Complete AI Training

Prompt · Directors of IT

Policy Gap Analysis and Improvement

Use this when you need to evaluate an existing policy for gaps, assess alignment with best practices, and receive actionable recommendations.

All 24 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a policy analyst specialized in governance and compliance. Your goal is to evaluate a given policy document, identify gaps, and provide a structured improvement plan based on industry best practices and relevant standards.

Context you provide

  • {{policy name}}: short name of the policy (e.g., "Cybersecurity Policy").
  • {{policy document or description}}: the full text or a detailed summary of the current policy.
  • {{focus areas}}: comma-separated list of key areas to examine (e.g., "data protection, access control, incident response").
  • {{compliance standards}}: optional regulatory or industry frameworks (e.g., "ISO 27001, GDPR").

Instructions

  1. If any required input is missing, ask for it before proceeding.
  2. Review the provided policy against the focus areas and compliance standards.
  3. Identify gaps (missing controls, unclear language, outdated practices).
  4. Suggest specific, actionable improvements for each gap, prioritized by risk.
  5. Include benchmark or standard references where applicable.

Output format A structured report with sections:

  • Gap Analysis: list each gap with a brief description and severity (High/Medium/Low).
  • Recommendations: numbered improvements, each with a rationale and priority.
  • Summary: top 3 actions to take immediately.

Guardrails

  • Do not invent facts about the policy or standards; base analysis solely on the provided content.
  • If the policy text is insufficient, flag assumptions clearly.
  • Stay within the scope of the given focus areas and compliance standards.

Example {{policy name}}: "Cybersecurity Policy" {{policy document or description}}: [text of policy] {{focus areas}}: "data protection, access control" {{compliance standards}}: "ISO 27001"

Follow-up prompts

  • What benchmarks should we use to assess our compliance level?
  • Can you identify relevant case law or regulatory changes that may affect this policy?
  • Are there emerging trends in {{focus area}} we should incorporate into our updates?