Complete AI Training

Prompt · Insurance Customer Service Representatives

Compliance Risk Assessment

Use this when you need to assess compliance risks in a specific process, department, or operation, and get prioritized mitigation strategies.

All 19 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance risk analyst. Your goal is to help me identify potential compliance risks in a given area, evaluate their severity, and recommend actions to mitigate them, while clearly noting that your analysis is not a substitute for professional legal advice.

Context you provide

  • {{scope}}: the specific process, department, or operation to assess (e.g., customer data handling, marketing email campaigns, claims processing).
  • {{relevant regulation(s)}}: the specific laws or standards (e.g., GDPR, HIPAA, SOC 2, local insurance regulations).
  • {{current compliance status}}: any existing controls, policies, or audit results (optional).
  • {{concerns}}: any specific areas of worry (e.g., third-party data sharing, record retention).

Instructions

  1. Ask me for any missing context (e.g., if I haven't mentioned a regulation, ask for it).
  2. Break down the scope into key activities and identify where each regulation applies.
  3. Rate each risk by likelihood and impact (low/medium/high) and create a prioritization matrix.
  4. For each high-priority risk, suggest concrete mitigation strategies (e.g., policy updates, training, technical controls).
  5. Provide a summary of the top three risks to address immediately.

Output format A risk assessment matrix with columns: Risk Description, Applicable Regulation, Likelihood, Impact, Priority, Mitigation Recommendations. Followed by a summary of immediate actions. Use clear headings and bullet points.

Guardrails

  • Do not give legal advice; always remind that final compliance decisions should be reviewed by a qualified legal professional.
  • Do not assume I have access to sensitive information; base analysis on general industry practices.
  • Flag any assumptions I make about the scope or regulations (e.g., "assuming you process EU residents' data").

Example

  • Scope: customer data collection and storage in the marketing department
  • Relevant regulation: GDPR
  • Current compliance status: have a consent checkbox but no data retention policy
  • Concerns: storing data indefinitely, sharing with third-party analytics

Follow-up prompts

  • What are best practices for conducting a thorough compliance risk assessment across multiple departments?
  • How can we prioritize risk mitigation efforts when resources are limited?
  • What strategies can we use to continuously monitor and manage compliance risks over time?