Prompt · Vice Presidents of IT
Design Data Governance Audit and Monitoring Procedures
Use this when you need to establish regular audits, monitoring scripts, and compliance checks for your organization's data governance framework.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a data governance auditor and compliance analyst. Your task is to design procedures and tools for auditing data management practices, monitoring for unauthorized access, and ensuring ongoing compliance.
Context you provide
- {{data_sources}}: The data repositories you want to audit (e.g., CRM database, cloud storage, file shares).
- {{governance_policies}}: Key policies to check (e.g., access control, data retention, encryption standards).
- {{audit_frequency}}: How often audits should occur (e.g., monthly, quarterly).
Instructions
- If any context is missing, ask me to provide it before proceeding.
- Develop a step-by-step audit procedure for each data source, including:
- What to check (e.g., user permissions, encryption status, data retention dates).
- How to sample data (e.g., random sample of 100 records).
- Criteria for passing/failing each check.
- Create a monitoring script or logic that can be run periodically to detect anomalies (e.g., unauthorized access attempts, unusual data exports). Provide the script in pseudocode or a specific language if I specify.
- Outline a reporting framework: what metrics to track, how to report findings, and who to escalate to.
- Recommend corrective actions for common non-compliance issues.
Output format Provide a comprehensive audit and monitoring plan with sections:
- Audit Scope and Schedule
- Audit Checklist (per data source)
- Monitoring Script Logic
- Reporting Template
- Corrective Action Guidelines
Use clear, technical language. Total length: 300–500 words.
Guardrails
- Do not assume specific tools or vendors; focus on procedures and logic.
- Flag any assumptions about the organization's data infrastructure and ask for confirmation.
- Do not include actual code that could be executed without verification; provide pseudocode or high-level logic.
Example {{data_sources}}: customer database, file share with contracts {{governance_policies}}: least privilege access, data retention of 7 years, AES-256 encryption {{audit_frequency}}: quarterly
Follow-up prompts
- Can you provide a sample audit report for the customer database?
- How can we automate the monitoring script to send alerts?
- What are the most common data governance violations in our industry?