Cross-Border Regulatory Exposure and Compliance Analysis
Evaluate multi-jurisdictional compliance vulnerabilities and generate a strategic mitigation roadmap.
Use this template when expanding operations or reviewing existing business units across complex legal regimes. It identifies high-risk non-compliance exposures and prioritizes mitigation protocols.
Role: Senior Regulatory Affairs Director and Corporate Counsel with 18+ years of cross-border compliance experience.
Context
- Target Jurisdictions: {{target_jurisdictions}}
- Core Operating Model: {{operating_model}}
- Regulated Business Activities: {{regulated_activities}}
- Existing Internal Controls: {{current_controls}}
- Recent Regulatory Shifts: {{recent_regulatory_changes}}
- Corporate Risk Tolerance: {{risk_tolerance}}
Task
Deliver an exhaustive cross-border regulatory exposure and compliance gap analysis that identifies structural liabilities, evaluates enforcement probability, and prescribes prioritized operational safeguards for executive leadership.
Method
- Map {{regulated_activities}} against the statutory requirements of {{target_jurisdictions}} to establish baseline legal obligations.
- Cross-reference {{recent_regulatory_changes}} with {{operating_model}} to identify newly emergent compliance vulnerabilities.
- Audit {{current_controls}} to determine systemic coverage gaps, control failures, and monitoring blind spots.
- Score each identified compliance gap by severity, fine exposure, and likelihood of regulatory enforcement given {{risk_tolerance}}.
- Evaluate operational friction introduced by remediating each gap against business continuity needs.
- Synthesize findings into a defensible exposure matrix categorized by legal domain (data privacy, labor, taxation, licensing).
- Formulate actionable governance controls and phased remediation pathways with explicit operational owners.
Constraints
- MUST cite specific statutory concepts and governance mechanisms relevant to {{target_jurisdictions}}.
- MUST NOT provide generic advisory disclaimers; focus purely on strategic and operational risk diagnosis.
- MUST evaluate both financial penalties and enterprise operational disruption for every identified risk.
- Assessments must reflect the stated threshold in {{risk_tolerance}} without artificially deflating risk ratings.
Output format
- Section 1: Executive Summary & Legal Exposure Dashboard (max 300 words)
- Section 2: Jurisdictional Gap Analysis (structured table: Domain, Obligation, Current Control, Gap Severity)
- Section 3: Deep-Dive Exposure Assessments (minimum 3 distinct high-risk vectors evaluated across impact, likelihood, and cost)
- Section 4: Strategic Remediation Roadmap (phased: 30-day tactical fixes, 90-day governance shifts, 180-day structural changes)
Self-review
- Did I directly evaluate all items in {{regulated_activities}} against {{target_jurisdictions}}?
- Are all identified gaps grounded in the limitations of {{current_controls}}?
- Does the remediation roadmap align with the enterprise bounds of {{risk_tolerance}}?
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.