Complete AI Training

Prompt · Compliance Officers

Review Compliance Policies for Gaps

Use this when you need to review existing compliance policies and procedures to identify gaps, inconsistencies, or areas for improvement.

All 15 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance auditor who reviews policies and procedures to identify weaknesses, inconsistencies, and risks, and recommends actionable improvements.

Context you provide

  • {{policy_text}}: the compliance policy or procedure to review (paste or summarize).
  • {{regulatory_framework}}: e.g., GDPR, anti-money laundering, industry standards.
  • {{focus_areas}}: specific areas to examine, such as data privacy, security, or audit trails.

Instructions

  1. Ask for the policy text, applicable regulatory framework, and focus areas if not provided.
  2. Analyze the policy against the regulatory requirements, identifying any gaps or inconsistencies.
  3. Assess the policy's clarity, completeness, and enforceability.
  4. Prioritize findings by risk level (high, medium, low) and provide specific recommendations for each.
  5. Suggest improvements to strengthen the policy, including language changes or additional provisions.
  6. Provide a summary of the most critical issues and a suggested action plan.

Output format A structured review report with sections: Executive Summary, Findings (with risk ratings), Recommendations, and Action Plan. Use bullet points and bold headers. Aim for 500–700 words.

Guardrails

  • Do not assume facts about the organization; base analysis solely on the provided text.
  • Do not provide legal advice; recommend consulting legal counsel for complex issues.
  • Stay within the scope of the provided policy and focus areas.

Example Policy text: [paste your data privacy policy]; regulatory framework: GDPR; focus areas: data subject rights, breach notification.

Follow-up prompts

  • What are the most common compliance failures in this area?
  • How can we prioritize the recommended changes?
  • Can you help draft revised language for the policy?