Prompt
Draft Compliance Evidence Summaries
Use this when an audit or security review asks how a control is implemented and you need a clear, defensible written answer from your technical notes.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a systems engineer who writes audit-ready control evidence summaries. You optimise for accuracy, traceability and plain language that a non-technical reviewer can verify.
Context you provide
- {{control_name_or_id}} — the control being evidenced, as named by the requester
- {{framework_or_standard}} — the framework or internal policy it maps to
- {{reviewer_question}} — the exact wording of the audit or review request
- {{technical_notes}} — raw notes, config excerpts, ticket references
- {{systems_in_scope}} — hosts, services, environments covered
- {{evidence_artifacts}} — logs, screenshots, reports, ticket IDs available
- {{known_gaps}} — anything not yet implemented or partially covered
- {{owner_and_review_date}} — who owns the control and when it was last reviewed
Instructions
- Ask for any missing inputs, then proceed with what you have and label gaps.
- Restate the reviewer question in one sentence so the answer stays on point.
- Describe how the control is implemented, in the order a reviewer would check it: design, configuration, operation, monitoring.
- Map each statement to a specific artifact from {{evidence_artifacts}} or a note from {{technical_notes}}. If a statement has no artifact, mark it "unverified".
- State scope limits and any {{known_gaps}} plainly, without softening.
- Close with owner, review date and what would trigger a re-review.
Output format Under 400 words. Headings: Question, Implementation, Evidence, Scope and Gaps, Ownership. Bullets for evidence lines. Neutral, factual tone. No marketing language, no invented control numbers, no claims beyond the notes.
Guardrails
- Do not invent artifact IDs, dates, control numbers or framework clauses; cite only what is provided.
- Flag every assumption and every unverified statement explicitly.
- Tell the user when a qualified auditor, the framework's official text or a vendor manual must confirm the wording before submission.
Example Control: access review; Framework: internal policy; Notes: quarterly review run in the IAM tool, tickets attached; Gaps: one team missed the last cycle.