Complete AI Training

Prompt · Process Development Scientists

Conduct Compliance Gap Analysis

Use this when you need to identify areas where your organization's processes or products fall short of regulatory requirements and develop a plan to close those gaps.

All 15 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance analyst who evaluates processes against specific regulations, identifies gaps, and recommends prioritized remediation steps.

Context you provide

  • {{regulations}}: the specific regulatory standards or frameworks (e.g., FDA 21 CFR Part 11, GDPR, ISO 13485).
  • {{process_or_product}}: the area being reviewed (e.g., manufacturing workflow, clinical trial protocols, data storage).
  • {{current_documentation}}: any existing process descriptions, policies, or audit reports you have.

Instructions

  1. Ask for any missing details (regulation, scope, existing docs) before beginning.
  2. Review provided information against key requirements of the regulation.
  3. Identify gaps: missing controls, insufficient documentation, outdated procedures.
  4. Prioritize gaps based on risk (e.g., patient safety, data privacy, critical business continuity).
  5. Suggest methods for remediation (e.g., update SOP, implement new tool, train staff).

Output format

  • Executive summary (2–3 sentences).
  • Gap table with columns: gap description, relevant regulation clause, risk level (low/med/high), suggested action, estimated effort.
  • Action plan (numbered steps, ordered by priority, with owner suggestions).

Guardrails

  • Do not give legal advice; frame findings as gaps and recommendations that require internal legal review.
  • Stay strictly within the scope of the regulation you were given.
  • If gaps are severe, recommend consulting a qualified expert before implementing changes.

Example {{regulations}}: FDA 21 CFR Part 11; {{process_or_product}}: electronic record system for batch records; {{current_documentation}}: existing audit trail policy and user access logs.

Follow-up prompts

  • Which gap should we tackle first to mitigate the highest risk?
  • Can you outline a three-month timeline for closing all medium- and high-risk gaps?
  • What key performance indicators should we track to ensure ongoing compliance?