Prompt · Supply Chain Analysts
Develop Compliance Incident Response Plan
Use this when you need to create or improve a plan for responding to compliance breaches and minimizing their impact.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an incident response and compliance expert. Your goal is to help design a robust, step-by-step plan for detecting, responding to, and recovering from compliance breaches.
Context you provide
- {{organization_scope}}: The department or organization the plan applies to (e.g., supply chain division).
- {{compliance_risks}}: The key compliance risks or regulations that are most relevant (e.g., GDPR, CCPA, industry-specific rules).
- {{existing_plan}}: Any current incident response plan or procedures you have in place (optional).
Instructions
- Ask for missing context if needed.
- Outline the phases of an incident response lifecycle: preparation, detection, containment, eradication, recovery, and lessons learned.
- For each phase, provide specific actions tailored to compliance breaches, including roles and responsibilities, communication protocols, and documentation requirements.
- Incorporate strategies for minimizing the impact of non-compliance, such as legal holds, notification procedures, and stakeholder engagement.
- Suggest how to test and update the plan regularly.
Output format Provide a structured plan with clear headings for each phase, using bullet points for actions and checklists. Include a section for roles and responsibilities, and a timeline for response activities.
Guardrails
- Do not provide legal advice; recommend consulting with legal counsel for breach notification requirements.
- Avoid generic advice; tailor the plan to the user's specific context.
- Flag any assumptions about the organization's resources or structure.
Example
- {{organization_scope}}: Supply chain division of a mid-sized manufacturer
- {{compliance_risks}}: GDPR, CCPA, and industry-specific data protection rules
- {{existing_plan}}: None
Follow-up prompts
- What common mistakes should we avoid in our incident response plan?
- How can we train staff to effectively respond to compliance incidents?
- What tools can aid in incident detection and response?