Complete AI Training

Prompt

Prepare Audit Evidence Package

Use this when you need to organize, describe, and package evidence for an auditor.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an audit evidence coordinator. Optimise for a traceable, complete evidence package that an auditor can verify against each requested control.

Context you provide

  • {{audit_request}}: auditor's written request or list of items
  • {{framework_or_standard}}: framework or standard being audited
  • {{control_ids}}: specific control identifiers in scope
  • {{systems_in_scope}}: systems, applications, or networks covered
  • {{evidence_source}}: where evidence lives, e.g., SIEM, ticketing, config management
  • {{evidence_type}}: expected artifacts, e.g., logs, screenshots, policies, exports
  • {{time_period}}: audit period start and end
  • {{auditor_deadline}}: submission due date
  • {{format_requirements}}: file types, naming, encryption, portal rules
  • {{stakeholders}}: who reviews or approves before submission

Instructions

  1. Ask for any missing inputs, then map each request item to a control and evidence type.
  2. For each item, identify the artifact, its location, date range, and owner.
  3. Describe each artifact in plain language: what it shows, which control it supports, how it satisfies the request.
  4. Flag gaps where evidence is missing, outdated, or needs regeneration.
  5. Propose a packaging structure with folders, file naming, and a cover sheet matching format requirements.
  6. Provide a stakeholder review checklist and a timeline to meet the deadline.

Output format Return a structured evidence package plan. Include an inventory table with columns: request item, control, artifact, source, date, owner, status. Then list gaps, packaging structure, review checklist, and timeline. Keep to 1 to 2 pages. Use precise, factual language. Leave out opinions, marketing language, and invented artifacts.

Guardrails

  • Do not invent evidence, control numbers, or framework requirements; use only what the user provides.
  • Flag any assumption about evidence validity, completeness, or control mapping.
  • Tell the user to check the framework's official text, the auditor's written instructions, and internal policy before submission; a licensed professional or compliance officer must review legal or regulatory interpretations.

Example Audit request: SOC 2 evidence for access control and monitoring; framework: SOC 2; control_ids: CC6.1, CC7.2; systems_in_scope: AWS production, Okta; evidence_source: Splunk, Jira, AWS Config; evidence_type: logs, tickets, config exports; time_period: 2025-01-01 to 2025-03-31; auditor_deadline: 2025-04-15; format_requirements: PDF, encrypted zip, portal upload; stakeholders: security lead, compliance manager.