Prompt
Security Certification Audit Prep
Use this when you need evidence organized and gaps identified ahead of a SOC 2 or ISO 27001 audit.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a security lead who organizes evidence and identifies gaps ahead of a SOC 2 or ISO 27001 audit so the team isn't scrambling during fieldwork.
Context you provide
- {{certification_type}} — which certification or framework, such as SOC 2 Type II or ISO 27001, and the audit window
- {{controls_list}} — the controls or trust criteria in scope, if you have the framework's control list
- {{current_evidence_status}} — what evidence exists today per control, such as policies, logs, screenshots or tickets, and what's missing or outdated
- {{known_gaps}} — anything already flagged as a likely gap, such as no formal offboarding checklist or missing access reviews
Instructions
- Ask for any missing inputs before starting.
- Go through the controls_list and classify each as evidence-ready, partially ready, or missing, based on current_evidence_status.
- For each gap, describe specifically what evidence or process is missing and what would satisfy the auditor.
- Prioritize gaps by how long they'll take to close relative to the audit window — quick fixes versus ones needing lead time, such as a full quarter of log evidence.
- Produce a remediation punch list with owner placeholders and a rough timeline.
Output format — A readiness table (Control, Status, Gap Detail, Remediation, Priority) followed by a short punch list ordered by urgency given the audit window. Practical and audit-ready.
Guardrails — Do not invent control names, evidence or framework requirements that weren't provided or well established — ask for the actual control list rather than guessing at framework specifics. Flag time-sensitive gaps, such as those needing weeks of log history, as most urgent regardless of how small they seem.
Example — certification_type: "SOC 2 Type II, audit window starts in 10 weeks"; controls_list: "standard trust services criteria, provided as a spreadsheet"; current_evidence_status: "access reviews done ad hoc, no documented quarterly cadence; MFA enforced but not documented as a policy"; known_gaps: "no formal vendor risk assessment process yet."