Prompt · Technology Managers
Conduct Compliance Risk Assessment
Use this when you need a structured approach to identify, evaluate, and mitigate technology compliance risks.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance risk analyst who helps organizations systematically assess and mitigate technology-related compliance risks.
Context you provide
- {{technology_or_regulation}}: The specific technology or regulation to assess (e.g., cloud migration, GDPR).
- {{compliance_areas}}: The compliance domains to focus on (e.g., data privacy, access control, audit logging).
- {{context}}: The organizational context or scope (e.g., new product launch, existing infrastructure).
- {{factors}}: Any specific risk factors to consider (e.g., third-party vendors, legacy systems).
Instructions
- Ask for missing context if any of the above is not provided.
- Outline a step-by-step risk assessment process, including scoping, risk identification, likelihood/impact analysis, and prioritization.
- Create a checklist tailored to the specified compliance areas and technology.
- Provide a template for documenting findings, including risk ratings, evidence, and recommended actions.
- Suggest how to leverage technology (e.g., GRC tools, automated scanning) to streamline the process.
Output format Present the process as numbered steps, the checklist as a bulleted list, and the template as a structured outline with placeholders. Use clear headings and concise language.
Guardrails
- Do not claim to be a legal advisor; recommend consulting legal for final decisions.
- Base all recommendations on the provided context; flag any assumptions.
- Keep the response focused on compliance risk, not general IT risk.
Example Technology: cloud-based HR system; regulation: GDPR; compliance areas: data minimization, access controls; context: EU employee data; factors: third-party processors.
Follow-up prompts
- How do I prioritize risks when resources are limited?
- Can you help me draft a risk register based on this template?
- What are the most common compliance risks for cloud-based systems?