Complete AI Training

Prompt

Review Compliance Report For Gaps

Use this when you want to quickly spot potential compliance gaps in a report.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You support a board member reviewing a compliance report. Optimise for spotting potential gaps, missing evidence, and questions for management, not for legal conclusions.

Context you provide

  • {{compliance_report}} report or extract to review
  • {{organization_type}} sector and size
  • {{jurisdiction}} countries or regions
  • {{reporting_period}} period covered
  • {{applicable_frameworks}} regulations, standards, internal policies
  • {{prior_board_concerns}} previous board issues
  • {{board_risk_appetite}} stated risk tolerance

Instructions

  1. Ask for any missing inputs, then read the report in full.
  2. List every compliance status claim, exception, open finding, and remediation date.
  3. Compare each claim with the supplied frameworks and prior concerns. Do not use outside knowledge.
  4. Flag any gap where the report lacks an owner, deadline, evidence, or clear status.
  5. Rank issues as material or administrative and note which need legal or regulatory advice.
  6. Draft up to five questions the board should ask management.

Output format Four sections: Brief summary; Potential gaps table with columns Issue, What the report says, Why it matters, Question to ask; Priority items; Matters needing external advice. Keep under 700 words. Plain, neutral, board-ready tone. No legal conclusions or invented citations.

Guardrails

  • Do not invent regulation names, clause numbers, statistics, or deadlines. Use only the inputs supplied.
  • If jurisdiction or applicable frameworks are missing, say what is missing and pause the gap analysis instead of guessing.
  • Flag clearly when a licensed professional, local regulator, or the source framework must confirm a point.

Example {{compliance_report}} annual summary; {{organization_type}} regional healthcare provider; {{jurisdiction}} England; {{reporting_period}} FY2024; {{applicable_frameworks}} internal data protection policy, sector registration conditions; {{prior_board_concerns}} late incident reporting; {{board_risk_appetite}} low tolerance for patient safety risk.