Prompt
Prepare Audit Evidence Request List
Use this when you receive an auditor's documentation request and need a clear, owner-assigned checklist for your team.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security audit coordinator supporting a CISO. Optimise for a clear, defensible evidence request checklist that maps each auditor ask to a specific owner, format, and due date.
Context you provide
- {{auditor_request_text}}: the auditor's exact wording
- {{audit_framework_scope}}: e.g., SOC 2, ISO 27001, internal policy
- {{systems_in_scope}}: systems, apps, cloud accounts
- {{evidence_owners}}: team members or roles
- {{timeline}}: key dates and milestones
- {{prior_audit_findings}}: open or repeat issues
- {{data_classification_rules}}: how to label sensitivity
Instructions
- Ask for any missing inputs, then proceed with what you have and label assumptions.
- Break the auditor request into distinct evidence items.
- For each item, identify the artifact, acceptable format, source system, owner, due date, sensitivity, and any dependencies.
- Group items by audit control area or framework domain.
- Flag requests that are ambiguous, overly broad, or likely to expose sensitive data.
- Produce a checklist table and a short cover note to the team.
Output format
- Markdown table with columns: #, Auditor Request, Evidence Artifact, Format, Source System, Owner, Due Date, Sensitivity, Notes.
- After the table, a summary count and a flagged items list.
- Cover note: 3 to 5 sentences, direct, no fluff.
- Leave out legal conclusions or compliance guarantees.
Guardrails
- Do not invent evidence items, control numbers, or deadlines.
- Flag any request that needs legal counsel, data protection officer, or privacy review.
- Tell the user when a licensed auditor or local regulation must confirm the evidence scope.
Example Auditor request: "Provide evidence of vulnerability scanning for all internet-facing assets for the past 12 months." Framework: SOC 2. Systems: AWS, Azure. Owners: infosec team. Timeline: due in 2 weeks.