AI tools, scored for your job
Learn AI in 30 days

Tested & copy-paste ready

AI Prompts for Compliance

25 copy-paste AI prompts for compliance, pulled from Zekai's tested prompt guides. See the full AI tools for compliance hub for the tools these prompts are built to work with.

The prompts

Summarize a New Regulation for a Board Report
You are a senior compliance analyst preparing a briefing for the board of directors. Your audience is smart but not composed of compliance experts. Based ONLY on the text of the new regulation provided below, write a 300-word executive summary. The summary must cover: 1. The name of the regulation and the issuing body. 2. The key requirements and prohibitions in simple, non-technical language. 3. The types of activities or products at our company that are most likely to be impacted. 4. The official effective date of the regulation. Do not offer opinions or analysis beyond what is explicitly stated in the provided text. [[PASTE REGULATION TEXT HERE]]
Create a Gap Analysis Checklist
You are a compliance manager for a [describe your company type, e.g., 'mid-sized fintech company that offers payment processing services in the United States and EU']. I am providing the text of a new regulation: [[Name of Regulation]]. Analyze the text and generate a gap analysis checklist in a markdown table format. The table should have four columns: 1. **Regulatory Requirement:** A concise summary of the specific rule or obligation. 2. **Relevant Section:** The specific section number from the regulation text. 3. **Potential Gap Question:** A question our team must answer to determine if our current controls are sufficient (e.g., "Do our current vendor onboarding procedures include [[new requirement]]?"). 4. **Priority:** Assign a 'High', 'Medium', or 'Low' priority based on the apparent risk and complexity of the requirement. Base your analysis only on the provided text. [[PASTE REGULATION TEXT HERE]]
Compare Two Versions of a Regulation
You are a compliance officer tracking changes to existing regulations. I will provide you with two versions of the same rule: an 'Old Version' and a 'New Version'. Your task is to identify and summarize the material changes between the two. Produce a bulleted list where each bullet point explains a specific change. For each change, note whether it is an addition of a new requirement, a removal of an old one, or a modification of an existing one. Start each bullet point with "Addition:", "Removal:", or "Modification:". **Old Version:** [[PASTE OLD REGULATION TEXT HERE]] **New Version:** [[PASTE NEW REGULATION TEXT HERE]]
Draft an Internal Alert on a Regulatory Update
You are the head of compliance. Draft a brief, clear, and actionable internal communication (under 250 words) for business unit leaders about a recent regulatory update. The regulation is [[Name of Regulation]]. The key change is [[briefly describe the single most important change]]. The effective date is [[Date]]. The communication should: 1. State the purpose of the alert immediately. 2. Explain the key change and which business activities it affects. 3. Specify the action required from the business leaders (e.g., "review your team's procedures," "attend a mandatory briefing"). 4. Provide a contact person within the compliance team for questions. Make the tone professional and direct. Do not use jargon.
Brainstorm Risks for a New Product
You are a GRC (Governance, Risk, and Compliance) expert. Our company, a [[company type]], is planning to launch a new product: [describe the new product and its core function in 2-3 sentences]. Based on this product description, generate a list of potential compliance and regulatory risks we should consider. For each risk, categorize it into one of the following areas: * Data Privacy & Security * Consumer Protection (e.g., UDAAP/UDAP) * Anti-Money Laundering (AML) / Financial Crime * Marketing & Advertising * Third-Party / Vendor Risk * Licensing & Registration Present the output as a bulleted list, grouped by category.
Populate a Risk Register from Meeting Notes
You are a compliance analyst tasked with updating the enterprise risk register. I am providing you with the raw, anonymized notes from a risk committee meeting. Your job is to parse these notes and extract any identified risks. For each risk, format it for a risk register table with the following columns: * **Risk ID:** (Leave as TBD-001, TBD-002, etc.) * **Risk Description:** A clear, one-sentence description of the risk. * **Risk Category:** (e.g., Regulatory, Operational, Financial, Reputational) * **Potential Cause:** The driver or cause of the risk as mentioned in the notes. * **Initial Assessment (Inherent Risk):** Note if the discussion mentioned a potential impact or likelihood. If the notes are unclear on a specific column for a given risk, mark it as "[[NOT SPECIFIED]]". **Meeting Notes:** [[PASTE ANONYMIZED MEETING NOTES HERE]]
Draft a Risk Control Description
You are a risk manager writing a description for a control in our GRC platform. The risk is: [Describe the risk, e.g., "Risk of inaccurate transaction monitoring alerts leading to missed suspicious activity."] The control activity is: [Describe the control, e.g., "The AML team performs a quarterly model validation on the transaction monitoring system's rules and thresholds."] Draft a formal, clear, and concise control description (under 75 words). The description should state the purpose of the control, the frequency, and the party responsible for performing it.
Identify Controls for a Specific Regulation
You are a compliance expert mapping controls to regulations. Based on the provided text of [[Name of Regulation]], identify 5-7 key requirements that necessitate a specific internal control. For each requirement, create a bullet point with: * **Requirement:** A brief quote or summary of the regulatory requirement. * **Control Objective:** A one-sentence description of what an internal control would need to achieve to meet this requirement. **Regulation Text:** [[PASTE REGULATION TEXT HERE]]
Draft a New Internal Policy
You are a compliance policy writer. Draft a new internal policy on [Topic, e.g., "Acceptable Use of Employee Social Media Accounts"]. The policy should be structured with the following sections: 1. **Purpose:** Why this policy exists. 2. **Scope:** Who this policy applies to. 3. **Policy Statement:** The core rules and principles. Break this down into clear sub-sections (e.g., "Representing the Company," "Confidential Information," "Personal Responsibility"). 4. **Roles and Responsibilities:** What is expected of employees, managers, and the compliance department. 5. **Violations:** The consequences of not adhering to the policy. The tone should be professional, clear, and easy for all employees to understand. The total length should be approximately 800-1000 words.
Simplify a Complex Policy for Employee Training
You are an instructional designer creating training materials for our company's employees. I am providing the text of our internal [[Name of Policy, e.g., "Anti-Bribery and Corruption Policy"]]. It is dense and legalistic. Your task is to rewrite the key concepts into a simple, easy-to-understand FAQ format. Create 5-7 questions that a typical employee might have, and provide clear, direct answers based on the policy text. Focus on practical, real-world scenarios. For example: "What should I do if a potential client offers me expensive tickets to a sporting event?" **Policy Text:** [[PASTE POLICY TEXT HERE]]
Update a Policy with New Regulatory Language
You are a compliance analyst. Our [[Name of Policy, e.g., "Data Privacy Policy"]] needs to be updated to reflect new requirements from [Name of New Regulation, e.g., "the State of Texas Data Privacy and Security Act"]. I will provide the existing policy and the text of the new regulation. Identify the sections of our policy that need to be changed and suggest revised language that incorporates the new requirements. Present your output as a series of "FIND/REPLACE" blocks. For each suggested change: * **FIND:** Quote the existing sentence or paragraph from our policy. * **REPLACE WITH:** Provide the new, updated text. * **REASON:** Briefly explain why the change is necessary based on the new regulation. **Existing Policy:** [[PASTE POLICY TEXT]] **New Regulation:** [[PASTE REGULATION TEXT]]
Create Scenarios for Code of Conduct Training
You are creating annual Code of Conduct training. Our company is in the [[your industry]] sector. Generate five short, realistic scenarios (100-150 words each) that present an ethical dilemma related to our Code of Conduct. The scenarios should not have obvious "right" answers but should force employees to think critically. Cover topics like: * Conflicts of interest * Gifts and entertainment * Handling of confidential information * Speaking to the media * Use of company assets For each scenario, end with a discussion question, such as "What are the potential risks here?" or "What should [[character name]] do next?".
Generate an Audit 'Request for Information' List
You are an experienced IT auditor. Our company is preparing for an external audit of our [[System or Process, e.g., "customer onboarding process"]]. The audit will be against the [Framework, e.g., "SOC 2 Trust Services Criteria for Security and Availability"]. Based on this scope, generate a comprehensive list of documents and evidence an auditor would likely request. Group the requests by category (e.g., "Policies and Procedures," "User Access Reviews," "Change Management," "System Configuration"). This list will be used internally by our team to gather documentation in advance.
Draft a Control Test Script
You are a compliance testing analyst. I need to design a test for a specific internal control. * **Control ID:** ABC-123 * **Control Description:** [Paste the full control description, e.g., "To ensure the principle of least privilege, user access to the production database is reviewed quarterly by the data owner. Any access that is no longer required is revoked within 5 business days."] * **Test Method:** [[e.g., "Inspection of Records"]] Draft a formal test script with the following sections: 1. **Test Objective:** What this test is intended to verify. 2. **Test Population:** The set of data to be sampled (e.g., "All user access review reports from the past 12 months"). 3. **Sample Selection:** How the sample will be chosen (e.g., "Select the most recent 2 quarterly reviews"). 4. **Test Steps:** A numbered list of specific actions the tester must perform (e.g., "1. Obtain the user access review reports for Q2 and Q3 2026. 2. For each report, verify the signature and date of the data owner. 3. For any access revocation requests noted, obtain the corresponding IT service ticket and verify the revocation was completed within 5 business days."). 5. **Expected Outcome:** The criteria for a successful test.
Summarize Audit Findings from a Report
You are a compliance director preparing a summary for senior leadership. I am providing the executive summary section of a recent internal audit report. Your task is to distill the provided text into a concise, 3-bullet-point summary. Each bullet should represent one key theme or finding. Focus on the business impact and the required actions, not the technical details. Use strong, direct language. **Audit Report Summary:** [[PASTE AUDIT FINDING TEXT HERE]]
Brainstorm Questions an Auditor Might Ask
You are an external regulator preparing to conduct an exam of our firm's [[Process, e.g., "AML transaction monitoring program"]]. Our firm is a [[firm type, e.g., "digital bank"]]. Our program uses an AI-based system from [[Vendor Name]] to flag suspicious activity, which is then reviewed by human analysts. Generate a list of 10-15 challenging questions you would ask the Head of AML Compliance during the exam. The questions should probe for potential weaknesses in the program's governance, model risk management, analyst training, and reporting.
Create an Investigation Plan Template
You are the head of the internal investigations unit. Create a generic, reusable template for an investigation plan. The template should be a markdown document with clear headings and placeholder text instructing the investigator on what information to fill in. Include the following sections: * Case Name & Number * Allegation Summary * Scope of Investigation (What we will and will not investigate) * Key Individuals to Interview * Key Documents/Data to Collect * Proposed Timeline * Communication Plan (Who will be kept informed and when) * Legal/Privilege Considerations
Structure a Final Investigation Report
You are a senior compliance investigator. Based on the following anonymized summary of facts, structure a formal final investigation report. Do not create any new information. Your job is to organize the provided facts into a logical report structure. Create the headings and subheadings, and place the relevant facts under each. The structure should be: 1. **Executive Summary:** (Placeholder for a summary to be written) 2. **Background:** The initial allegation. 3. **Investigative Steps:** A summary of what was done (interviews, data analysis). 4. **Findings of Fact:** A numbered list of established facts. 5. **Analysis & Conclusion:** A section analyzing the facts against the relevant company policy. 6. **Recommendations:** (Placeholder for recommendations) **Anonymized Summary of Facts:** [PASTE A FULLY ANONYMIZED AND SANITIZED SUMMARY OF THE CASE FACTS HERE]
Draft a Board Update on Compliance Metrics
You are the Chief Compliance Officer. Draft the talking points for your quarterly update to the board's Audit & Risk Committee. Use the following (anonymized) metrics to create a short, narrative update. The tone should be objective and data-driven. Highlight both positive trends and areas of concern. * **Policy Exceptions Granted:** [[Number, and trend vs. last quarter]] * **Overdue Employee Training:** [[Percentage, and trend vs. last quarter]] * **Whistleblower Hotline Reports:** [[Number, broken down by category]] * **Time to Close Investigations:** [[Average in days, and trend vs. last quarter]] * **Significant Audit Findings (High Risk):** [[Number]] Structure the update into three parts: 1. Overall health of the compliance program. 2. Key metric highlights and what they indicate. 3. Focus areas for the upcoming quarter.
Analyze Anonymous Hotline Data for Themes
You are a compliance analyst reviewing anonymous data from our employee ethics hotline for the past year. I am providing a list of report categories and the number of reports in each. Your task is to identify the top 3 themes or areas of concern based on this data. Then, suggest one proactive compliance action for each theme. For example, if a top theme is "Conflicts of Interest," a proactive action might be "Launch a targeted training campaign for the sales team on gift and entertainment policies." **Hotline Data:** * Harassment & Discrimination: [[Number]] * Conflicts of Interest: [[Number]] * Bullying/Inappropriate Behavior: [[Number]] * Accounting/Financial Irregularities: [[Number]] * Data Privacy Concerns: [[Number]] * Safety Violations: [[Number]] Present your analysis as three bullet points, with each bullet containing the Theme and the Suggested Action.
Generate Due Diligence Questions for an AI Vendor
You are a compliance officer conducting due diligence on a potential new AI vendor. The vendor provides a [describe service, e.g., "customer service chatbot that will handle customer account inquiries"]. Generate a list of 10-15 specific due diligence questions to send to this vendor. The questions should focus on compliance, security, and data governance risks. Include questions about: * Data handling and encryption (in transit and at rest). * Whether our company's data will be used for training their model. * The vendor's own compliance with regulations like GDPR or CCPA. * Their process for managing and disclosing data breaches. * Their model governance and bias mitigation strategies. * Logic for explainability if the AI makes decisions impacting customers.
Draft a Suspicious Activity Report (SAR) Narrative
You are an experienced AML investigator drafting a SAR narrative. I am providing a set of fully anonymized, structured facts about a subject's activity. Your task is to weave these facts into a clear, chronological, and compelling narrative for Part V of the SAR form. The narrative should be written in the third person and state the facts objectively. Start with an introductory sentence summarizing the nature of the suspicious activity. Then, detail the activity chronologically. End with a concluding sentence explaining why the activity is deemed suspicious. **Anonymized Facts:** * Subject: [[e.g., Corporate entity C-1, est. 2024]] * Activity Period: [[e.g., Jan-Mar 2026]] * Fact 1: [e.g., C-1 received 15 incoming wire transfers from 10 different jurisdictions, all in round dollar amounts just under $10,000.] * Fact 2: [e.g., The stated purpose on all wires was 'consulting services', but C-1 has no public website or business presence.] * Fact 3: [e.g., Within 48 hours of receipt, all funds were wired out to a single account in Jurisdiction X, an area known for high financial crime risk.] * Fact 4: [e.g., Negative news search revealed the owner of C-1 was previously associated with a shell company scheme.] [[PASTE FULLY SANITIZED FACTS HERE]]
Evaluate Marketing Copy for UDAAP/UDAP Risk
You are a compliance officer with expertise in UDAAP (Unfair, Deceptive, or Abusive Acts or Practices) and other consumer protection rules. I am providing a piece of draft marketing copy for a new financial product. Your task is to review this text and identify any words, phrases, or claims that could pose a high risk of being deemed deceptive or unfair. For each issue you find, quote the problematic phrase and explain in 1-2 sentences why it is risky. **Marketing Copy:** [[PASTE DRAFT MARKETING COPY HERE]]
Translate Technical Jargon for a Policy
You are a compliance writer. A subject matter expert from our cybersecurity team has provided the following technical description for our new Data Classification Policy. Your task is to rewrite it in plain English that a non-technical employee can understand. **Technical Text:** "[e.g., All PII and MNPI data at rest must be encrypted using AES-256 bit encryption. Data in transit must be protected via TLS 1.3 or higher. Access is controlled via RBAC, authenticated through our federated identity provider using SAML 2.0.]" Produce a "Plain English Version" of this text.
Create a Sanctions Screening Disposition Checklist
You are a senior sanctions compliance analyst. Create a checklist for junior analysts to use when dispositioning a potential OFAC sanctions match. The checklist should be a series of questions the analyst must answer before clearing an alert or escalating it. It should force them to document their reasoning. Include questions like: * Does the name match exactly, or is it a fuzzy match? What is the match percentage? * Are other identifiers (Date of Birth, Nationality, Passport Number) available and do they match? * Have you reviewed the context of the transaction? Does it involve a sanctioned jurisdiction or entity? * Have you checked the source of the name match against the official OFAC SDN list to rule out a false positive from vendor data? * What is your final conclusion (Apparent Match or False Positive)? * What is the business rationale for your conclusion?

Frequently asked

Are these AI prompts free to use?

Yes. All 25 prompts on this page are free to copy and use with any AI assistant, including ChatGPT, Claude and Gemini. You only need an account with one of those tools to run them.

How do I use these AI prompts for compliance?

Copy the full prompt text with the Copy button, paste it into your AI assistant of choice, and replace any bracketed placeholder — like [Your State] or [Company Name] — with your own details before you send it.

Where do these prompts come from?

Each prompt is pulled from one of Zekai's tested prompt guides. The "From" link under every prompt goes to the full article, which explains the reasoning behind the prompt and how it was tested.

See Zekai first in Google