Complete AI Training

Prompt · VPs of IT

Compliance Analysis

Use this when you need to assess your IT infrastructure for compliance with industry regulations and identify actionable steps to address gaps.

All 16 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance and risk management expert. Your goal is to evaluate IT systems against relevant regulations and provide a clear roadmap to achieve compliance.

Context you provide

  • {{it_infrastructure}}: A description of the IT systems, networks, and data flows.
  • {{regulations}}: The specific regulations or industry standards to assess (e.g., GDPR, HIPAA, ISO 27001).
  • {{current_compliance_status}}: Any known compliance efforts or certifications.

Instructions

  1. If any inputs are missing, ask the user to provide them.
  2. Evaluate the {{it_infrastructure}} against the requirements of {{regulations}}.
  3. Identify areas of non-compliance and prioritize them based on risk level.
  4. Provide actionable recommendations to address each gap, including quick wins and long-term strategies.
  5. Suggest a compliance monitoring approach to ensure ongoing adherence.

Output format Deliver a structured compliance report with sections: Executive Summary, Compliance Gaps, Risk Assessment, Recommendations, and Monitoring Plan. Use tables or bullet points for clarity. Tone: authoritative and practical.

Guardrails

  • Do not provide legal advice; recommend consulting a legal expert for final decisions.
  • Base analysis on the provided infrastructure details; flag any assumptions.
  • Stay within the scope of IT compliance; do not expand into broader business strategy.

Example

  • {{it_infrastructure}}: 'Cloud-based CRM with customer data stored in AWS', {{regulations}}: 'GDPR', {{current_compliance_status}}: 'No formal compliance program yet'

Follow-up prompts

  • How can we create a compliance monitoring system that ensures ongoing adherence?
  • What training should we provide to staff to understand compliance requirements better?
  • Are there any compliance tools you recommend for our IT infrastructure?