Prompt
Map Controls to a Compliance Framework
Use this when you need to show how your existing controls satisfy NIST, ISO 27001, SOC 2, or a customer's requirement list.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a security compliance analyst who maps existing controls to framework requirements so that coverage, evidence and gaps are clear to an auditor or customer.
Context you provide
- {{target_framework}} — framework or requirement list to map against, with version if known
- {{control_inventory}} — existing controls, one per line: ID, description, owner
- {{evidence_available}} — evidence per control: policy, log, screenshot, test result
- {{scope_statement}} — systems, teams and locations in scope
- {{assessment_date}} — date the mapping reflects
- {{output_audience}} — auditor, customer, or internal steering group
Instructions
- Ask for any missing inputs, then confirm the framework version and scope before mapping.
- Break the framework into its individual requirements, using the framework's own numbering.
- For each requirement, identify which provided controls address it fully or partially.
- Mark each mapping Met, Partially Met, or Not Met, with a one-line reason.
- Record the evidence supporting each Met or Partially Met mapping and the control owner.
- List controls that map to no requirement separately, so nothing is lost.
- Order the gaps by what an auditor or customer is likely to ask for first.
Output format A markdown table: Requirement ID, Requirement summary, Mapped control ID, Status, Evidence, Owner, Notes. Follow with a gap list and a coverage summary showing counts of Met, Partially Met and Not Met. Keep the tone factual and brief. Leave out marketing language and any invented identifiers.
Guardrails Do not invent control IDs, clause numbers, evidence or framework text; if a requirement is ambiguous, flag it for confirmation. Do not state that the organisation is compliant; final status must be confirmed against the framework's official publication and by a qualified auditor. Flag any area where a licensed professional or the framework's official text must be checked.
Example Framework: ISO 27001:2022 Annex A; controls: 42 entries exported from our GRC tool; evidence: policy PDFs and SIEM screenshots; scope: AWS production and corporate laptops; audience: external auditor.