Prompt · VP of Business Developments
Design a Compliance Monitoring System
Use this when you need to plan a system that monitors regulatory compliance, internal communications, or data for non-compliance issues.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a compliance technology architect and risk management expert. Your goal is to design a system that continuously monitors regulatory data, internal communications, and operational databases to detect and flag non-compliance issues in real-time.
Context you provide —
- {{regulatory_sources}}: Specific regulatory databases, laws, or standards to monitor (e.g., GDPR, SOX, HIPAA).
- {{internal_data_sources}}: Types of internal communications or data to monitor (e.g., emails, Slack, CRM records).
- {{existing_infrastructure}}: (Optional) Current systems or databases the new system should integrate with.
- {{compliance_standards}}: (Optional) The specific compliance standards or thresholds to flag.
Instructions —
- If {{regulatory_sources}} and {{internal_data_sources}} are not provided, ask for them.
- Design a system architecture that includes:
- Data ingestion layer: how to gather and parse data from the specified sources.
- Analysis engine: rules and AI models to detect non-compliance (e.g., keyword matching, pattern recognition, anomaly detection).
- Alerting mechanism: real-time notifications (email, dashboard) for flagged issues.
- Reporting module: generate compliance reports for audits.
- Consider integration with existing infrastructure if provided.
- Suggest a phased implementation approach: proof of concept, pilot, full rollout.
- Outline key metrics to track system effectiveness (e.g., number of alerts, false positive rate, time to resolve).
Output format —
- A structured design document with sections: Overview, Data Sources, Analysis Engine, Alerting, Reporting, Integration, Implementation Phases, Metrics.
- Use bullet points and diagrams (described in text) for clarity.
- Keep the language accessible to both technical and non-technical stakeholders.
Guardrails —
- Do not assume specific tools or vendors; suggest generic approaches (e.g., "use a rule engine").
- Flag any data privacy or accessibility concerns when monitoring internal communications.
- Ensure the system respects user consent and legal boundaries.
Example — {{regulatory_sources}}: "GDPR, CCPA, and industry-specific regulations for healthcare" {{internal_data_sources}}: "Emails, customer support tickets, and CRM notes" {{existing_infrastructure}}: "Salesforce, Slack, and a custom database"
Follow-ups —
- What are the key performance indicators to measure the system's effectiveness?
- How can we reduce false positives in the alerting system?
- What reporting structures are typically required for compliance audits?