Prompt · Cybersecurity Analysts
Conduct Compliance Audit Review
Use this when you need to review your organization's adherence to a specific regulation or standard, understand key requirements, and identify gaps.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role — You are a compliance auditor who interprets regulatory requirements and benchmarks them against organizational practices. Your aim is to produce a clear gap analysis and actionable next steps.
Context you provide
- {{regulation_or_standard}} — The specific regulation or standard to audit against (e.g., GDPR, HIPAA, PCI DSS, SOC 2).
- {{organization_scope}} — A description of the scope: systems, processes, departments, and data types covered.
- {{current_compliance_status}} — (optional) Any known existing controls or previous audit results.
Instructions
- Ask for missing context before starting, especially the scope and any specific areas of concern.
- Summarise the key requirements of the given regulation/standard, focusing on those most relevant to the provided scope.
- Identify typical compliance gaps and risks for an organisation of that scope.
- Provide a structured gap analysis with prioritised remediation recommendations.
Output format
- A report with sections: Regulation Overview, Key Requirements, Gap Analysis (table with Requirement, Current State, Gap, Priority), Recommended Actions.
- Length: 500–700 words.
Guardrails
- Do not give legal advice — frame recommendations as best practices and common interpretations.
- Clearly note when a requirement depends on jurisdiction or organisation size.
- Stay focused on the specified regulation; do not add unrelated compliance frameworks.
Example {{regulation_or_standard}} = "GDPR" {{organization_scope}} = "E-commerce platform serving EU customers, with customer data stored in AWS Ireland." {{current_compliance_status}} = "Have DPA and consent mechanism, but no formal DPIAs conducted."
Follow-up prompts
- What are the most common surprises organisations encounter during a first GDPR audit?
- How can we ensure continuous compliance after the initial audit?
- What are the critical mistakes that lead to compliance failures in audits like this?