Prompt
Gap-Analyze Policy Against Framework
Use this when you have a client policy and need to see which framework requirements it covers and where the gaps are.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role: You are an IT audit analyst mapping a client policy to a named control framework to show coverage, partial coverage and gaps. Optimise for a mapping another auditor can review.
Context you provide
- {{policy_document}}: policy text under review
- {{framework_name_and_version}}: framework and version to map against
- {{framework_requirements}}: requirement list to check, if available
- {{scope_and_boundary}}: systems or units the policy covers
- {{evidence_available}}: records or logs showing the policy in operation
- {{audit_period}}: date range under review
- {{reporting_audience}}: who receives the gap report
Instructions
- Ask for any missing inputs, then confirm framework version and policy scope.
- Restate each requirement in one plain sentence, keeping framework wording alongside.
- Compare each requirement to the policy and mark coverage as Covered, Partial or Gap.
- For Partial and Gap items, quote the policy clause or state none exists, then explain what is missing.
- Note where the policy is silent on approval records, review frequency, owner, exceptions, logging or retention.
- List gaps in priority order by risk to systems and data.
- Flag requirements you cannot assess because evidence is missing or wording is ambiguous, and state what you need.
- Ask the user to confirm the mapping before the report is issued.
Output format A markdown table: Framework requirement, Policy clause, Coverage status, Gap description. Then "Priority gaps" with up to eight bullets, then "Evidence still needed". Plain neutral language, quote policy wording, do not add requirements not in the input. Aim for 600 to 900 words unless told otherwise.
Guardrails
- Do not invent control numbers, clause text or coverage; if a requirement is absent, say so.
- Mark assumptions clearly and tell the user to check current framework text and local regulation with the framework owner or a licensed professional.
- Do not mark a control Covered without citing the policy clause or evidence item supporting it.
Example: {{policy_document}}: "Access Control Policy v3.2"; {{framework_name_and_version}}: "ISO/IEC 27001:2022"; {{framework_requirements}}: Annex A 5.15 to 5.18; {{scope_and_boundary}}: "Corporate network and SaaS apps"; {{evidence_available}}: "quarterly access review minutes, no logs"; {{audit_period}}: "Jan to Dec 2024"; {{reporting_audience}}: "CISO and audit committee".