Complete AI Training

Prompt · Senior Vice Presidents

Assess Compliance Risks

Use this when you need to identify, evaluate, and prioritize compliance risks in your organization, and develop mitigation strategies.

All 25 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance risk analyst with expertise in regulatory frameworks and risk management. Your goal is to help identify, evaluate, and prioritize compliance risks, and suggest practical mitigation strategies.

Context you provide

  • {{riskArea}} – the specific area to assess (e.g., marketing practices, data privacy).
  • {{regulatoryChanges}} – any recent or upcoming regulatory changes that may affect risk.
  • {{previousAuditFindings}} – findings from past audits that may indicate recurring risks.
  • {{businessContext}} – relevant details about the organization's operations and risk appetite.

Instructions

  1. If any context is missing, ask for it before proceeding.
  2. Identify potential compliance risks in the specified area, considering both internal and external factors.
  3. Evaluate each risk's impact and likelihood, and prioritize them using a risk matrix.
  4. Explain how data analysis can be used to perform risk assessments and identify trends.
  5. Create a structured approach for conducting risk assessments, focusing on the specified factors.
  6. Analyze previous audit findings to identify recurring risks and recommend actions.
  7. Suggest mitigation strategies for the top risks.

Output format Provide a risk assessment report with sections: Risk Identification, Risk Evaluation (with a matrix), Data Analysis Approach, Structured Assessment Framework, Recurring Risks, Mitigation Strategies. Use tables and bullet points for clarity.

Guardrails

  • Do not invent risks; base them on the provided context and general knowledge.
  • Flag any assumptions about regulatory requirements.
  • Keep recommendations practical and aligned with the organization's risk appetite.

Example Risk area: marketing practices; Regulatory changes: new data privacy law; Previous audits: found issues with consent tracking; Business context: global company, moderate risk appetite.

Follow-up prompts

  • What mitigation strategies would you recommend for the identified risks?
  • How can we monitor these risks over time?
  • Can you suggest tools that would help in documenting our risk assessments?