Help me prepare a factual first draft of a compliance report for professional review. Do not provide legal advice, determine legal compliance, or invent requirements, evidence, controls, dates, or conclusions. Organization and scope: [ORGANIZATION AND ACTIVITY] Frameworks, laws, contracts, or internal policies to assess: [REQUIREMENTS] Review period and locations/business units: [SCOPE AND PERIOD] Available evidence, controls, incidents, and prior findings: [EVIDENCE AND FINDINGS] Audience and reporting purpose: [AUDIENCE AND PURPOSE] First, identify up to 3 clarifying questions only if a required input is missing. Otherwise produce a report of 900–1,300 words with these sections: 1. Executive summary: scope, high-level status stated as “reported,” “evidenced,” or “not yet verified,” and the decisions needed. 2. Scope and assessment method: what was reviewed, what was excluded, evidence sources, and limitations. 3. Requirements register: a table with each cited requirement, plain-English obligation, relevant business process, evidence reviewed, and status. Separate confirmed evidence from management assertions. 4. Findings and risk register: for each gap or uncertainty, state the specific requirement, condition observed, risk, severity rationale, owner, corrective action, target date if supplied, and proof of closure needed. Do not call something a violation unless my materials explicitly establish that conclusion. 5. Control assessment: note preventive/detective controls, frequency, control owner, evidence of operation, and testing limitations. 6. Recommendations and professional-review questions. Use neutral, audit-ready wording and cite the source label from my materials beside every factual claim. Self-check before answering: flag any claim unsupported by my inputs; flag every area where jurisdiction, contract language, or professional interpretation is required.
Fill in
| Placeholder | What to enter | Example |
|---|---|---|
| [ORGANIZATION AND ACTIVITY] | Describe the organization, regulated activity, products, and relevant operating context. | Harborline Health, a 45-person telehealth provider handling patient scheduling and billing data. |
| [REQUIREMENTS] | List the laws, regulations, contracts, standards, or policies that may apply. | HIPAA Security Rule, signed BAAs, company access-control policy v3.2. |
| [SCOPE AND PERIOD] | State the review dates, jurisdictions, teams, systems, and locations included. | January–June 2026; US operations; patient portal, billing vendor, and support team. |
| [EVIDENCE AND FINDINGS] | Paste or summarize policies, logs, training records, incidents, control evidence, and prior audit findings. | Access review spreadsheet, MFA rollout tickets, two vendor BAAs, annual training completion export, incident ticket INC-184. |
| [AUDIENCE AND PURPOSE] | Name the intended readers and explain why the report is being prepared. | Privacy officer and outside healthcare counsel; quarterly readiness review. |
How to use
- Paste the frameworks and scope before pasting evidence so the model can separate obligations from facts.
- Label each source you provide, such as “Access review—May 2026,” so citations in the draft are traceable.
- Check every status label against the underlying record, especially anything described as compliant, complete, or effective.
- Follow up with: “Turn the findings into a 30-day remediation tracker with owners, closure evidence, and dependencies; do not add dates I did not provide.”
Variations
Audit evidence matrix
Use this when you need a working-paper table before writing the report.
Create an audit evidence matrix for [REQUIREMENTS] covering [PROCESS OR SYSTEM] during [PERIOD]. Use only [EVIDENCE PROVIDED]. Return a table with requirement, test objective, evidence source, population or sample if known, result, exception, and evidence gap. Distinguish documents reviewed from unverified assertions. Add a short list of evidence requests needed to complete testing. Do not state legal conclusions or create sample sizes, results, or citations that I did not supply. Ask up to 3 questions only if a required input is missing.
Remediation plan
Use this after findings have been agreed in principle.
Convert these compliance findings, [FINDINGS], into a remediation plan for [AUDIENCE]. For each finding, return the requirement or policy reference, root-cause hypothesis clearly labeled as unconfirmed unless supported, corrective action, accountable owner from [OWNER LIST], dependency, target date only if supplied, interim safeguard, and closure evidence. Prioritize by [RISK METHOD]. Do not invent owners, deadlines, or regulatory conclusions. End with decisions requiring counsel or compliance-officer review. Ask up to 3 questions only for missing essential inputs.
Board summary
Use this for a concise governance update rather than a detailed report.
Draft a one-page compliance update for [BOARD OR COMMITTEE] about [PROGRAM OR REVIEW] for [PERIOD]. Base it only on [EVIDENCE AND FINDINGS]. Include scope, material changes, top three risks, remediation progress, decisions requested, and limitations. Use plain governance language; keep operational detail in an appendix list. Do not describe the program as compliant, certified, or violation-free unless that conclusion is explicitly supported by my materials. Flag items that need qualified legal or compliance review before circulation.
Tips
- Map each finding to one exact obligation or policy clause; a generic “privacy issue” cannot be remediated or tested reliably.
- Keep evidence of control design separate from evidence that the control actually operated during the review period.
- Use “not verified” for missing records instead of assuming a control failed or passed.
- Have counsel or the responsible compliance professional validate jurisdiction-specific obligations, materiality, and any disclosure duties.
FAQ
Can AI tell me whether we are compliant?
No. It can organize evidence and draft a report, but a qualified professional must interpret applicable rules and reach legal or regulatory conclusions.
What evidence should I provide?
Provide the relevant policies, system exports, training records, contracts, tickets, access reviews, testing results, and prior findings, with dates and source labels.
Can I use confidential records?
Follow your organization’s approved AI-use and data-handling rules. Redact personal, protected, or client information when the tool is not approved for it.