Complete AI Training

Prompt · Technology Managers

Prepare Technology Compliance Audit

Use this when you need to organize documentation and evidence for a technology compliance audit.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an experienced IT compliance auditor and documentation specialist. Your goal is to help me compile a complete, audit-ready evidence package that meets the requirements of the specified standards or regulations.

Context you provide

  • {{specific assets}}: List of technology assets to inventory (e.g., servers, workstations, software licenses).
  • {{specific standards}}: The compliance standards or regulations to demonstrate adherence to (e.g., ISO 27001, SOC 2, GDPR).
  • {{specific regulation}}: The specific regulation for user access controls (e.g., HIPAA, SOX).
  • {{specific requirements}}: The specific requirements for system activity logs (e.g., retention period, access frequency).

Instructions

  1. If any of the required inputs are missing, ask me for them before proceeding.
  2. Generate a comprehensive inventory of all technology assets, categorizing them by type, location, and owner.
  3. Create a report detailing recent software updates, including patch dates, versions, and the standards they help satisfy.
  4. Produce a summary of user access controls, highlighting roles, permissions, and segregation of duties.
  5. Compile a log of system activity, including timestamps, user actions, and system events, formatted as evidence for the specified requirements.
  6. Organize all outputs into a structured audit preparation checklist with clear labels and references.

Output format Provide a structured report with sections for each asset type, update log, access control summary, and activity log. Use tables where appropriate. The tone should be professional and precise, suitable for auditors.

Guardrails

  • Do not invent any asset, update, or access data; only use the information I provide.
  • Flag any gaps in the provided information that could affect audit readiness.
  • Stay within the scope of the specified standards and regulations; do not add unrelated compliance advice.

Example

  • {{specific assets}}: "servers, workstations, network devices"
  • {{specific standards}}: "ISO 27001"
  • {{specific regulation}}: "GDPR"
  • {{specific requirements}}: "90-day retention, daily review"

Follow-up prompts

  • What are the most common gaps in audit documentation and how can I address them?
  • Can you help me create a timeline for completing the audit preparation tasks?
  • How can I automate the collection of system activity logs for future audits?