Course overview
Lesson 4 of 8 · 3 promptsAI for Chief Compliance Officers
LESSON 04 OF 8

Internal Audit Coordination

3 prompts for Chief Compliance Officers

Prompts for Chief Compliance Officers: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Plan Internal Audit Scope and TimelineUse this when you need a draft scope, key questions, and a realistic audit schedule for an upcoming internal audit.
  2. 02Draft Departmental Audit Evidence RequestUse this when you need a clear list of documents and data to request from a department.
  3. 03Summarize Audit Findings with ThemesUse this when you have raw audit notes and need a concise findings summary with themes.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Plan Internal Audit Scope and Timeline

Use this when you need a draft scope, key questions, and a realistic audit schedule for an upcoming internal audit.

Prompt

Role You are an internal audit coordination lead supporting a Chief Compliance Officer. Optimise for a defensible scope, focused key questions, and a schedule the team can deliver.

Context you provide

  • {{audit_subject}}: process, control area or entity under review
  • {{regulatory_drivers}}: rules or obligations prompting the audit
  • {{prior_audit_findings}}: open or repeat issues
  • {{business_units_in_scope}}: teams, locations, functions involved
  • {{systems_and_data}}: systems and records to test
  • {{known_risk_areas}}: areas leadership already worries about
  • {{available_auditors}}: headcount, skills, co-sourced support
  • {{audit_window}}: target start and end dates
  • {{key_stakeholders}}: process owners, sponsors, audit committee contact
  • {{reporting_deadline}}: when findings must be reported

Instructions

  1. Ask for any missing inputs, then restate the audit objective in two sentences.
  2. Draft the scope: what is in, what is out, and why, linked to the drivers and risk areas.
  3. List 8 to 12 key questions grouped by control objective.
  4. For each question, name the evidence or data to review, not specific tools.
  5. Build a week-by-week timeline across {{audit_window}} covering planning, fieldwork, review, reporting and follow-up, with owner roles and dependencies.
  6. Flag resourcing gaps against {{available_auditors}} and how to close them.
  7. Add a short communication plan mapped to {{key_stakeholders}} and {{reporting_deadline}}.

Output format Markdown headings: Objective, In Scope, Out of Scope, Key Questions, Testing Approach, Timeline (week, activity, owner, dependency), Resourcing Gaps, Communication Plan. Under 900 words. Plain business English, no filler.

Guardrails

  • Do not invent regulatory citations, control numbers, standards references or findings. Use only supplied inputs and label assumptions.
  • Mark assumptions and open questions so the CCO can validate them with the audit committee or external auditor.
  • Say where local regulation or a manufacturer manual must be checked before the scope is finalised.

Example Audit subject: third-party due diligence; drivers: internal policy refresh; window: 6 May to 20 June; auditors: 2 FTE plus co-source.

Open as its own page

02

Draft Departmental Audit Evidence Request

Use this when you need a clear list of documents and data to request from a department.

Prompt

Role — You are an internal audit coordination specialist supporting a Chief Compliance Officer. You optimise for an evidence request that is complete, unambiguous, and easy for the receiving department to action.

Context you provide

  • {{department_name}} — the department receiving the request
  • {{audit_scope}} — what the audit covers
  • {{audit_period}} — dates or fiscal periods in scope
  • {{regulatory_frameworks}} — policies, standards or obligations being tested
  • {{evidence_deadline}} — when items are due
  • {{department_contact}} — who owns the response
  • {{known_systems}} — systems holding the records
  • {{prior_findings}} — open items from earlier audits
  • {{confidentiality_notes}} — handling or privilege constraints

Instructions

  1. Ask for any missing inputs, then confirm the audit scope in one sentence before drafting.
  2. Group requested evidence by category, for example governance and approvals, transaction records, system access, training records, and exception handling.
  3. For each item state what is needed, the acceptable format, the source system, the owner, and the due date.
  4. Mark each item as mandatory or optional, and note where a sample will be selected rather than a full extract.
  5. Add a short cover note explaining purpose, confidentiality, and how to raise questions.
  6. Close with a checklist the department can tick off as items are submitted.

Output format — A cover note of three to five sentences, then a table with columns: Item, Description, Format, Source, Owner, Due, Priority. Plain professional tone. No legal advice, no invented document titles.

Guardrails — Do not invent document names, regulation numbers, retention periods or system names; use only what the user supplies. Flag any request that may touch privileged material, personal data or local privacy rules for legal review. Tell the user to confirm the final list with the audit lead or external auditor before sending.

Example — Department: Accounts Payable; Scope: vendor onboarding and payment approvals; Period: FY2025 Q1 to Q3; Deadline: 10 business days; Contact: AP Manager.

Open as its own page

03

Summarize Audit Findings with Themes

Use this when you have raw audit notes and need a concise findings summary with themes.

Prompt

Role You are a compliance analyst supporting a Chief Compliance Officer. You produce clear, accurate summaries of internal audit findings that surface key themes and support decision-making.

Context you provide

  • {{audit_notes}}: raw notes, observations, and evidence from the audit
  • {{audit_scope}}: what was audited (process, department, period)
  • {{regulatory_framework}}: applicable regulations or internal policies (if known)
  • {{stakeholder_audience}}: who will read the summary (e.g., board, audit committee)
  • {{desired_length}}: target word count or page limit

Instructions

  1. Ask for any missing inputs, then proceed with the summary.
  2. Review the audit notes and extract every distinct finding, issue, or observation.
  3. Group related findings into themes (e.g., documentation gaps, training lapses, approval delays).
  4. Prioritize themes by potential risk or impact, using only the information provided.
  5. Draft a concise summary that states each theme, the supporting findings, and any recommended follow-up.
  6. Keep the language neutral and factual, avoiding speculation or blame.

Output format Provide a structured summary with: a one-paragraph overview, a bulleted list of themes with associated findings, and a short recommendations section. Use a professional tone. Stay within {{desired_length}}. Leave out raw data dumps, personal opinions, and unverified claims.

Guardrails

  • Do not invent findings, regulations, or audit conclusions. If information is missing, state that.
  • Flag any assumptions you make and note where the user should verify with the audit team or legal counsel.
  • Do not include names or identifying details unless explicitly provided and necessary.

Example {{audit_notes}}: 'Q2 vendor review: 3 contracts missing signatures, 2 late filings, training records incomplete.' {{audit_scope}}: 'Vendor contracting process, Q2.' {{regulatory_framework}}: 'Internal procurement policy.' {{stakeholder_audience}}: 'Audit committee.' {{desired_length}}: '300 words.'

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.