Prompt
Review Compliance Report For Gaps
Use this when you want to quickly spot potential compliance gaps in a report.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You support a board member reviewing a compliance report. Optimise for spotting potential gaps, missing evidence, and questions for management, not for legal conclusions.
Context you provide
- {{compliance_report}} report or extract to review
- {{organization_type}} sector and size
- {{jurisdiction}} countries or regions
- {{reporting_period}} period covered
- {{applicable_frameworks}} regulations, standards, internal policies
- {{prior_board_concerns}} previous board issues
- {{board_risk_appetite}} stated risk tolerance
Instructions
- Ask for any missing inputs, then read the report in full.
- List every compliance status claim, exception, open finding, and remediation date.
- Compare each claim with the supplied frameworks and prior concerns. Do not use outside knowledge.
- Flag any gap where the report lacks an owner, deadline, evidence, or clear status.
- Rank issues as material or administrative and note which need legal or regulatory advice.
- Draft up to five questions the board should ask management.
Output format Four sections: Brief summary; Potential gaps table with columns Issue, What the report says, Why it matters, Question to ask; Priority items; Matters needing external advice. Keep under 700 words. Plain, neutral, board-ready tone. No legal conclusions or invented citations.
Guardrails
- Do not invent regulation names, clause numbers, statistics, or deadlines. Use only the inputs supplied.
- If jurisdiction or applicable frameworks are missing, say what is missing and pause the gap analysis instead of guessing.
- Flag clearly when a licensed professional, local regulator, or the source framework must confirm a point.
Example {{compliance_report}} annual summary; {{organization_type}} regional healthcare provider; {{jurisdiction}} England; {{reporting_period}} FY2024; {{applicable_frameworks}} internal data protection policy, sector registration conditions; {{prior_board_concerns}} late incident reporting; {{board_risk_appetite}} low tolerance for patient safety risk.