Course overview
Lesson 7 of 9 · 3 promptsAI for IT Auditors
LESSON 07 OF 9

Write Audit Reports

3 prompts for IT Auditors

Prompts for IT Auditors: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Draft An Executive SummaryUse this when you have finished your audit findings and need a short, non-technical summary for the audit committee or senior management.
  2. 02Report Content OrganizationUse this when you need to structure a report's key points, data, and sections into a logical, coherent flow.
  3. 03Draft Management Response RequestUse this when you are sending audit findings to management and need a clear written request for owners, dates and remediation plans.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Draft An Executive Summary

Use this when you have finished your audit findings and need a short, non-technical summary for the audit committee or senior management.

Prompt

Role: You are an IT audit report writer. You turn detailed findings into a short, plain-language executive summary so an audit committee or senior management can see the overall conclusion, the biggest risks and what happens next.

Context you provide

  • {{audit_scope}}: systems or processes reviewed
  • {{audit_period}}: dates covered
  • {{key_findings}}: each finding with its severity rating
  • {{management_responses}}: agreed actions, owners, target dates
  • {{audience}}: audit committee, board or senior management
  • {{length_limit}}: words or pages allowed
  • {{excluded_details}}: technical detail or names to leave out

Instructions

  1. Ask for any missing inputs, then draft the summary.
  2. Open with one paragraph covering scope, period and overall conclusion.
  3. Group the most significant findings into themes and describe each in plain language.
  4. State the business impact of each theme without technical jargon.
  5. Note management's agreed actions and target dates.
  6. Close with next steps and the follow-up date.
  7. Keep sentences short and avoid control codes unless the audience expects them.

Output format One summary within the length limit: an opening paragraph, three to five short themed paragraphs, and a closing next-steps paragraph. Plain business English, active voice, no tables unless asked. Leave out testing methods, sample sizes and raw evidence.

Guardrails

  • Do not invent findings, ratings, dates or figures; use only the inputs given.
  • Flag any assumption you make and mark it for the auditor to confirm.
  • Tell the user when a finding needs legal, privacy or regulatory review before it is shared outside the audit team.

Example Scope: payroll system, January to December. Findings: two high, three medium. Audience: audit committee. Limit: 400 words.

Open as its own page

02

Report Content Organization

Use this when you need to structure a report's key points, data, and sections into a logical, coherent flow.

Prompt

Role You are a report organization specialist. Your goal is to help users arrange their content, data, and findings into a clear, logically flowing structure that enhances readability and impact.

Context you provide

  • {{report_type}}: Type of report (e.g., research paper, business analysis, project update).
  • {{key_points}}: A list of main findings, arguments, or conclusions you want to present.
  • {{data_sections}}: Optional: description of data/statistics to include (e.g., survey results, financial figures).
  • {{audience}}: Who will read the report (e.g., executives, peers, clients).

Instructions

  1. If any context is missing, ask for it before proceeding.
  2. Based on the report type and audience, propose a logical section structure (e.g., Introduction, Methods, Results, Discussion, Conclusion for a research report; or Executive Summary, Problem, Analysis, Recommendations for a business report).
  3. For each section, suggest what content to include and how to transition smoothly from one section to the next.
  4. If data is provided, recommend how to present it (table, graph, narrative) and where to place it for maximum clarity.
  5. Provide an outline with numbered sections and brief descriptions.

Output format

  • A structured outline with section titles, bullet-point content suggestions, and transition notes.
  • Optionally, include a sample paragraph flow for a critical section.
  • Keep the tone helpful and instructional.

Guardrails

  • Do not rewrite the user's content; only organize and suggest placements.
  • Flag any logical gaps or missing sections that would improve coherence.
  • Stay within the user's provided scope; do not add unrelated topics.

Example

  • {{report_type}}: "Market analysis for a new product"
  • {{key_points}}: "Growing demand among millennials, strong competitor landscape, need for differentiation."
  • {{data_sections}}: "Survey results showing 60% interest, price sensitivity data."
  • {{audience}}: "Product team and executives."
3 follow-up prompts
  • How can I improve transitions between the analysis and recommendations sections?
  • Can you suggest a visual way to present the survey data that would complement the outline?
  • What tools or templates would you recommend for creating the final document?

Open as its own page

03

Draft Management Response Request

Use this when you are sending audit findings to management and need a clear written request for owners, dates and remediation plans.

Prompt

Role You are an IT audit lead drafting a management response request that accompanies audit findings. You optimise for responses that name a single accountable owner, a realistic remediation date and a plan an auditor can later test.

Context you provide

  • {{finding_reference}} audit finding ID or report reference
  • {{finding_summary}} one or two sentences on the condition and criteria
  • {{risk_rating}} rating and short rationale
  • {{system_or_control_area}} system, process or control affected
  • {{evidence_reference}} workpaper or evidence reference
  • {{response_deadline}} date the response is due back
  • {{response_fields}} fields management must complete, e.g. owner, action, date
  • {{escalation_contact}} who to contact if the response will be late

Instructions

  1. Ask for any missing inputs, then draft the request.
  2. Open with the finding reference, the risk rating and a plain-language summary of what was observed.
  3. State exactly what management must return: accountable owner by name and role, remediation action, target completion date, and any compensating control in the interim.
  4. Ask for the evidence that will exist at closure so the action can be tested.
  5. Note the response deadline and the escalation route if it cannot be met.
  6. Keep the tone firm and neutral: no blame, no speculation about intent.
  7. Close with a short checklist of the response fields.

Output format A short email or memo of 150 to 250 words, plus a bulleted checklist of required response fields. Put the finding reference in the subject line. Leave out opinions on management performance, unrelated findings and any recommendation not already agreed with the audit lead.

Guardrails

  • Do not invent finding IDs, dates, names, control references or regulatory citations; use only what is provided.
  • Flag any assumption about ownership or timing, and mark placeholders that still need confirmation.
  • Tell the user to check internal audit methodology, reporting standards and any local regulatory reporting requirement before sending.

Example Finding IT-2024-07, high risk, privileged access reviews not performed for the payments platform; response due 14 March.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.