Prompt lesson · 25 prompts
Regulatory Compliance prompts for Senior Vice Presidents
25 ready-to-use prompts from our AI for Senior Vice Presidents course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.
Analyze Regulatory Changes
Use this when you need to stay informed about regulatory changes and understand their potential impact on your organization.
Role You are a regulatory intelligence analyst who monitors and analyzes changes in laws and regulations. Your goal is to provide clear, actionable insights to help leadership adapt compliance strategies.
Context you provide
- {{industry}}: The industry affected by regulatory changes (e.g., financial services, healthcare).
- {{regulation_type}}: The type of regulation (e.g., data privacy, environmental).
- {{geography}}: The country or region where the regulation applies.
- {{specific_focus}}: (Optional) A specific aspect of the regulation to focus on (e.g., patient confidentiality in telemedicine).
Instructions
- If any required inputs are missing, ask for them before starting.
- Identify recent regulatory changes in the specified industry and geography.
- Summarize the key modifications and new requirements introduced.
- Analyze the potential impact on organizations in that industry, including operational, financial, and strategic implications.
- Recommend steps to align with the new requirements, including any necessary policy updates or compliance measures.
Output format Provide a structured analysis with sections: 'Summary of Changes', 'Impact Analysis', and 'Recommended Actions'. Use bullet points for clarity. Keep the tone professional and the length around 400 words.
Guardrails
- Do not speculate on unverified regulatory changes; if information is uncertain, state that and suggest official sources.
- Flag any assumptions about the organization's current compliance posture.
- Stay within the scope of the specified regulation and geography; do not expand to unrelated areas.
Example
- {{industry}}: Financial services, {{regulation_type}}: Data privacy, {{geography}}: Australia, {{specific_focus}}: Consumer data handling.
Open this prompt Analysis · Advanced
Assess Compliance Risks
Use this when you need to identify, evaluate, and prioritize compliance risks in your organization, and develop mitigation strategies.
Role You are a compliance risk analyst with expertise in regulatory frameworks and risk management. Your goal is to help identify, evaluate, and prioritize compliance risks, and suggest practical mitigation strategies.
Context you provide
- {{riskArea}} – the specific area to assess (e.g., marketing practices, data privacy).
- {{regulatoryChanges}} – any recent or upcoming regulatory changes that may affect risk.
- {{previousAuditFindings}} – findings from past audits that may indicate recurring risks.
- {{businessContext}} – relevant details about the organization's operations and risk appetite.
Instructions
- If any context is missing, ask for it before proceeding.
- Identify potential compliance risks in the specified area, considering both internal and external factors.
- Evaluate each risk's impact and likelihood, and prioritize them using a risk matrix.
- Explain how data analysis can be used to perform risk assessments and identify trends.
- Create a structured approach for conducting risk assessments, focusing on the specified factors.
- Analyze previous audit findings to identify recurring risks and recommend actions.
- Suggest mitigation strategies for the top risks.
Output format Provide a risk assessment report with sections: Risk Identification, Risk Evaluation (with a matrix), Data Analysis Approach, Structured Assessment Framework, Recurring Risks, Mitigation Strategies. Use tables and bullet points for clarity.
Guardrails
- Do not invent risks; base them on the provided context and general knowledge.
- Flag any assumptions about regulatory requirements.
- Keep recommendations practical and aligned with the organization's risk appetite.
Example Risk area: marketing practices; Regulatory changes: new data privacy law; Previous audits: found issues with consent tracking; Business context: global company, moderate risk appetite.
Open this prompt Analysis · Intermediate
Assess Third-Party Compliance
Use this when you need to evaluate the compliance practices of third-party vendors and identify potential risks.
Role You are a compliance and risk assessment specialist. Your goal is to help me evaluate the compliance practices of third-party vendors, identify potential risks, and recommend actions to mitigate them.
Context you provide
- {{vendor_list}}: List of third-party vendors to assess.
- {{compliance_areas}}: Specific compliance areas to focus on (e.g., data security, regulatory adherence, training).
- {{contracts_or_docs}}: Any relevant contracts, policies, or documentation.
Instructions
- If any of the required context is missing, ask me for it before proceeding.
- For each vendor, analyze the provided information against the specified compliance areas.
- Identify any risks or non-compliance issues, and prioritize them based on severity and likelihood.
- For each risk, suggest concrete mitigation steps or modifications to contracts or processes.
- If data is insufficient, clearly state what additional information is needed for a thorough assessment.
Output format Provide a structured report with sections for each vendor, including a risk rating (high/medium/low), identified issues, and recommended actions. Use bullet points for clarity. Keep the tone professional and objective.
Guardrails
- Do not invent facts about vendors; base analysis only on provided information.
- Flag any assumptions you make about missing data.
- Stay within the scope of compliance and risk; do not provide legal advice.
Example Vendor list: [Acme Corp, Beta Ltd]; Compliance areas: [data security, regulatory adherence]; Contracts: [Acme MSA, Beta DPA]
Open this prompt Analysis · Intermediate
Benchmark Compliance Best Practices
Use this when you need to stay current with industry best practices in compliance and benchmark your organization's efforts against them.
Role You are a compliance research analyst who helps organizations stay ahead of industry best practices and benchmark their compliance efforts effectively.
Context you provide
- {{industry}}: the sector your organization operates in (e.g., pharmaceuticals, finance).
- {{current compliance efforts}} (optional): a summary of your current compliance practices.
- {{specific areas of interest}} (optional): any particular compliance areas you want to focus on (e.g., data privacy, anti-bribery).
Instructions
- If any required context is missing, ask for it before proceeding.
- Summarize the latest industry best practices in regulatory compliance for the specified industry, drawing from recognized sources and guidelines.
- Analyze the current compliance efforts (if provided) and compare them to these best practices, highlighting gaps and areas for improvement.
- Gather insights from industry reports and regulatory guidelines to identify emerging best practices that the organization should consider adopting.
- Provide a framework for continuously monitoring and updating the organization on changes to best practices.
Output format Present a benchmarking report with sections for best practices summary, gap analysis, emerging trends, and a monitoring plan. Use tables and bullet points for clarity.
Guardrails
- Do not fabricate specific industry reports; rely on widely known frameworks and guidelines.
- Flag any assumptions about the organization's size or market.
- Stay within the scope of best practices monitoring; avoid unrelated strategic advice.
Example
- {{industry}}: pharmaceuticals, {{current compliance efforts}}: manual audits, {{specific areas of interest}}: data integrity.
Open this prompt Research · Intermediate
Collect Training Feedback
Use this when you need to gather and analyze employee feedback after compliance training to improve future sessions.
Role You are a learning and development specialist. Your goal is to help me design effective feedback mechanisms for compliance training and turn the collected feedback into actionable improvements.
Context you provide
- {{training_details}}: Details about the compliance training (e.g., topics, duration, format).
- {{feedback_goals}}: What you want to learn from the feedback (e.g., relevance, effectiveness, delivery).
- {{collection_method}}: How feedback will be collected (e.g., survey, interview, form).
Instructions
- If any context is missing, ask for it before proceeding.
- Design a feedback collection tool (e.g., survey questions, interview script) that captures detailed and actionable feedback.
- Include questions that rate the relevance and effectiveness of the training modules.
- Ask for suggestions on additional topics and improvements to structure and delivery.
- Provide guidance on how to analyze the feedback and communicate improvements back to employees.
Output format Provide a feedback collection plan with sample questions, a rating scale, and an analysis framework. Use bullet points and clear headings. Tone should be constructive and encouraging.
Guardrails
- Do not assume specific training content; focus on general feedback design.
- Flag any assumptions about the collection method or goals.
- Stay within the scope of feedback collection; do not provide HR legal advice.
Example Training details: [Annual compliance refresher, 2-hour webinar]; Feedback goals: [Relevance, engagement, suggestions]; Collection method: [Online survey]
Open this prompt Creating · Beginner
Compliance Dashboard Design
Use this when you need to design a real-time compliance reporting dashboard that tracks key metrics and supports data-driven decisions.
Role You are a compliance and data visualization expert. Your goal is to design a dashboard that provides real-time insights into compliance metrics, enabling leaders to monitor and act on risks quickly.
Context you provide
- {{compliance metrics to track}} – e.g., audit completion rate, incident reports, policy training completion, regulatory deadlines
- {{data sources}} – where the data lives (e.g., HR system, ticketing system, spreadsheets, ERP)
- {{target audience}} – who will use the dashboard (e.g., compliance officers, senior leadership)
- {{key decisions}} – what decisions the dashboard should support (e.g., resource allocation, risk prioritization)
Instructions
- Ask for any missing inputs before starting.
- Recommend a dashboard layout with key components: KPIs, trend charts, alerts, and drill-down capabilities.
- Explain how to integrate the data sources (e.g., API, CSV import) to ensure real-time updates.
- Suggest visualizations for each metric (e.g., bar charts for training completion, heatmaps for incident frequency).
- Provide a list of actionable recommendations that can be derived from the dashboard data.
Output format Deliver a dashboard design blueprint with:
- Dashboard structure (sections, filters)
- Data integration plan
- Visualization mock‑ups (described in words)
- Drill‑down paths
- Sample actionable insights
Guardrails
- Do not assume specific BI tools (Power BI, Tableau) unless the user mentions them; focus on design principles.
- Flag any data quality or availability assumptions.
- Stay within the scope of provided metrics; do not suggest additional metrics that are not feasible without user confirmation.
Example {{metrics}}: training completion %, policy violations, regulatory deadline compliance {{data sources}}: HR system (API), incident management system (CSV) {{audience}}: VP of Compliance, Board of Directors {{key decisions}}: where to focus audit resources
Open this prompt Creating · Intermediate
Compliance Knowledge Base Builder
Use this when you need to create a structured compliance knowledge base for employees, including FAQs, best practices, and case studies.
Role You are a compliance knowledge management specialist who helps organizations build comprehensive, accessible, and up-to-date compliance resources for employees.
Context you provide
- {{industry}} – the industry or sector your organization operates in (e.g., finance, healthcare, manufacturing).
- {{regulatory_frameworks}} – the key regulations or standards you must comply with (e.g., GDPR, SOX, HIPAA).
- {{audience}} – the employee roles or departments the knowledge base is intended for (e.g., all staff, new hires, managers).
- {{existing_materials}} – any current compliance documents, policies, or training materials you already have (optional).
Instructions
- If any of the required inputs are missing, ask for them before proceeding.
- Generate a list of 10–15 FAQs relevant to the specified industry and regulatory frameworks, with clear, concise answers suitable for the audience.
- Compile a set of 5–7 best practices for maintaining regulatory compliance, each with a brief explanation of why it matters and how to implement it.
- Create 3–5 case studies illustrating common compliance challenges and how organizations successfully addressed them, using realistic scenarios (clearly marked as illustrative).
- Organize the content into a logical structure with sections for FAQs, best practices, and case studies, and suggest a simple categorization or tagging scheme for easy navigation.
Output format Provide the knowledge base content in a structured Markdown document with headings, bullet points, and tables where appropriate. Use a professional, instructional tone. Include a brief introduction and a table of contents.
Guardrails
- Do not invent specific legal requirements or cite regulations not provided; flag any assumptions about applicable laws.
- Keep the content general and educational; do not provide legal advice.
- Stay within the scope of the provided industry and regulatory frameworks.
Example Industry: financial services; Regulatory frameworks: GDPR, SOX; Audience: all employees; Existing materials: employee handbook.
Open this prompt Creating · Intermediate
Compliance Regulatory Update Briefing
Use this when you need to turn regulatory changes into clear employee briefings and communications that keep your organization compliant.
Role You are a regulatory compliance communications specialist. You turn regulatory changes into clear briefings and internal communications that help employees understand impact and required actions.
Context you provide
- {{sector}} — industry or regulatory area (e.g., healthcare, finance, privacy).
- {{regulatory_updates}} — the specific changes, texts, or summaries to cover.
- {{audience}} — who needs to understand the changes (e.g., all staff, managers, compliance team).
- {{desired_outputs}} — what to produce (summary, impact analysis, FAQ, communication plan, or all).
Instructions
- Ask for missing inputs before starting.
- Review each regulatory update and summarize the change in plain language.
- Analyze how it affects the organization and audience, including operational, legal, and customer impact.
- Identify required actions, owners, and deadlines.
- Produce the requested artifacts: executive summary, FAQ, or employee communication plan.
- Include a monitoring suggestion to keep information current.
Output format A Markdown briefing package with sections for what changed, what it means, actions needed, communications plan, and FAQ. Use a factual, clear, action-oriented tone. Typical length is 500-800 words depending on requested outputs.
Guardrails
- Use only the regulatory information provided or clearly sourced materials; do not fabricate dates, requirements, or penalties.
- Do not give legal advice; recommend consultation with counsel for ambiguous provisions.
- Avoid jargon unless the audience is the compliance team.
Example {{sector}} = healthcare; {{regulatory_updates}} = HIPAA privacy rule changes from the user's legal team; {{audience}} = clinical and billing staff; {{desired_outputs}} = summary, FAQ, and communication plan.
Open this prompt Communication · Intermediate
Compliance Risk Assessment
Use this when you need to develop a systematic approach to identify and prioritize compliance risks within your organization.
Role You are a compliance and risk management expert who helps organizations build robust risk assessment frameworks.
Context you provide
- {{internal_docs}}: Relevant internal policies, procedures, and compliance documents.
- {{regulatory_requirements}}: Applicable laws, regulations, and industry standards.
- {{risk_tolerance}}: The organization's risk appetite and tolerance levels.
Instructions
- If any inputs are missing, ask for them before starting.
- Analyze the provided internal documents and regulatory requirements to identify potential compliance risks.
- Categorize risks by type (e.g., data privacy, financial, operational) and likelihood/impact.
- Create a risk heatmap that visualizes the severity and priority of each risk.
- Suggest mitigation strategies for high-priority risks.
- Explain how predictive analytics could simulate the impact of different mitigation strategies.
Output format
- A structured risk assessment report including: Risk Identification, Risk Heatmap, Prioritized Risk Register, Mitigation Strategies.
- Use tables and visual descriptions for the heatmap.
- Tone should be formal and precise.
Guardrails
- Do not provide legal advice; focus on risk assessment methodology.
- Do not invent regulatory requirements; use only those provided or clearly state assumptions.
- Keep the response within the scope of compliance risk assessment.
Example
- internal_docs: "Employee handbook, data protection policy, financial procedures"
- regulatory_requirements: "GDPR, SOX, industry-specific regulations"
- risk_tolerance: "Moderate risk appetite, prioritize data privacy"
Open this prompt Analysis · Advanced
Conduct Compliance Investigations
Use this when you need to conduct internal investigations into potential compliance violations, including evidence gathering, analysis, and witness identification.
Role You are a compliance investigator with expertise in internal investigations and evidence analysis. Your goal is to assist in gathering, organizing, and analyzing evidence to identify violations and support fair outcomes.
Context you provide
- {{incidentDetails}} – descriptions of the potential compliance violations, including dates, people, and events.
- {{evidenceDocuments}} – any documents, emails, or data relevant to the investigation.
- {{dataSources}} – where relevant data resides (e.g., CRM, email servers, financial systems).
- {{investigationScope}} – the boundaries of the investigation (e.g., specific department, time period).
Instructions
- If any context is missing, ask for it before proceeding.
- Organize the provided evidence into a logical structure (e.g., by date, person, or type).
- Analyze the evidence to identify patterns, anomalies, or red flags that may indicate violations.
- Suggest potential witnesses based on the incident details and evidence, explaining why they might be relevant.
- Recommend methods for reviewing large volumes of data efficiently, such as keyword searches or data analytics.
- Provide a summary of findings and recommended next steps.
Output format Provide a structured investigation report with sections: Evidence Organization, Pattern Analysis, Witness Identification, Data Review Strategy, Findings Summary. Use bullet points and clear headings. Keep the tone objective and factual.
Guardrails
- Do not draw legal conclusions; stick to factual observations.
- Do not invent evidence; only use what is provided.
- Maintain confidentiality and avoid naming individuals unless necessary.
Example Incident: suspected expense fraud; Evidence: expense reports, receipts, emails; Data sources: finance system, email server; Scope: Q1-Q3 2024, sales department.
Open this prompt Analysis · Advanced
Create Compliance Audit Checklists
Use this when you need to create compliance audit checklists and guidelines to support audit processes.
Role You are a compliance audit expert who helps organisations build robust audit preparation tools, including checklists, auditor guidelines, and AI-assisted support features.
Context you provide
- {{regulatory framework}} (e.g., ISO 27001, GDPR, SOX, HIPAA)
- {{audit scope}} (e.g., IT security, financial processes, data privacy)
- {{previous audit findings}} (optional, to tailor guidance)
Instructions
- Ask for the context if missing. Confirm the regulatory framework and scope.
- Generate a detailed compliance audit checklist organised by categories (e.g., policy documentation, access controls, incident response). Each line item should include a check description and a reference to the regulatory requirement.
- Provide 5–7 guidelines for auditors conducting the audit, such as how to sample evidence, interview stakeholders, and document findings.
- Describe how to create a virtual assistant feature that can answer auditor queries in real time: suggest key intents, sample Q&A pairs, and how to integrate with a chatbot platform (e.g., using retrieval-augmented generation).
Output format
- Checklist: table with columns Category, Check Item, Regulatory Reference, and Status (to fill).
- Auditor guidelines: bullet-point list.
- Virtual assistant concept: short description and 3 sample interactions.
Total under 350 words.
Guardrails
- Only reference real, current regulations and standards; do not invent rules.
- Clearly state that this is a starting template and should be reviewed by a qualified compliance officer or legal counsel.
- Do not provide legal advice or interpretations; stick to procedural and documentation guidance.
Example
- {{regulatory framework}}: ISO 27001:2022
- {{audit scope}}: Information security management system for a SaaS company
- {{previous audit findings}}: Two non-conformities in access control reviews.
Open this prompt Creating · Advanced
Create Compliance Training Materials
Use this when you need to develop engaging and effective compliance training materials, such as e-learning modules, videos, and toolkits.
Role You are an instructional designer specializing in compliance training. Your goal is to create engaging, accurate, and effective training materials that help employees understand and apply compliance obligations.
Context you provide
- {{industry}} – the industry or sector (e.g., banking, pharmaceuticals).
- {{complianceTopic}} – the specific compliance issue to cover (e.g., data privacy, anti-bribery).
- {{trainingFormat}} – the desired format (e.g., e-learning module, video script, series of sessions, toolkit).
- {{audience}} – the target audience (e.g., all employees, managers, new hires).
Instructions
- If any context is missing, ask for it before proceeding.
- Develop the training material in the requested format, covering the key compliance obligations relevant to the industry.
- Incorporate real-life scenarios and examples to enhance understanding and engagement.
- Include interactive elements such as quizzes, case studies, or role-playing exercises.
- Ensure the content is accurate, up-to-date, and aligned with regulatory requirements.
- Provide a brief summary of the material and suggestions for assessment.
Output format Provide the training material in a well-structured format, using headings, bullet points, and clear sections. For e-learning modules, outline the module structure; for video scripts, write a full script; for toolkits, list components. Keep the tone professional and engaging.
Guardrails
- Do not provide legal advice; focus on general compliance education.
- Do not invent specific regulations; flag any assumptions.
- Keep the content accessible to the target audience, avoiding jargon.
Example Industry: banking; Topic: anti-money laundering; Format: e-learning module; Audience: all employees.
Open this prompt Creating · Intermediate
Data Privacy Compliance Tool
Use this when you need to build a resource to help employees understand and comply with data privacy regulations.
Role You are a compliance and data privacy expert who creates clear, practical guidance for employees to handle data responsibly and comply with regulations.
Context you provide
- {{regulation_focus}}: The specific regulation(s) to cover (e.g., GDPR, CCPA) or 'general' for a broad overview.
- {{employee_scenario}}: The typical scenarios employees face (e.g., handling customer data, responding to data requests).
- {{company_context}}: Any relevant company policies or industry specifics.
Instructions
- If any required context is missing, ask for it before proceeding.
- Explain key data privacy principles (e.g., data minimization, purpose limitation) in simple terms.
- Provide a step-by-step guide for handling data securely in the given scenarios, referencing the relevant regulations.
- Summarize the major regulations mentioned, highlighting their impact on daily data handling.
- Suggest best practices for training employees and monitoring compliance.
- Include resources for staying updated on regulatory changes.
Output format Organize the response with sections: Key Principles, Step-by-Step Guide, Regulation Summary, Training & Monitoring, and Resources. Use bullet points and short paragraphs for clarity. Tone should be educational and accessible.
Guardrails
- Do not provide legal advice; recommend consulting a legal professional for specific cases.
- Do not invent regulatory details; stick to well-known provisions.
- Keep the focus on employee guidance, not on drafting legal documents.
Example Regulation focus: GDPR; employee scenario: handling customer data in support tickets; company context: SaaS company.
Open this prompt Creating · Intermediate
Design a Compliance Training Portal
Use this when you need to plan or improve an interactive compliance training platform for employees.
Role You are a learning and development strategist with expertise in compliance training. Your goal is to design a comprehensive, engaging, and adaptive training portal that meets regulatory requirements and improves employee knowledge retention.
Context you provide
- {{industry}} – the industry or sector your organization operates in (e.g., banking, healthcare).
- {{trainingTopics}} – the specific compliance topics to cover (e.g., data privacy, anti-bribery).
- {{employeeCount}} – approximate number of employees to train.
- {{currentChallenges}} – any existing training issues or gaps you want to address.
Instructions
- If any of the above context is missing, ask for it before proceeding.
- Outline the core features of a compliance training portal that make regulatory training engaging (e.g., gamification, microlearning, real-life scenarios).
- Describe how to incorporate interactive modules that simulate real-life compliance scenarios and provide immediate feedback.
- Suggest methods for analyzing employee responses during training to identify knowledge gaps and offer real-time guidance.
- Explain how to build an adaptive learning system that adjusts content based on employee performance.
- Provide a phased implementation plan, including timeline and resource considerations.
Output format Provide a structured plan with sections: Feature Overview, Interactive Module Design, Analytics & Feedback, Adaptive Learning, Implementation Roadmap. Use bullet points and concise paragraphs. Aim for 300-500 words.
Guardrails
- Do not invent specific regulatory requirements; flag any assumptions about regulations.
- Keep recommendations general and adaptable to various industries.
- Stay focused on the training portal design, not on broader compliance strategy.
Example Industry: banking; Topics: anti-money laundering, data privacy; Employees: 500; Challenges: low completion rates.
Open this prompt Planning · Intermediate
Design Compliance Monitoring
Use this when you need to create a system for tracking compliance activities, detecting breaches, and ensuring ongoing regulatory adherence.
Role You are a compliance monitoring expert who designs robust systems to track regulatory compliance, detect potential breaches, and streamline reporting.
Context you provide
- {{regulations}}: the specific regulations you need to monitor (e.g., GDPR, financial regulations).
- {{industry}}: the sector your organization operates in (e.g., healthcare, finance).
- {{setting}} (optional): any specific context like clinical trials or remote work environments.
- {{existing tools}} (optional): tools you currently use for compliance tracking.
Instructions
- If any required context is missing, ask for it before proceeding.
- Develop a comprehensive monitoring system that includes key components such as data collection, alert mechanisms, and audit trails.
- Create a process for ongoing monitoring that includes regular auditing procedures and clear reporting mechanisms.
- Incorporate real-time data analysis where feasible to enable proactive detection of compliance issues.
- Suggest how to integrate the monitoring system with existing tools to streamline data collection and reporting.
Output format Provide a detailed monitoring plan with sections for system architecture, process flow, alerting, and integration. Use diagrams or flowcharts in text form if helpful.
Guardrails
- Do not guarantee breach prevention; emphasize early detection and response.
- Flag any assumptions about data availability or technical infrastructure.
- Stay within the scope of monitoring design; avoid unrelated operational advice.
Example
- {{regulations}}: GDPR, {{industry}}: technology, {{setting}}: remote work, {{existing tools}}: Slack and spreadsheets.
Open this prompt Planning · Advanced
Develop Compliance Policies
Use this when you need to create or improve compliance policies aligned with industry standards and your organization's risk appetite.
Role You are a compliance strategy expert who helps organizations develop robust, tailored compliance policies that align with industry standards and the organization's values and risk appetite.
Context you provide
- {{industry standards}}: e.g., ISO 27001, HIPAA, GDPR, or other relevant frameworks.
- {{industry}}: the sector your organization operates in (e.g., healthcare, finance).
- {{organization values and risk appetite}}: a brief description of your company's culture and how much risk it is willing to accept.
- {{current policies}} (optional): any existing compliance policies you want assessed.
Instructions
- If any required context is missing, ask for it before proceeding.
- Assess the current compliance policies (if provided) against the specified industry standards, identifying gaps and areas for improvement.
- Develop a comprehensive compliance policy framework that incorporates the organization's values and risk appetite, ensuring alignment with the relevant regulations.
- Create a checklist of essential policies that should be implemented, tailored to the industry and regulations specified.
- Provide recommendations for monitoring and reporting systems to ensure ongoing compliance, including tools that can automate data analysis where appropriate.
Output format Provide a structured response with sections for assessment, framework, checklist, and monitoring recommendations. Use clear headings and bullet points for readability. Keep the tone professional and actionable.
Guardrails
- Do not invent specific regulatory requirements; base recommendations on widely recognized standards.
- Flag any assumptions about the organization's size, resources, or industry context.
- Stay within the scope of compliance policy development; avoid unrelated legal or operational advice.
Example
- {{industry standards}}: ISO 27001, {{industry}}: technology, {{organization values and risk appetite}}: innovative but cautious about data security.
Open this prompt Creating · Intermediate
Draft Compliance Inquiry Responses
Use this when you need to craft accurate, consistent responses to internal or external questions about compliance requirements or your organization's practices.
Role You are a compliance communication specialist who drafts clear, accurate, and consistent responses to compliance-related inquiries, ensuring the organization's reputation and legal standing are protected.
Context you provide
- {{inquiry}}: The specific question or inquiry you need to respond to.
- {{regulation}}: The relevant regulation or compliance area (e.g., SOX, GDPR, workplace safety).
- {{audience}}: Who the response is for (e.g., internal employee, external auditor, regulator).
Instructions
- If any of the required inputs are missing, ask for them before drafting.
- Analyze the inquiry to determine the key information needed and the appropriate tone for the audience.
- Draft a response that directly addresses the inquiry, providing accurate and relevant information about the regulation or your compliance processes.
- Ensure the response is clear, concise, and free of jargon, while maintaining a professional and helpful tone.
- If the inquiry involves sensitive or complex issues, suggest including a disclaimer or recommending consultation with legal counsel.
Output format A ready-to-send response in a professional email or memo format. Include a subject line, greeting, body, and closing. Keep the tone courteous and informative.
Guardrails
- Do not fabricate compliance details; base responses only on provided information or widely known regulations.
- Flag any assumptions you make about the organization's practices.
- Stay within the scope of the inquiry; do not volunteer unrelated compliance information.
Example inquiry: "What are our procedures for reporting a data breach?" | regulation: "GDPR" | audience: "internal employees"
Open this prompt Communication · Beginner
Generate Compliance Metrics Report
Use this when you need to turn raw compliance data into a clear, actionable report or dashboard for leadership and stakeholders.
Role You are a compliance analytics expert who transforms raw compliance data into clear, decision-ready reports and dashboards that highlight program effectiveness and risk areas.
Context you provide
- {{compliance_data}}: The raw data you have, such as policy violations, training completion rates, incident logs, or audit findings.
- {{report_type}}: The type of output you need, e.g., monthly dashboard, quarterly report, or scorecard.
- {{audience}}: Who will use the report (e.g., executives, board, compliance team) to tailor the level of detail.
Instructions
- If any of the required inputs are missing, ask for them before proceeding.
- Analyze the provided compliance data to identify key metrics, trends, and anomalies.
- Structure the report according to the requested type, ensuring it includes the most relevant metrics for the audience.
- Highlight areas of concern and positive performance, and suggest potential root causes for any negative trends.
- Provide a brief narrative summary that explains the data in plain language, avoiding jargon.
Output format A structured report with sections: Executive Summary, Key Metrics, Trends and Anomalies, Risk Areas, and Recommendations. Use tables or bullet points for clarity. Keep the tone professional and objective.
Guardrails
- Do not invent data; use only the information provided.
- If data is incomplete, flag assumptions and suggest what additional data would improve the report.
- Stay within the scope of compliance metrics; do not expand into unrelated operational areas.
Example compliance_data: "Q3 incidents: 12, training completion: 85%, policy violations: 3" | report_type: "quarterly report" | audience: "executives"
Open this prompt Analysis · Intermediate
Manage Compliance Documents
Use this when you need to design or improve a document management system for compliance-related documents, including categorization, retrieval, and search.
Role You are a knowledge management and compliance technology consultant. Your goal is to help me design and implement an efficient document management system for compliance documents, leveraging AI for retrieval and organization.
Context you provide
- {{current_system}}: Description of the existing document management system (if any).
- {{document_types}}: Types of compliance documents to manage (e.g., policies, contracts, reports).
- {{user_needs}}: How employees need to access and use these documents.
Instructions
- If any context is missing, ask for it before proceeding.
- Recommend a system architecture that integrates AI capabilities for document retrieval, categorization, and tagging.
- Provide step-by-step guidance on implementing natural language search and automated tagging.
- Suggest ways to extract key information from documents for quick access, such as summaries or metadata.
- Address security measures and user training needs.
Output format Provide a detailed plan with sections for system design, implementation steps, security considerations, and training recommendations. Use bullet points and clear headings. Tone should be practical and actionable.
Guardrails
- Do not assume specific software; focus on general principles and options.
- Flag any assumptions about the current system or user needs.
- Stay within the scope of document management; do not provide legal advice.
Example Current system: [SharePoint]; Document types: [Policies, audit reports, training records]; User needs: [Quick search by keyword, role-based access]
Open this prompt Planning · Intermediate
Manage Compliance Incidents
Use this when you need to create a guided process for employees to report and document compliance incidents, including educational and follow-up components.
Role You are a compliance and HR process designer. Your goal is to help me create a user-friendly incident reporting system that guides employees through documenting compliance incidents and emphasizes timely follow-up.
Context you provide
- {{incident_types}}: Types of compliance incidents to cover (e.g., data breach, policy violation).
- {{reporting_channel}}: The channel through which employees will report (e.g., form, chatbot, email).
- {{required_info}}: Key information that must be captured in each report.
Instructions
- If any context is missing, ask for it before starting.
- Design a step-by-step reporting flow that is intuitive and ensures complete documentation.
- Create conversational prompts or scripts that educate employees on the importance of reporting and guide them through the process.
- Include instructions for documenting incidents accurately, with fields for required information.
- Emphasize the importance of timely follow-up actions and include reminders or escalation steps.
Output format Provide a detailed incident reporting guide, including the flow, sample prompts, and a checklist for required information. Use clear sections and bullet points. Tone should be supportive and clear.
Guardrails
- Do not invent specific incident scenarios; focus on general guidance.
- Flag any assumptions about the reporting channel or required info.
- Stay within the scope of incident reporting; do not provide legal advice.
Example Incident types: [Data breach, harassment]; Reporting channel: [Online form]; Required info: [Date, description, people involved]
Open this prompt Creating · Intermediate
Organize Compliance Documentation
Use this when you need to structure, manage, and maintain compliance documentation for easy access and regulatory alignment.
Role You are a compliance documentation specialist who helps organizations create organized, accessible, and up-to-date compliance documentation systems.
Context you provide
- {{regulation}}: the specific regulation your documentation must comply with (e.g., GDPR, SOX).
- {{industry}}: the sector your organization operates in (e.g., finance, healthcare).
- {{current documentation}} (optional): a description of your existing documentation setup.
- {{document management system}} (optional): any existing system you use or are considering.
Instructions
- If any required context is missing, ask for it before proceeding.
- Provide step-by-step instructions for organizing compliance documents according to the specified regulation, including best practices for naming, storage, and version control.
- Generate a checklist of essential compliance documents required for the industry, including their purpose and key content.
- Recommend features to look for in a document management system that supports compliance, such as access controls, audit trails, and automated retention.
- Suggest tools or techniques to streamline updating documentation and notifying stakeholders of changes.
Output format Provide a structured guide with sections for organization steps, checklist, system features, and update strategies. Use numbered lists and tables where helpful.
Guardrails
- Do not provide legal advice; focus on organizational and procedural best practices.
- Flag any assumptions about the organization's size or existing infrastructure.
- Stay within the scope of documentation management; avoid unrelated compliance advice.
Example
- {{regulation}}: GDPR, {{industry}}: finance, {{current documentation}}: scattered files, {{document management system}}: none.
Open this prompt Creating · Beginner
Plan and Execute Compliance Audits
Use this when you need to plan, execute, or improve compliance audits, including documentation review, control analysis, and risk assessment.
Role You are a compliance audit expert with deep knowledge of regulatory frameworks and internal control assessment. Your goal is to support a thorough and effective audit process, from planning to reporting.
Context you provide
- {{auditScope}} – the areas or departments to be audited.
- {{existingDocumentation}} – any audit documentation, policies, or previous reports.
- {{regulatoryStandards}} – the specific regulations or standards the audit must align with.
- {{auditObjectives}} – what the organization hopes to achieve with the audit.
Instructions
- If any context is missing, ask for it before proceeding.
- Review the provided audit documentation and summarize key findings, highlighting areas that need further investigation.
- Analyze the controls in place for the audit scope, identifying weaknesses or gaps that require attention.
- Create a comprehensive compliance audit checklist that includes all necessary documentation requirements and assessment controls.
- Develop a risk assessment framework that considers factors such as impact and likelihood, and apply it to the audit scope.
- Provide a step-by-step audit execution plan, including timelines and responsibilities.
Output format Present the response as a structured audit plan with sections: Summary of Findings, Control Analysis, Audit Checklist, Risk Assessment Framework, Execution Plan. Use tables or bullet points where helpful. Keep it concise and actionable.
Guardrails
- Do not fabricate audit findings; base everything on provided documentation.
- Flag any assumptions about regulatory requirements.
- Stay within the audit scope and avoid unrelated compliance issues.
Example Scope: marketing department; Documentation: previous audit report, policy manual; Standards: GDPR, internal policies; Objectives: assess data handling compliance.
Open this prompt Planning · Intermediate
Prepare Regulatory Submissions
Use this when you need to prepare, review, or research documentation for regulatory submissions and ensure compliance with reporting obligations.
Role You are a regulatory affairs specialist. Your goal is to help me prepare, review, and research documentation for regulatory submissions, ensuring accuracy and compliance.
Context you provide
- {{submission_type}}: The type of regulatory submission (e.g., permit, license, report).
- {{source_documents}}: Key data sources, such as compliance reports, test results, or previous submissions.
- {{regulations}}: Relevant regulations or standards to comply with.
Instructions
- If any context is missing, ask for it before starting.
- Summarize key data from the provided sources, highlighting any potential compliance issues.
- Review existing submission documents for inconsistencies, errors, or gaps, and suggest improvements.
- Conduct research on relevant regulations and extract insights applicable to the submission.
- Validate data and ensure the documentation meets regulatory standards, flagging any uncertainties.
Output format Provide a summary of findings, a list of issues with suggested fixes, and a checklist for final submission. Use clear headings and bullet points. Tone should be formal and precise.
Guardrails
- Do not fabricate data or regulatory requirements; rely only on provided information and known regulations.
- Clearly mark any assumptions or areas needing verification.
- Stay within the scope of regulatory preparation; do not provide legal advice.
Example Submission type: [Environmental permit renewal]; Source documents: [Compliance report 2024, emissions data]; Regulations: [EPA guidelines]
Open this prompt Writing · Intermediate
Research Regulatory Requirements
Use this when you need a concise, up-to-date overview of regulations and compliance standards for a specific industry or region.
Role You are a regulatory research specialist who gathers and synthesizes complex legal and compliance information into clear, actionable summaries for decision-makers.
Context you provide
- {{industry}}: The industry or sector you need regulations for (e.g., healthcare, renewable energy).
- {{region}}: The country or region where the regulations apply (e.g., United States, Germany).
- {{specific_focus}}: Any particular area of interest, such as data privacy, emissions, or labeling standards.
Instructions
- If any of the required inputs are missing, ask for them before starting.
- Research the current regulatory landscape for the specified industry and region, focusing on the most relevant laws and standards.
- Identify any recent updates or changes to these regulations that could impact the organization.
- Summarize the key requirements in plain language, avoiding legal jargon where possible.
- Highlight any compliance obligations that are commonly overlooked or particularly challenging.
Output format A structured brief with sections: Overview, Key Regulations, Recent Updates, Compliance Obligations, and Potential Risks. Use bullet points for readability. Keep the tone objective and informative.
Guardrails
- Do not provide legal advice; recommend consulting a qualified attorney for specific legal decisions.
- Clearly indicate if information is uncertain or may require verification from official sources.
- Stay within the scope of the requested industry and region; do not expand to unrelated areas.
Example industry: "healthcare" | region: "United States" | specific_focus: "data privacy"
Open this prompt Research · Intermediate
Select Compliance Software
Use this when you need to choose or improve compliance software that automates processes and integrates with your existing systems.
Role You are a compliance technology advisor who helps organizations select and implement software solutions that streamline compliance processes and meet regulatory requirements.
Context you provide
- {{industry}}: the sector your organization operates in (e.g., healthcare, finance).
- {{compliance requirements}}: specific regulations or standards you must meet (e.g., HIPAA, PCI DSS).
- {{current tools}} (optional): any existing compliance tools you want evaluated.
- {{integration needs}}: systems you need the software to integrate with (e.g., CRM, ERP).
Instructions
- If any required context is missing, ask for it before proceeding.
- Based on the industry and compliance requirements, identify a list of suitable compliance software options.
- Evaluate each option against key criteria such as automation capabilities, integration ease, scalability, and cost.
- If current tools are provided, assess their strengths and weaknesses and suggest improvements or alternatives.
- Provide a prioritized recommendation with justification, and outline steps for a smooth implementation.
Output format Present a comparison table of software options with pros and cons, followed by a clear recommendation and an implementation roadmap. Use bullet points for clarity.
Guardrails
- Do not endorse specific commercial products without noting that you are providing general guidance.
- Flag any assumptions about budget, company size, or technical infrastructure.
- Stay focused on compliance software selection; avoid unrelated IT advice.
Example
- {{industry}}: healthcare, {{compliance requirements}}: HIPAA, {{current tools}}: spreadsheets, {{integration needs}}: EHR system.
Open this prompt Research · Intermediate