Gains:
- Ability to translate a regulation or standard into an actionable compliance checklist
- Ability to put each requirement into an auditable table with responsible role, evidence and fulfillment status
- Ability to configure compliance gaps (gap analysis) and corrective action plan
A regulation, standard or policy text alone is useless; It is necessary to translate it into concrete controls that the organization can implement every day. The sentence "We will comply with KVKK" is an intention; "A legal basis record will be kept for each data processing activity, the Data Protection Officer is responsible, and the evidence processing inventory" is a control. Artificial intelligence (AI) is very fast at turning long, abstract regulatory texts into auditable checklists and gap analyses. In this unit, we will learn how to translate a regulation into an enforceable compliance framework, charting each requirement with the responsible-evidence-situation triad, and connecting gaps to a corrective action plan.
Let's clarify the terms. Compliance is the fulfillment of the requirements of the laws, regulations and standards to which the institution is subject. Control is a concrete measure implemented to reduce a risk or meet a requirement. Evidence is a document/record (log, signed form, screenshot) that shows that a control was actually implemented. Gap analysis is the study that reveals the difference between "what should be" and "the current situation". Corrective action plan (CAP) is a plan that answers the questions of who, what and when to close the identified gaps.
Turning Organization into a Checklist
What makes an abstract text controllable is breaking it down into “requirement → responsible → evidence → situation.” If you give the AI this structure, it will translate each sentence of the edit into a followable line. Step by step:
- Identify the source and scope. Which regulation, which departments, for which units.
- Parse the requirements. Each "must/provide" statement is a separate requirement line.
- Assign a responsible role. Every necessity must have an owner; orphan control is not applied.
- Identify evidence. What will indicate that this requirement has been met?
- Assess the situation. It is met / partially / not met.
- Connect the spaces to the action. Corrective step for each vulnerability with a responsible and date.
Your role: a compliance expert. Transform the following regulatory text into an auditable checklist. Output table:| No | Requirement (text-based) | Source (article/chapter) | Responsible role (recommendation) | Expected evidence | Condition (leave blank) |Rules:- Make each "must/provided" statement separate line; concatenation.- Give responsible role and evidence as SUGGESTION, add note "must be verified".- Fitting requirement not in text; don't comment.<edit>[edit or canon text]</edit>
Tip: Adding an “expected evidence” column to each requirement transforms the checklist from a wish list to an auditable tool. It is not enough to say "we are sleeping" in the audit; You should be able to say "here is the proof". Defining the evidence from the beginning ensures that you are always ready for the audit.
Gap Analysis and Corrective Action
The checklist tells you "what should happen"; Gap analysis shows "where we are not". You give the AI the current status (current policy, implementation, registration) and compare it with the requirements.
Below are the compliance requirements on the left, and the CURRENT status of our organization on the right. Produce a gap analysis table:| Necessity | Current situation | Space (present/absent/partial) | Risk level | Recommended corrective action | Responsible (suggestion) | Target duration (recommendation) | Sort spaces by risk level (high/medium/low). If the evidence is currently unclear, write "evidence confirmation required"; fabrication.<requirements>[...]</requirements><current_status>[...]</current_status>
Adaptation work is not done once and finished; It requires regular repetition. AI is also helpful in producing a periodic self-assessment survey or set of internal audit questions.
From the checklist above, produce a self-assessment survey for unit managers to complete quarterly. For each requirement: yes/no/partially option, “link to evidence” field, and “last reviewed” field. Keep the survey short and clear; Simplify legal jargon.
In institutions that are subject to more than one regulation at the same time, matching the equivalents of the same control in different regulations (control mapping) provides great efficiency. A single piece of evidence may meet multiple requirements; Seeing this reduces both workload and repetition.
Below are the requirements of two different regulations. Match common or overlapping controls:| Joint control | Regulation A requirement | Regulation B requirement | Is it satisfied by single evidence |Match only those that actually overlap; do not force similarities. List non-overlapping requirements specific to each regulation separately.
Weak Prompt / Strong Prompt
Weak prompt:Make a checklist for compliance with this regulation.
Result: A list of abstract article titles with no responsible, no evidence and no status. It is unclear who will do what and how we will show that we comply; cannot be tracked.
Powerful prompt: [compliance expert role + requirement-responsible-evidence-situation table + "separate line for each should be done" + evidence column + gap analysis with current situation + risk ranking + corrective action + responsible/date]
Conclusion: The owner of every necessity, the evidence and the situation; An auditable framework that ranks gaps by risk and links them to corrective action.
Maturity Levels of Compliance Control
Level
symptom
problem
intention
"We will comply" he says
Intangible, untraceable
List
Requirements written
responsible/no evidence
control
Responsible + evidence defined
Status not measured
auditable
Situation + gap + action
Periodic repetition or it will get old
Continuous
Quarterly self-assessment
ideal target
Three Mini Cases
Case 1 — Audit readiness. A fintech company divided a 60-page regulation into 84 lines of requirements with AI before a regulatory audit; added responsible role and expected evidence to each line. The team recognized 17 requirements for which there was no proof and prepared the documentation. In the audit, "how do you meet this requirement?" They answered their questions with a folder of evidence; The audit duration was reduced from an estimated 5 days to 3 days, and no significant findings emerged.
Case 2 — Hidden cavity. When a manufacturing company analyzed its occupational health and safety requirements, it discovered that the last drill was held 19 months ago, even though it thought that the "emergency drill should be held once a year" requirement was met. AI's "evidence verification required" flag exposed this gap. The company planned the exercise and calendared the period; It closed the risk of liability that would aggravate in the event of a work accident.
Case 3 — From abstract to concrete. An organization thought it had been implementing a policy stating "ethical principles are followed" for years, but it had no control. With AI, the policy was translated into 22 concrete controls (gift registration, conflict of interest declaration, training completion); Each was assigned responsibility and evidence. In the first quarterly self-assessment, only 41% of controls were proven; Within a year, this rate was increased to 88%. Abstract intention turned into a measurable program.
Common mistakes
- Making lists responsibly and without evidence. The unclaimed and evidence-free requirement is unenforceable and useless in the audit.
- Combining the requirements. If there is more than one "must do" in a line, it becomes impossible to keep track; Each should be a separate line.
- Saying "we are sleeping" without verifying the current situation. Assumed compliance without proof verification means hidden loophole.
- Not connecting gaps to action. Gap analysis becomes shelf decoration without an accountable and dated corrective plan.
- Do it once and leave it at that. Harmony requires periodic repetition; If a self-evaluation cycle is not established, the framework becomes obsolete.
- Assuming that the responsible/time period suggested by the AI is certain. Roles and durations are suggestions; People must approve it according to the structure of the institution and the legislation.
In summary
Compliance is the task of translating abstract regulations into concrete, owned and evidenced controls. AI speeds up this translation: breaking the regulation down into requirement-responsible-evidence-status lines, comparing it to the current state, revealing gaps, and linking it to corrective action. But every responsible, evidence and time proposal must be verified by man; The current situation should be confirmed with evidence and the framework should be repeated periodically. AI produces the checklist and gap analysis; The competent professional decides whether compliance has actually been achieved and who is responsible.
Application task
Select a regulation or standard that concerns your organization. (1) Turn it into a requirement-responsible-evidence-situation table with the checklist prompt; Verify that each "should" is a separate line. (2) Enter the current situation and produce a gap analysis and rank the gaps in risk order. (3) Define corrective action with responsibility and date for the 3 highest risk gaps. (4) Produce and schedule a quarterly self-assessment survey.
checklist
- [ ] Is each requirement parsed as a separate line?
- [ ] Has the responsible role and expected evidence been assigned to each requirement?
- [ ] Has the status (met/partial/not met) been evaluated?
- [ ] Is the current situation confirmed (not assumed) by evidence?
- [ ] Have the gaps been ranked in order of risk and linked to corrective action?
- [ ] Have the responsible and time recommendations been approved by the human?
- [ ] Has a periodic self-evaluation cycle been established?