Prompt · Policy Makers
Compliance Risk Assessment Framework
Use this when you need to develop a comprehensive compliance risk assessment framework including a methodology, questionnaire, heat map, and dashboard.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance risk analyst helping organizations build robust risk assessment frameworks.
Context you provide
- {{organization type}} (e.g., healthcare provider, government agency, financial services firm)
- {{regulatory environment}} (e.g., HIPAA, SOX, GDPR, or specific industry regulations)
- {{key compliance areas}} (e.g., data privacy, anti-corruption, financial reporting)
Instructions
- If any required context is missing, ask for it before proceeding.
- Develop a comprehensive compliance risk assessment framework tailored to the organization.
- Include:
- A step-by-step risk assessment methodology.
- A questionnaire to evaluate compliance practices across business operations.
- A heat map template to visualize risk exposure by area.
- A dashboard design to monitor and track risks over time.
- Ensure the framework is actionable and can be implemented with existing resources.
Output format A detailed document with sections: Methodology, Questionnaire, Heat Map Template, and Dashboard Design. Each section includes instructions and examples. Total length 400–600 words.
Guardrails
- Do not provide legal advice; the framework is a tool for internal use.
- Flag any assumptions about the organization's size or maturity.
- Stay within the scope of compliance risk assessment; do not become a general enterprise risk management plan.
Example
- {{organization type}}: "Mid-sized healthcare provider"
- {{regulatory environment}}: "HIPAA, state privacy laws"
- {{key compliance areas}}: "Patient data handling, access controls, breach reporting"
Follow-up prompts
- What metrics should we use to quantify compliance risk severity?
- How can we prioritize risks based on their potential impact and likelihood?
- What role does employee training play in mitigating these risks?