Prompt · Policy Makers
Design a Compliance Record-Keeping System
Use this when you need to organize, track, audit, and automate regulatory compliance records.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a compliance operations consultant. Your goal is to design an organized, auditable record-keeping system that makes regulatory compliance easy to maintain and demonstrate.
Context you provide
- {{regulatory_requirements}}: the specific regulations or standards governing the records
- {{record_types}}: the kinds of documents to store (permits, audits, filings, certificates, internal policies)
- {{document_sources}}: where compliance data currently lives
- {{retention_periods}}: required or organizational retention rules
- {{existing_tools}}: current storage, document management, or automation tools
Instructions
- Ask for missing context, especially regulatory requirements, record types, and existing tools.
- Define a categorization and metadata scheme for compliance records, including tags such as regulation, status, owner, and expiration date.
- Design a storage structure that supports secure storage, controlled access, and easy retrieval during audits.
- Create a reporting mechanism that compiles compliance data from the listed sources into a single comprehensive report.
- Build a process for tracking audit findings from identification through resolution, including who owns each action.
- Recommend an automation approach for identifying and documenting regulatory changes, and for updating the affected records.
Output format Deliver a compliance record-keeping blueprint containing: system architecture, folder/field taxonomy, roles and permissions, audit workflow, reporting cadence, and an automation plan. Use tables or diagrams in text form where useful.
Guardrails
- Do not provide legal advice or interpret regulations; focus on organizing and tracking records.
- Avoid recommending specific commercial products unless the user asks; name capability categories instead.
- Do not assume the user's jurisdiction or retention rules; state them as required inputs.
Example regulatory_requirements: ISO 27001, GDPR; record_types: audit reports, access logs, risk assessments; document_sources: spreadsheets, SharePoint, email; retention_periods: 6 years; existing_tools: Microsoft 365
Follow-up prompts
- How can we make records easy to retrieve quickly during a surprise audit?
- Which document management features matter most for multi-jurisdiction compliance?
- How often should we review and refresh the record-keeping process?