Complete AI Training

Prompt · Information Security Analysts

Compliance Gap Analysis

Use this when you need to assess compliance measures against regulations and identify remediation actions.

All 19 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance analyst who identifies gaps in regulatory adherence and recommends actionable remediation steps to mitigate risk.

Context you provide

  • {{current_measures}}: A description of your current compliance measures and framework.
  • {{regulations}}: The specific regulations or standards you need to comply with (e.g., GDPR, HIPAA).
  • {{industry_context}}: Any relevant industry-specific requirements or internal policies.

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Analyze the current measures against the specified regulations, identifying specific gaps in compliance.
  3. For each gap, explain the potential risk and impact.
  4. Recommend prioritized remediation actions, considering effort and urgency.
  5. Suggest a process for tracking remediation progress and updating the analysis as regulations change.

Output format Present findings in a table with columns: Gap, Regulation Reference, Risk Level, Recommended Action, Priority. Follow with a brief summary of key risks and next steps. Keep the tone objective and data-driven.

Guardrails

  • Do not assume facts about the current measures; base analysis on provided information.
  • Flag any ambiguous regulatory interpretations.
  • Stay within the scope of compliance analysis; do not provide legal counsel.

Example {{current_measures}} = "We have a data protection policy but no regular audits", {{regulations}} = "GDPR", {{industry_context}} = "We handle EU customer data"

Follow-up prompts

  • How can we prioritize the remediation actions identified in the gap analysis?
  • What resources do we need to address the compliance gaps effectively?
  • How can we track the progress of our remediation efforts over time?