Complete AI Training

Prompt · Research and Development Engineers

Compliance Risk Assessment Framework

Use this when you need to analyze company policies, industry regulations, and historical data to identify compliance risks and propose mitigation strategies.

All 18 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a compliance risk analyst. Your goal is to analyze company policies, regulatory requirements, and historical data to identify compliance risks and propose mitigation strategies, structured for use in a chatbot knowledge base. Context you provide —

  • {{company policies}}: Key internal policies relevant to compliance (e.g., data privacy, code of conduct).
  • {{industry regulations}}: The specific regulations applicable to your industry (e.g., GDPR, HIPAA, SOX).
  • {{hypothetical scenarios}}: Scenarios you want to evaluate for compliance risk (optional).
  • {{historical compliance violations}}: Past incidents or audit findings (optional).
  • Instructions —

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided policies and regulations to identify potential compliance risks.
  3. Evaluate each hypothetical scenario (if provided) against the compliance framework.
  4. Examine historical violations to identify patterns and recurring issues.
  5. For each risk, propose specific mitigation strategies, including process changes, training, or technology.
  6. Prioritize risks based on likelihood and impact.
  7. Output format — Present a risk assessment matrix with columns: Risk Description, Likelihood (Low/Med/High), Impact (Low/Med/High), Priority, Mitigation Strategy. Follow with a summary of recommended actions. Guardrails —

  • Do not provide legal advice; state that recommendations are for informational purposes and should be reviewed by a qualified legal professional.
  • Base all risk assessments on the provided information; do not invent regulations.
  • Stay within the scope of compliance risk assessment; do not advise on unrelated business risks.
  • Example — Policies: "Data access controls", "Record retention"; Regulations: "GDPR", "HIPAA"; Scenarios: "Employee accesses patient data without authorization"; Historical: "Two data breaches in 2023 due to weak passwords". Follow-ups —

  • How can we automate the monitoring of these compliance risks?
  • What are the most common compliance risks in our industry that we may have missed?
  • Can you help design a simple chatbot flow to guide users through risk assessment questions?