General engineering
AuraScore 83/100

Regulatory Architecture Gap Matrix

Map legacy engineering services against legal compliance mandates to prioritize remediation debt.

Use this template when facing statutory updates, data governance laws, or industry privacy audits across existing software services. It helps engineering leaders systematically quantify architectural risk and schedule remediation.

Template

Role: Principal Compliance Systems Architect with 15+ years of experience in high-assurance systems and technical governance.

Context

  • Regulatory framework: {{compliance_framework}}
  • In-scope services and subsystems: {{evaluated_subsystems}}
  • Statutory remediation deadline: {{remediation_timeline}}
  • Financial and legal risk tolerance: {{penalty_threshold}}
  • Available engineering capacity: {{engineering_headcount}}

Task

Produce an actionable regulatory architecture gap matrix that evaluates {{evaluated_subsystems}} against the mandates of {{compliance_framework}}, ranking technical exposure and recommending specific remediation paths within {{remediation_timeline}}.

Method

  1. Deconstruct the requirements in {{compliance_framework}} into concrete technical control categories.
  2. Inventory data flows, persistence tiers, and access boundaries within {{evaluated_subsystems}}.
  3. Identify architecture mismatches between current implementations and required compliance controls.
  4. Grade each vulnerability's statutory exposure against {{penalty_threshold}}.
  5. Score the engineering effort required to remediate each gap given {{engineering_headcount}}.
  6. Rank priorities by calculating a composite severity-to-effort ratio for each service.
  7. Define the primary architectural remedy and fallback mitigation for each deficient component.

Constraints

  • MUST express findings primarily through a markdown comparison matrix.
  • MUST include explicit remediation milestones aligned with {{remediation_timeline}}.
  • MUST NOT suggest full platform rewrites when incremental encapsulation resolves the violation.
  • Keep risk definitions tied strictly to technical debt, data residency, and audit telemetry.

Output format

  • Executive Context Summary (1 paragraph, under 100 words)
  • Regulatory Gap Matrix (Markdown table with columns: Subsystem, Control Gap, Risk Tier [High/Med/Low], Estimated Effort [Story Points/Weeks], Recommended Remediation, Fallback Mitigation)
  • Prioritized Execution Sequencing (3-5 ordered milestone phases)

Self-review

  • Are all components from {{evaluated_subsystems}} represented in the matrix?
  • Does every remediation item directly satisfy a rule in {{compliance_framework}}?
  • Are timeline projections realistic given {{engineering_headcount}}?
AuraScore breakdown
83/100Provisional
Instruction clarity15/15 · Strong

Explicit role, a named task, and discrete steps the model can follow.

Context architecture12/12 · Strong

Background, inputs and variables the model needs before it starts.

Constraint engineering10/12 · Adequate

Hard boundaries — what the model must and must not do.

Output specification6/14 · Thin

A named, field-level shape for the response.

Reasoning structure10/10 · Strong

Ordered work items that force analysis before an answer.

Model compatibility10/10 · Strong

Length and structure that travel across frontier models.

Token efficiency7/10 · Adequate

Signal density — instruction weight without padding.

Reusability7/7 · Strong

Documented variables so the scaffold adapts to new inputs.

Robustness5/5 · Strong

Quality bar, assumptions and behaviour when inputs are thin.

Observed performance1/5 · Thin

How much real usage the template has behind it.

developers
developers-general
research-productivity-operations
compliance
tech-debt
architecture