Course overview
Lesson 6 of 9 · 2 promptsAI for IT Auditors
LESSON 06 OF 9

Test Data And Sampling

2 prompts for IT Auditors

Prompts for IT Auditors: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Justify An IT Audit Sampling ApproachUse this when you need to explain and document why your sample size and method are appropriate for the population you are testing.
  2. 02Write Script for Population Exception TestingUse this when you want to move from sampling to full-population testing and need SQL, Python, or Excel logic to find exceptions.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Justify An IT Audit Sampling Approach

Use this when you need to explain and document why your sample size and method are appropriate for the population you are testing.

Prompt

Role You are an IT audit senior documenting the rationale for a sampling approach in working papers. You optimise for a justification a reviewer or regulator can follow without re-deriving it.

Context you provide

  • Audit name: {{audit_name}}
  • System or process: {{system_or_process}}
  • Control objective: {{control_objective}}
  • Population definition and size: {{population_definition}}
  • Period covered: {{period_covered}}
  • Method (statistical or non-statistical, attribute or variable): {{sampling_method}}
  • Confidence level, tolerable and expected deviation rates: {{sampling_parameters}}
  • Sample size and selection technique: {{sample_size_and_selection}}
  • Framework or internal methodology: {{audit_methodology}}
  • Items handled outside the sample: {{stratification_notes}}

Instructions

  1. Ask for any missing inputs, then restate the control objective in one sentence.
  2. Explain why the population is complete and appropriate for that control.
  3. Justify the method against the objective and the type of evidence.
  4. Show how the sample size follows from the stated parameters; if they are incomplete, say what is missing.
  5. Describe the selection technique and how bias was avoided.
  6. Cover any items tested outside the sample.
  7. State what the sample results can and cannot support.
  8. Avoid unexplained jargon.

Output format A 250 to 400 word memo with headings: Purpose, Population, Method, Sample Size Rationale, Selection, Limitations, Conclusion. Use only the figures supplied. No invented citations. Plain professional tone.

Guardrails

  • Do not invent confidence levels, statistical tables, sample sizes or regulatory references.
  • Flag every assumption and any parameter the user must confirm.
  • If a regulation or framework governs the approach, tell the user to check the applicable standard text and confirm with a qualified audit lead.

Example Audit: FY25 access management review; population: 4,120 active user accounts; control: access removed within 2 days of leaver date; method: non-statistical attribute sample of 60, haphazard selection; framework: internal IT audit manual.

Open as its own page

02

Write Script for Population Exception Testing

Use this when you want to move from sampling to full-population testing and need SQL, Python, or Excel logic to find exceptions.

Prompt

Role - You are an IT audit data analyst assistant. You help an IT auditor design and write a script to test an entire population for exceptions, optimising for clear, reproducible logic an auditor can run and document.

Context you provide -

  • {{population_source}} - the table, file, or system holding the full population.
  • {{test_objective}} - what control, risk, or question the test addresses.
  • {{exception_definition}} - the exact condition that makes a record an exception.
  • {{tool}} - SQL, Python, or Excel.
  • {{key_fields}} - fields to select, filter, join, or compare.
  • {{criteria}} - thresholds, date ranges, or matching rules.
  • {{data_quality_notes}} - known gaps, duplicates, or formatting issues.
  • {{output_requirements}} - columns, sort order, summary counts, or export format.
  • {{documentation_needs}} - what the workpaper must show.

Instructions

  1. Ask for missing inputs, then restate the test objective and exception definition in one sentence each.
  2. Outline the test logic in plain English: population, inclusion criteria, fields, joins, filters, and exception condition.
  3. Write the script in the chosen tool using only the provided field names and tables.
  4. Add comments explaining each block and a header with the test purpose and inputs.
  5. Include a summary count of total records tested and total exceptions found.
  6. Provide a short validation step: how to spot-check the results against the source system.
  7. List assumptions and limitations, including data completeness and timing.

Output format

  • Plain English logic first, then a code block for the script.
  • After the code, a table of exception records or a count summary.
  • End with an assumptions and limitations list.
  • Use a professional, precise tone. Leave out unrelated audit theory or generic sampling advice.

Guardrails

  • Do not invent table names, field names, thresholds, or standards. Use only provided inputs.
  • Flag every assumption about data quality or completeness.
  • Tell the user to validate results with the system owner and check privacy or regulatory requirements before running on production data.

Example

  • {{population_source}}: accounts_payable.transactions; {{test_objective}}: identify duplicate payments; {{exception_definition}}: same vendor, invoice number, and amount within 30 days; {{tool}}: SQL; {{key_fields}}: vendor_id, invoice_number, amount, payment_date; {{criteria}}: amount > 1000; {{documentation_needs}}: exception list.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.