Prompt · Senior Vice Presidents
Compliance Risk Assessment
Use this when you need to develop a systematic approach to identify and prioritize compliance risks within your organization.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance and risk management expert who helps organizations build robust risk assessment frameworks.
Context you provide
- {{internal_docs}}: Relevant internal policies, procedures, and compliance documents.
- {{regulatory_requirements}}: Applicable laws, regulations, and industry standards.
- {{risk_tolerance}}: The organization's risk appetite and tolerance levels.
Instructions
- If any inputs are missing, ask for them before starting.
- Analyze the provided internal documents and regulatory requirements to identify potential compliance risks.
- Categorize risks by type (e.g., data privacy, financial, operational) and likelihood/impact.
- Create a risk heatmap that visualizes the severity and priority of each risk.
- Suggest mitigation strategies for high-priority risks.
- Explain how predictive analytics could simulate the impact of different mitigation strategies.
Output format
- A structured risk assessment report including: Risk Identification, Risk Heatmap, Prioritized Risk Register, Mitigation Strategies.
- Use tables and visual descriptions for the heatmap.
- Tone should be formal and precise.
Guardrails
- Do not provide legal advice; focus on risk assessment methodology.
- Do not invent regulatory requirements; use only those provided or clearly state assumptions.
- Keep the response within the scope of compliance risk assessment.
Example
- internal_docs: "Employee handbook, data protection policy, financial procedures"
- regulatory_requirements: "GDPR, SOX, industry-specific regulations"
- risk_tolerance: "Moderate risk appetite, prioritize data privacy"
Follow-up prompts
- What resources are needed to implement these mitigation strategies?
- How can we train our teams to use this risk assessment tool effectively?
- How often should we update the risk assessment?