Prompts / Legal Drafting & Compliance

ChatGPT prompt for a compliance report

This prompt produces a first-draft compliance report organized around applicable requirements, evidence, gaps, and remediation. Use it to prepare a reviewable working document for your compliance lead or qualified counsel.

PromptOpen ChatGPTOpen Claude
Help me prepare a factual first draft of a compliance report for professional review. Do not provide legal advice, determine legal compliance, or invent requirements, evidence, controls, dates, or conclusions.

Organization and scope: [ORGANIZATION AND ACTIVITY]
Frameworks, laws, contracts, or internal policies to assess: [REQUIREMENTS]
Review period and locations/business units: [SCOPE AND PERIOD]
Available evidence, controls, incidents, and prior findings: [EVIDENCE AND FINDINGS]
Audience and reporting purpose: [AUDIENCE AND PURPOSE]

First, identify up to 3 clarifying questions only if a required input is missing. Otherwise produce a report of 900–1,300 words with these sections:
1. Executive summary: scope, high-level status stated as “reported,” “evidenced,” or “not yet verified,” and the decisions needed.
2. Scope and assessment method: what was reviewed, what was excluded, evidence sources, and limitations.
3. Requirements register: a table with each cited requirement, plain-English obligation, relevant business process, evidence reviewed, and status. Separate confirmed evidence from management assertions.
4. Findings and risk register: for each gap or uncertainty, state the specific requirement, condition observed, risk, severity rationale, owner, corrective action, target date if supplied, and proof of closure needed. Do not call something a violation unless my materials explicitly establish that conclusion.
5. Control assessment: note preventive/detective controls, frequency, control owner, evidence of operation, and testing limitations.
6. Recommendations and professional-review questions.

Use neutral, audit-ready wording and cite the source label from my materials beside every factual claim. Self-check before answering: flag any claim unsupported by my inputs; flag every area where jurisdiction, contract language, or professional interpretation is required.

Fill in

PlaceholderWhat to enterExample
[ORGANIZATION AND ACTIVITY]Describe the organization, regulated activity, products, and relevant operating context.Harborline Health, a 45-person telehealth provider handling patient scheduling and billing data.
[REQUIREMENTS]List the laws, regulations, contracts, standards, or policies that may apply.HIPAA Security Rule, signed BAAs, company access-control policy v3.2.
[SCOPE AND PERIOD]State the review dates, jurisdictions, teams, systems, and locations included.January–June 2026; US operations; patient portal, billing vendor, and support team.
[EVIDENCE AND FINDINGS]Paste or summarize policies, logs, training records, incidents, control evidence, and prior audit findings.Access review spreadsheet, MFA rollout tickets, two vendor BAAs, annual training completion export, incident ticket INC-184.
[AUDIENCE AND PURPOSE]Name the intended readers and explain why the report is being prepared.Privacy officer and outside healthcare counsel; quarterly readiness review.

How to use

  1. Paste the frameworks and scope before pasting evidence so the model can separate obligations from facts.
  2. Label each source you provide, such as “Access review—May 2026,” so citations in the draft are traceable.
  3. Check every status label against the underlying record, especially anything described as compliant, complete, or effective.
  4. Follow up with: “Turn the findings into a 30-day remediation tracker with owners, closure evidence, and dependencies; do not add dates I did not provide.”

Variations

Audit evidence matrix

Use this when you need a working-paper table before writing the report.

Variation
Create an audit evidence matrix for [REQUIREMENTS] covering [PROCESS OR SYSTEM] during [PERIOD]. Use only [EVIDENCE PROVIDED]. Return a table with requirement, test objective, evidence source, population or sample if known, result, exception, and evidence gap. Distinguish documents reviewed from unverified assertions. Add a short list of evidence requests needed to complete testing. Do not state legal conclusions or create sample sizes, results, or citations that I did not supply. Ask up to 3 questions only if a required input is missing.

Remediation plan

Use this after findings have been agreed in principle.

Variation
Convert these compliance findings, [FINDINGS], into a remediation plan for [AUDIENCE]. For each finding, return the requirement or policy reference, root-cause hypothesis clearly labeled as unconfirmed unless supported, corrective action, accountable owner from [OWNER LIST], dependency, target date only if supplied, interim safeguard, and closure evidence. Prioritize by [RISK METHOD]. Do not invent owners, deadlines, or regulatory conclusions. End with decisions requiring counsel or compliance-officer review. Ask up to 3 questions only for missing essential inputs.

Board summary

Use this for a concise governance update rather than a detailed report.

Variation
Draft a one-page compliance update for [BOARD OR COMMITTEE] about [PROGRAM OR REVIEW] for [PERIOD]. Base it only on [EVIDENCE AND FINDINGS]. Include scope, material changes, top three risks, remediation progress, decisions requested, and limitations. Use plain governance language; keep operational detail in an appendix list. Do not describe the program as compliant, certified, or violation-free unless that conclusion is explicitly supported by my materials. Flag items that need qualified legal or compliance review before circulation.

Tips

  • Map each finding to one exact obligation or policy clause; a generic “privacy issue” cannot be remediated or tested reliably.
  • Keep evidence of control design separate from evidence that the control actually operated during the review period.
  • Use “not verified” for missing records instead of assuming a control failed or passed.
  • Have counsel or the responsible compliance professional validate jurisdiction-specific obligations, materiality, and any disclosure duties.

FAQ

Can AI tell me whether we are compliant?

No. It can organize evidence and draft a report, but a qualified professional must interpret applicable rules and reach legal or regulatory conclusions.

What evidence should I provide?

Provide the relevant policies, system exports, training records, contracts, tickets, access reviews, testing results, and prior findings, with dates and source labels.

Can I use confidential records?

Follow your organization’s approved AI-use and data-handling rules. Redact personal, protected, or client information when the tool is not approved for it.

Related prompts

All Legal Drafting & Compliance prompts →

Get a few prompts like this every week

Something Big is a free AI newsletter read by 50,000+ professionals. One email a week with prompts and tools that work, plus what changed in AI and what to do about it.