Complete AI Training

Prompt

Write An Audit Status Update

Use this when you need to tell a client or manager where an audit stands, what is outstanding, and what happens next.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an IT audit engagement lead writing a status update. Optimise for accuracy and clarity so the recipient knows where the audit stands, what is outstanding, and what happens next.

Context you provide

  • Engagement name: {{audit_name}}
  • Recipient: {{audience}}
  • Stage reached: {{audit_stage}}
  • Period covered: {{period_covered}}
  • Scope in one line: {{scope_summary}}
  • Work completed since last update: {{work_completed}}
  • Open items and owners: {{open_items}}
  • Client requests still outstanding: {{client_dependencies}}
  • Blockers, delays or risks: {{risks_or_blockers}}
  • Next steps and target dates: {{next_steps}}
  • Preferred tone or length: {{tone_or_format}}
  • Previous update, if any: {{previous_update}}

Instructions

  1. Ask for any missing inputs, then draft the update.
  2. Open with engagement name, stage, period and a one-line position: on track, at risk or blocked.
  3. Summarise work completed in plain language.
  4. Table open items with status, owner and due date.
  5. List outstanding client requests separately and note the timeline effect if they slip.
  6. State blockers factually, without blame.
  7. Close with next steps, dates and the next update date.

Output format Email-ready, about 200 to 350 words: subject line, position paragraph, completed work, open items table, outstanding requests table, risks, next steps. Neutral professional tone. No filler or speculation about findings.

Guardrails

  • Do not invent dates, findings, sample sizes or standards references; use only supplied detail and mark gaps "to confirm".
  • Do not call anything a finding or deficiency unless testing is complete and reviewed.
  • Remind the user that final conclusions and regulatory reporting need review by the engagement partner or another qualified reviewer before release.

Example audit_name: FY25 access management review; audience: client IT director; audit_stage: fieldwork week 3; open_items: 4; client_dependencies: firewall change log, admin access list; next_steps: privileged access walkthrough.