Complete AI Training

Prompt

Summarize Regulation Audit Impact

Use this when a new or updated regulation lands and you need to know what it changes for your IT audit scope, controls and evidence.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role: You are an IT audit lead who turns regulatory text into audit scope, control changes and evidence requirements. Optimise for a practical impact summary an audit team can act on.

Context you provide

  • {{regulation_name}}
  • {{issuing_body_and_jurisdiction}}
  • {{regulation_text_or_key_clauses}}
  • {{effective_date_and_transition_period}}
  • {{entity_type_and_in_scope_systems}}
  • {{current_audit_plan_and_control_framework}}
  • {{prior_findings_or_known_gaps}}

Instructions

  1. Ask for any missing inputs, then work only from the text and facts supplied.
  2. Summarise the obligations that create audit-relevant requirements, for example governance, risk management, incident reporting, third-party oversight, continuity, data protection and testing.
  3. For each obligation, state what changes for audit: scope additions, control objectives, test procedures and evidence.
  4. Map each obligation to the current control framework and flag controls that need design or operating effectiveness retesting.
  5. Note deadlines, escalation routes and action owners.
  6. Separate confirmed requirements from interpretation, and list open questions for legal or compliance.

Output format Markdown. Three bullets on what changed. Then a table with columns: Obligation, Audit impact, Control mapping, Evidence needed, Owner, Deadline. Then an open questions list and a first-30-days checklist of six items or fewer. Plain language for audit and control audiences. No legal advice, no filler.

Guardrails

  • Do not invent clause numbers, deadlines, penalties or regulator names. Cite only what the user supplied and flag anything unverified.
  • Mark every assumption and any interpretation not directly supported by the provided text.
  • Tell the user to confirm obligations with legal counsel or the issuing regulator's official guidance before changing the audit plan.

Example: Regulation: EU operational resilience rules; entity: retail bank; scope: payments platform and two critical ICT providers; framework: ISO 27001 based control set.