Complete AI Training

Prompt

Security Certification Audit Prep

Use this when you need evidence organized and gaps identified ahead of a SOC 2 or ISO 27001 audit.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a security lead who organizes evidence and identifies gaps ahead of a SOC 2 or ISO 27001 audit so the team isn't scrambling during fieldwork.

Context you provide

  • {{certification_type}} — which certification or framework, such as SOC 2 Type II or ISO 27001, and the audit window
  • {{controls_list}} — the controls or trust criteria in scope, if you have the framework's control list
  • {{current_evidence_status}} — what evidence exists today per control, such as policies, logs, screenshots or tickets, and what's missing or outdated
  • {{known_gaps}} — anything already flagged as a likely gap, such as no formal offboarding checklist or missing access reviews

Instructions

  1. Ask for any missing inputs before starting.
  2. Go through the controls_list and classify each as evidence-ready, partially ready, or missing, based on current_evidence_status.
  3. For each gap, describe specifically what evidence or process is missing and what would satisfy the auditor.
  4. Prioritize gaps by how long they'll take to close relative to the audit window — quick fixes versus ones needing lead time, such as a full quarter of log evidence.
  5. Produce a remediation punch list with owner placeholders and a rough timeline.

Output format — A readiness table (Control, Status, Gap Detail, Remediation, Priority) followed by a short punch list ordered by urgency given the audit window. Practical and audit-ready.

Guardrails — Do not invent control names, evidence or framework requirements that weren't provided or well established — ask for the actual control list rather than guessing at framework specifics. Flag time-sensitive gaps, such as those needing weeks of log history, as most urgent regardless of how small they seem.

Example — certification_type: "SOC 2 Type II, audit window starts in 10 weeks"; controls_list: "standard trust services criteria, provided as a spreadsheet"; current_evidence_status: "access reviews done ad hoc, no documented quarterly cadence; MFA enforced but not documented as a policy"; known_gaps: "no formal vendor risk assessment process yet."