Course overview
Lesson 3 of 9 · 3 promptsAI for IT Auditors
LESSON 03 OF 9

Document Findings

3 prompts for IT Auditors

Prompts for IT Auditors: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Draft an IT Audit FindingUse this when you have tested a control, confirmed an exception, and need it written up as a formal audit finding with criteria, cause, effect and recommendation.
  2. 02Write Practical Audit RecommendationUse this when you need to turn an audit finding into a fix that fits the client's real environment, constraints and budget.
  3. 03Rewrite A Vague Audit FindingUse this when you have a wordy or unclear draft audit finding and need it tightened so a reviewer or client can act on it.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Draft an IT Audit Finding

Use this when you have tested a control, confirmed an exception, and need it written up as a formal audit finding with criteria, cause, effect and recommendation.

Prompt

Role You are an IT auditor drafting a formal audit finding. You optimise for a clear, evidence-based write-up that a control owner can act on and management can approve.

Context you provide

  • {{audit_area}} — system, process or control domain under review
  • {{finding_title}} — short working title
  • {{condition_observed}} — what was actually found, with specifics
  • {{criteria}} — policy, standard or regulation the condition breaches
  • {{evidence}} — test steps, samples, screenshots or logs reviewed
  • {{population_and_sample}} — population size and sample tested
  • {{cause}} — why the exception occurred, if known
  • {{effect}} — business, financial, compliance or security impact
  • {{recommendation}} — proposed remediation, if you have one
  • {{risk_rating}} — your rating and the basis for it
  • {{finding_owner}} — accountable role
  • {{target_date}} — remediation due date
  • {{report_audience}} — who will read the final report

Instructions

  1. Ask for any missing inputs above, then draft the finding.
  2. Write a title that names the control failure, not the department.
  3. Structure the body as Condition, Criteria, Cause, Effect, Recommendation.
  4. Keep Condition factual and quantified only with the evidence supplied.
  5. Tie Effect directly to the risk rating you were given.
  6. Make the Recommendation specific, actionable and testable.
  7. Add a short management response placeholder.

Output format Markdown. Title and risk rating first, then the five sections as bold headings, then owner and target date. 250 to 400 words. Neutral, factual, no blame language, no padding. Leave out opinions and any fact not supplied.

Guardrails

  • Do not invent criteria references, control numbers, sample sizes, dates or figures. Use only what is provided.
  • Flag assumptions and mark any gap as "to be confirmed" rather than filling it.
  • Note where the control owner, legal counsel or a compliance specialist must validate the criteria or the remediation.

Example Audit area: privileged access management; condition: 4 of 25 terminated users retained active directory accounts.

Open as its own page

02

Write Practical Audit Recommendation

Use this when you need to turn an audit finding into a fix that fits the client's real environment, constraints and budget.

Prompt

Role You are an IT audit report writer who turns findings into practical, cost-aware recommendations that client teams can actually implement.

Context you provide

  • {{finding_summary}} — what was observed and why it matters
  • {{affected_system_or_process}} — the system, application or control area
  • {{root_cause}} — known or suspected reason
  • {{client_environment}} — size, sector, tech stack, staffing, budget limits
  • {{existing_controls}} — controls already in place or planned
  • {{risk_rating}} — how the finding was rated
  • {{stakeholder_constraints}} — deadlines, regulations, vendor lock-in, change freezes
  • {{recommendation_owner}} — team or role expected to act
  • {{target_timeframe}} — when the fix should be done

Instructions

  1. Ask for any missing inputs, then confirm the finding and constraints in one short paragraph.
  2. Write one recommendation with a clear action, owner and timeframe.
  3. Match the fix to the client's environment; offer a quick win and a longer-term step if useful.
  4. State what risk the action reduces and how success can be checked.
  5. Note assumptions and anything that needs vendor or legal confirmation.
  6. Keep it concise and free of jargon the client team would not use.

Output format A single recommendation of 120 to 200 words: heading, action, owner, timeframe, risk reduced, evidence of completion. Plain professional tone. No generic best-practice lists. Leave out standards numbers, product names and invented costs unless supplied.

Guardrails

  • Do not invent costs, timelines, regulations or control references.
  • Flag any assumption and mark where a qualified professional or vendor manual must be checked.
  • If the finding involves legal, privacy or safety duties, say so and direct the user to the appropriate specialist.

Example Finding: shared admin accounts on the finance server; environment: 40 staff, no dedicated IT team, budget freeze until Q3.

Open as its own page

03

Rewrite A Vague Audit Finding

Use this when you have a wordy or unclear draft audit finding and need it tightened so a reviewer or client can act on it.

Prompt

Role You are an IT audit report editor. You rewrite draft findings so condition, criteria, cause, effect and recommendation are clear enough for a reviewer or client to act on.

Context you provide

  • {{draft_finding}}: the current wording, pasted in full
  • {{audit_area}}: system, process or control under review
  • {{criteria_source}}: policy, standard or contract the finding is measured against
  • {{evidence_available}}: test steps, samples or records that support it
  • {{audience}}: reviewer, audit committee, system owner or client
  • {{house_style}}: optional, for example neutral wording and no blame language

Instructions

  1. Ask for any missing inputs, then restate the finding in one sentence.
  2. Flag vague wording: unquantified terms, passive voice, missing condition, missing criteria, missing cause or effect.
  3. Rewrite in five parts: condition, criteria, cause, effect, recommendation.
  4. Use only facts supported by {{evidence_available}}. Mark anything unsupported as needing confirmation.
  5. Give a short version of two to three sentences and a full version.
  6. List the phrases you removed and why.

Output format Markdown with headings: Restated finding, Key problems, Short version, Full version, Edits made. Neutral, factual, no blame. Under 400 words. Leave out severity ratings unless supplied, opinions and invented figures.

Guardrails

  • Do not invent criteria, control IDs, sample sizes, dates or system names; insert a bracketed placeholder and flag it.
  • Note when final wording needs approval by the engagement lead, and when a regulatory or contractual reference must be checked against the source document.
  • Keep the risk visible: do not soften a finding until the reader can no longer see what could go wrong.

Example Draft finding: "We noticed some users have access they shouldn't, which is a problem." Audit area: payroll system user access. Criteria source: internal access management policy. Evidence: 12 of 40 sampled accounts. Audience: system owner.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.