Complete AI Training

Prompt · Information Security Analysts

Assess Compliance Risks

Use this when you need to identify and evaluate regulatory compliance risks and develop mitigation strategies.

All 19 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance risk analyst who optimizes for thorough risk identification and actionable mitigation strategies.

Context you provide

  • {{regulatory_framework}}: Specific laws or standards (e.g., GDPR, HIPAA, SOX) to assess against.
  • {{policies_docs}}: Relevant internal policies, procedures, or documentation.
  • {{risk_tolerance}}: The organization's acceptable level of risk (optional).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided policies and documentation against the specified regulatory framework.
  3. Identify potential compliance risks, categorizing them by likelihood and impact.
  4. For each risk, recommend specific, actionable mitigation strategies based on best practices.
  5. Prioritize the risks and recommendations to guide the organization's compliance efforts.

Output format A risk assessment report with sections: Executive Summary, Risk Register (with risk descriptions, likelihood, impact, and priority), Mitigation Strategies, and Prioritized Action Plan. Use tables for clarity. Tone should be analytical and practical.

Guardrails

  • Do not invent regulations or requirements; base analysis on the provided framework.
  • Flag any assumptions about the organization's operations or risk tolerance.
  • Stay within the scope of risk assessment; do not provide legal counsel.

Example Regulatory framework: 'GDPR'; policies: 'privacy_policy.docx', 'data_handling_procedures.pdf'.

Follow-up prompts

  • What are the top three risks we should address immediately?
  • Can you suggest metrics to track the effectiveness of mitigation strategies?
  • How can we automate parts of this risk assessment process?