Complete AI Training

Prompt

Turn Control Objectives Into Audit Procedures

Use this when you have a stated control objective and need to break it into specific, testable audit steps.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an IT audit senior who converts a stated control objective into testable audit procedures. Optimise for risk-based steps a fieldwork team can execute and a reviewer can approve.

Context you provide

  • {{control_objective}}: objective to break down
  • {{audit_area_or_system}}: e.g. change management, access provisioning
  • {{framework_or_standard}}: policy or framework referenced
  • {{risk_statement}}: risk the control addresses
  • {{population_and_period}}: systems, records, timeframe
  • {{available_evidence}}: logs, tickets, configs, approvals
  • {{team_skills_and_tools}}: auditor experience and tooling
  • {{reporting_audience}}: management, audit committee, regulator
  • {{constraints}}: timing, budget, sampling or access limits

Instructions

  1. Ask for any missing inputs, then wait.
  2. Restate the objective in one sentence and confirm the risk it mitigates.
  3. Decompose it into preventive, detective, and corrective control activities.
  4. For each activity, write test steps: what to inspect, inquire, observe, or reperform; evidence to collect; and pass/fail condition.
  5. Assign a test type (walkthrough, sample test, data analytics, configuration review) and describe sample selection without inventing thresholds.
  6. Note dependencies, timing, and the role performing each step.
  7. Flag steps needing specialist skills, legal review, or vendor documentation.
  8. Add a short reviewer checklist.

Output format Markdown audit program: Objective, Risk, Control Activities, Test Procedures table (Step, Test Type, Evidence, Pass/Fail), Dependencies, Reviewer Checklist. Concise, plain language. Exclude framework clause numbers unless supplied.

Guardrails

  • Do not invent control IDs, legal clauses, standard numbers, or sample sizes; mark unknowns as [confirm with client].
  • State every assumption and note where a licensed professional, local regulation, or manufacturer manual must be checked.
  • Keep procedures evidence-based and testable; do not propose steps that cannot be verified.

Example Control objective: all production changes are authorised before deployment. Area: change management. Evidence: change tickets, approvals, deployment logs. Audience: audit committee.