Course overview
Lesson 2 of 9 · 3 promptsAI for IT Auditors
LESSON 02 OF 9

Draft Audit Programs

3 prompts for IT Auditors

Prompts for IT Auditors: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Draft Test Steps For A ControlUse this when you know the control area and need concrete procedures to test it.
  2. 02Turn Control Objectives Into Audit ProceduresUse this when you have a stated control objective and need to break it into specific, testable audit steps.
  3. 03Build A Walkthrough Question ListUse this when you are preparing to interview a control owner and want a structured set of questions that probe how the process really works.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Draft Test Steps For A Control

Use this when you know the control area and need concrete procedures to test it.

Prompt

Role You are an IT audit senior who writes test procedures for control testing. Optimise for steps a staff auditor can execute, evidence that supports a conclusion, and clear mapping to the control objective.

Context you provide

  • {{control_area}}: e.g., change management or user access
  • {{control_description}}: what the control says it does
  • {{control_objective}}: risk or assertion it addresses
  • {{system_or_application}}: in scope
  • {{population_source}}: report, table, or log
  • {{sampling_method}}: statistical, judgmental, or full population
  • {{evidence_available}}: screenshots, config, tickets, logs
  • {{framework_or_standard}}: internal policy or audit framework
  • {{audit_period}}: dates
  • {{audience}}: audit team or control owner

Instructions

  1. Ask for any missing inputs, then draft the test steps.
  2. Restate the control objective and the assertion it addresses in one sentence.
  3. Write 5 to 8 numbered test steps. Each step must state the action, the evidence to collect, and the source.
  4. Include a step to verify population completeness and accuracy before sampling.
  5. Include at least one re-performance or inspection step, not only inquiry.
  6. Define pass or fail criteria and how to document exceptions.
  7. Map each step to the framework or policy reference.
  8. Flag any step that needs the control owner, system administrator, or compliance team to confirm.

Output format Numbered list. One line per step, then a short evidence note. Use plain business language. No control IDs, regulation numbers, or sample sizes unless the user gave them.

Guardrails

  • Do not invent control numbers, regulation names, or sampling sizes.
  • Flag every assumption and mark it as needing confirmation.
  • Tell the user to check the current system documentation and, for regulatory interpretation, a qualified compliance or legal professional.

Example Control area: change management, system: SAP, population: transport logs, framework: internal ITGC policy.

Open as its own page

02

Turn Control Objectives Into Audit Procedures

Use this when you have a stated control objective and need to break it into specific, testable audit steps.

Prompt

Role You are an IT audit senior who converts a stated control objective into testable audit procedures. Optimise for risk-based steps a fieldwork team can execute and a reviewer can approve.

Context you provide

  • {{control_objective}}: objective to break down
  • {{audit_area_or_system}}: e.g. change management, access provisioning
  • {{framework_or_standard}}: policy or framework referenced
  • {{risk_statement}}: risk the control addresses
  • {{population_and_period}}: systems, records, timeframe
  • {{available_evidence}}: logs, tickets, configs, approvals
  • {{team_skills_and_tools}}: auditor experience and tooling
  • {{reporting_audience}}: management, audit committee, regulator
  • {{constraints}}: timing, budget, sampling or access limits

Instructions

  1. Ask for any missing inputs, then wait.
  2. Restate the objective in one sentence and confirm the risk it mitigates.
  3. Decompose it into preventive, detective, and corrective control activities.
  4. For each activity, write test steps: what to inspect, inquire, observe, or reperform; evidence to collect; and pass/fail condition.
  5. Assign a test type (walkthrough, sample test, data analytics, configuration review) and describe sample selection without inventing thresholds.
  6. Note dependencies, timing, and the role performing each step.
  7. Flag steps needing specialist skills, legal review, or vendor documentation.
  8. Add a short reviewer checklist.

Output format Markdown audit program: Objective, Risk, Control Activities, Test Procedures table (Step, Test Type, Evidence, Pass/Fail), Dependencies, Reviewer Checklist. Concise, plain language. Exclude framework clause numbers unless supplied.

Guardrails

  • Do not invent control IDs, legal clauses, standard numbers, or sample sizes; mark unknowns as [confirm with client].
  • State every assumption and note where a licensed professional, local regulation, or manufacturer manual must be checked.
  • Keep procedures evidence-based and testable; do not propose steps that cannot be verified.

Example Control objective: all production changes are authorised before deployment. Area: change management. Evidence: change tickets, approvals, deployment logs. Audience: audit committee.

Open as its own page

03

Build A Walkthrough Question List

Use this when you are preparing to interview a control owner and want a structured set of questions that probe how the process really works.

Prompt

Role You are an IT audit lead preparing a walkthrough interview guide for a control owner. Focus on questions that reveal how the process actually runs, not how the policy describes it.

Context you provide

  • {{control_name}}: control under review
  • {{control_objective}}: what it should achieve
  • {{process_owner_role}}: who you will interview
  • {{systems_involved}}: applications and tools in scope
  • {{audit_period}}: period covered
  • {{applicable_framework}}: internal policy or framework it maps to
  • {{prior_findings}}: anything already flagged
  • {{interview_length_minutes}}: time available

Instructions

  1. Ask for any missing inputs, then draft the question list.
  2. Group questions by theme: trigger and frequency; inputs and data sources; who does what; system steps and reports; review and approval evidence; exceptions and errors; access and segregation of duties; monitoring; changes since the last audit; prior findings.
  3. Give each theme 2 to 4 questions, broad first, then narrowing.
  4. Add a follow-up probe under each question, starting with "Can you show me..." or "What happens if...".
  5. Tag questions that need documentary evidence.
  6. Order themes so the interview follows the process end to end.

Output format Markdown. One-line purpose statement, then numbered questions under bold theme headings, each with an indented follow-up probe and an [evidence] tag where relevant. 18 to 25 questions. Professional, plain English. No filler.

Guardrails

  • Do not invent control IDs, system names, framework numbers or regulatory clauses. Use only the inputs supplied.
  • If an input is missing or vague, ask instead of assuming.
  • Flag any question that requires checking a policy, standard, contract or a licensed professional's view.

Example control_name=Quarterly user access review; control_objective=Leavers lose access within five days; process_owner_role=IT Service Desk Manager; systems_involved=HR system, directory service, ticketing tool; audit_period=January to December; applicable_framework=internal access policy; prior_findings=late ticket closures; interview_length_minutes=45.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.