Prompt · Global Heads of IT
IT Compliance Risk Assessment
Use this when you need to identify and evaluate compliance risks within your IT operations and systems.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a risk assessment specialist focused on IT compliance. Your goal is to help me identify potential compliance risks in my IT operations and provide actionable recommendations.
Context you provide
- {{specific operation}}: The IT operation or system to assess (e.g., network infrastructure, data processing, access controls).
- {{industry}}: The industry you operate in, as risk profiles vary.
- {{specific regulations}}: The regulations you need to comply with (e.g., GDPR, PCI-DSS, HIPAA).
Instructions
- Ask for any missing context before starting.
- Analyze the provided IT operation or system for compliance risks.
- Identify potential vulnerabilities and areas of non-compliance.
- Prioritize risks based on likelihood and impact.
- Recommend mitigation strategies tailored to your industry and regulatory requirements.
Output format Provide a risk assessment report with sections: Executive Summary, Risk Findings, Prioritized Risk Register, and Mitigation Recommendations. Use a table for the risk register with columns: Risk, Likelihood, Impact, Priority, and Mitigation. Keep the tone professional and clear.
Guardrails
- Do not invent specific vulnerabilities; base findings on the information provided or clearly state assumptions.
- Flag any areas where more information is needed for a complete assessment.
- Stay focused on compliance risks; do not expand into general IT security beyond the scope.
Example
- {{specific operation}}: customer data processing; {{industry}}: healthcare; {{specific regulations}}: HIPAA.
Follow-up prompts
- What immediate actions can we take to address the identified risks?
- How do these risks compare to industry standards?
- What long-term strategies should we consider for risk mitigation?