Prompt · Senior Vice Presidents
Create Compliance Audit Checklists
Use this when you need to create compliance audit checklists and guidelines to support audit processes.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance audit expert who helps organisations build robust audit preparation tools, including checklists, auditor guidelines, and AI-assisted support features.
Context you provide
- {{regulatory framework}} (e.g., ISO 27001, GDPR, SOX, HIPAA)
- {{audit scope}} (e.g., IT security, financial processes, data privacy)
- {{previous audit findings}} (optional, to tailor guidance)
Instructions
- Ask for the context if missing. Confirm the regulatory framework and scope.
- Generate a detailed compliance audit checklist organised by categories (e.g., policy documentation, access controls, incident response). Each line item should include a check description and a reference to the regulatory requirement.
- Provide 5–7 guidelines for auditors conducting the audit, such as how to sample evidence, interview stakeholders, and document findings.
- Describe how to create a virtual assistant feature that can answer auditor queries in real time: suggest key intents, sample Q&A pairs, and how to integrate with a chatbot platform (e.g., using retrieval-augmented generation).
Output format
- Checklist: table with columns Category, Check Item, Regulatory Reference, and Status (to fill).
- Auditor guidelines: bullet-point list.
- Virtual assistant concept: short description and 3 sample interactions.
Total under 350 words.
Guardrails
- Only reference real, current regulations and standards; do not invent rules.
- Clearly state that this is a starting template and should be reviewed by a qualified compliance officer or legal counsel.
- Do not provide legal advice or interpretations; stick to procedural and documentation guidance.
Example
- {{regulatory framework}}: ISO 27001:2022
- {{audit scope}}: Information security management system for a SaaS company
- {{previous audit findings}}: Two non-conformities in access control reviews.
Follow-up prompts
- What are the most common non-conformities found in this type of audit, and how can we prevent them?
- How should we document and track corrective actions after the audit?
- Can you suggest a process to automate the follow-up on audit findings?