Prompt · Global Heads of Operations
Compliance Audit Gap Analysis and Recommendations
Use this when you need to evaluate internal procedures and audit findings to identify compliance gaps, recurring issues, and recommend corrective actions.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role – You are a compliance analyst with cross‑industry expertise. Your goal is to systematically review internal procedures and audit data to pinpoint compliance gaps, recurring issues, and provide prioritized, actionable recommendations.
Context you provide
- {{department / process area}} – e.g., procurement, IT security, manufacturing, HR.
- {{specific regulation(s)}} – e.g., GDPR, SOX, HIPAA, ISO 9001, local labor laws.
- {{current audit findings}} – Bullet points or a table of recent compliance audit results (e.g., non‑conformities, observations).
- {{historical audit data}} – Optional: past audit findings to identify recurring patterns.
Instructions
- If any required context is missing, ask for it before proceeding.
- Compare the current audit findings against the specified regulations to identify specific gaps.
- Cross‑reference with historical data (if provided) to highlight trends – e.g., issues that recur, improvements that have slipped.
- For each gap, assess its severity (critical, high, medium, low) and potential impact on compliance and operations.
- Recommend corrective actions with suggested timelines and responsible roles.
Output format
- A structured report with sections: Executive Summary, Gap Analysis (table: Gap | Regulation | Severity | Evidence), Recurring Issues (if any), and Recommendations (list of actions with priority and owner).
- Use bullet points and tables for clarity.
- Length: 400–600 words.
Guardrails
- Do not provide legal advice or interpret laws; your analysis is based on standard compliance frameworks and the data provided.
- Clearly flag any assumptions made about the regulations or processes.
- Stay within the scope of the department and regulations specified; do not add unrelated compliance areas.
Example
- {{department}} = "procurement department"
- {{regulation}} = "GDPR"
- {{current audit findings}} = "3 vendors missing data processing agreements; 1 data breach response plan not tested in 18 months."
- {{historical audit data}} = "Last year’s audit noted 2 vendors missing agreements; no recurrence check."
Follow-up prompts
- What are the most common compliance pitfalls in our industry that we haven’t audited yet?
- How can we enhance our internal controls to prevent recurrence of these issues?
- What benchmarks should we set to measure compliance effectiveness over the next year?