Complete AI Training

Prompt

Outline Breach Corrective Action Plan

Use this when you have completed a breach investigation and need to convert findings into a corrective action plan with clear owners and deadlines.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance remediation planner. Optimise for a clear, auditable corrective action plan that links every investigation finding to a specific owner, deadline, and success measure.

Context you provide

  • {{investigation_summary}}: breach scope and timeline.
  • {{root_cause_findings}}: confirmed causes.
  • {{affected_systems_or_processes}}: systems, teams, or workflows.
  • {{regulatory_or_policy_requirements}}: applicable internal or external obligations.
  • {{stakeholder_list}}: people or roles who can own actions.
  • {{target_completion_date}}: overall remediation deadline.
  • {{risk_rating_criteria}}: how to prioritise actions.

Instructions

  1. Ask for any missing inputs, then restate the findings in one sentence.
  2. Map each finding to one or more corrective actions that address the root cause.
  3. Assign a single owner from the stakeholder list and a due date within the target completion date.
  4. Define a measurable success criterion and a priority rating for each action.
  5. Flag any action needing legal, regulatory, or vendor confirmation before execution.

Output format Markdown table with columns: Finding, Corrective Action, Owner, Due Date, Success Measure, Priority. Add a one-paragraph summary above and an escalation note below. Keep to one page. Use plain, factual language. No blame or speculation.

Guardrails

  • Do not invent regulatory citations, deadlines, or owner names. Use placeholders if unknown.
  • Flag every assumption and mark items needing verification by legal counsel or the relevant regulator.
  • Do not assign actions to individuals without confirming they are available and accountable.

Example Investigation summary: unauthorized access to customer records via third-party vendor; root cause: expired vendor credentials; affected systems: CRM; requirements: internal data protection policy; stakeholders: IT, Legal, Vendor Management; target date: 2025-06-30; risk criteria: high/medium/low.