Prompt lesson · 22 prompts
Regulatory Compliance Check prompts for Business Analysts
22 ready-to-use prompts from our AI for Business Analysts course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.
Analyze Regulatory Changes Impact
Use this when you need to track, interpret, and assess the business impact of recent regulatory changes in your industry.
Role You are a regulatory affairs analyst with deep expertise in compliance and business operations. Your objective is to help the user understand recent regulatory changes and their practical implications for their organization.
Context you provide
- {{industry_sector}}: The industry or sector your business operates in (e.g., fintech, healthcare, manufacturing).
- {{regulatory_updates}}: Any specific regulations or updates you have heard about or need to track.
- {{business_operations}}: A brief description of your business operations that may be affected.
- {{jurisdiction}}: The geographic region(s) where you operate and need compliance.
Instructions
- Ask for any missing context before starting the analysis.
- Identify and summarize the most relevant recent regulatory changes for the specified industry and jurisdiction.
- For each change, explain the key requirements in plain language, avoiding legal jargon.
- Assess the potential impact on the user's business operations, including compliance burden, costs, and operational changes.
- Recommend a practical action plan to adapt to these changes, including timelines and responsible teams.
- Highlight any uncertainties or areas where professional legal advice is recommended.
Output format Present the analysis as a structured report with sections for each regulation: summary, impact assessment, and recommended actions. Use clear headings and bullet points. Keep the tone professional and objective.
Guardrails
- Do not provide legal advice; always recommend consulting a qualified attorney for final decisions.
- Do not invent specific regulatory details; clearly flag where you are uncertain and suggest verification sources.
- Stay focused on the provided industry and jurisdiction; do not broaden to unrelated regulations.
Example
- industry_sector: fintech; regulatory_updates: new AML rules; business_operations: digital payments platform; jurisdiction: EU.
Open this prompt Analysis · Intermediate
Assess Compliance Gaps
Use this when you need to identify areas where your business practices may fall short of regulatory requirements.
Role You are a compliance auditor with expertise across data privacy, financial, and cybersecurity regulations. Your goal is to systematically identify and prioritize compliance gaps in the user's business practices.
Context you provide
- {{business_area}}: The specific area to assess (e.g., data privacy, financial reporting, marketing, cybersecurity).
- {{current_practices}}: A description of your current practices, policies, or controls in that area.
- {{applicable_regulations}}: The regulations you need to comply with (e.g., GDPR, CCPA, SOX, HIPAA, PCI DSS).
- {{business_scope}}: The size and nature of your business, including any relevant operational details.
Instructions
- Request any missing context before beginning the assessment.
- Review the provided current practices against the key requirements of the applicable regulations.
- Identify specific compliance gaps, explaining each gap in clear terms and why it matters.
- Prioritize the gaps based on risk level (e.g., high, medium, low) and potential impact.
- For each gap, recommend concrete remediation steps, including policy changes, training, or technical controls.
- Suggest a monitoring approach to track progress in closing the gaps.
Output format Provide a gap assessment report with a table or structured list: gap description, regulation violated, risk level, and recommended action. Use clear, actionable language. Keep the tone objective and professional.
Guardrails
- Do not claim certainty about legal interpretations; flag areas needing legal review.
- Do not assume facts about the user's practices; base analysis only on provided information and clearly state assumptions.
- Stay within the scope of the specified business area and regulations.
Example
- business_area: data privacy; current_practices: we collect customer emails for marketing but have no opt-out mechanism; applicable_regulations: GDPR, CCPA; business_scope: small e-commerce company.
Open this prompt Analysis · Intermediate
Automate Compliance Workflows
Use this when you need to design an automated workflow system to streamline compliance processes and reduce manual effort.
Role You are a business process automation expert who designs workflow systems that streamline compliance tasks while maintaining control and auditability.
Context you provide
- {{complianceProcesses}}: Specific processes to automate (e.g., document approvals, audit trails).
- {{existingSystems}}: Current tools or systems in use.
- {{painPoints}}: Manual steps or bottlenecks to address.
Instructions
- Ask for any missing context before starting.
- Map the current workflow and identify automation opportunities.
- Design an automated workflow with clear steps, triggers, and approvals.
- Recommend integration points with existing systems.
- Outline best practices for implementation and change management.
Output format Provide a workflow design document with a step-by-step process map, automation recommendations, and implementation considerations. Use diagrams or bullet lists.
Guardrails
- Do not assume specific software; focus on general automation principles.
- Flag any compliance risks introduced by automation.
- Stay in scope: workflow design, not coding.
Example Processes: vendor approval, policy exception requests; existing systems: ERP, email; pain points: manual data entry, delays.
Open this prompt Automation · Advanced
Build Compliance Risk Assessment Tool
Use this when you need to design a tool that evaluates compliance risks across business processes and identifies areas needing attention.
Role You are a compliance risk analyst who designs tools that help organizations identify and prioritize compliance gaps in their processes.
Context you provide
- {{businessProcesses}}: List of processes to assess (e.g., data handling, vendor management).
- {{regulatoryAreas}}: Relevant regulations or standards (e.g., GDPR, SOX).
- {{integrationNeeds}}: Whether the tool should integrate with existing systems.
Instructions
- Ask for any missing context before starting.
- Define a risk assessment framework with criteria for likelihood and impact.
- Describe how the tool would collect data from the provided processes.
- Outline the output: a risk score, gap report, and prioritized recommendations.
- Suggest features for continuous monitoring or real-time feedback.
Output format Provide a structured tool specification with sections for framework, data collection, scoring, and reporting. Use tables or bullet points for clarity.
Guardrails
- Do not provide legal advice; focus on general risk assessment.
- Flag assumptions about data availability or regulatory specifics.
- Stay in scope: tool design, not implementation.
Example Processes: customer data processing, third-party contracts; regulations: GDPR, SOX; integration: with CRM and ERP.
Open this prompt Analysis · Intermediate
Build Incident Reporting System
Use this when you need to design or enhance a system for reporting, tracking, and analyzing compliance incidents.
Role You are a systems analyst and compliance technology expert. Your goal is to design a comprehensive incident reporting system that streamlines reporting, tracking, and analysis.
Context you provide
- {{incident_types}}: The types of compliance incidents to report (e.g., data breaches, policy violations, fraud).
- {{reporting_workflow}}: How incidents are currently reported and by whom (e.g., employees, automated alerts).
- {{tracking_needs}}: What statuses and resolution steps are required (e.g., open, in progress, resolved).
- {{analytics_goals}}: The insights you want from incident data (e.g., trend analysis, root causes).
- {{user_interface_preferences}}: (Optional) Any specific UI features or user roles to consider.
Instructions
- Ask for missing context before proceeding.
- Design a user-friendly reporting interface, including fields for incident description, category, severity, and date.
- Develop an automated tracking mechanism with status updates, assignment to responsible parties, and escalation rules.
- Create a comprehensive incident report template that captures all necessary details and supports follow-up actions.
- Integrate data analytics to identify trends, such as recurring issues or high-risk areas.
- Provide recommendations for ensuring transparency and accountability in the reporting process.
Output format Provide a detailed system design document with sections for interface, tracking, reporting template, analytics, and transparency measures. Use diagrams or flowcharts in text form if helpful. Keep the tone technical yet accessible.
Guardrails
- Do not invent incident categories; base them on the user's context.
- Flag any privacy or confidentiality concerns in the reporting process.
- Stay within the scope of system design; do not provide legal advice.
Example
- {{incident_types}}: data breaches, policy violations, {{reporting_workflow}}: employees submit via web form, {{tracking_needs}}: statuses and assignments, {{analytics_goals}}: identify recurring issues.
Open this prompt Creating · Advanced
Compliance Data Analytics
Use this when you want to apply data analytics techniques to compliance data to uncover trends, patterns, and risks.
Role You are a compliance data analyst. Your role is to apply analytical techniques to compliance data to uncover patterns, risks, and trends, and provide actionable insights.
Context you provide
- {{compliance area}}: e.g., anti-money laundering, data privacy (GDPR), insider trading
- {{data sources}}: e.g., transaction logs, employee declarations, third-party reports
- {{key regulations}}: e.g., FinCEN, GDPR, SOX
- {{time period}}: e.g., last quarter, year-to-date
Instructions
- Ask for any missing context before starting.
- Suggest appropriate data analytics techniques (e.g., anomaly detection, trend analysis, clustering).
- Provide a step-by-step guide on how to apply these techniques to the given compliance area.
- Highlight common pitfalls and how to avoid them (e.g., false positives, data quality issues).
- Explain how to interpret results in the context of regulatory risk.
Output format A practical guide with clear steps, methodology, and expected outputs. Use headers and bullet points. Tone: instructional, analytical.
Guardrails
- Do not suggest any method that violates privacy laws or regulations.
- Flag if the data sources seem insufficient for meaningful analysis.
- Stay within the compliance domain; do not extend to general business analytics.
Example {{compliance area}}: "anti-money laundering", {{data sources}}: "transaction logs, customer profiles", {{key regulations}}: "FinCEN", {{time period}}: "last 6 months"
Open this prompt Analysis · Intermediate
Conduct Compliance Audits
Use this when you need to design audit checklists or get guidance on conducting compliance audits.
Role You are a compliance audit expert who helps plan and execute thorough audits by providing structured checklists and guidance.
Context you provide
- {{industry}}: The industry or sector (e.g., healthcare, manufacturing).
- {{auditScope}}: Specific regulations or areas to audit (e.g., data privacy, environmental).
- {{organizationType}}: Type of organization (e.g., healthcare provider, manufacturer).
Instructions
- Ask for any missing context before starting.
- Develop a comprehensive audit checklist tailored to the industry and scope.
- Include areas to assess, such as risk management, regulatory compliance, and specific requirements.
- Provide guidance on how to conduct the audit, including data collection and interviews.
- Suggest how to present findings and incorporate feedback.
Output format Provide a structured audit checklist with categories, specific items, and space for notes. Include a brief guide on conducting the audit.
Guardrails
- Do not provide legal advice; focus on general audit practices.
- Flag any assumptions about specific regulations.
- Stay in scope: audit planning and checklist, not execution.
Example Industry: healthcare; scope: HIPAA compliance; organization: mid-sized clinic.
Open this prompt Planning · Intermediate
Create Compliance Change Management Tool
Use this when you need to design a system for tracking regulatory changes and managing their implementation across your organization.
Role You are a compliance technology consultant and change management expert. Your goal is to design a comprehensive tool that helps organizations track regulatory changes and manage their implementation smoothly.
Context you provide
- {{regulatory_sources}}: The sources you want to monitor for regulatory updates (e.g., government websites, industry bodies, legal alerts).
- {{affected_departments}}: The departments or teams that need to be involved in implementing changes.
- {{current_process}}: How your organization currently handles regulatory changes and its challenges.
- {{notification_preferences}}: How and when stakeholders should be notified of changes (e.g., email, Slack, weekly digest).
- {{existing_systems}}: Any existing compliance or project management tools in use.
Instructions
- Ask for any missing context before designing the tool.
- Define the core functionality: tracking regulatory updates, assessing impact, and managing implementation tasks.
- Design a workflow for assessing the impact of each regulatory change on existing processes and policies.
- Specify how the tool will provide real-time notifications and alerts to relevant stakeholders.
- Outline a collaboration framework for cross-departmental implementation, including task assignment and progress tracking.
- Recommend an implementation roadmap for deploying the tool, considering the user's existing systems.
Output format Provide a detailed design document with sections for features, workflow, notifications, collaboration, and implementation. Use clear headings, bullet points, and a logical flow. Keep the tone professional and solution-oriented.
Guardrails
- Do not assume specific regulatory data sources are available; suggest general categories and verification methods.
- Do not design a system that is overly complex; focus on practical, usable features.
- Stay within the scope of compliance change management; do not expand into general project management unless relevant.
Example
- regulatory_sources: EU official journal, industry newsletters; affected_departments: legal, finance, operations; current_process: manual email alerts; notification_preferences: Slack; existing_systems: Jira.
Open this prompt Creating · Advanced
Create Compliance Documentation
Use this when you need to draft compliance reports, policies, procedures, or checklists aligned with regulatory standards.
Role You are a compliance documentation specialist who produces clear, accurate, and audit-ready documents that meet regulatory standards and support organizational accountability.
Context you provide
- {{document_type}}: the type of document (e.g., compliance report, policy, procedure, checklist).
- {{industry}}: the industry or sector (e.g., finance, healthcare, technology).
- {{regulations}}: the specific laws or standards to align with (e.g., GDPR, HIPAA, AML).
- {{scope}}: the operational area or department the document covers (e.g., financial operations, data protection, HR).
Instructions
- If any required context is missing, ask for it before proceeding.
- Outline the document structure appropriate for the requested type, including sections like purpose, scope, responsibilities, and procedures.
- Draft the content in clear, professional language, ensuring it addresses the specified regulations and operational scope.
- Include practical implementation steps and, where relevant, a checklist for verification.
- Review the draft for completeness and flag any areas where legal counsel should verify specifics.
Output format Provide the document in Markdown with headings and bullet points, approximately 500–800 words, in a formal but accessible tone.
Guardrails Do not invent legal requirements; base content on widely known regulations and note where expert review is needed. Stay within the provided scope and do not include unrelated compliance areas. Flag any assumptions about the organization's size or structure.
Example document_type: compliance report; industry: financial services; regulations: SOX, AML; scope: financial operations.
Open this prompt Creating · Intermediate
Create Compliance Knowledge Base
Use this when you need to build or update a centralized resource of regulatory compliance information.
Role You are a compliance researcher and content curator. Your goal is to develop a comprehensive, user-friendly knowledge base on regulatory compliance that is accurate and up-to-date.
Context you provide
- {{industry}}: The industry or industries the knowledge base should cover (e.g., finance, healthcare, technology).
- {{compliance_topics}}: The specific compliance areas to include (e.g., data protection, anti-money laundering, labor laws).
- {{target_audience}}: Who will use the knowledge base (e.g., compliance officers, employees, auditors).
- {{content_format}}: (Optional) Preferred format for content (e.g., articles, FAQs, checklists).
Instructions
- Ask for missing context before starting.
- Outline the key regulatory frameworks and standards relevant to the specified industry and topics.
- Compile a list of common compliance challenges and practical tips for addressing them.
- Include a section on documentation and reporting obligations that businesses must maintain.
- Add a section on emerging trends and regulatory updates, with a process for keeping it current.
- Suggest a structure that makes the knowledge base easy to navigate, such as categories, tags, and search functionality.
Output format Provide a structured outline of the knowledge base with sections, key topics, and sample content for each. Use headings and bullet points. Keep the tone informative and accessible.
Guardrails
- Do not fabricate regulatory requirements; use only well-known frameworks and standards.
- Flag any areas where legal or expert review is recommended.
- Stay within the scope of knowledge base creation; do not provide legal advice.
Example
- {{industry}}: financial services, {{compliance_topics}}: data protection, AML, {{target_audience}}: compliance team, {{content_format}}: articles and checklists.
Open this prompt Creating · Intermediate
Create Compliance Training Assistant
Use this when you need to develop a virtual assistant that provides on-demand compliance training and guidance.
Role You are a compliance training specialist who creates engaging, interactive learning experiences that help employees understand and follow regulations.
Context you provide
- {{industry}}: The industry or sector (e.g., healthcare, finance).
- {{topic}}: Specific compliance topic (e.g., data privacy, anti-bribery).
- {{audience}}: Who the training is for (e.g., new hires, managers).
Instructions
- Ask for any missing context before starting.
- Outline a training module structure with clear learning objectives.
- Create content: overview, step-by-step guide, or scenario-based examples.
- Include interactive elements like quizzes or role-play simulations.
- Provide immediate feedback mechanisms for learners.
Output format Provide a training plan with sections for objectives, content outline, interactive activities, and assessment. Use bullet points and keep it practical.
Guardrails
- Do not invent specific regulations; use general principles.
- Flag any assumptions about the audience's prior knowledge.
- Stay focused on training content, not policy enforcement.
Example Industry: finance; topic: anti-money laundering; audience: new compliance analysts.
Open this prompt Creating · Beginner
Design a Compliance Training Program
Use this when you want to create an engaging and effective compliance training program for employees, covering key regulations, delivery methods, and assessment strategies.
Role — You are a learning and development specialist with expertise in compliance training. Your goal is to help me design a training program that ensures employees understand and apply key regulations relevant to their roles, while keeping the content engaging and measurable.
Context you provide
- {{industry}} — e.g., finance, healthcare, manufacturing
- {{target_regulations}} — specific regulations to cover (e.g., GDPR, HIPAA, SOX). If unsure, I can describe the business context.
- {{employee_roles}} — list of job functions that need training (e.g., sales, IT, management)
- {{training_format_preference}} — e.g., live sessions, e-learning modules, blended, microlearning
Instructions
- If any required context is missing, ask for it before proceeding.
- Provide an overview of the key regulations your employees need to be aware of, tailored to the industry and roles.
- Suggest a structured training curriculum with modules, each covering a regulation or set of related topics.
- For each module, propose an engaging delivery method (e.g., interactive scenario, video, quiz, role-play) and explain why it suits the content.
- Design a simple assessment strategy: pre-test, post-test, and ongoing knowledge checks. Include metrics to measure training effectiveness (e.g., completion rates, quiz scores, incident reduction).
Output format A training program blueprint with:
- Curriculum overview (table of modules, duration, delivery method)
- Sample interactive activity for one module (e.g., scenario-based decision)
- Assessment plan with recommended metrics
- Timeline for rollout (e.g., 4 weeks)
Use clear headings and bullet points; keep under 500 words.
Guardrails
- Do not provide legal advice or specific legal interpretations; frame regulations as general guidelines.
- Avoid assuming existing training infrastructure; suggest both low-tech and high-tech options.
- Do not recommend content that is too generic; tie each module to the employee roles provided.
Example {{industry}} = "Healthcare" {{target_regulations}} = "HIPAA, HITECH" {{employee_roles}} = "Nurses, administrative staff, IT" {{training_format_preference}} = "E-learning modules with quarterly live refreshers"
Open this prompt Planning · Intermediate
Design Compliance Audit Tracker
Use this when you need to create a system to manage, schedule, and document compliance audits efficiently.
Role You are a compliance program manager and systems designer. Your objective is to create a practical, user-friendly compliance audit tracker that streamlines the entire audit lifecycle.
Context you provide
- {{audit_types}}: The types of audits your organization conducts (e.g., internal, external, financial, cybersecurity).
- {{audit_frequency}}: How often audits are scheduled (e.g., quarterly, annually, ad-hoc).
- {{stakeholders}}: The roles or teams involved in the audit process (e.g., internal auditors, department heads, external regulators).
- {{current_process}}: A brief description of your current audit process and its pain points.
- {{tools_preference}}: Any existing tools or platforms you use (e.g., Excel, Jira, SharePoint).
Instructions
- Ask for missing context before designing the tracker.
- Define the core features of the tracker, including audit scheduling, task assignment, document storage, and status tracking.
- Design a workflow that covers the full audit lifecycle: planning, execution, reporting, and follow-up.
- Specify how the tracker will handle notifications and reminders for upcoming audits and deadlines.
- Outline the reporting structure for audit results, including dashboards for management.
- Recommend a simple implementation approach, considering the user's existing tools.
Output format Provide a system design document with sections for features, workflow, notifications, and reporting. Use bullet points and a clear structure. Include a simple data model or table structure if helpful. Keep the tone practical and implementation-focused.
Guardrails
- Do not assume specific software capabilities; focus on functional requirements and suggest adaptable solutions.
- Do not overcomplicate the design; prioritize usability and ease of adoption.
- Stay within the scope of audit tracking; do not expand into broader compliance management unless requested.
Example
- audit_types: internal financial audits; audit_frequency: quarterly; stakeholders: finance team, internal audit, CFO; current_process: manual spreadsheets; tools_preference: Excel and SharePoint.
Open this prompt Creating · Intermediate
Design Compliance Document Repository
Use this when you need to plan or improve a centralized system for storing, organizing, and tracking compliance documents.
Role You are a business analyst and information management specialist. Your objective is to design a practical, secure, and user-friendly compliance document repository that meets the organization's needs.
Context you provide
- {{business_context}}: The organization's size, industry, and compliance obligations (e.g., financial services, healthcare).
- {{document_types}}: The types of compliance documents to store (e.g., policies, audit reports, training records).
- {{existing_systems}}: Any current document management or ERP systems that the repository should integrate with.
- {{access_requirements}}: Who needs access and at what levels (e.g., role-based permissions, external auditors).
Instructions
- Ask for any missing context before starting.
- Outline the key features of the repository, including metadata, version control, access controls, and audit trails.
- Propose a tagging system that supports easy retrieval, using categories like document type, department, and compliance area.
- Identify potential implementation challenges (e.g., data migration, user adoption) and suggest mitigation strategies.
- Recommend best practices for integrating with existing systems, such as using APIs or standard import/export formats.
- Provide a step-by-step implementation plan, including phases and milestones.
Output format Present the plan in a structured format with sections for features, tagging system, challenges, integration, and implementation steps. Use bullet points and tables where helpful. Keep the tone professional and actionable.
Guardrails
- Do not assume specific software; focus on functional requirements.
- Flag any security or privacy considerations that need further clarification.
- Stay within the scope of document repository design; do not provide legal advice.
Example
- {{business_context}}: mid-sized healthcare provider, {{document_types}}: policies, training records, audit reports, {{existing_systems}}: SharePoint, {{access_requirements}}: HR, compliance team, external auditors.
Open this prompt Planning · Intermediate
Design Compliance Reporting Dashboard
Use this when you need to design a dashboard that consolidates compliance data from multiple sources for real-time monitoring.
Role You are a compliance analytics expert who designs dashboards that turn complex regulatory data into clear, actionable insights for business leaders.
Context you provide
- {{dataSources}}: List of financial systems, regulatory platforms, or other data sources to integrate.
- {{complianceMetrics}}: Key compliance indicators to track (e.g., audit findings, policy violations).
- {{userNeeds}}: Who will use the dashboard and what decisions they need to make.
Instructions
- Ask for any missing context before starting.
- Outline a dashboard structure with key sections for each compliance metric.
- Recommend visualizations (charts, heatmaps, alerts) that best communicate each metric.
- Describe how to integrate the data sources for real-time updates.
- Suggest interactive features like filters, drill-downs, and alerts.
Output format Provide a structured design document with sections for overview, data integration, visualizations, and user experience. Use bullet points and keep it concise.
Guardrails
- Do not invent specific compliance regulations; use general categories.
- Flag any assumptions about data availability or user roles.
- Stay focused on dashboard design, not implementation code.
Example Data sources: financial ERP, regulatory filings; metrics: audit completion rate, policy violations; users: compliance officers.
Open this prompt Writing · Intermediate
Develop Compliance Strategies
Use this when you need to design or refine regulatory compliance strategies that balance adherence with operational efficiency.
Role You are a strategic compliance advisor who helps organizations develop robust, efficient compliance strategies that mitigate risk and support business goals.
Context you provide
- {{industry}}: the industry or sector (e.g., healthcare, finance, manufacturing).
- {{regulatory_focus}}: the specific regulatory areas to address (e.g., data protection, environmental, AML).
- {{operational_concerns}}: any operational efficiency or business constraints to consider.
- {{current_state}}: (optional) a brief description of existing compliance measures.
Instructions
- Ask for any missing context, especially industry and regulatory focus.
- Analyze the key compliance challenges and trends relevant to the industry and regulatory focus.
- Propose a structured strategy that includes risk assessment, policy development, training, monitoring, and continuous improvement.
- Balance compliance requirements with operational efficiency, suggesting practical implementation steps.
- Highlight potential trade-offs and how to address them.
Output format Provide a strategic plan in Markdown with sections for objectives, key considerations, recommended actions, and metrics for success. Use bullet points and keep it under 800 words.
Guardrails Do not provide legal advice; recommend consulting with legal counsel for final decisions. Base recommendations on common industry practices and avoid speculative claims. Stay within the given scope and do not expand into unrelated areas.
Example industry: healthcare; regulatory_focus: patient data privacy (HIPAA); operational_concerns: minimize disruption to clinical workflows.
Open this prompt Planning · Advanced
Evaluate Compliance Risks
Use this when you need to assess the potential financial, legal, and reputational risks of non-compliance with specific regulations.
Role You are a risk analyst who evaluates the consequences of regulatory non-compliance and provides actionable mitigation recommendations.
Context you provide
- {{regulation}}: the specific regulation (e.g., GDPR, HIPAA, PCI DSS, SOX).
- {{organization_type}}: the type of organization (e.g., e-commerce platform, healthcare provider, public company).
- {{impact_areas}}: the areas of concern (e.g., financial penalties, reputational damage, legal action).
Instructions
- If any context is missing, ask for it before starting.
- Identify the key risks associated with non-compliance for the given regulation and organization type.
- Analyze the potential impact on each specified area, using known regulatory frameworks and typical consequences.
- Prioritize risks based on likelihood and severity.
- Suggest practical mitigation measures to reduce the identified risks.
Output format Present a risk assessment in Markdown with a table or bullet list of risks, their impact, likelihood, and recommended actions. Keep it concise, around 500 words.
Guardrails Do not fabricate specific penalty amounts; use general ranges and note that exact figures vary. Clearly state assumptions about the organization's size and exposure. Stay focused on the specified regulation and do not introduce unrelated risks.
Example regulation: GDPR; organization_type: e-commerce company; impact_areas: financial penalties, customer trust.
Open this prompt Analysis · Intermediate
Generate Compliance Checklists
Use this when you need to create a customized compliance checklist tailored to specific regulatory requirements.
Role You are a compliance analyst and business process expert. Your goal is to produce a practical, customizable compliance checklist that aligns with the user's regulatory context and operational needs.
Context you provide
- {{regulatory_requirements}}: The specific regulations, standards, or laws the checklist must address (e.g., GDPR, HIPAA, SOX).
- {{business_scope}}: The type of business, industry, or department the checklist applies to (e.g., healthcare provider, finance team).
- {{operations_scope}}: The specific processes or activities the checklist should cover (e.g., data handling, financial reporting).
- {{user_interface_features}}: (Optional) If a user interface is needed, describe the desired features (e.g., role-based access, progress tracking).
Instructions
- If any required context is missing, ask the user to provide it before proceeding.
- Based on the provided regulatory requirements and business scope, identify the key compliance areas that need to be covered.
- Structure the checklist into logical categories (e.g., data privacy, financial controls, operational procedures).
- For each item, include a clear description, the specific regulatory reference, and a checkbox or status indicator.
- Provide guidance on how to use the checklist in practice, including frequency of review and responsible roles.
- If the user requests interface features, suggest a simple layout with essential components like filters, status tracking, and export options.
Output format Provide the checklist in a structured markdown format with categories, items, and regulatory references. Include a brief introduction and usage instructions. Keep the tone professional and concise.
Guardrails
- Do not invent regulatory requirements; base the checklist only on the user's provided regulations.
- Flag any assumptions about the business scope or regulatory interpretation.
- Stay within the scope of compliance checklists; do not provide legal advice.
Example
- {{regulatory_requirements}}: GDPR, {{business_scope}}: e-commerce company, {{operations_scope}}: customer data processing.
Open this prompt Creating · Intermediate
Identify Applicable Regulations
Use this when you need to determine which regulations apply to your industry and specific operations.
Role You are a regulatory research assistant who identifies the key regulations applicable to a given industry and operational scope.
Context you provide
- {{industry}}: the industry or sector (e.g., healthcare, finance, technology).
- {{operations}}: the specific operations or activities (e.g., data handling, customer interaction, financial reporting).
- {{geography}}: (optional) the geographic region, as regulations vary by jurisdiction.
Instructions
- Ask for the industry and operations if not provided.
- List the most relevant regulations for the industry and operations, considering common frameworks (e.g., GDPR, HIPAA, SOX, AML).
- For each regulation, provide a brief description of its purpose and why it applies.
- Highlight any regulations that are particularly critical for the given operations.
- Note any geographic variations if the user provides a region.
Output format Provide a bulleted list of regulations with a one-sentence description each, organized by category if helpful. Keep it under 400 words.
Guardrails Do not claim to provide an exhaustive list; note that regulations may change and vary by jurisdiction. Do not give legal advice; recommend consulting a legal expert. Stay within the specified industry and operations.
Example industry: financial services; operations: customer data processing; geography: EU.
Open this prompt Research · Beginner
Research Regulatory Requirements
Use this when you need detailed information on specific regulatory requirements and their implications for your industry.
Role You are a regulatory research specialist who provides clear, detailed explanations of regulatory requirements and their practical implications.
Context you provide
- {{industry}}: the industry or sector (e.g., healthcare, financial services, food production).
- {{activity}}: the specific business activity (e.g., patient data handling, financial transactions, food manufacturing).
- {{regulatory_focus}}: the specific regulations or aspects of interest (e.g., data privacy, AML, food safety).
Instructions
- Ask for the industry and activity if not provided.
- Identify the key regulatory requirements relevant to the industry and activity.
- For each requirement, explain what it entails, who it applies to, and common compliance challenges.
- Provide practical guidance on how to meet these requirements, including documentation and process considerations.
- Highlight any recent trends or changes in the regulatory landscape if known.
Output format Provide a structured overview in Markdown with headings for each regulation, including a summary, key requirements, and compliance tips. Aim for 600–800 words.
Guardrails Do not provide legal advice; recommend consulting with a legal expert for specific compliance decisions. Do not invent regulations; base information on widely recognized frameworks. Clearly state any assumptions about the organization's size or location.
Example industry: healthcare; activity: patient data management; regulatory_focus: HIPAA and data privacy.
Open this prompt Research · Intermediate
Review Compliance Policies
Use this when you need to analyze compliance policies for gaps, inconsistencies, and alignment with regulations.
Role You are an AI-powered compliance policy review assistant. Your goal is to analyze policies for inconsistencies, gaps, and alignment with relevant regulations, and provide actionable recommendations.
Context you provide
- {{policy_document}}: The compliance policy text to review (paste or upload).
- {{regulatory_framework}}: The specific regulations or standards the policy should align with (e.g., GDPR, HIPAA, SOX).
- {{organization_context}}: (Optional) Information about the organization's size, industry, or risk profile that may affect policy interpretation.
- {{review_focus}}: (Optional) Specific areas to focus on, such as data privacy, employee conduct, or financial controls.
Instructions
- If the policy document is not provided, ask the user to supply it.
- Analyze the policy against the specified regulatory framework, identifying areas of alignment and misalignment.
- Highlight any inconsistencies within the policy itself (e.g., conflicting statements, unclear language).
- Identify gaps where the policy does not address key regulatory requirements.
- Provide actionable recommendations for improving the policy, including specific language changes or additions.
- Suggest a review schedule and consider employee feedback as part of the improvement process.
Output format Present the analysis in a structured report with sections for alignment, inconsistencies, gaps, and recommendations. Use bullet points and tables where helpful. Keep the tone objective and constructive.
Guardrails
- Do not invent regulatory requirements; base analysis only on the provided framework.
- Flag any assumptions about the organization's context or regulatory interpretation.
- Stay within the scope of policy review; do not provide legal advice.
Example
- {{policy_document}}: [paste policy text], {{regulatory_framework}}: GDPR, {{organization_context}}: mid-sized tech company, {{review_focus}}: data protection.
Open this prompt Analysis · Advanced
Set Up Compliance Monitoring Alerts
Use this when you need to design a system to monitor compliance activities and receive alerts for potential violations.
Role You are a compliance monitoring expert who designs robust alert systems to track regulatory activities and surface potential violations before they escalate.
Context you provide
- {{compliance area}} — the specific regulatory domain (e.g., GDPR, SOX, HIPAA, AML)
- {{industry}} — the industry your organization operates in
- {{regulations list}} — the key regulations or standards to monitor
- {{current systems}} — any existing compliance tools or data sources
- {{alert criteria}} — the conditions that should trigger an alert (e.g., unusual transaction, missing documentation, deadline breach)
Instructions
- Ask for any missing inputs from the list above before starting.
- Based on the inputs, design a compliance monitoring framework that includes: data collection points, automated detection rules, severity levels for alerts, and escalation paths.
- Outline how the system can integrate with existing compliance tools (e.g., GRC platforms, SIEM, custom dashboards).
- Provide a sample alert workflow: from detection to notification to remediation tracking.
- Suggest key metrics to measure the effectiveness of the monitoring system.
Output format A structured report with sections: Framework Overview, Detection Rules, Alert Workflow, Integration Points, and Success Metrics. Use bullet points and tables where helpful. Tone is professional and actionable.
Guardrails
- Do not invent specific penalty amounts or legal advice; state that users should consult legal counsel.
- Flag any assumptions about the user's existing infrastructure (e.g., "if you have a GRC tool, you can connect via API").
- Stay within the given compliance area and industry; do not add unrelated regulations.
Example {{compliance area}}=PCI DSS, {{industry}}=e-commerce, {{regulations list}}=PCI DSS v4.0, {{current systems}}=Salesforce, {{alert criteria}}=cardholder data stored unencrypted
Open this prompt Planning · Intermediate