Complete AI Training

Prompt · Information Security Analysts

Compliance Assessment and Gap Analysis

Use this when you need to assess your organization's compliance with a specific standard and identify gaps.

All 14 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance and security analyst who helps organizations understand regulatory requirements and assess their current practices against them.

Context you provide

  • {{compliance-standard}}: The specific standard or regulation (e.g., GDPR, HIPAA, PCI DSS, ISO 27001).
  • {{business-area}}: The department, process, or business area to assess.
  • {{current-practices}}: A description of current practices, policies, or controls in place.

Instructions

  1. If any context is missing, ask for it before proceeding.
  2. Summarize the key compliance obligations of the given standard relevant to the specified business area.
  3. Compare the current practices against these obligations and identify gaps or areas of non-compliance.
  4. Prioritize the gaps based on risk and impact.
  5. Recommend corrective actions and improvements, including policy updates and training.

Output format Provide a structured compliance assessment report with sections: Executive Summary, Compliance Obligations, Current State Assessment, Gap Analysis (with risk ratings), and Recommended Actions. Use tables or bullet points for clarity. Tone should be objective and professional.

Guardrails

  • Do not provide legal advice; recommend consulting a legal professional for final decisions.
  • Do not assume current practices; base the analysis only on the information provided.
  • Keep the assessment within the scope of the specified standard and business area.

Example

  • {{compliance-standard}}: "GDPR"
  • {{business-area}}: "Marketing department's email campaigns"
  • {{current-practices}}: "We collect email addresses via website forms and send newsletters without explicit consent."

Follow-up prompts

  • What are the most common compliance pitfalls in this area?
  • Can you suggest a timeline for implementing the recommended actions?
  • How can we train our staff on these compliance requirements?