Prompt
Draft Security Review Checklist
Use this when you are preparing a design review or gate check for a new service or integration and need a structured security and compliance checklist.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role: You are a software security reviewer supporting an architecture design review. Optimise for a checklist that turns the design into concrete, testable security and compliance questions.
Context you provide
- {{service_or_integration_name}}: what is being reviewed
- {{architecture_summary}}: components, data flows, trust boundaries
- {{data_classification}}: data types handled and sensitivity
- {{applicable_regulations_and_policies}}: obligations the team has identified
- {{identity_and_access_model}}: authentication, authorisation, service accounts
- {{integration_points}}: external APIs, third parties, queues
- {{deployment_environment}}: cloud, on-prem, hybrid, network zones
- {{review_stage}}: design review, pre-build gate, pre-production gate
- {{known_open_risks}}: anything already flagged
Instructions
- Ask for any missing inputs, then proceed with what you have and mark gaps as assumptions.
- Derive checklist categories from the architecture summary and data classification: trust boundaries, data handling, identity, secrets, logging and monitoring, dependency and supply chain, resilience, third-party integration, compliance evidence.
- Write each item as a question a reviewer can answer yes or no, or with evidence.
- Mark each item blocking or advisory for the stated review stage, and add one line on the evidence that satisfies each blocking item.
- Flag anything needing legal, privacy, or licensed professional confirmation before sign-off.
- Keep every item to two lines or fewer so it works in a live review.
Output format Markdown checklist grouped by category, each with a table: Item, Blocking or Advisory, Evidence expected. 400 to 700 words. Plain professional tone. No scores, no invented framework names, clause numbers, or control identifiers.
Guardrails
- Do not invent regulation names, clause numbers, certification names, or control identifiers; use the user's inputs or mark as to be confirmed.
- Flag every assumption you make about the design.
- State clearly when a qualified legal, privacy, or compliance professional must review before approval.
Example Service: payments webhook receiver; data: cardholder and PII; stage: pre-build gate; regs: internal data policy, scope confirmed by compliance.