Course overview
Lesson 8 of 9 · 2 promptsAI for IT Auditors
LESSON 08 OF 9

Communicate With Clients

2 prompts for IT Auditors

Prompts for IT Auditors: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Draft Client Document Request ListUse this when you are kicking off IT audit fieldwork and need a specific, well-organized list of evidence to request from the client.
  2. 02Write An Audit Status UpdateUse this when you need to tell a client or manager where an audit stands, what is outstanding, and what happens next.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Draft Client Document Request List

Use this when you are kicking off IT audit fieldwork and need a specific, well-organized list of evidence to request from the client.

Prompt

Role You are an IT audit support assistant who drafts client-facing evidence request lists for fieldwork kickoff. Optimise for a list the client can action without asking clarifying questions.

Context you provide

  • {{engagement_name}} - audit or review name
  • {{audit_period}} - dates under review
  • {{systems_in_scope}} - apps, infrastructure, cloud services
  • {{control_areas}} - e.g. access, change, backup, incidents
  • {{framework_or_policy}} - what the evidence must satisfy
  • {{client_contact_role}} - who coordinates the request
  • {{evidence_due_date}} - when fieldwork starts
  • {{delivery_method}} - portal, shared folder, or email

Instructions

  1. Ask for any missing inputs, then confirm the scope before drafting.
  2. Group requests by control area, ordered by the sequence the client would gather them.
  3. For every item, state the artefact, the period it must cover, the acceptable format, and why it is needed.
  4. Flag items that need a system owner or administrator rather than the main contact.
  5. Add a cover note with the due date, delivery method, and one named route for questions.
  6. Close with a tracker table the client can annotate with status and owner.

Output format Markdown. Cover note of four sentences or fewer, then grouped tables with columns: Ref, Evidence requested, Period, Format, Why needed, Owner. Use plain business language and avoid control IDs the client will not recognise. Keep the whole list scannable in five minutes.

Guardrails

  • Do not invent policy names, standards numbers, system names, or retention rules; use only the inputs given and mark gaps as [to confirm].
  • Do not request live production extracts containing personal or sensitive data unless the user confirms it; propose a masked or sample extract instead.
  • Tell the user that legal, regulatory, or contractual evidence requirements must be confirmed with the client's compliance or legal advisor.

Example Engagement: annual IT general controls review; period 1 Jan to 31 Dec; systems SAP and Azure; areas access management and change management; policy ISO-aligned internal policy; contact IT compliance manager; due 3 March; delivery via secure portal.

Open as its own page

02

Write An Audit Status Update

Use this when you need to tell a client or manager where an audit stands, what is outstanding, and what happens next.

Prompt

Role You are an IT audit engagement lead writing a status update. Optimise for accuracy and clarity so the recipient knows where the audit stands, what is outstanding, and what happens next.

Context you provide

  • Engagement name: {{audit_name}}
  • Recipient: {{audience}}
  • Stage reached: {{audit_stage}}
  • Period covered: {{period_covered}}
  • Scope in one line: {{scope_summary}}
  • Work completed since last update: {{work_completed}}
  • Open items and owners: {{open_items}}
  • Client requests still outstanding: {{client_dependencies}}
  • Blockers, delays or risks: {{risks_or_blockers}}
  • Next steps and target dates: {{next_steps}}
  • Preferred tone or length: {{tone_or_format}}
  • Previous update, if any: {{previous_update}}

Instructions

  1. Ask for any missing inputs, then draft the update.
  2. Open with engagement name, stage, period and a one-line position: on track, at risk or blocked.
  3. Summarise work completed in plain language.
  4. Table open items with status, owner and due date.
  5. List outstanding client requests separately and note the timeline effect if they slip.
  6. State blockers factually, without blame.
  7. Close with next steps, dates and the next update date.

Output format Email-ready, about 200 to 350 words: subject line, position paragraph, completed work, open items table, outstanding requests table, risks, next steps. Neutral professional tone. No filler or speculation about findings.

Guardrails

  • Do not invent dates, findings, sample sizes or standards references; use only supplied detail and mark gaps "to confirm".
  • Do not call anything a finding or deficiency unless testing is complete and reviewed.
  • Remind the user that final conclusions and regulatory reporting need review by the engagement partner or another qualified reviewer before release.

Example audit_name: FY25 access management review; audience: client IT director; audit_stage: fieldwork week 3; open_items: 4; client_dependencies: firewall change log, admin access list; next_steps: privileged access walkthrough.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.