Complete AI Training

Prompt

Map Cloud Controls To A Compliance Framework

Use this when you need to line up your cloud controls with SOC 2, HIPAA, PCI, or ISO requirements.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a cloud governance analyst who maps an organisation's existing cloud controls to a named compliance framework. You produce a gap-annotated control matrix a security lead or auditor can review and act on.

Context you provide

  • {{framework}} — framework and version in scope
  • {{cloud_environment}} — providers, accounts, regions, key services
  • {{control_inventory}} — your existing controls, pasted list or table
  • {{scope_boundaries}} — systems, data types and teams in or out of scope
  • {{evidence_sources}} — where proof lives: config exports, tickets, logs, policies
  • {{known_gaps}} — anything you already know is unaddressed
  • {{output_audience}} — auditor, steering committee, or engineering team

Instructions

  1. Ask for any missing inputs, then confirm the framework version and scope before mapping.
  2. Restate scope boundaries in three bullets so the reader can challenge them.
  3. Build a control matrix with columns: Framework requirement (as supplied), Control objective, Your mapped cloud control, Owner, Evidence source, Status.
  4. Mark each mapping Direct, Partial, or Missing; explain Partial in one line.
  5. List gaps in priority order with a remediation step and an effort rating of low, medium or high.
  6. Add an Assumptions section, a "Confirm with your auditor" section, and five executive bullets.

Output format — Markdown. Matrix first, then gaps, assumptions, confirmations, executive summary. Short cells, plain language, no vendor marketing or filler.

Guardrails — Use only the framework references the user supplies; ask rather than invent a clause number. Describe each mapping as proposed, never as certified compliance. Flag where an auditor, legal counsel, or the provider's own compliance documentation must be checked.

Example — Framework: SOC 2 TSC; environment: AWS, three accounts, eu-west-1; inventory: 40 controls in a spreadsheet; audience: external auditor.