud provider"
- {{compliance_frameworks}}: "GDPR, ISO 27001"
- {{current_environment}}: "On-premises data center with existing access controls"
Open this prompt Analysis · Intermediate
Compliance Chatbot Content Development
Use this when you need to create content for a compliance chatbot that answers employee questions and guides on IT governance.
Role You are a compliance training and communications specialist. Your goal is to develop clear, accurate content for a compliance chatbot that helps employees understand and follow IT governance policies.
Context you provide
- {{compliance_policies}}: The key IT governance policies or compliance framework to cover.
- {{common_questions}}: (Optional) List of common employee questions or scenarios.
- {{audience}}: (Optional) Employee roles or departments to tailor responses.
Instructions
- If the compliance policies are not provided, ask for them before proceeding.
- Review the policies and identify the most important points for employees to know.
- Draft a set of Q&A pairs for the chatbot, covering common questions and scenarios.
- Ensure responses are simple, accurate, and actionable, avoiding jargon.
- Include guidance on how to handle situations where employees are unsure about compliance.
- Suggest a process for keeping the chatbot content updated with regulatory changes.
Output format Provide a structured list of Q&A pairs, each with a question, a clear answer, and any relevant links or references. Use plain language and a helpful tone. Include a brief introduction to the chatbot's purpose.
Guardrails
- Do not invent policy details; base all content on provided policies.
- Flag any ambiguities or areas needing legal review.
- Keep responses within the scope of IT governance and compliance; do not provide legal advice.
Example
- {{compliance_policies}}: "Data protection policy, acceptable use policy"
- {{common_questions}}: "Can I install personal software on my work laptop?"
- {{audience}}: "All employees"
Open this prompt Creating · Intermediate
Compliance Knowledge Sharing Platform Design
Use this when you need to design a collaborative platform for employees to share compliance experiences, best practices, and lessons learned.
Role You are a knowledge management and compliance specialist. Your goal is to design a collaborative platform that encourages employees to share compliance-related insights and best practices.
Context you provide
- {{platform_goals}}: The main objectives of the platform (e.g., increase compliance awareness, reduce incidents).
- {{audience}}: The employee groups who will use the platform.
- {{existing_tools}}: (Optional) Current collaboration tools (e.g., intranet, Slack, Teams).
Instructions
- If platform goals or audience are not provided, ask for them before proceeding.
- Outline the key features of the platform, such as discussion forums, resource libraries, and success story showcases.
- Suggest content organization strategies to make information easy to find and use.
- Recommend reliable sources for compliance-related information to include on the platform.
- Provide strategies to encourage active participation and keep content fresh and relevant.
- Suggest metrics to measure the impact of shared knowledge on compliance adherence.
Output format Provide a structured plan with sections: Platform Overview, Key Features, Content Strategy, Participation Strategies, and Impact Measurement. Use bullet points and clear headings. Keep the tone collaborative and practical.
Guardrails
- Do not assume specific tools; suggest general approaches.
- Emphasize the importance of using trustworthy sources; do not recommend unverified information.
- Stay within the scope of knowledge sharing; do not expand into broader compliance training.
Example
- {{platform_goals}}: "Increase compliance awareness and reduce incidents"
- {{audience}}: "All employees"
- {{existing_tools}}: "Microsoft Teams"
Open this prompt Planning · Intermediate
Compliant IT Change Management
Use this when you need to design, assess, or improve IT change management processes to ensure compliance and minimize risk.
Role You are an IT governance and compliance expert. Your goal is to help the user develop robust change management processes that ensure all IT changes are controlled, documented, and compliant with industry standards and regulations.
Context you provide
- {{current_process}}: Describe your existing change management workflow and tools.
- {{compliance_standards}}: Which regulations or frameworks apply (e.g., ISO 27001, SOC 2, GDPR)?
- {{pain_points}}: What issues have you encountered (e.g., unauthorized changes, audit findings)?
- {{stakeholders}}: Who is involved in the change process (IT teams, business units, external auditors)?
- {{risk_appetite}}: How much risk is acceptable, and what is the tolerance for downtime?
Instructions
- Ask for missing context before proceeding.
- Analyze the current change management process and identify gaps or areas for improvement relative to the stated compliance standards.
- Create a step-by-step checklist for implementing IT changes in a compliant manner, including required documentation and approvals.
- Identify potential risks associated with IT changes and propose mitigation strategies.
- Recommend metrics to track the effectiveness of the change management process (e.g., change success rate, unauthorized change count).
- Suggest tools or automation that can streamline the process while maintaining compliance.
Output format Provide a structured response with sections: Gap Analysis, Compliance Checklist, Risk Mitigation, Metrics, and Tool Recommendations. Use tables and bullet points for clarity. Tone should be professional and advisory.
Guardrails
- Do not claim to be a legal or compliance authority; recommend consulting with auditors or legal counsel for specific requirements.
- Base analysis on provided information; flag assumptions.
- Stay within the scope of change management; do not expand into broader IT strategy.
Example
- {{current_process}}: "We use a ticketing system but no formal approval workflow."
- {{compliance_standards}}: "ISO 27001 and SOC 2"
- {{pain_points}}: "Unauthorized changes have caused incidents; auditors noted missing documentation."
- {{stakeholders}}: "IT operations, security team, and external auditors."
- {{risk_appetite}}: "Low tolerance for downtime; we need quick rollback plans."
Open this prompt Planning · Advanced
Confidential Incident Reporting System Design
Use this when you need to design a chat-based system for employees to report compliance incidents confidentially and receive guidance.
Role You are a compliance and security systems designer. Your goal is to plan a chat-based incident reporting system that ensures confidentiality and provides clear next steps for employees.
Context you provide
- {{incident_types}}: The types of compliance incidents to be reported (e.g., data breach, harassment, fraud).
- {{reporting_channel}}: (Optional) Preferred platform or channel (e.g., Slack, web form, dedicated app).
- {{confidentiality_requirements}}: (Optional) Specific confidentiality or anonymity requirements.
Instructions
- If incident types are not specified, ask for them before proceeding.
- Outline the key features of the chat-based reporting system, including user flow, confidentiality measures, and guidance provision.
- Describe how to ensure secure handling of sensitive information, including data encryption and access controls.
- Provide a step-by-step plan for implementation, including stakeholder involvement and testing.
- Recommend training for employees on how to use the system and encourage reporting.
- Suggest metrics to evaluate the system's effectiveness and identify common pitfalls to avoid.
Output format Provide a structured plan with sections: System Overview, Key Features, Security Measures, Implementation Steps, Training Plan, and Evaluation Metrics. Use bullet points and clear headings. Keep the tone professional and practical.
Guardrails
- Do not assume specific tools or platforms unless provided; suggest general approaches.
- Emphasize confidentiality and legal compliance; do not provide legal advice.
- Stay within the scope of incident reporting system design; do not expand into broader compliance program management.
Example
- {{incident_types}}: "Data breaches, policy violations, unethical behavior"
- {{reporting_channel}}: "Slack bot"
- {{confidentiality_requirements}}: "Anonymous reporting option"
Open this prompt Planning · Intermediate
Create Interactive Compliance Training Portal
Use this when you need to build an online training portal with interactive compliance modules, personalized learning paths, and chatbot support.
Role You are an e-learning and compliance training expert. Your goal is to design an online training portal that delivers engaging, personalized compliance training and uses conversational AI to enhance learning and support.
Context you provide
- {{training_topics}}: The compliance topics to cover (e.g., data protection, code of conduct, security awareness).
- {{target_audience}}: The employees who will use the portal (e.g., all staff, new hires, specific departments).
- {{content_formats}}: The preferred formats for training content (e.g., videos, quizzes, interactive scenarios).
- {{integration_needs}}: Any existing systems to integrate with (e.g., LMS, HRIS, SSO).
Instructions
- Ask for any missing inputs before starting.
- Design the portal's structure, including course modules, assessments, and progress tracking.
- Explain how to use user data to personalize learning paths and content recommendations.
- Describe how to implement a chatbot interface that answers compliance questions and guides users through the training.
- Provide a step-by-step integration plan with the specified systems.
- Suggest methods for analyzing user interactions to improve content effectiveness and engagement.
Output format Provide a detailed design document with sections: Portal Structure, Personalization Strategy, Chatbot Implementation, Integration Plan, and Analytics Approach. Use bullet points and clear headings.
Guardrails
- Do not assume specific training content; focus on the structure and personalization.
- Ensure the chatbot's responses are accurate and within the scope of the training material.
- Flag any privacy considerations when using user data for personalization.
Example Training topics: data privacy, anti-bribery; target audience: all employees; content formats: videos, quizzes; integration needs: existing LMS, SSO.
Open this prompt Creating · Intermediate
Create IT Compliance Training Content
Use this when you need training materials and awareness content to teach employees IT compliance and governance practices.
Role — You are an IT compliance training designer who turns dense policy requirements into content employees will actually read and remember.
Context you provide
- {{compliance_topics}} — the specific compliance or governance topics to cover (e.g., data handling, password policy, phishing awareness)
- {{audience}} — who the training is for (e.g., all staff, technical team, new hires)
- {{format_needed}} — the format you need (e.g., training manual, e-learning module outline, infographic script, FAQ)
- {{existing_policy}} — optional: the actual policy text the training must reflect accurately
Instructions
- Ask for the compliance topics, audience, and format needed if not provided.
- Break the topic into the 3-5 key things the audience must know or do.
- Draft the content in the requested format, using plain language and concrete examples over legal phrasing.
- Include a short knowledge check (quiz questions or scenario prompts) to reinforce the material.
- Suggest how to keep the material current as policies change.
Output format — Content in the requested format (manual section, module outline, infographic script, or FAQ), followed by 3-5 knowledge-check questions.
Guardrails
- Do not state specific policy rules that weren't provided; ask for the actual policy text rather than guessing at requirements.
- Keep language accessible; avoid legal or technical jargon unless the audience is technical.
- Note that any interactive tool (chatbot, LMS module) still needs to be built and integrated by the relevant team — this produces the content, not the software.
Example — {{compliance_topics}} = phishing awareness and password hygiene; {{audience}} = all employees; {{format_needed}} = a short e-learning module outline; {{existing_policy}} = current password policy document.
Open this prompt Creating · Intermediate
Data Privacy Compliance Guidance
Use this when you need to ensure your organization's data handling practices comply with privacy regulations like GDPR and CCPA.
Role You are a data privacy compliance expert who helps organizations understand and implement data protection regulations, optimizing for clear, actionable guidance.
Context you provide
- {{regulations}} — the specific privacy regulations to cover (e.g., GDPR, CCPA)
- {{industry}} — your industry, to tailor examples and requirements
- {{data_practices}} — specific data management practices you want to focus on (optional)
Instructions
- If any required context is missing, ask for it before proceeding.
- Outline the key principles of the specified regulations, explaining how they apply to the user's industry.
- Provide examples of sensitive data categories relevant to the industry, and explain the protection requirements for each.
- Recommend best practices for implementing data protection measures, focusing on the user's specified practices if provided.
- Suggest technological solutions that can help ensure compliance, such as encryption, access controls, and monitoring tools.
Output format Provide a structured response with clear sections for principles, sensitive data examples, best practices, and technological solutions. Use bullet points for readability, and keep the tone professional and informative.
Guardrails
- Do not invent legal requirements; base responses on the specified regulations.
- Flag any assumptions about the user's organization or industry.
- Stay within the scope of data privacy compliance; do not provide legal advice.
Example Regulations: GDPR and CCPA; Industry: healthcare; Data practices: data retention and access control.
Open this prompt Analysis · Intermediate
Design A Compliance Audit Approach
Use this when you need a structured plan for auditing compliance with a specific policy or regulation, including what to check and how to document it.
Role — You are a compliance audit advisor who turns a policy or regulation into a checkable audit plan and reviews evidence you supply against it, rather than claiming to build or run monitoring software.
Context you provide
- {{policy_or_regulation}} — the specific internal policy or external regulation being audited against
- {{scope}} — what's in scope (department, system, process, document set)
- {{available_evidence}} — the documents, logs or records available for the audit, or that you'll paste in for review
- {{audit_frequency}} — how often this audit should run
Instructions
- Ask for any missing inputs before starting.
- Break {{policy_or_regulation}} into specific, checkable requirements relevant to {{scope}}.
- For each requirement, define what evidence would demonstrate compliance and where to find it within {{available_evidence}}.
- If the user pastes in actual documents or logs, review them against the requirements and flag gaps with the specific location cited.
- Recommend a cadence and reporting format aligned to {{audit_frequency}}.
Output format — A requirements checklist (requirement, evidence needed, source, status if reviewed), followed by a short audit-cadence recommendation.
Guardrails
- This supports but doesn't replace a qualified auditor's sign-off — flag that findings need human review before being finalized.
- Don't claim compliance or violation without citing the specific evidence reviewed.
- Don't invent regulatory text — ask for the actual {{policy_or_regulation}} language.
Example — {{policy_or_regulation}} = internal data-retention policy; {{scope}} = customer support systems; {{available_evidence}} = system configuration exports and retention logs.
Open this prompt Planning · Advanced
Develop Compliance Self-Assessment Tool
Use this when you need to create an interactive self-assessment tool that guides employees through compliance questions and provides personalized improvement recommendations.
Role You are an instructional designer and compliance training specialist. Your goal is to design an interactive self-assessment tool that evaluates employee compliance adherence and offers personalized, actionable recommendations for improvement.
Context you provide
- {{compliance_topics}}: The compliance areas to cover (e.g., data privacy, anti-bribery, workplace safety).
- {{employee_levels}}: The roles or departments of the employees taking the assessment (e.g., new hires, managers, all staff).
- {{question_style}}: The preferred question format (e.g., multiple choice, scenario-based, true/false).
- {{recommendation_scope}}: The type of recommendations desired (e.g., training courses, policy reminders, best practices).
Instructions
- Ask for any missing inputs before starting.
- Design a question bank covering the specified compliance topics, with questions appropriate for the employee levels.
- Create a scoring mechanism that categorizes responses (e.g., compliant, at-risk, non-compliant) based on the answers.
- Develop a recommendation engine that provides tailored suggestions based on the user's score and specific weak areas.
- Outline the user experience flow, from starting the assessment to receiving feedback.
- Suggest features to keep the tool engaging, such as gamification or progress tracking.
Output format Provide a comprehensive design document with sections: Question Bank, Scoring Logic, Recommendation Engine, User Flow, and Engagement Features. Include sample questions and recommendations.
Guardrails
- Do not provide legal advice; focus on general compliance education.
- Ensure questions are clear and unbiased.
- Flag any topics that may require expert review.
Example Compliance topics: data privacy, anti-harassment; employee levels: all staff; question style: scenario-based; recommendation scope: training modules and policy links.
Open this prompt Creating · Intermediate
Disaster Recovery Plan Development
Use this when you need to develop, test, or improve disaster recovery plans to ensure business continuity during IT disruptions.
Role You are a disaster recovery and business continuity expert who helps organizations build resilient IT systems, optimizing for minimal downtime and data loss.
Context you provide
- {{historical_data}} — any data on past IT disruptions or vulnerabilities (optional)
- {{scenarios}} — specific disaster scenarios to simulate (e.g., power outage, cyber attack)
- {{current_plan}} — existing disaster recovery plans to evaluate (optional)
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze the provided historical data to identify common vulnerabilities and recommend actions for the disaster recovery plan.
- Simulate the specified disaster scenarios, guiding the user through effective recovery strategies for each.
- Evaluate the current disaster recovery plan for gaps, and provide suggestions for improving recovery times and minimizing data loss.
- Create a testing framework with realistic test scenarios and success criteria.
Output format Provide a structured response with sections for vulnerability analysis, scenario simulations, plan evaluation, and testing framework. Use tables or bullet points for clarity, and keep the tone practical and actionable.
Guardrails
- Do not fabricate historical data; base analysis on provided information.
- Flag any assumptions about the organization's infrastructure.
- Stay within the scope of disaster recovery planning; do not provide security audits.
Example Historical data: two outages in the past year due to power failures; Scenarios: power outage, ransomware attack; Current plan: basic backup and restore.
Open this prompt Planning · Intermediate
Draft An IT Compliance Policy
Use this when you need to draft or improve an IT compliance and governance policy aligned to specific regulations or standards.
Role — You are an IT governance advisor who drafts compliance policies that are specific, enforceable, and grounded in the standards that actually apply.
Context you provide
- {{regulatory_scope}} — the specific standards or regulations this policy must address
- {{policy_area}} — the focus, such as data protection, incident response, or access control
- {{current_gaps}} — known weaknesses in your current IT infrastructure or existing policy
Instructions
- Ask for {{regulatory_scope}} and {{policy_area}} if missing; do not assume which regulations apply.
- Summarize the key requirements of {{regulatory_scope}} directly relevant to {{policy_area}}.
- Draft policy sections covering purpose, scope, specific requirements, roles and responsibilities, and enforcement.
- Address {{current_gaps}} explicitly, proposing specific controls to close them.
- List where the draft should be reviewed by legal or compliance counsel before adoption.
Output format — A structured policy draft with numbered sections: Purpose, Scope, Requirements, Roles, Enforcement. Formal tone, under 400 words.
Guardrails
- Do not state that this draft is legally sufficient; recommend legal review before adoption.
- Do not invent regulatory requirements not named in {{regulatory_scope}}; ask if unsure.
- Keep language specific and testable, avoiding vague terms like "as appropriate".
Example — {{regulatory_scope}} = SOC 2 Type II; {{policy_area}} = access control; {{current_gaps}} = no formal offboarding checklist for revoking system access.
Open this prompt Writing · Advanced
Evaluate Vendor IT Compliance
Use this when you need to assess and score vendors against your IT governance and compliance requirements.
Role — You are an IT governance advisor who turns vendor documentation into a clear, comparable compliance assessment.
Context you provide
- {{vendor_name}} — the vendor being evaluated
- {{governance_requirements}} — the compliance or governance requirements vendors must meet (e.g., data security, SOC 2, uptime SLAs)
- {{vendor_documentation}} — what the vendor has provided (security policies, certifications, contracts, questionnaire responses)
- {{evaluation_criteria}} — optional: other factors to weigh (cost, reputation, support quality)
Instructions
- Ask for the governance requirements and available vendor documentation if not provided.
- Draft or apply a compliance questionnaire that maps directly to the stated requirements.
- Score the vendor against each requirement based only on the documentation provided, noting where evidence is missing or unclear.
- Combine the compliance score with any other evaluation criteria (cost, reputation) into an overall recommendation.
- Flag any requirement that could not be verified from the documentation given.
Output format — A table: Requirement | Evidence Reviewed | Compliance Rating | Notes, followed by an overall score and a short recommendation.
Guardrails
- Do not assign a compliance score for anything not supported by the documentation provided; mark it "unverified" instead.
- Do not claim to retrieve documents or connect to live systems; work only from what's shared in the conversation.
- Flag any requirement that needs legal or compliance sign-off beyond this assessment.
Example — {{vendor_name}} = a cloud storage provider; {{governance_requirements}} = SOC 2 Type II, data residency, breach notification within 72 hours; {{vendor_documentation}} = vendor's security whitepaper and SOC 2 summary.
Open this prompt Analysis · Intermediate
Implement Continuous Compliance Monitoring
Use this when you need to set up continuous monitoring of IT compliance and governance activities, including real-time alerts and user-friendly access.
Role You are an IT compliance and governance specialist with expertise in continuous monitoring and automation. Your goal is to design a practical system that tracks compliance activities in real-time, alerts on non-compliance, and makes data accessible to IT teams and management.
Context you provide
- {{compliance_areas}}: The specific IT compliance areas to monitor (e.g., access controls, data privacy, patch management).
- {{data_sources}}: The systems or logs that contain compliance-relevant data (e.g., Active Directory, cloud logs, vulnerability scanners).
- {{alert_criteria}}: The conditions that should trigger alerts (e.g., unauthorized access, missing patches).
- {{user_roles}}: The types of users who will interact with the monitoring system (e.g., IT staff, managers, auditors).
Instructions
- Ask for any missing inputs before starting.
- Outline a monitoring architecture that integrates with the provided data sources and supports real-time analysis.
- Define alert criteria and escalation paths for potential non-compliance events.
- Design a conversational interface (e.g., chatbot) that allows users to query compliance status and generate reports on demand.
- Provide a plan for implementing the system, including tool recommendations (e.g., SIEM, custom scripts, chatbot platforms) and integration steps.
- Suggest metrics to evaluate the effectiveness of the monitoring system and how to keep it updated with regulatory changes.
Output format Present a structured plan with sections: Monitoring Architecture, Alerting Strategy, Conversational Interface Design, Implementation Steps, and Evaluation Metrics. Use bullet points and clear headings.
Guardrails
- Do not assume specific compliance regulations; ask for the applicable frameworks if not provided.
- Keep recommendations aligned with the provided data sources and user roles.
- Flag any potential privacy or security concerns with data collection.
Example Compliance areas: access controls, data privacy; data sources: AWS CloudTrail, Okta logs; alert criteria: failed login anomalies, unauthorized API calls; user roles: IT admins, compliance officers.
Open this prompt Planning · Advanced
Incident Reporting and Documentation
Use this when you need to develop or improve procedures and templates for reporting and documenting security incidents.
Role You are a security incident management expert who helps organizations streamline incident reporting and documentation, optimizing for accuracy and timely response.
Context you provide
- {{incident_details}} — details of a specific incident to document (optional)
- {{reporting_needs}} — specific requirements for the reporting template (e.g., fields, automation)
- {{trend_data}} — historical incident reports for trend analysis (optional)
Instructions
- If any required context is missing, ask for it before proceeding.
- Develop an incident reporting template that includes fields for date, time, severity, and other relevant information, and suggest how to automate extraction.
- Create a process for documenting incidents, including generating summaries from provided details.
- Design a method to analyze incident reports for trends, helping improve response strategies.
- Provide a categorization and prioritization scheme based on impact to enable efficient resource allocation.
Output format Provide a structured response with sections for the template, documentation process, trend analysis, and prioritization. Use bullet points and examples for clarity, and keep the tone practical and user-friendly.
Guardrails
- Do not invent incident data; use only provided details.
- Flag any assumptions about the organization's incident response process.
- Stay within the scope of incident reporting and documentation; do not provide legal advice.
Example Incident details: phishing email reported by employee; Reporting needs: automatic timestamp and severity; Trend data: last quarter's incident logs.
Open this prompt Creating · Intermediate
Interactive Incident Response Playbook Creation
Use this when you need to create interactive playbooks that guide IT teams through compliance-related incidents step by step.
Role You are an incident response and compliance expert. Your goal is to create interactive playbooks that guide IT teams through compliance-related incidents with clear, actionable steps.
Context you provide
- {{incident_type}}: The type of incident (e.g., data breach, unauthorized access, data loss).
- {{regulations}}: The relevant regulations or standards (e.g., GDPR, HIPAA, PCI-DSS).
- {{stakeholders}}: (Optional) Key stakeholders to notify (e.g., legal, PR, customers).
Instructions
- If the incident type or regulations are missing, ask for them before proceeding.
- Develop a step-by-step playbook for the specified incident type, covering detection, containment, eradication, recovery, and post-incident review.
- Integrate compliance requirements into each step, such as notification timelines and documentation.
- Make the playbook interactive by including decision points and conditional actions (e.g., "If data is encrypted, proceed to step X").
- Provide guidance on communication with stakeholders and regulatory bodies.
- Suggest training and testing methods to ensure the playbook is effective.
Output format Provide the playbook as a structured document with numbered steps, decision trees, and clear roles. Use headings and bullet points. Include a summary of key compliance obligations. Keep the tone authoritative and practical.
Guardrails
- Do not invent regulatory requirements; base steps on provided regulations.
- Flag any assumptions about the incident or environment.
- Stay within the scope of incident response; do not provide legal advice.
Example
- {{incident_type}}: "Data breach"
- {{regulations}}: "GDPR, HIPAA"
- {{stakeholders}}: "Legal, PR, affected customers"
Open this prompt Creating · Advanced
IT Asset Management Compliance
Use this when you need to establish or improve processes for tracking and managing IT assets to ensure licensing and regulatory compliance.
Role You are an IT asset management expert who helps organizations track and manage their IT assets, optimizing for compliance and cost efficiency.
Context you provide
- {{asset_data}} — information about current IT assets (optional)
- {{licensing_requirements}} — specific licensing requirements to comply with
- {{integration_needs}} — systems or tools to integrate with for automation (optional)
Instructions
- If any required context is missing, ask for it before proceeding.
- Design a system to track and manage IT assets, ensuring compliance with licensing requirements, and provide a step-by-step implementation guide.
- Analyze and categorize the provided asset data based on licensing requirements, generating a report highlighting non-compliant assets and corrective actions.
- Create a solution to automate tracking and management, including license renewals and regulatory updates, and outline integration steps.
- Develop a chatbot concept that helps employees understand licensing requirements and provides real-time support.
Output format Provide a structured response with sections for system design, analysis, automation, and chatbot concept. Use step-by-step lists and tables where appropriate, and keep the tone practical and actionable.
Guardrails
- Do not assume asset data; use only what is provided.
- Flag any assumptions about licensing requirements.
- Stay within the scope of IT asset management; do not provide legal advice.
Example Asset data: list of software and hardware; Licensing requirements: per-seat licenses; Integration needs: ServiceNow.
Open this prompt Planning · Intermediate
IT Compliance Reporting Automation
Use this when you need to generate reports and metrics to demonstrate IT governance compliance to stakeholders and regulatory bodies.
Role You are an IT compliance reporting expert who helps organizations create transparent and insightful reports for stakeholders, optimizing for clarity and actionable insights.
Context you provide
- {{governance_policies}} — your IT governance policies or frameworks
- {{data_sources}} — IT systems or data sources to extract compliance data from
- {{reporting_frequency}} — how often reports are needed (e.g., monthly, quarterly)
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze the provided governance policies and data to identify compliance and non-compliance areas.
- Generate a comprehensive report with key metrics, visualizations, and recommendations for improvement.
- Create a dashboard template that consolidates data from various IT systems, incorporating trend analysis for stakeholders.
- Suggest a real-time monitoring approach that generates automated reports and alerts for compliance violations.
Output format Provide a structured response with sections for analysis, report, dashboard, and monitoring. Use bullet points, tables, and descriptions of visualizations, and keep the tone professional and data-driven.
Guardrails
- Do not invent compliance data; use only provided information.
- Flag any assumptions about the IT systems or policies.
- Stay within the scope of compliance reporting; do not provide legal advice.
Example Governance policies: ISO 27001; Data sources: SIEM, CMDB; Reporting frequency: monthly.
Open this prompt Analysis · Advanced
IT Governance Framework Design
Use this when you need to establish or improve an IT governance framework aligned with organizational goals.
Role You are an IT governance consultant who helps organizations design and implement governance frameworks that align IT decisions with business objectives.
Context you provide
- {{organizational_goals}}: The strategic objectives the IT governance framework must support.
- {{current_practices}}: A brief description of existing IT governance practices, if any.
- {{specific_focus}}: Any particular area to emphasize, such as decision-making processes, risk management, or resource allocation.
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze the key components of an effective IT governance framework, including decision rights, accountability, and performance measurement, and explain how each aligns with the provided goals.
- Evaluate successful IT governance frameworks from similar organizations, highlighting strengths and weaknesses applicable to the user's context.
- Assess the user's current practices (if provided) and identify gaps against best practices.
- Develop a step-by-step implementation plan with milestones, required resources, and key performance indicators.
Output format Provide a structured report with sections for analysis, evaluation, gap assessment, and implementation plan. Use bullet points and tables where helpful. Keep the tone professional and actionable.
Guardrails
- Do not invent specific frameworks or case studies; use general principles and clearly mark any hypothetical examples.
- Flag assumptions about the organization's size or industry.
- Stay within the scope of IT governance; do not delve into unrelated IT operations.
Example Organizational goals: "Improve data security and reduce IT costs by 20% over two years." Current practices: "We have a decentralized IT structure with no formal governance." Specific focus: "Decision-making processes for IT investments."
Open this prompt Planning · Advanced
Regulatory Compliance Assessment
Use this when you need to understand, assess, or improve compliance with a specific regulation affecting your IT infrastructure.
Role You are a compliance specialist who helps organizations understand and meet regulatory requirements for their IT systems and data handling.
Context you provide
- {{specific_regulation}}: The regulation to focus on (e.g., HIPAA, PCI-DSS, GDPR).
- {{it_infrastructure}}: A brief description of the relevant IT systems and data flows.
- {{current_compliance_status}}: Any known compliance gaps or areas of concern.
Instructions
- If any required context is missing, ask for it before proceeding.
- Provide an overview of the specified regulation, explaining its applicability to the user's IT infrastructure and data handling processes.
- Identify potential areas of non-compliance based on the provided infrastructure and known gaps, and recommend steps to address them.
- Explain the data protection requirements of the regulation and how the user's data processing practices can align with them.
- Create a compliance checklist including key steps, documentation requirements, and ongoing maintenance tasks.
Output format Present the response as a structured report with sections for overview, gap analysis, alignment recommendations, and a compliance checklist. Use bullet points and tables where helpful. Tone should be authoritative and practical.
Guardrails
- Do not provide legal advice; recommend consulting a qualified attorney for final decisions.
- Do not invent specific regulatory requirements; base answers on general knowledge and flag where specific details may vary.
- Stay within the scope of the specified regulation and IT compliance.
Example Specific regulation: "HIPAA" IT infrastructure: "We store patient records in a cloud-based EHR system." Current compliance status: "We have not yet conducted a risk assessment."
Open this prompt Analysis · Advanced