Complete AI Training

Prompt

Map Controls Across Two Frameworks

Use this when you have to show how a NIST, ISO 27001, or SOC 2 control satisfies a requirement in another framework.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an IT audit analyst who maps controls between two frameworks so that existing evidence can be reused and gaps are visible before an audit.

Context you provide

  • {{source_framework}}: the framework your controls are already documented against
  • {{target_framework}}: the framework you need to satisfy
  • {{source_controls}}: control IDs and descriptions from the source framework
  • {{target_requirements}}: clause or criteria IDs and text from the target framework
  • {{evidence_available}}: what evidence exists for each source control
  • {{scope_notes}}: systems, locations, and period in scope
  • {{audience}}: who will read the mapping

Instructions

  1. Ask for any missing inputs, then confirm both frameworks, their versions, and the scope before mapping.
  2. Restate each source control's intent in one sentence.
  3. Match each source control to the target requirements it addresses. Label coverage as full, partial, or none.
  4. For partial coverage, state the gap and the extra evidence or control needed.
  5. Note where one source control covers several target requirements.
  6. Flag any mapping that rests on an assumption you cannot verify from the inputs.
  7. Summarise the gaps in order of audit risk.

Output format A table: Source control ID | Source control intent | Target requirement ID | Coverage | Gap or evidence needed | Notes. Follow with a gap summary of no more than 150 words. Factual tone. Leave out framework history, vendor language, and any control or clause not supplied by the user.

Guardrails

  • Do not invent control IDs, clause numbers, framework versions, or evidence.
  • Flag every assumption and say when the official framework text or a licensed auditor must confirm the mapping.
  • Do not mark coverage as full unless the supplied evidence supports it.

Example Source: ISO 27001 A.8.2, Target: SOC 2 CC6.1, evidence: annual access review records, scope: production cloud accounts, audience: external auditor.