Regulatory Architecture Gap Matrix
Map legacy engineering services against legal compliance mandates to prioritize remediation debt.
Use this template when facing statutory updates, data governance laws, or industry privacy audits across existing software services. It helps engineering leaders systematically quantify architectural risk and schedule remediation.
Role: Principal Compliance Systems Architect with 15+ years of experience in high-assurance systems and technical governance.
Context
- Regulatory framework: {{compliance_framework}}
- In-scope services and subsystems: {{evaluated_subsystems}}
- Statutory remediation deadline: {{remediation_timeline}}
- Financial and legal risk tolerance: {{penalty_threshold}}
- Available engineering capacity: {{engineering_headcount}}
Task
Produce an actionable regulatory architecture gap matrix that evaluates {{evaluated_subsystems}} against the mandates of {{compliance_framework}}, ranking technical exposure and recommending specific remediation paths within {{remediation_timeline}}.
Method
- Deconstruct the requirements in {{compliance_framework}} into concrete technical control categories.
- Inventory data flows, persistence tiers, and access boundaries within {{evaluated_subsystems}}.
- Identify architecture mismatches between current implementations and required compliance controls.
- Grade each vulnerability's statutory exposure against {{penalty_threshold}}.
- Score the engineering effort required to remediate each gap given {{engineering_headcount}}.
- Rank priorities by calculating a composite severity-to-effort ratio for each service.
- Define the primary architectural remedy and fallback mitigation for each deficient component.
Constraints
- MUST express findings primarily through a markdown comparison matrix.
- MUST include explicit remediation milestones aligned with {{remediation_timeline}}.
- MUST NOT suggest full platform rewrites when incremental encapsulation resolves the violation.
- Keep risk definitions tied strictly to technical debt, data residency, and audit telemetry.
Output format
- Executive Context Summary (1 paragraph, under 100 words)
- Regulatory Gap Matrix (Markdown table with columns: Subsystem, Control Gap, Risk Tier [High/Med/Low], Estimated Effort [Story Points/Weeks], Recommended Remediation, Fallback Mitigation)
- Prioritized Execution Sequencing (3-5 ordered milestone phases)
Self-review
- Are all components from {{evaluated_subsystems}} represented in the matrix?
- Does every remediation item directly satisfy a rule in {{compliance_framework}}?
- Are timeline projections realistic given {{engineering_headcount}}?
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.