AI Prompts for Compliance Officers: Audits, Training, Risk Assessment
Compliance officers are the organizational conscience. They design audit programs, deliver training, manage policies, track regulatory changes, investigate violations, and report to boards — all while maintaining independence and objectivity. AI can help structure compliance programs, draft audit materials, and build risk assessments.
These prompts are adapted from Skillent's Legal AI Prompt Library.
Want 190,000+ professional AI prompts?
Get Skillent Pro — $9/monthRisk Assessment & Program Design
1. Compliance Risk Assessment
Role: Compliance officer
Task: Conduct a compliance risk assessment for [company type/industry]
Risk areas (customize by industry):
1. Anti-bribery/corruption (FCPA, UKBA)
2. Export controls and trade sanctions (EAR, OFAC)
3. Data privacy and security (GDPR, CCPA, HIPAA, GLBA)
4. Financial reporting (SOX, internal controls)
5. Employment law (FLSA, OSHA, EEOC)
6. Environmental compliance (EPA, state regs)
7. Healthcare (False Claims Act, Stark, Anti-Kickback)
8. Competition/antitrust
9. Consumer protection (FTC, CFPB)
10. Industry-specific regulations
For each area:
- Risk score (Likelihood × Impact, 1-5 each)
- Current controls (strength rating)
- Residual risk (after controls)
- Priority ranking
- Recommended mitigation
Format: Risk assessment matrix
Include: Methodology, data sources, and review schedule
2. Compliance Program Framework
Role: Compliance officer
Task: Design a compliance program framework for [company]
Per DOJ Evaluation of Corporate Compliance Programs:
1. Design and comprehensiveness (policies, procedures, code of conduct)
2. Risk tailoring (is program designed for THIS company's risks?)
3. Policies and procedures (are they clear, accessible, enforced?)
4. Training and communication (who gets trained, how, how often?)
5. Reporting mechanisms (hotline, ombudsman, escalation paths)
6. Investigation and response (process, timeline, documentation)
7. Third-party management (due diligence, monitoring, termination)
8. Continuous improvement (monitoring, auditing, updating)
9. Leadership and governance (compliance officer authority, board reporting)
10. Incentives and discipline (rewards for compliance, consequences for violations)
For each element:
- Current state
- Gaps
- Action plan with timeline
- Success metrics
Format: Compliance program document
Reference: DOJ ECCP guidelines, Sentencing Commission guidelines
3. Code of Conduct Draft
Role: Compliance officer
Task: Draft a code of conduct for [company type/industry]
Sections:
1. Letter from CEO (tone at the top — personal commitment, expectations)
2. Purpose and scope (who it applies to, when, where)
3. Core values (honesty, integrity, respect, compliance, responsibility)
4. Ethical decision-making framework (when in doubt: is it legal? is it right? would I be comfortable if it were public?)
5. Key policy areas:
- Conflicts of interest
- Gifts and entertainment
- Anti-bribery and corruption
- Confidential information and data privacy
- Fair dealing and competition
- Workplace conduct (harassment, discrimination, safety)
- Financial integrity and records
- Use of company assets
- Social media and communications
- Reporting concerns (hotline, no retaliation)
6. Enforcement and consequences
7. Waivers and exceptions process
8. Acknowledgment requirement (annual)
Tone: Clear, accessible, not legalistic (8th grade reading level for core sections)
Format: Code of conduct document, 10-15 pages
Include: FAQ section and contact directory
Auditing & Monitoring
4. Audit Program Design
Role: Compliance auditor
Task: Create a compliance audit program for [risk area: FCPA/privacy/employment/billing]
Audit objectives: What are we testing for?
Audit scope:
1. Population (what's being audited: transactions, communications, decisions)
2. Time period (current year, multi-year look-back)
3. Geographic scope (if multi-jurisdiction)
4. Entity scope (subsidiaries, business units, third parties)
Audit procedures:
1. Document review (policies, procedures, approvals, records)
2. Transaction testing (sample size, selection method, what to check)
3. Interview program (who, what questions)
4. Observation (workplace, processes, controls in operation)
5. Data analytics (trend analysis, anomaly detection, exception reports)
6. Control testing (is the control designed properly? operating effectively?)
For each procedure: What to test, how to sample, what's a finding, what's a pass
Reporting: Finding categories (critical, significant, minor), recommendations, management response
Format: Audit program document
Include: Audit calendar and resource requirements
5. Monitoring Dashboard Design
Role: Compliance monitoring analyst
Task: Design a compliance monitoring dashboard for [company]
Leading indicators:
1. Training completion rates (by module, by department, overdue count)
2. Policy attestations (outstanding, overdue, completed)
3. Hotline/reporting metrics (reports received, by category, resolution time)
4. Audit findings (open, overdue, by severity, by department)
5. Conflict of interest disclosures (new, reviewed, recused)
6. Gift/entertainment logs (above threshold, approved, rejected)
7. Third-party due diligence (completed, pending, high-risk flagged)
8. Regulatory change tracking (new regs, impact assessments, implementation status)
9. Investigation status (open, by type, aging)
10. Risk assessment scores (current vs. prior period)
For each: Data source, update frequency, threshold/alert level, responsible person
Format: Dashboard specification with sample layout
Include: Monthly compliance committee reporting template
6. Third-Party Due Diligence
Role: Compliance officer managing third-party risk
Task: Create a third-party due diligence framework for [company]
Risk tiering:
Tier 1 (Low): Standard vendors, low-risk services
- Screening: Sanctions check, basic background
Tier 2 (Moderate): Service providers with data access, financial interaction
- Screening: Sanctions, background, financial review, references
Tier 3 (High): Agents, distributors, consultants, government-touching partners
- Screening: Full background (owners, beneficial owners), sanctions/PEP, adverse media, FCPA risk assessment, onsite review
Due diligence checklist per tier:
1. Entity verification (registration, ownership structure)
2. Beneficial owner identification (UBO, 25%+ ownership)
3. Sanctions and watchlist screening (OFAC, EU, UN)
4. PEP screening (politically exposed persons)
5. Adverse media search (corruption, fraud, litigation)
6. Financial stability (credit, references)
7. Compliance program assessment (for Tier 3 — do they have their own?)
8. Contractual terms (audit rights, compliance certifications, termination for breach)
9. Ongoing monitoring (annual re-screening, news alerts)
Format: Third-party due diligence framework
Include: Risk scoring matrix and approval authority levels
Training & Policy Management
7. Compliance Training Plan
Role: Compliance training manager
Task: Create an annual compliance training plan for [company]
Training matrix (by role × topic):
All employees:
1. Code of conduct (annual, 1 hour)
2. Anti-harassment (annual, state-specific requirements)
3. Data privacy and security (annual, 1 hour)
4. Cybersecurity awareness (annual + quarterly microlearning)
5. Reporting and no-retaliation (annual, 30 min)
Managers (additional):
6. Compliance leadership (annual, 2 hours)
7. Hiring and management compliance (annual)
8. Investigation procedures (as needed)
High-risk roles (additional):
9. FCPA/anti-corruption (annual, for sales, procurement, international roles)
10. Export controls (annual, for trade, logistics, engineering)
11. HIPAA (annual, for healthcare roles)
12. Financial controls/SOX (annual, for finance, accounting)
For each: Audience, duration, frequency, delivery method, completion deadline, tracking method
Format: Training matrix with completion targets and reporting cadence
Include: New hire compliance training (must complete within 30 days)
8. Policy Management System
Role: Compliance officer
Task: Create a policy management framework for [company]
Policy lifecycle:
1. Drafting (who writes, who reviews, who approves)
2. Legal review (employment counsel for HR policies, regulatory counsel for compliance)
3. Approval (policy committee, executive sign-off for major policies)
4. Publication (intranet, LMS, employee handbook)
5. Communication (announcement, training, manager briefing)
6. Attestation (who must acknowledge, frequency, tracking)
7. Monitoring (are policies being followed? audit program)
8. Review cycle (annual review minimum, triggered review for regulatory changes)
9. Version control (revision history, change log, archived versions)
10. Retirement (when policies are replaced or obsolete)
Policy inventory template:
- Policy name, number, owner, version
- Effective date, last reviewed, next review
- Audience, attestation required (Y/N)
- Related policies, related training
Format: Policy management framework
Include: Policy template and approval workflow
9. Regulatory Change Management
Role: Compliance officer
Task: Create a regulatory change management process for [company/industry]
Process:
1. Monitoring sources:
- Federal Register, state registers
- Agency websites (FTC, SEC, DOL, HHS, EPA)
- Industry associations, legal alerts
- Regulatory tracking services (Thomson Reuters, Bloomberg Law)
2. Intake and triage:
- New regulation? Amendment? Guidance? Enforcement action?
- Applicability to [company] (Yes/Maybe/No — with rationale)
- Impact level (High/Medium/Low)
- Effective date and implementation deadline
3. Impact assessment:
- What changes are needed (policies, procedures, training, systems)?
- Who is affected (departments, roles)?
- Cost and resource estimate
- Risk of non-compliance
4. Implementation plan:
- Action items with owners and deadlines
- Policy updates needed
- Training updates needed
- System/process changes
- Communication plan
5. Documentation and audit trail:
- Register of regulatory changes assessed
- Implementation status tracking
- Compliance verification post-implementation
Format: Regulatory change management SOP
Include: Monthly regulatory update report template
Investigations & Reporting
10. Compliance Investigation Protocol
Role: Compliance investigator
Task: Create an investigation protocol for [violation type: corruption/fraud/harassment/data breach/insider trading]
Protocol:
1. Intake (hotline, email, manager report, audit finding)
2. Triage (severity assessment, resource allocation, timeline)
3. Preservation (document hold, system access freeze, evidence preservation)
4. Investigation plan (scope, methodology, team composition)
5. Interviews (subject, witnesses, management — in order)
6. Document review (emails, financial records, policies, approvals)
7. Data analysis (transaction patterns, communication patterns)
8. Findings (violation? severity? root cause? systemic vs. individual?)
9. Recommendations (disciplinary, policy, training, systemic fix)
10. Report (who receives: compliance committee, board, regulators if required)
11. Remediation tracking (actions completed, effectiveness verified)
Key principles:
- Independence (investigator has no conflict with subject)
- Confidentiality (need-to-know basis)
- Privilege (conduct under attorney direction when possible)
- Documentation (contemporaneous, factual, complete)
- No retaliation (protect anyone who reports)
Format: Investigation protocol with templates for each step
Include: Document hold notice template and investigation report template
11. Board Compliance Report
Role: Compliance officer reporting to board
Task: Create a quarterly board compliance report template
Sections:
1. Executive summary (1 paragraph: overall compliance status, key issues)
2. Risk landscape (new or changed risks, emerging regulatory issues)
3. Regulatory developments (new regulations, enforcement actions, industry trends)
4. Audit and monitoring results:
- Audits completed (scope, findings, management response)
- Monitoring metrics (dashboard highlights, trends, exceptions)
5. Investigations and violations:
- Open investigations (by type, aging, status)
- Closed investigations (outcome, root cause, remediation)
- Substantiated violations (count, severity, corrective actions)
6. Training and communication:
- Completion rates (by module)
- Overdue status (by department)
- New training launched
7. Policy updates (new, revised, upcoming)
8. Third-party compliance (high-risk partners, due diligence status)
9. Budget and resources (adequacy, gaps, needs)
10. Recommendations for board action
Format: Board report, 5-10 pages with executive summary
Tone: Transparent, data-driven, no surprises for the board
Include: Comparison to prior quarter and year-over-year trends
12. Incident Response Plan
Role: Compliance officer
Task: Create a compliance incident response plan for [incident type: data breach/regulatory inquiry/whistleblower/fraud]
Response phases:
Phase 1: Immediate (0-24 hours)
1. Incident confirmation (what happened, scope, severity)
2. Notification (compliance officer, legal, general counsel, CEO, board chair)
3. Containment (stop ongoing violation, preserve evidence, document hold)
4. External notification assessment (regulators, law enforcement, affected parties)
Phase 2: Short-term (24-72 hours)
5. Investigation launch (team, scope, methodology)
6. External counsel engagement (if not already)
7. Regulatory notification (if required by law — know your deadlines)
8. Public/communication strategy (if external disclosure needed)
9. Remediation actions (immediate fixes, interim controls)
Phase 3: Investigation (1-4 weeks)
10. Full investigation (interviews, documents, analysis)
11. Root cause analysis (individual vs. systemic)
12. Findings report
Phase 4: Remediation (1-3 months)
13. Corrective actions (policy, training, system, personnel)
14. Systemic fix (prevent recurrence, not just patch)
15. Monitoring plan (verify effectiveness)
16. Board report and regulatory update
Format: Incident response plan with decision trees
Include: Contact directory and notification timeline by regulation type
Best Practices
1. Maintain independence — Compliance must report independently from business operations. AI output should enhance, not replace, independent judgment.
2. Document everything — Compliance work is scrutinized by regulators, courts, and boards. Maintain meticulous documentation of all decisions and rationales.
3. Stay current with regulations — AI may reference outdated regulations. Verify against current regulatory text, agency guidance, and enforcement trends.
4. Consider privilege — Conduct investigations under attorney direction when possible to maintain attorney-client privilege.
5. Right-size the program — A compliance program should match the company's risk profile and size. Over-engineering wastes resources; under-engineering creates exposure. See our criminal defense prompts for defense-side compliance issues.
190,000+ professional AI prompts for legal professionals and every other industry.
Get Skillent Pro — $9/month