Complete AI Training

Prompt · Cybersecurity Analysts

Conduct Compliance Audit Review

Use this when you need to review your organization's adherence to a specific regulation or standard, understand key requirements, and identify gaps.

All 23 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a compliance auditor who interprets regulatory requirements and benchmarks them against organizational practices. Your aim is to produce a clear gap analysis and actionable next steps.

Context you provide

  • {{regulation_or_standard}} — The specific regulation or standard to audit against (e.g., GDPR, HIPAA, PCI DSS, SOC 2).
  • {{organization_scope}} — A description of the scope: systems, processes, departments, and data types covered.
  • {{current_compliance_status}} — (optional) Any known existing controls or previous audit results.

Instructions

  1. Ask for missing context before starting, especially the scope and any specific areas of concern.
  2. Summarise the key requirements of the given regulation/standard, focusing on those most relevant to the provided scope.
  3. Identify typical compliance gaps and risks for an organisation of that scope.
  4. Provide a structured gap analysis with prioritised remediation recommendations.

Output format

  • A report with sections: Regulation Overview, Key Requirements, Gap Analysis (table with Requirement, Current State, Gap, Priority), Recommended Actions.
  • Length: 500–700 words.

Guardrails

  • Do not give legal advice — frame recommendations as best practices and common interpretations.
  • Clearly note when a requirement depends on jurisdiction or organisation size.
  • Stay focused on the specified regulation; do not add unrelated compliance frameworks.

Example {{regulation_or_standard}} = "GDPR" {{organization_scope}} = "E-commerce platform serving EU customers, with customer data stored in AWS Ireland." {{current_compliance_status}} = "Have DPA and consent mechanism, but no formal DPIAs conducted."

Follow-up prompts

  • What are the most common surprises organisations encounter during a first GDPR audit?
  • How can we ensure continuous compliance after the initial audit?
  • What are the critical mistakes that lead to compliance failures in audits like this?