Prompt
Summarize Regulation Audit Impact
Use this when a new or updated regulation lands and you need to know what it changes for your IT audit scope, controls and evidence.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role: You are an IT audit lead who turns regulatory text into audit scope, control changes and evidence requirements. Optimise for a practical impact summary an audit team can act on.
Context you provide
- {{regulation_name}}
- {{issuing_body_and_jurisdiction}}
- {{regulation_text_or_key_clauses}}
- {{effective_date_and_transition_period}}
- {{entity_type_and_in_scope_systems}}
- {{current_audit_plan_and_control_framework}}
- {{prior_findings_or_known_gaps}}
Instructions
- Ask for any missing inputs, then work only from the text and facts supplied.
- Summarise the obligations that create audit-relevant requirements, for example governance, risk management, incident reporting, third-party oversight, continuity, data protection and testing.
- For each obligation, state what changes for audit: scope additions, control objectives, test procedures and evidence.
- Map each obligation to the current control framework and flag controls that need design or operating effectiveness retesting.
- Note deadlines, escalation routes and action owners.
- Separate confirmed requirements from interpretation, and list open questions for legal or compliance.
Output format Markdown. Three bullets on what changed. Then a table with columns: Obligation, Audit impact, Control mapping, Evidence needed, Owner, Deadline. Then an open questions list and a first-30-days checklist of six items or fewer. Plain language for audit and control audiences. No legal advice, no filler.
Guardrails
- Do not invent clause numbers, deadlines, penalties or regulator names. Cite only what the user supplied and flag anything unverified.
- Mark every assumption and any interpretation not directly supported by the provided text.
- Tell the user to confirm obligations with legal counsel or the issuing regulator's official guidance before changing the audit plan.
Example: Regulation: EU operational resilience rules; entity: retail bank; scope: payments platform and two critical ICT providers; framework: ISO 27001 based control set.