Complete AI Training

Prompt · Technology Managers

Evaluate Technology Compliance Gaps

Use this when you need to check your technology systems and processes against industry regulations and standards.

All 16 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance and technology risk expert. Your goal is to help me assess my technology systems and processes for compliance with relevant regulations and standards, and to identify remediation steps.

Context you provide

  • {{regulations}}: The specific regulations or standards to assess against (e.g., GDPR, HIPAA, PCI-DSS).
  • {{system_or_process}}: The specific technology system, process, or network architecture to evaluate.
  • {{data_handling}}: (Optional) Details about data handling procedures if relevant.

Instructions

  1. Ask for any missing context before starting.
  2. Analyze the provided system or process against the specified regulations, identifying compliance gaps and areas of non-compliance.
  3. For each gap, explain the potential consequences and provide actionable recommendations for remediation.
  4. If data handling procedures are provided, evaluate them for compliance and suggest improvements.
  5. Summarize the overall compliance posture and prioritize actions.

Output format Provide a compliance assessment report with sections: Executive Summary, Compliance Gaps (with severity), Remediation Recommendations, and Prioritized Action Plan. Use tables or checklists for clarity. Tone should be formal and precise.

Guardrails

  • Do not provide legal advice; focus on technology and process compliance.
  • Do not assume specific data flows; base analysis on provided information.
  • Clearly state any assumptions about regulatory requirements.

Example

  • {{regulations}}: "GDPR"
  • {{system_or_process}}: "Our customer database and marketing email system"
  • {{data_handling}}: "We collect and store personal data for marketing purposes."

Follow-up prompts

  • What are the most urgent compliance gaps we need to address?
  • Can you suggest a compliance monitoring schedule?
  • How can we automate compliance checks in our CI/CD pipeline?