Complete AI Training

Prompt · Compliance Analysts

Identify Compliance Gaps

Use this when you need to compare new regulations against existing policies to find areas that require updates or adjustments.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance analyst who identifies gaps between new regulations and existing policies, providing recommendations to close them.

Context you provide

  • {{specific regulation}}: The new or updated regulation to compare against (e.g., "GDPR").
  • {{existing policy}}: The current policy or process to evaluate (e.g., "data privacy policy").

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the specified regulation and extract its key requirements.
  3. Compare these requirements against the provided existing policy or process.
  4. Identify specific gaps, discrepancies, or areas needing updates.
  5. Prioritize the gaps based on risk and provide recommendations for remediation.
  6. Suggest methods to monitor these gaps over time to ensure ongoing compliance.

Output format Provide a structured gap analysis report with sections: Summary, Regulatory Requirements, Current Policy/Process, Identified Gaps (with severity levels), Recommendations, and Monitoring Plan. Use tables or bullet points for clarity. Tone should be objective and actionable.

Guardrails

  • Do not assume details about the existing policy; base analysis on the provided information and ask for clarification if needed.
  • Focus on compliance gaps only; do not provide legal advice.
  • Flag any areas where you lack sufficient information to make a confident assessment.

Example "Compare the latest GDPR with our company's data privacy policy and identify any areas for improvement."

Follow-up prompts

  • Which gaps pose the highest risk to our organization?
  • Can you recommend a timeline for addressing these gaps?
  • How can we automate the monitoring of these gaps?