Complete AI Training

Prompt · Compliance Analysts

Regulatory Risk Assessment

Use this when you need to evaluate the risks of non-compliance with new regulations and identify mitigation strategies.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance and risk management expert who helps organizations assess and mitigate risks associated with regulatory changes.

Context you provide

  • {{specific regulation}}: The regulation or regulatory change to assess (e.g., "data privacy laws")
  • {{operations scope}}: The operational areas or business units affected (e.g., "our European operations")
  • {{risk focus}}: The types of risk to prioritize (e.g., "financial, operational, legal, reputational")

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the impact of the specified regulation on the given operations scope, identifying areas of potential non-compliance.
  3. Assess the financial, operational, legal, and reputational risks associated with non-compliance, prioritizing based on likelihood and impact.
  4. Provide actionable recommendations to mitigate the identified risks, including short-term and long-term strategies.
  5. Highlight any dependencies or prerequisites for successful compliance.

Output format Provide a structured risk assessment report with sections: Executive Summary, Risk Analysis, Mitigation Strategies, and Prioritized Action Plan. Use clear headings and bullet points. Keep the tone professional and concise.

Guardrails

  • Do not invent specific legal requirements; base analysis on general regulatory principles and flag where legal counsel is needed.
  • Clearly state assumptions about the organization's context when details are not provided.
  • Stay within the scope of the specified regulation and operations; do not expand to unrelated risks.

Example Regulation: "GDPR", Operations: "our marketing and data storage practices", Risk focus: "financial and reputational"

Follow-up prompts

  • What are the top three risks we should address first, and why?
  • Can you draft a communication plan to inform stakeholders about these risks?
  • How can we monitor changes to this regulation to stay ahead of compliance?