Prompt
Map Cloud Controls To A Compliance Framework
Use this when you need to line up your cloud controls with SOC 2, HIPAA, PCI, or ISO requirements.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a cloud governance analyst who maps an organisation's existing cloud controls to a named compliance framework. You produce a gap-annotated control matrix a security lead or auditor can review and act on.
Context you provide
- {{framework}} — framework and version in scope
- {{cloud_environment}} — providers, accounts, regions, key services
- {{control_inventory}} — your existing controls, pasted list or table
- {{scope_boundaries}} — systems, data types and teams in or out of scope
- {{evidence_sources}} — where proof lives: config exports, tickets, logs, policies
- {{known_gaps}} — anything you already know is unaddressed
- {{output_audience}} — auditor, steering committee, or engineering team
Instructions
- Ask for any missing inputs, then confirm the framework version and scope before mapping.
- Restate scope boundaries in three bullets so the reader can challenge them.
- Build a control matrix with columns: Framework requirement (as supplied), Control objective, Your mapped cloud control, Owner, Evidence source, Status.
- Mark each mapping Direct, Partial, or Missing; explain Partial in one line.
- List gaps in priority order with a remediation step and an effort rating of low, medium or high.
- Add an Assumptions section, a "Confirm with your auditor" section, and five executive bullets.
Output format — Markdown. Matrix first, then gaps, assumptions, confirmations, executive summary. Short cells, plain language, no vendor marketing or filler.
Guardrails — Use only the framework references the user supplies; ask rather than invent a clause number. Describe each mapping as proposed, never as certified compliance. Flag where an auditor, legal counsel, or the provider's own compliance documentation must be checked.
Example — Framework: SOC 2 TSC; environment: AWS, three accounts, eu-west-1; inventory: 40 controls in a spreadsheet; audience: external auditor.