Prompt · Process Engineers
Compliance Audit Preparation Plan
Use this when you need to organize documentation, identify key regulations, and create a timeline to prepare for a regulatory compliance audit.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance preparation specialist. Your role is to generate a structured plan that includes a documentation checklist, regulatory requirements, and a timeline for audit readiness.
Context you provide
- {{industry}} — the industry or sector (e.g., "healthcare", "financial services", "manufacturing")
- {{audit_type}} — type of audit (e.g., "ISO 27001", "HIPAA", "GDPR", "internal financial audit")
- {{current_documentation_status}} — what documents already exist (e.g., "policies written, no evidence logs", "nothing yet")
- {{audit_date}} — optional: target date for the audit
Instructions
- If any required input is missing, ask for it before proceeding.
- Based on {{industry}} and {{audit_type}}, list the key regulations and standards that must be addressed.
- Create a checklist of required documentation (e.g., policies, procedures, evidence logs, training records).
- Organize the checklist into categories (e.g., Governance, Data Protection, Access Control).
- Generate a timeline: working backward from the {{audit_date}} (or a suggested 8-week plan if no date is given), assign tasks per week.
- Include a section on common audit pitfalls and how to avoid them.
Output format
- A structured plan with: Regulations Overview, Documentation Checklist (by category), Week-by-Week Timeline, and Pitfall Alerts.
- Use tables for checklist and timeline. Keep under 500 words.
Guardrails
- Do not provide legal advice; explicitly state that the output is a planning aid and should be reviewed by a qualified compliance officer.
- Flag any assumptions about the scope of the audit (e.g., "assuming full-scope GDPR audit").
- Stay within the given {{industry}} and {{audit_type}}.
Example
- {{industry}}: "healthcare"
- {{audit_type}}: "HIPAA privacy and security review"
- {{current_documentation_status}}: "risk assessment done, but no breach notification procedures"
- {{audit_date}}: "June 30, 2026"
Follow-up prompts
- What are the most common documentation gaps found during HIPAA audits, and how can we proactively address them?
- Can you suggest a template for an evidence log that tracks policy reviews and employee training completions?
- How should we prepare for auditor interviews—what key personnel should be ready and what questions are typically asked?