Compliance Checks
Check a document against specific requirements and cite the provision behind each finding.
What you'll need
- Document to review
- Applicable regulations/policies
- Compliance checklist
- Prior findings (if any)
- Regulatory guidance documents
Put it to work
Save these instructions in a Claude Skill or Project, or in a ChatGPT Project or Custom GPT. Add your context, run the sample prompt, and check the result against your team's standards before anyone relies on it.
Reusable playbook
Learn the method, adapt the details, then put it to work.
Start here
Reusable instruction — Claude: save as a skill file at ~/.claude/skills/legal/compliance-review.md · ChatGPT: paste into a Custom GPT's instructions or a Project.
Give the AI a clear role
You are a compliance operations assistant who maps a provided document to provided requirements and drafts possible gaps for review by a qualified compliance or legal professional. You do not make a final compliance determination.
Required Boundaries
- Use current, authoritative requirements supplied or explicitly approved for research; record jurisdiction, version, and access date.
- Cite the exact requirement and document passage behind every finding. Mark missing or conflicting authority as unresolved.
- Label conclusions "Draft for Qualified Review" and separate observed text from interpretation.
- Do not represent the organization to a regulator, approve remediation, file anything, or claim legal compliance.
Bring the right context
- {{regulations_path}} - Applicable regulations/policies
- {{checklist_path}} - Compliance checklist
- {{guidance_path}} - Regulatory guidance documents (optional)
- Document to review
- Applicable regulations/policies
- Prior findings (if any)
- Specific compliance areas to focus on
Run the method
Given a document to review
- 1
Requirement Mapping
- Identify applicable regulations
- Map document sections to requirements
- Note gaps in coverage
- 1
Potential Gap Assessment
- Check each requirement
- Cite specific regulation sections
- Document evidence relevant to the requirement
- Flag potential gaps for qualified review
- 1
Remediation Guidance
- Specific fixes needed
- Priority ranking
- Sample language if helpful
04Preview the deliverableSee the shape of a strong answer before you run the workflow.
Draft Requirement-Mapping Review: [Document Name]
Status: Draft for Qualified Compliance/Legal Review — Not a Compliance Determination Document Type: [Type] Applicable Regulations: [List] Review Date: [Date] Overall Status: No Gap Observed in Provided Requirements / Potential Gap / Unresolved / Needs Qualified Review
Requirement Coverage Matrix
- Requirement
- Privacy notice
- Reg Citation
- GDPR Art. 13
- Document Section
- Section 3
- Status
- OK
- Requirement
- Data retention
- Reg Citation
- GDPR Art. 5(1)(e)
- Document Section
- Not addressed
- Status
- Missing
| Requirement | Reg Citation | Document Section | Status |
|---|---|---|---|
| Privacy notice | GDPR Art. 13 | Section 3 | OK |
| Data retention | GDPR Art. 5(1)(e) | Not addressed | Missing |
Detailed Findings
Finding 1: Missing Data Retention Disclosure
Severity: High Regulation: GDPR Article 5(1)(e), Article 13(2)(a)
Requirement:
"Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary..." (Art. 5(1)(e)) "The controller shall provide the data subject with...the period for which personal data will be stored..." (Art. 13(2)(a))
Current State: Document does not address how long personal data is retained.
Remediation:
Add section specifying
- Retention periods by data category
- Criteria used to determine periods
- Process for deletion after retention
Sample Language: "We retain your personal data for as long as necessary to provide our services and fulfill the purposes described in this policy. Specifically: [table of retention periods by category]"
Finding 2: [Title]
...
Compliance Summary
- Category
- Privacy
- No Gap Observed
- 8
- Potential Gap
- 2
- Unresolved
- 1
- N/A
- Category
- Security
- No Gap Observed
- 5
- Potential Gap
- 0
- Unresolved
- 0
- N/A
| Category | No Gap Observed | Potential Gap | Unresolved | N/A |
|---|---|---|---|---|
| Privacy | 8 | 2 | 1 | |
| Security | 5 | 0 | 0 |
Remediation Priority
- #
- 1
- Finding
- Data retention
- Effort
- Low
- Risk
- High
- Priority
- Immediate
- #
- 2
- Finding
- [Finding]
- Effort
- Med
- Risk
- Med
- Priority
- This quarter
| # | Finding | Effort | Risk | Priority |
|---|---|---|---|---|
| 1 | Data retention | Low | High | Immediate |
| 2 | [Finding] | Med | Med | This quarter |
Try this prompt
Review our privacy policy against GDPR requirements: [Paste privacy policy] Check specifically for: - Article 13/14 disclosure requirements - Legal basis documentation - Data subject rights information - International transfer disclosures - Contact information for DPO Cite specific GDPR articles for any findings.
Before you trust the output
- Keep regulation database current
- Link to official regulatory text
- Require qualified review before any compliance conclusion, remediation approval, or filing
Your next step
Want this workflow to run reliably every week?
Bring Compliance Checks to our free live workshop. We'll show you how to turn the reusable instructions into a working AI Agent Skill—without writing code.