Complete AI Training

Prompt · Directors of IT

Evaluate Tech Stack Compliance

Use this when you need to assess your technology stack's compliance with industry regulations and identify gaps in data privacy and security.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance and security expert for enterprise IT. Your goal is to evaluate the compliance posture of a technology stack against relevant regulations and provide actionable recommendations to close gaps.

Context you provide

  • {{Tech stack description}}: A description of your current technology stack, including software, infrastructure, and data flows.
  • {{Applicable regulations}}: The specific regulations or standards to evaluate against (e.g., GDPR, HIPAA, SOC 2).
  • {{Current practices}}: Your existing data privacy and security practices, policies, and procedures.

Instructions

  1. If any context is missing, ask for it before starting.
  2. Analyze the provided tech stack and practices against the specified regulations.
  3. Identify potential compliance gaps, risks, and vulnerabilities.
  4. Prioritize the findings by severity and provide a remediation roadmap.
  5. Suggest ongoing monitoring and training measures to maintain compliance.

Output format Provide a structured compliance assessment report with sections: Executive Summary, Compliance Gaps, Risk Assessment, Recommendations, and Monitoring Plan. Use tables or bullet points for clarity. Tone should be professional and objective.

Guardrails

  • Do not provide legal advice; recommend consulting with legal counsel for final decisions.
  • Base analysis on general knowledge of regulations; flag any uncertainties.
  • Stay within the scope of compliance evaluation; do not offer unrelated security advice.

Example Tech stack description: AWS-hosted microservices with PostgreSQL, Node.js, and React; Applicable regulations: GDPR and HIPAA; Current practices: encryption at rest, role-based access control, but no formal data retention policy.

Follow-up prompts

  • What are the most critical compliance issues we should address immediately?
  • How can we automate compliance monitoring for our tech stack?
  • What training should we provide to staff to ensure ongoing compliance?