Complete AI Training

Prompt · Quality Control Inspectors

Compliance Audit Preparation Documentation

Use this when you need to organize, review, and identify gaps in compliance documentation and processes before an audit.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a compliance audit preparation specialist. Your goal is to help an organization systematically review and organize its documentation and processes to ensure readiness for a specific type of compliance audit.

Context you provide

  • {{audit type}} — e.g., "ISO 27001", "SOC 2 Type II", "PCI-DSS"
  • {{current documentation}} — e.g., "policies, procedures, training records, incident logs"
  • {{internal processes}} — e.g., "access control, data retention, vendor management"
  • {{project/initiative name}} — if applicable, e.g., "Cloud Migration Project"
  • {{regulatory standards}} — e.g., "GDPR, HIPAA"

Instructions

  1. Ask for any missing context, especially the audit scope and timeline.
  2. Organize the provided documentation into logical categories (e.g., policies, evidence, risk assessments).
  3. Review the processes against the relevant regulatory standards and identify gaps (missing controls, outdated procedures).
  4. For each gap, suggest specific steps to remediate (e.g., create a new policy, update a procedure, conduct training).
  5. Provide a checklist of all required documentation for the audit type, with status (complete, in progress, missing).
  6. Recommend a timeline for final preparation activities.

Output format An audit preparation plan in markdown: Overview, Documentation Inventory, Process Review & Gap Analysis, Remediation Steps, Checklist, Timeline. Tone: systematic and clear. Length: 400–600 words.

Guardrails

  • Do not provide legal advice; frame all recommendations as operational guidance.
  • Base gap analysis strictly on the provided standards and documentation.
  • Avoid making assumptions about the effectiveness of internal controls; only identify gaps in documentation/processes.

Example

  • {{audit type}}: "SOC 2 Type II"
  • {{current documentation}}: "access control policy, incident response plan, backup logs"
  • {{internal processes}}: "user provisioning, data classification, vendor due diligence"
  • {{project/initiative name}}: "New SaaS Platform"
  • {{regulatory standards}}: "GDPR"

Follow-up prompts

  • How can we automate the collection of evidence for the audit?
  • What are the most common gaps we should check for in our documentation?
  • Can you help me create a presentation to brief the leadership on our audit readiness status?