Legal & Compliance

Verified against ChatGPT · 2026-08-12

Build an audit-readiness checklist from your actual control list, not a generic compliance framework

Turns your organization's stated controls and known gaps into a prioritized, evidence-mapped audit prep checklist that flags what documentation is missing before the auditor asks for it, framed as a working draft for a qualified compliance professional or lawyer to finalize.

ChatGPT (GPT-5.1)4 fillable variables
Scope for this category: Drafting, summarizing and organizing support only — every prompt states plainly that output is not legal advice and needs review by a qualified lawyer before being relied on or sent externally.

The prompt

Ready to copy — highlighted parts are example details you can swap.

Build an audit-readiness checklist from the control list and known gaps below, prioritized by what's most likely to get flagged first.

AUDIT TYPE AND SCOPE
Annual SOC 2 Type II readiness review, focused on access control and change management domains.

OUR STATED CONTROLS
Quarterly access review, change approval workflow in Jira, offboarding checklist for departing employees.

KNOWN GAPS OR WEAK SPOTS
Offboarding checklist exists but we don't have consistent evidence it was completed for the last two departures.

PRIOR AUDIT FINDINGS, IF ANY
Last year's audit flagged that access reviews were completed but not signed off by the control owner.

HOW TO BUILD THE CHECKLIST
For each control on the list, state what documentary evidence an auditor would typically expect to see to verify it's actually operating (not just written as policy) — a signed log, a system-generated report, a sample of completed reviews — and mark whether we've told you that evidence currently exists, is partially available, or is a known gap. Rank every item by audit risk: prior findings on the same control area should rank highest, since auditors specifically check whether previously flagged issues were actually remediated, followed by known gaps we've told you about, followed by controls we believe are solid but haven't been evidence-tested recently. For any known gap, suggest what interim compensating step (not a permanent fix, just something to have in place before the audit) could reduce exposure if there's genuinely no time to close the gap fully before the audit date.

WHAT NOT TO DO
Do not assume a control is adequately evidenced just because it's described in policy — policy language and operating evidence are different things, and conflating them is exactly the gap auditors are trained to catch. Do not invent specific regulatory citations, audit standards, or required evidence types beyond general good-practice patterns — if this audit is against a named standard or regulation, ask me to confirm its specific requirements rather than asserting them, since audit standards vary and an incorrect assumption here could leave a real gap looking falsely covered.

OUTPUT FORMAT
A prioritized table: Control | Expected Evidence Type | Evidence Status (have / partial / gap) | Risk Rank (based on prior findings > known gaps > untested) | Interim Compensating Step (if gap). Followed by a short summary of the top 3 highest-risk items to address first given time constraints. Close with a line stating this checklist is an audit-preparation draft only, and that a qualified compliance professional or lawyer must confirm the actual regulatory or standard-specific requirements and review this checklist before it's used to represent audit readiness.

Customize

Optional — swap in your own details for the highlighted parts above.

Why this works

The distinction drawn throughout this prompt between a control existing in policy versus being evidenced in operation is the central mechanism auditors themselves use, and it's the exact distinction a naive AI summary would collapse — asked simply to 'check our controls,' a model will tend to treat a well-written policy description as if it implies operating evidence, when in reality an auditor's actual job is verifying the gap between the two, and a checklist that makes the same assumption an auditor is specifically trained to distrust would be actively counterproductive prep. Ranking prior audit findings above newly-known gaps, above untested-but-believed-solid controls, reflects how audits actually work in practice: an auditor who flagged something last cycle will specifically check whether it was remediated, so an unaddressed repeat finding carries materially higher risk than a fresh gap the auditor hasn't seen yet, and a flat, unprioritized checklist would waste limited prep time treating both with equal urgency. Suggesting interim compensating steps rather than full fixes is a deliberately narrow scope decision — with real time constraints before an audit date, the useful output is 'what reduces exposure right now,' not a long-term remediation plan that can't be executed before the audit anyway, and conflating the two would produce a checklist too ambitious to actually act on in the available window. The refusal to invent specific regulatory citations or standard-specific evidence requirements matters most in audits against a named framework (SOC 2, ISO 27001, a specific regulation), because those standards have precise, versioned requirements that change over time and vary by scope — a model confidently asserting what 'SOC 2 typically requires' from general pattern-matching risks giving false comfort that a gap is covered when the actual current standard requires something different, which is precisely the kind of false readiness an audit is meant to catch, not create.

What you get back

CONTROL: Offboarding checklist completion. EXPECTED EVIDENCE: Signed-off checklist per departure, system access-removal timestamp. EVIDENCE STATUS: Partial — checklist exists, sign-off evidence missing for last two departures. RISK RANK: High (known gap, and adjacent to last year's access-review sign-off finding). INTERIM STEP: Retroactively document and have the control owner sign off on the last two departures' completion before the audit window opens. This checklist is an audit-preparation draft only — a qualified compliance professional or lawyer must confirm actual requirements and review it before it represents audit readiness.

Verified against

ChatGPT GPT-5.1 · 2026-08-12

Changelog

  • 2026-08-12 Initial publish, verified against ChatGPT GPT-5.1.

Need this built into your business?

If a prompt isn't enough — what Scult builds, built and maintained for you — that's Scult's day job.

EXPLORE WHAT SCULT BUILDS
All Legal & Compliance prompts

Check your AI visibility

One URL in, a 0–100 score and the exact fixes out.

RUN THE CHECK

Browse all the tools

15 tools across six categories
13 of them never send your data anywhere

Free · No signup · No trial clock

SEE THE DIRECTORY