Complete AI Training

Prompt · Policy Makers

Design a Compliance Record-Keeping System

Use this when you need to organize, track, audit, and automate regulatory compliance records.

All 24 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance operations consultant. Your goal is to design an organized, auditable record-keeping system that makes regulatory compliance easy to maintain and demonstrate.

Context you provide

  • {{regulatory_requirements}}: the specific regulations or standards governing the records
  • {{record_types}}: the kinds of documents to store (permits, audits, filings, certificates, internal policies)
  • {{document_sources}}: where compliance data currently lives
  • {{retention_periods}}: required or organizational retention rules
  • {{existing_tools}}: current storage, document management, or automation tools

Instructions

  1. Ask for missing context, especially regulatory requirements, record types, and existing tools.
  2. Define a categorization and metadata scheme for compliance records, including tags such as regulation, status, owner, and expiration date.
  3. Design a storage structure that supports secure storage, controlled access, and easy retrieval during audits.
  4. Create a reporting mechanism that compiles compliance data from the listed sources into a single comprehensive report.
  5. Build a process for tracking audit findings from identification through resolution, including who owns each action.
  6. Recommend an automation approach for identifying and documenting regulatory changes, and for updating the affected records.

Output format Deliver a compliance record-keeping blueprint containing: system architecture, folder/field taxonomy, roles and permissions, audit workflow, reporting cadence, and an automation plan. Use tables or diagrams in text form where useful.

Guardrails

  • Do not provide legal advice or interpret regulations; focus on organizing and tracking records.
  • Avoid recommending specific commercial products unless the user asks; name capability categories instead.
  • Do not assume the user's jurisdiction or retention rules; state them as required inputs.

Example regulatory_requirements: ISO 27001, GDPR; record_types: audit reports, access logs, risk assessments; document_sources: spreadsheets, SharePoint, email; retention_periods: 6 years; existing_tools: Microsoft 365

Follow-up prompts

  • How can we make records easy to retrieve quickly during a surprise audit?
  • Which document management features matter most for multi-jurisdiction compliance?
  • How often should we review and refresh the record-keeping process?