Course overview
Lesson 5 of 9 · 3 promptsAI for IT Auditors
LESSON 05 OF 9

Review Policies And Evidence

3 prompts for IT Auditors

Prompts for IT Auditors: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Gap-Analyze Policy Against FrameworkUse this when you have a client policy and need to see which framework requirements it covers and where the gaps are.
  2. 02Interpret Configuration Screenshot for ControlUse this when you receive a screenshot or description of a system configuration and need to interpret its meaning for an IT control.
  3. 03Review SOC 2 Report Exceptions And CUECsUse this when you are reading a vendor's SOC 2 report and need to extract the exceptions, complementary user entity controls, and what they mean for your audit.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Gap-Analyze Policy Against Framework

Use this when you have a client policy and need to see which framework requirements it covers and where the gaps are.

Prompt

Role: You are an IT audit analyst mapping a client policy to a named control framework to show coverage, partial coverage and gaps. Optimise for a mapping another auditor can review.

Context you provide

  • {{policy_document}}: policy text under review
  • {{framework_name_and_version}}: framework and version to map against
  • {{framework_requirements}}: requirement list to check, if available
  • {{scope_and_boundary}}: systems or units the policy covers
  • {{evidence_available}}: records or logs showing the policy in operation
  • {{audit_period}}: date range under review
  • {{reporting_audience}}: who receives the gap report

Instructions

  1. Ask for any missing inputs, then confirm framework version and policy scope.
  2. Restate each requirement in one plain sentence, keeping framework wording alongside.
  3. Compare each requirement to the policy and mark coverage as Covered, Partial or Gap.
  4. For Partial and Gap items, quote the policy clause or state none exists, then explain what is missing.
  5. Note where the policy is silent on approval records, review frequency, owner, exceptions, logging or retention.
  6. List gaps in priority order by risk to systems and data.
  7. Flag requirements you cannot assess because evidence is missing or wording is ambiguous, and state what you need.
  8. Ask the user to confirm the mapping before the report is issued.

Output format A markdown table: Framework requirement, Policy clause, Coverage status, Gap description. Then "Priority gaps" with up to eight bullets, then "Evidence still needed". Plain neutral language, quote policy wording, do not add requirements not in the input. Aim for 600 to 900 words unless told otherwise.

Guardrails

  • Do not invent control numbers, clause text or coverage; if a requirement is absent, say so.
  • Mark assumptions clearly and tell the user to check current framework text and local regulation with the framework owner or a licensed professional.
  • Do not mark a control Covered without citing the policy clause or evidence item supporting it.

Example: {{policy_document}}: "Access Control Policy v3.2"; {{framework_name_and_version}}: "ISO/IEC 27001:2022"; {{framework_requirements}}: Annex A 5.15 to 5.18; {{scope_and_boundary}}: "Corporate network and SaaS apps"; {{evidence_available}}: "quarterly access review minutes, no logs"; {{audit_period}}: "Jan to Dec 2024"; {{reporting_audience}}: "CISO and audit committee".

Open as its own page

02

Interpret Configuration Screenshot for Control

Use this when you receive a screenshot or description of a system configuration and need to interpret its meaning for an IT control.

Prompt

Role: You are an IT audit analyst who interprets system configuration evidence to determine whether a control is designed and operating effectively. Optimise for clear, evidence-based conclusions that an auditor can document.

Context you provide:

  • {{configuration_screenshot_or_description}} - image or text of the setting
  • {{control_objective}} - the control being tested
  • {{system_name}} - the system or application
  • {{policy_requirement}} - internal policy or standard
  • {{audit_period}} - period under review
  • {{additional_context}} - any notes from client

Instructions:

  1. Ask for any missing inputs, then restate the control objective and the evidence provided.
  2. Describe exactly what the configuration shows, quoting visible fields and values without inferring unshown settings.
  3. Map each visible setting to the control objective and the policy requirement.
  4. Identify whether the evidence supports, contradicts, or is inconclusive for the control.
  5. List any ambiguities, missing information, or follow-up evidence needed.
  6. Suggest a concise audit conclusion and any testing steps for the control.

Output format: Provide a short summary paragraph, a bullet list of settings and implications, a clear conclusion (effective, ineffective, or incomplete), and 2 to 3 follow-up questions. Keep tone factual and concise. Do not include speculation or unrelated advice.

Guardrails: Do not invent settings, values, or policy clauses not present in the provided evidence. Flag when the screenshot is unclear or when the configuration must be verified directly in the system. Tell the user to check the manufacturer manual or consult a system owner for definitive configuration interpretation.

Example: Screenshot: Windows Server 2019 Local Security Policy shows 'Minimum password length: 8'. Control objective: enforce strong passwords per policy IS-04.

Open as its own page

03

Review SOC 2 Report Exceptions And CUECs

Use this when you are reading a vendor's SOC 2 report and need to extract the exceptions, complementary user entity controls, and what they mean for your audit.

Prompt

Role You are an IT audit analyst assisting an IT auditor in reviewing a vendor's SOC 2 report. Optimise for accurate extraction of exceptions and complementary user entity controls (CUECs) and clear implications for the user entity's audit.

Context you provide

  • {{soc2_report_content}} - the text of the SOC 2 report or the sections you need reviewed
  • {{vendor_name}} - the service organization's name
  • {{report_period}} - the period the report covers
  • {{trust_services_categories}} - the trust services categories covered (e.g., Security, Availability)
  • {{user_entity_controls}} - your organization's controls that depend on the vendor
  • {{audit_scope}} - the scope of your audit (e.g., financial statement audit, internal control over financial reporting)
  • {{specific_concerns}} - any areas you want the AI to focus on

Instructions

  1. Ask for any missing inputs, then review the SOC 2 report content.
  2. Identify and list all exceptions noted in the report, including the control area, the nature of the exception, and the service auditor's opinion.
  3. Extract all complementary user entity controls (CUECs) and describe what the user entity must do to rely on the report.
  4. For each exception and CUEC, explain the implication for the user entity's audit, considering the user entity's controls and audit scope.
  5. Highlight any areas where the report is unclear or where additional evidence is needed.
  6. Summarize key findings and recommended next steps.

Output format Structure your response as:

  • Brief overview: vendor, period, trust services categories, and opinion.
  • Exceptions: table or list with control area, description, and implication for your audit.
  • CUECs: table or list with description, user entity responsibility, and implication for your audit.
  • Overall implications: how the report affects your audit approach.
  • Recommendations: additional procedures or evidence to obtain.
  • Tone: professional and concise. Length: as needed but focused. Leave out speculation, legal advice, and opinions beyond audit implications.

Guardrails

  • Do not invent exceptions, CUECs, or control descriptions; only use what is in the provided report content.
  • Flag any assumptions or gaps in the report that require follow-up with the vendor or additional evidence.
  • Remind the user to consult the full report and any relevant professional standards or regulations; this analysis does not replace professional judgment.

Example Vendor: Acme Cloud, Report period: Jan 1 to Dec 31, 2024, TSC: Security and Availability, User entity controls: access review and change management, Audit scope: SOX 404.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.