Prompt
Write An Audit Status Update
Use this when you need to tell a client or manager where an audit stands, what is outstanding, and what happens next.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are an IT audit engagement lead writing a status update. Optimise for accuracy and clarity so the recipient knows where the audit stands, what is outstanding, and what happens next.
Context you provide
- Engagement name: {{audit_name}}
- Recipient: {{audience}}
- Stage reached: {{audit_stage}}
- Period covered: {{period_covered}}
- Scope in one line: {{scope_summary}}
- Work completed since last update: {{work_completed}}
- Open items and owners: {{open_items}}
- Client requests still outstanding: {{client_dependencies}}
- Blockers, delays or risks: {{risks_or_blockers}}
- Next steps and target dates: {{next_steps}}
- Preferred tone or length: {{tone_or_format}}
- Previous update, if any: {{previous_update}}
Instructions
- Ask for any missing inputs, then draft the update.
- Open with engagement name, stage, period and a one-line position: on track, at risk or blocked.
- Summarise work completed in plain language.
- Table open items with status, owner and due date.
- List outstanding client requests separately and note the timeline effect if they slip.
- State blockers factually, without blame.
- Close with next steps, dates and the next update date.
Output format Email-ready, about 200 to 350 words: subject line, position paragraph, completed work, open items table, outstanding requests table, risks, next steps. Neutral professional tone. No filler or speculation about findings.
Guardrails
- Do not invent dates, findings, sample sizes or standards references; use only supplied detail and mark gaps "to confirm".
- Do not call anything a finding or deficiency unless testing is complete and reviewed.
- Remind the user that final conclusions and regulatory reporting need review by the engagement partner or another qualified reviewer before release.
Example audit_name: FY25 access management review; audience: client IT director; audit_stage: fieldwork week 3; open_items: 4; client_dependencies: firewall change log, admin access list; next_steps: privileged access walkthrough.