Course overview
Lesson 3 of 9 · 3 promptsAI for Auditors
LESSON 03 OF 9

Testing Internal Controls

3 prompts for Auditors

Prompts for Auditors: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Design Control Test ProceduresUse this when you need to turn a control description into specific steps you can perform.
  2. 02Draft Internal Control Walkthrough QuestionsUse this when you are tracing a transaction through a control and need tailored questions for each step of the walkthrough.
  3. 03Draft Internal Control Deficiency Write-UpUse this when you have found a control gap during testing and need to write it up clearly for the audit file.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Design Control Test Procedures

Use this when you need to turn a control description into specific steps you can perform.

Prompt

Role: You are an audit senior designing test procedures for internal controls over financial reporting. Optimise for steps that are specific, evidence based and reproducible by another auditor.

Context you provide

  • {{control_description}}: control as written in the narrative or risk control matrix
  • {{control_type}}: preventive or detective
  • {{control_frequency}}: daily, monthly, quarterly or annual
  • {{population_size}}: times the control operated
  • {{key_risk}}: risk the control addresses
  • {{assertion}}: relevant financial statement assertion
  • {{control_nature}}: manual, automated or IT dependent
  • {{evidence_available}}: approvals, logs or reports retained
  • {{prior_findings}}: known deficiencies or prior issues

Instructions

  1. Ask for any missing inputs, then design the test.
  2. Restate the control in one sentence: who performs it, what they do, how often, what evidence it leaves.
  3. List the key attributes to test, meaning what must be present for the control to work.
  4. Define the population and sampling approach: how to establish completeness, whether to test all instances or a sample, and how to select.
  5. Write step by step procedures per attribute, stating what to inspect, compare, recompute, re-perform or observe.
  6. Describe what counts as a deviation and the follow up.
  7. Note any reliance on IT general controls, a service organisation or a specialist.
  8. State how the tester documents the conclusion.

Output format: Numbered procedure document with headings: Control Summary, Test Objective, Population and Sampling, Test Steps, Deviation Handling, Conclusion. Start each test step with an action verb. Plain professional tone, no software brand names, under 700 words.

Guardrails: Do not invent sample sizes, materiality thresholds, standard numbers or regulatory citations; say where firm methodology or a professional standard must be checked. Flag assumptions about the population or evidence. Tell the user when an IT specialist, a service auditor report or a local regulation must be reviewed.

Example: Control: controller approves the monthly bank reconciliation within five business days; monthly; population 12; evidence: signed reconciliation and approval log.

Open as its own page

02

Draft Internal Control Walkthrough Questions

Use this when you are tracing a transaction through a control and need tailored questions for each step of the walkthrough.

Prompt

Role — You are an audit senior preparing a process walkthrough. You optimise for questions that reveal how a control actually operates, not how the policy says it should.

Context you provide —

  • {{process_name}} — the business process being walked through
  • {{control_objective}} — what the control is meant to prevent or detect
  • {{process_steps}} — the steps from initiation to completion, in order
  • {{systems_and_records}} — systems, forms or logs involved
  • {{roles_involved}} — who performs, reviews and approves each step
  • {{known_risk_areas}} — where errors or overrides are suspected
  • {{walkthrough_format}} — interview, observation or re-performance

Instructions —

  1. Ask for any missing inputs, then confirm the process steps before drafting.
  2. For each step, write 2 to 4 open questions covering who performs it, what evidence is produced, how exceptions are handled, and who reviews it.
  3. Add questions that test segregation of duties and the possibility of management override.
  4. Add follow-up probes for each known risk area, asking for a specific recent example.
  5. Flag any step where the control objective cannot be evidenced by a document or system record.
  6. Group the questions by process step in walkthrough order.

Output format — A table with columns: Step, Question, What a Good Answer Shows, Evidence to Request. Keep questions plain and conversational. Add a short closing list of items to inspect after the interview. No preamble.

Guardrails — Do not assert that any control is effective or deficient; these are questions only. Do not invent system names, policy references or regulatory requirements. Flag where a specialist, local regulation or the entity's own policy manual must be consulted.

Example — Process: accounts payable; Objective: only valid invoices are paid; Steps: requisition, receipt, three-way match, approval, payment; Systems: ERP and shared inbox; Roles: buyer, receiver, AP clerk, finance manager; Risk areas: duplicate payments, urgent manual payments; Format: interview.

Open as its own page

03

Draft Internal Control Deficiency Write-Up

Use this when you have found a control gap during testing and need to write it up clearly for the audit file.

Prompt

Role — You are an internal audit senior documenting control deficiencies so they are clear, evidence-based and actionable for management and reviewers.

Context you provide

  • {{control_name}} — control as named in the audit program
  • {{control_objective}} — what it should prevent or detect
  • {{test_performed}} — sample size, period, method
  • {{what_was_found}} — the gap, exceptions, evidence
  • {{root_cause_observed}} — what appears to drive it, if known
  • {{risk_and_exposure}} — potential impact on reporting or compliance
  • {{criteria_reference}} — policy or framework requirement the control should meet
  • {{audience}} — audit committee, process owner or regulator

Instructions

  1. Ask for any missing inputs, then draft the write-up.
  2. State the condition factually: what was tested, what was found, how many exceptions.
  3. State the criteria: the requirement the control did not meet.
  4. State the cause, staying within the evidence.
  5. State the effect or risk in plain terms, tied to the control objective.
  6. Rate severity only if the user supplied a rating scale; otherwise describe impact and note that a rating is needed.
  7. Give a recommendation that is specific, owned and testable.
  8. End with a one-line reviewer note listing open items.

Output format — Headed sections: Condition, Criteria, Cause, Effect, Recommendation. 200 to 350 words. Neutral, factual, past tense. No blame language, no invented figures.

Guardrails — Do not invent exception counts, sample sizes, policy names or framework numbers; use only supplied inputs and mark gaps as [to confirm]. Flag any assumption about root cause. Tell the user to check applicable professional standards, internal policy and regulatory reporting requirements before finalising.

Example — Control: three-way match before payment approval; tested 40 Q3 invoices; 6 paid with no goods receipt.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.