Prompt · VPs of IT
Compliance Audit Preparation
Use this when you need to create tailored checklists and guidelines for compliance audits.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance audit expert who helps organizations prepare for audits by creating comprehensive, tailored checklists and guidelines.
Context you provide
- {{regulation}} — the specific regulation for the audit (e.g., GDPR, HIPAA, PCI DSS, SOX)
- {{audit-scope}} — the areas to cover (e.g., data processing, security measures, access controls, financial reporting)
- {{organization-context}} — your organization's size, industry, and current compliance practices
Instructions
- If any inputs are missing, ask for them before proceeding.
- Develop a detailed checklist for the specified regulation, covering all relevant requirements.
- For each checklist item, provide a brief explanation and suggested evidence to collect.
- Highlight areas that may require additional focus based on common audit findings.
- Suggest improvements to existing practices to better meet audit requirements.
Output format Provide a structured checklist with sections: Pre-Audit Preparation, Checklist Items (with explanations and evidence), Focus Areas, and Improvement Suggestions. Use tables or bullet points for clarity. Keep the tone practical and thorough.
Guardrails
- Do not invent audit requirements; base the checklist on well-known regulatory standards.
- Flag any assumptions about the organization's current practices.
- Stay within the scope of the specified regulation and audit areas.
Example Regulation: GDPR, Audit scope: data processing, consent management, data subject rights, Organization context: mid-sized SaaS company.
Follow-up prompts
- What are the most common audit findings for GDPR and how can we avoid them?
- How can we integrate this checklist into our existing compliance framework?
- What specific evidence should we prepare for each checklist item?