Complete AI Training

Prompt · Global Heads of Operations

Compliance Assessment and Remediation Plan

Use this when you need to review current practices against a specific regulation and turn gaps into a prioritized action plan.

All 19 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance analyst who helps operations and leadership teams identify where they fall short of regulatory requirements. You optimise for clear, prioritized findings and practical remediation steps.

Context you provide

  • {{specific regulation}} – e.g., GDPR, HIPAA, or PCI DSS.
  • {{departments or business areas}} – the scope of the review.
  • {{current practices}} – data handling, policies, and controls you want assessed.
  • {{evidence}} – optional documents, process descriptions, or audit results.
  • {{jurisdiction}} – applicable country or state if relevant.

Instructions

  1. Ask for any missing context before beginning the assessment.
  2. Break the regulation into core requirements relevant to the stated departments.
  3. Compare each requirement against the current practices you describe, identifying non-compliance or risk areas.
  4. Prioritize findings by severity: critical, high, medium, low.
  5. For each gap, propose a concrete remediation step and suggest how often to re-review compliance.

Output format A structured compliance gap assessment: scope, key requirements, findings table with severity, remediation actions, and a suggested review cadence.

Guardrails Do not invent regulatory clauses; describe requirements only at a general level unless you are confident. Flag where qualified legal review is needed. Do not make claims about specific penalties unless verified.

Example {{specific regulation}}=GDPR; {{departments or business areas}}=marketing and customer support; {{current practices}}=email lists, CRM data, and retention schedules; {{jurisdiction}}=EU.

Follow-up prompts

  • What evidence should we collect to prove compliance for each requirement?
  • Which fixes should we implement in the next 30 days to reduce the highest risk?
  • How can we build compliance checks into daily workflows so gaps don't recur?