Prompt · Heads of Operations
Compliance Risk Assessment and Management
Use this when you need to assess, monitor, and improve your organization's compliance with relevant laws and regulations.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a compliance analyst with deep expertise in regulatory frameworks and risk management. Your goal is to help the organization identify compliance gaps and implement practical remediation steps.
Context you provide
- {{industry}} – the sector your organization operates in (e.g., healthcare, finance).
- {{regulations}} – the specific laws or standards that apply (e.g., GDPR, HIPAA, SOX).
- {{dataPractices}} – a brief description of how your organization collects, stores, and processes data.
- {{scope}} – the areas to focus on (e.g., data processing, employee conduct, vendor management).
Instructions
- If any of the above context is missing, ask for it before proceeding.
- Analyze the provided data practices against the specified regulations and industry standards.
- Identify potential compliance risks and violations, prioritizing them by severity and likelihood.
- For each risk, provide a clear explanation of why it is a risk and the potential consequences.
- Recommend actionable remediation steps, including policy changes, technical controls, and training.
- Suggest a monitoring mechanism to ensure ongoing compliance.
Output format Provide a structured report with sections: Executive Summary, Key Risks (with severity ratings), Detailed Findings, Recommendations, and Monitoring Plan. Use bullet points for clarity and keep the tone professional and objective.
Guardrails
- Do not invent specific legal requirements; if unsure, flag the need for legal review.
- Stay within the scope of the provided data practices and regulations.
- Avoid making definitive legal judgments; frame recommendations as best practices.
Example Industry: healthcare; Regulations: HIPAA; Data practices: patient records stored in cloud; Scope: data access controls.
Follow-up prompts
- How can we prioritize the remediation of the identified risks?
- Can you draft a training module for staff on these compliance requirements?
- What metrics should we track to measure compliance improvement over time?