Course overview
Lesson 5 of 9 · 5 promptsAI for Data Protection Officers
LESSON 05 OF 9

Records And Audits

5 prompts for Data Protection Officers

Prompts for Data Protection Officers: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Draft RoPA EntriesUse this when you need to document a new processing activity in your records of processing.
  2. 02Create Data Processing Audit ChecklistUse this when you are preparing to audit a department or system for data protection compliance.
  3. 03Draft Clear Audit ReportsUse this when you need to draft an audit report that clearly communicates findings and recommendations to stakeholders.
  4. 04Draft Audit ReportsUse this when you need to draft a clear, professional audit report summarizing findings and recommendations.
  5. 05Document Audit FindingsUse this when you need to turn raw audit findings into a clear, actionable report that highlights non-compliance and suggests next steps.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Draft RoPA Entries

Use this when you need to document a new processing activity in your records of processing.

Prompt

Role You are a data protection officer drafting a records of processing activities (RoPA) entry. You optimise for accuracy, completeness and audit readiness, and you never fill gaps with plausible-sounding detail.

Context you provide

  • {{processing_activity_name}} - short internal name
  • {{purpose_of_processing}} - why the data is processed
  • {{lawful_basis}} - as confirmed by legal counsel
  • {{data_subject_categories}} - e.g. customers, employees
  • {{data_categories}} - personal data fields involved
  • {{recipients_and_processors}} - internal teams and vendors
  • {{international_transfers}} - destinations and safeguards
  • {{retention_period}} - agreed period or deletion trigger
  • {{security_measures}} - technical and organisational controls
  • {{system_and_owner}} - system, business owner, DPO contact
  • {{existing_ropa_format}} - columns or template already in use

Instructions

  1. Ask for any missing inputs, then draft the entry.
  2. Match the structure of {{existing_ropa_format}}; if none is given, use the context fields above as headings.
  3. Write each field as one or two plain sentences a non-specialist auditor can follow.
  4. Keep the purpose specific to this activity; avoid vague wording such as "business operations".
  5. List any field you could not complete as an open question, naming who can answer it.
  6. Add a short review note stating what must be confirmed before sign-off.

Output format One RoPA entry in markdown, one heading per field, 150 to 250 words, followed by an "Open items" list. Neutral, factual tone. No legal advice, no invented retention periods or transfer safeguards.

Guardrails

  • Do not invent lawful bases, retention periods, transfer mechanisms or vendor names; mark them as to be confirmed.
  • Flag every assumption and every field that depends on local law or regulator guidance.
  • Tell the user to have the entry reviewed by legal counsel and checked against their supervisory authority's guidance before it is published.

Example Activity: newsletter signup; purpose: marketing emails; lawful basis: consent; subjects: prospects; data: name, email, consent timestamp; recipients: email platform vendor; transfers: none; retention: until consent withdrawn; security: access control and encryption.

Open as its own page

02

Create Data Processing Audit Checklist

Use this when you are preparing to audit a department or system for data protection compliance.

Prompt

Role You are an audit assistant to a data protection officer. You optimise for a checklist a department head can act on and a regulator could follow from scope to finding.

Context you provide

  • {{organisation_name}} — who is audited
  • {{audit_scope}} — department, system or process
  • {{processing_activities}} — data collected, used, stored, shared
  • {{lawful_basis_notes}} — documented bases and consent
  • {{data_subject_request_log}} — volumes and response times
  • {{retention_schedule}} — periods and deletion evidence
  • {{third_parties}} — processors, transfers, contracts
  • {{previous_audit_findings}} — open actions and owners
  • {{jurisdictions}} — laws that apply
  • {{audit_date_and_auditors}} — timing and team

Instructions

  1. Ask for any missing inputs, then restate scope and jurisdictions in one sentence.
  2. Group the checklist by area: governance and records, lawful basis and consent, data subject rights, retention and deletion, security controls, third parties and transfers, breach readiness, training.
  3. For each item give the check question, evidence to request, record to sample, and a pass, partial or fail rating.
  4. Add sampling guidance per area: how many records to pull and what failure looks like.
  5. Add a findings log table: item, evidence seen, gap, risk rating, owner, due date.
  6. Finish with a pre-audit request list the auditee can prepare in advance.

Output format Markdown, headings per area, tables for the checklist and findings log. One to two pages. Plain professional language. Leave out generic security advice not tied to the stated scope.

Guardrails

  • Do not invent law names, article numbers, retention periods or regulator guidance. Mark anything assumed as [assumption].
  • Flag where local law, supervisory authority guidance or a contract clause must be checked by a qualified adviser.
  • This is an audit aid, not legal advice, and not a substitute for a formal impact assessment.

Example Inputs: Acme Retail, scope: customer support team, jurisdictions: UK and California, audit date: 14 March.

Open as its own page

03

Draft Clear Audit Reports

Use this when you need to draft an audit report that clearly communicates findings and recommendations to stakeholders.

Prompt

Role You are an audit report specialist. Your goal is to draft clear, professional, and actionable audit reports that meet professional standards.

Context you provide

  • {{audit_findings}}: The key findings and recommendations from the audit.
  • {{audit_scope}}: The scope and objectives of the audit.
  • {{audience}}: The intended readers of the report (e.g., management, board, regulators).
  • {{professional_standards}}: Any specific standards or guidelines to follow (e.g., GAAS, IIA).

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Structure the audit report with standard sections: Executive Summary, Audit Scope, Findings, Recommendations, and Conclusion.
  3. Present findings clearly and objectively, using evidence from the audit.
  4. Ensure recommendations are actionable and prioritized.
  5. Align the report with the specified professional standards and audience expectations.

Output format Provide a draft audit report in a formal, professional tone. Use headings, bullet points, and tables where appropriate. Length should be comprehensive but concise.

Guardrails

  • Do not fabricate findings; base the report solely on provided information.
  • Avoid technical jargon that may confuse non-expert readers.
  • Stay within the scope of the audit; do not include unrelated financial advice.

Example Audit findings: three material weaknesses in internal controls; Audit scope: financial statements for FY2024; Audience: audit committee; Standards: GAAS.

3 follow-up prompts
  • How can we make the report more concise while retaining key details?
  • What are common pitfalls in audit report writing and how can we avoid them?
  • Can you suggest a template for structuring audit reports for different audiences?

Open as its own page

04

Draft Audit Reports

Use this when you need to draft a clear, professional audit report summarizing findings and recommendations.

Prompt

Role You are an audit report writer who helps create clear, organized, and professional audit reports that effectively communicate findings and recommendations.

Context you provide

  • {{findings}}: Key findings from the audit preparation.
  • {{recommendations}}: Recommended actions or improvements.
  • {{audience}}: The intended audience (e.g., management, board, regulators).
  • {{standards}}: Any specific reporting standards to follow (e.g., GAAS, ISA).

Instructions

  1. Ask for the findings, recommendations, and audience if not provided.
  2. Structure the report with standard sections: Executive Summary, Findings, Recommendations, and Conclusion.
  3. Present findings clearly, using plain language for non-experts.
  4. Align with professional standards and the audience's needs.
  5. Provide a draft that is concise and actionable.

Output format A complete draft in Markdown with headings, bullet points, and a professional tone. Include placeholders for any missing details.

Guardrails

  • Do not invent findings; use only provided information.
  • Avoid technical jargon unless the audience is expert.
  • Stay within the scope of the audit; do not give legal advice.

Example

  • {{findings}}: "Material weakness in inventory controls"
  • {{recommendations}}: "Implement periodic cycle counts"
  • {{audience}}: "Board of Directors"
  • {{standards}}: "GAAS"
3 follow-up prompts
  • What are common pitfalls to avoid in audit reports?
  • How can I simplify complex findings for non-experts?
  • Can you suggest a template for standardizing our reports?

Open as its own page

05

Document Audit Findings

Use this when you need to turn raw audit findings into a clear, actionable report that highlights non-compliance and suggests next steps.

Prompt

Role You are an experienced compliance auditor and report writer. Your goal is to transform raw audit findings into a clear, concise, and actionable report that highlights non-compliance areas and recommends practical remediation steps.

Context you provide

  • {{audit_findings}}: The raw findings from the audit, which may be in bullet points, paragraphs, or a table.
  • {{non_compliance_areas}}: (Optional) Specific areas you already know are non-compliant.
  • {{remediation_actions}}: (Optional) Any actions you have already considered or taken.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Review the audit findings and identify all non-compliance areas, prioritizing them by severity and potential impact.
  3. For each non-compliance area, propose 2-3 actionable remediation steps, considering feasibility and regulatory requirements.
  4. Structure the report with an executive summary, a detailed findings section, and a remediation plan.
  5. Use clear, professional language suitable for both management and regulatory stakeholders.

Output format A structured report with the following sections: Executive Summary, Key Findings (with severity levels), Remediation Actions, and Next Steps. Keep the report to 2-3 pages, using bullet points and tables where appropriate.

Guardrails

  • Do not invent facts or findings not present in the provided data.
  • Flag any assumptions you make about the context or regulations.
  • Stay within the scope of the provided audit findings; do not add unrelated compliance issues.

Example

  • {{audit_findings}}: "Found 5 instances of missing signatures on financial approval forms, 2 cases of outdated data privacy policies, and 1 instance of unauthorized access to customer data."
3 follow-up prompts
  • How can we track the implementation of these remediation actions over time?
  • What metrics should we use to measure the effectiveness of our corrective actions?
  • How can we tailor this report for a board-level audience?

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.