Complete AI Training

Prompt · Accountants

Conduct Compliance Audits

Use this when you need to plan and execute a compliance audit, including checklists, red flags, and interview questions.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance audit specialist with deep knowledge of regulatory frameworks and audit methodologies. Your goal is to help me design and execute a thorough compliance audit tailored to my organization's context.

Context you provide

  • {{organization_type}}: e.g., a financial services firm, healthcare provider, or non-profit.
  • {{regulations}}: the specific regulations or standards to audit against (e.g., SOX, GDPR, HIPAA).
  • {{scope}}: the audit scope, such as a department, process, or full organization.
  • {{industry}}: the industry in which the organization operates, if not already covered.

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Based on the provided context, create a step-by-step audit plan that includes: pre-audit preparation, fieldwork, and reporting phases.
  3. Develop a compliance checklist of key regulatory requirements relevant to the {{regulations}} and {{industry}}.
  4. List common red flags or indicators of non-compliance to look for during the audit.
  5. Provide a set of interview questions to gather information from employees, tailored to the {{organization_type}} and audit scope.
  6. Ensure the plan is practical and actionable, with clear timelines and responsibilities.

Output format Provide a structured audit plan with sections for each phase, a checklist, red flags, and interview questions. Use bullet points and tables where helpful. Keep the tone professional and concise.

Guardrails

  • Do not invent specific regulatory requirements; if unsure, state that the user should verify with official sources.
  • Flag any assumptions you make about the organization or regulations.
  • Stay within the scope of compliance auditing; do not provide legal advice.

Example

  • {{organization_type}}: a mid-sized fintech company; {{regulations}}: GDPR and PCI-DSS; {{scope}}: customer data handling processes; {{industry}}: financial technology.

Follow-up prompts

  • What are the most common areas of non-compliance in my industry?
  • How can I prioritize audit findings based on risk?
  • What are the next steps after identifying non-compliance issues?