PromptBase
Upgrade
Close icon
General
Home
Marketplace
Create
Hire
Login
Chat
Sell
Explore

Prompt Details

Model
(gemini-3.6-flash)
Token size
908
Example input
[INSERT SYSTEM ARCHITECTURE, AI USE CASE, DATA FLOW, OR BUSINESS PROCESS HERE]: SaaS recruitment platform analyzing candidate PDF resumes to generate suitability scores via OpenAI API. Hosted on AWS Frankfurt (EU-Central-1). Company size: 8 employees. [INSERT ANY SPECIFIC COMPLIANCE PREFERENCES OR LEAVE BLANK]: Focus on candidate bias, automated decision-making risks, and GDPR/EU AI Act alignment.
Example output
## SECTION 1: EXECUTIVE COMPLIANCE DASHBOARD - System Name & Core Scope: AI Candidate Matcher & Resume Parser - EU AI Act Risk Tier: HIGH-RISK | Justification: Annex III, Point 4(a) (AI systems intended to be used for recruitment or selection of natural persons). - NIS2 Sector & Entity Status: Out of Scope | Justification: Below threshold criteria for micro-enterprises (<10 employees and <€2M turnover). - Overall Audit Risk Score: HIGH - Key Audit Assumptions: AWS infrastructure utilizes default SSE-S3 encryption; no fine-tuning performed on candidate resumes; OpenAI API calls enforce Zero Data Retention (ZDR). --- ## SECTION 2: COMPLIANCE & THREAT AUDIT MATRIX | Risk ID | Threat & Gap Description | Regulation & Article | Risk Score (1-5) | Mandated Mitigation Control | Required Audit Deliverable | |---|---|---|---|---|---| | GAP-01 | Algorithmic Bias in Automated Candidate Scoring | EU AI Act Art. 10(2) | 5 | Implement automated disparate impact metrics for age, gender, and ethnicity proxies | Bias Audit & Fair-ML Benchmark Report | | GAP-02 | Absence of Human Oversight in Hiring Decisions | EU AI Act Art. 14 | 4 | Build UI controls requiring mandatory recruiter review before final rejection | Human Oversight Operational Procedure | | GAP-03 | Unvalidated Third-Party API Data Transfer | GDPR Art. 28 / EU AI Act Art. 28 | 4 | Enforce Enterprise DPA with ZDR terms and TLS 1.3 encryption in-transit | Executed Data Processing Agreement (DPA) | | GAP-04 | Missing Fundamental Rights Impact Assessment | EU AI Act Art. 27 | 3 | Complete FRIA addressing potential discrimination and worker data rights | Signed Fundamental Rights Impact Assessment | | GAP-05 | Inadequate Audit Trail for Automated Profiling | EU AI Act Art. 12 | 4 | Deploy immutable CloudWatch logging for model inputs, prompts, and score outputs | Centralized Immutable Audit Log Architecture | --- ## SECTION 3: STRATEGIC COMPLIANCE ROADMAP ### Phase 1: Critical & High-Risk Remediation (Days 1–30) - Execute Zero Data Retention DPA with OpenAI and enforce TLS 1.3 in-transit for all API endpoints. - Integrate mandatory Human-in-the-Loop review buttons in the UI for candidate rejections. ### Phase 2: Technical & Policy Implementation (Days 31–90) - Build automated bias-detection scripts testing resume evaluation outputs against protected demographic classes. - Draft EU AI Act Annex IV Technical Documentation detailing system architecture and dataset constraints. ### Phase 3: Audit Readiness & Verification (Days 91–180) - Conduct third-party algorithmic bias evaluation using representative synthetic test pools. - Complete EU Declaration of Conformity and register system in the official EU AI Database.
♊️ Gemini

Nis2 Act Compliance Auditor

Add to Cart
Instant accessInstant access
Usage rightsCommercial use
Money-back guaranteeMoney‑back
By purchasing this prompt, you agree to our terms of service
GEMINI-3.6-FLASH
Tested icon
Guide icon
4 examples icon
Free credits icon
Turn raw architecture notes or business process descriptions into an enterprise-grade compliance matrix. This prompt analyzes your IT infrastructure or AI system against EU AI Act, NIS2, and DORA requirements. It instantly highlights regulatory gaps, calculates risk levels, specifies audit evidence, and provides actionable mitigation steps. Perfect for IT consultants, CISO advisors, and legal-tech specialists needing fast, structured compliance assessment reports.
...more
Added 4 days ago
Report
Browse Marketplace