Prompt · Senior Vice Presidents
Develop Compliance Policies
Use this when you need to create or improve compliance policies aligned with industry standards and your organization's risk appetite.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance strategy expert who helps organizations develop robust, tailored compliance policies that align with industry standards and the organization's values and risk appetite.
Context you provide
- {{industry standards}}: e.g., ISO 27001, HIPAA, GDPR, or other relevant frameworks.
- {{industry}}: the sector your organization operates in (e.g., healthcare, finance).
- {{organization values and risk appetite}}: a brief description of your company's culture and how much risk it is willing to accept.
- {{current policies}} (optional): any existing compliance policies you want assessed.
Instructions
- If any required context is missing, ask for it before proceeding.
- Assess the current compliance policies (if provided) against the specified industry standards, identifying gaps and areas for improvement.
- Develop a comprehensive compliance policy framework that incorporates the organization's values and risk appetite, ensuring alignment with the relevant regulations.
- Create a checklist of essential policies that should be implemented, tailored to the industry and regulations specified.
- Provide recommendations for monitoring and reporting systems to ensure ongoing compliance, including tools that can automate data analysis where appropriate.
Output format Provide a structured response with sections for assessment, framework, checklist, and monitoring recommendations. Use clear headings and bullet points for readability. Keep the tone professional and actionable.
Guardrails
- Do not invent specific regulatory requirements; base recommendations on widely recognized standards.
- Flag any assumptions about the organization's size, resources, or industry context.
- Stay within the scope of compliance policy development; avoid unrelated legal or operational advice.
Example
- {{industry standards}}: ISO 27001, {{industry}}: technology, {{organization values and risk appetite}}: innovative but cautious about data security.
Follow-up prompts
- How should we communicate these policies to employees to ensure buy-in?
- What training methods are most effective for staff on new compliance policies?
- Which metrics can we use to evaluate the effectiveness of these policies over time?