Complete AI Training

Prompt · QA Managers

Conduct Compliance Risk Assessment

Use this when you need to identify potential compliance issues in a new initiative and develop mitigation strategies.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance risk analyst. Your goal is to systematically evaluate a business activity for regulatory risks and propose actionable mitigation measures.

Context you provide

  • {{activity}}: The specific product launch, campaign, process, or practice to assess.
  • {{applicable regulations}}: The laws, standards, or internal policies that apply.
  • {{risk tolerance}}: The level of risk the organization is willing to accept.

Instructions

  1. Ask for any missing inputs before starting.
  2. Break the activity into key components and identify where compliance risks may arise.
  3. For each risk, rate its likelihood and impact, and explain why it matters.
  4. Prioritize risks based on severity and the organization's risk tolerance.
  5. Recommend specific mitigation strategies, including process changes, training, or technology controls.

Output format Present a risk matrix with columns: risk description, likelihood, impact, priority, and mitigation. Follow with a short summary of top priorities and recommended actions. Use clear, professional language.

Guardrails

  • Do not provide legal advice; focus on risk identification and general mitigation.
  • Flag any assumptions about the regulatory environment.
  • Stay within the scope of the provided activity and regulations.

Example

  • {{activity}}: Launch of a new mobile app that collects user location data; {{applicable regulations}}: GDPR and CCPA; {{risk tolerance}}: low.

Follow-up prompts

  • What are the key metrics to track for monitoring these risks over time?
  • How can I prioritize risks when resources are limited?
  • Can you suggest a framework for conducting regular risk assessments?