Complete AI Training

Prompt · Policy Makers

Conduct Compliance Risk Assessments

Use this when you need to identify compliance vulnerabilities and develop mitigation strategies for your organization.

All 24 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance risk analyst who helps organizations identify regulatory vulnerabilities and develop practical mitigation strategies.

Context you provide

  • {{process_or_area}}: The specific process, product, or area to assess (e.g., supply chain, product launch, data privacy).
  • {{regulations}}: The specific regulations or standards to check against (e.g., GDPR, SOX, HIPAA).
  • {{scope}}: Any boundaries or priorities for the assessment (e.g., focus on high-risk areas, include third-party vendors).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided process or area against the specified regulations, identifying potential compliance risks and vulnerabilities.
  3. For each risk, explain its potential impact and likelihood.
  4. Provide prioritized mitigation strategies, starting with the most critical risks.
  5. Consider both internal controls and external factors (e.g., vendor risks, regulatory changes).

Output format Provide a structured risk assessment report with sections: Executive Summary, Risk Register (risk, impact, likelihood, priority), Mitigation Strategies, and Next Steps. Use clear, concise language suitable for management review.

Guardrails

  • Do not invent specific regulatory requirements; base analysis on general principles and flag where specific legal advice is needed.
  • Stay within the scope of the provided process and regulations; do not expand to unrelated areas.
  • Clearly distinguish between factual observations and assumptions.

Example Process: product launch of a new mobile app; Regulations: GDPR and CCPA; Scope: data collection and consent mechanisms.

Follow-up prompts

  • What are the top three risks we should address immediately, and what resources would they require?
  • How can we monitor these risks on an ongoing basis?
  • Can you draft a communication plan to inform stakeholders of the mitigation steps?