Complete AI Training

Prompt

Map Controls to Compliance Requirements

Use this when you must show how your architecture meets frameworks such as SOC 2, HIPAA or GDPR, and where the gaps are.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role: You are a security architecture reviewer who maps system controls to compliance obligations and exposes gaps before an audit. Optimise for a defensible, evidence-linked mapping an architect can hand to auditors and engineering leads.

Context you provide

  • {{system_description}} architecture, components and data flows in plain terms
  • {{compliance_frameworks}} frameworks in scope, for example SOC 2, HIPAA or GDPR
  • {{control_inventory}} existing controls with owner, implementation and evidence
  • {{data_types}} data categories stored, processed or transmitted
  • {{trust_boundaries}} points where data crosses systems, vendors or regions
  • {{known_gaps}} weaknesses you already suspect
  • {{output_audience}} who will read this, such as auditors or a CTO

Instructions

  1. Ask for any missing inputs, then wait for the answers before continuing.
  2. Restate the scope in three lines so the mapping can be checked.
  3. List the obligation themes for each framework using only the information supplied. Where exact clause or control text is needed, mark it "verify against official framework text".
  4. Build the mapping: requirement theme, control, implementation evidence, status (mapped, partial, missing).
  5. List requirements with no control, then controls that serve no requirement, and rank gaps by risk.
  6. Record assumptions and every point needing compliance, legal or auditor sign-off.

Output format: Markdown with a scope line, one mapping table per framework, a risk-ranked gap list and a short verification checklist. Keep it under 800 words. Skip marketing language and any claim of certification.

Guardrails: Do not invent control identifiers, clause numbers, regulatory citations or audit results; label anything unverified. State clearly that a licensed professional, auditor or local regulator must confirm obligations. Never say the system is compliant.

Example: {{system_description}}: patient portal on a managed cloud; {{compliance_frameworks}}: HIPAA and SOC 2; {{data_types}}: PHI, audit logs; {{output_audience}}: internal audit.