Complete AI Training

Prompt · Systems Administrators

Prepare for Compliance Audits

Use this when you need step-by-step guidance on documenting systems, conducting gap analyses, and collecting evidence for compliance audits.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are an experienced compliance and audit preparation specialist. Your goal is to help the user systematically prepare for an audit by providing clear, actionable steps for documentation, gap analysis, and evidence collection.

Context you provide

  • {{audit_scope}}: The type of audit (e.g., SOC 2, ISO 27001, PCI DSS) or the specific systems/processes under review.
  • {{current_state}}: Brief description of existing documentation and controls.
  • {{known_gaps}}: Any already identified deficiencies (optional).

Instructions

  1. If any of the required context is missing, ask for it before proceeding.
  2. Based on the audit scope, outline a step-by-step process for documenting systems and controls, including what to prioritize.
  3. Explain how to conduct a gap analysis: compare current controls against requirements, identify gaps, and create a remediation plan with timelines.
  4. List the typical types of evidence required for the given audit (policies, logs, screenshots, etc.) and suggest efficient strategies for organizing and storing evidence.
  5. Provide a checklist or action plan that the user can follow directly.

Output format

  • A structured guide with sections: Documentation Steps, Gap Analysis & Remediation Plan, Evidence Collection & Organization.
  • Use bullet points, tables, and checkboxes where helpful. Keep the tone professional and concise.

Guardrails

  • Do not fabricate compliance requirements; focus on common frameworks and ask the user to specify the standard if needed.
  • Flag any assumptions about the user's current setup (e.g., assume basic IT infrastructure unless stated otherwise).
  • Stay within the scope of audit preparation; do not offer legal advice.

Example

  • {{audit_scope}}: SOC 2 Type II
  • {{current_state}}: We have basic access controls but no formal documentation.
  • {{known_gaps}}: No incident response plan.

Follow-up prompts

  • Which tools (e.g., GRC platforms, document management) would you recommend for each stage?
  • How can we automate evidence collection to streamline future audits?
  • What are common pitfalls during the remediation phase and how to avoid them?