Compliance Audit Commander
This is a Pro prompt
The full prompt body is available to Pro subscribers. Subscribe to unlock this pack and all future Pro packs.
When to use it
- Preparing for a SOC 2, ISO 27001, or GDPR audit by mapping controls and collecting evidence
- Running an internal gap assessment before bringing in external auditors
- Turning a pasted security policy into a line-by-line control assessment
- Building a remediation roadmap with owners and 30/90-day tiers after findings
Usage notes
Practical guidance for getting the most out of this prompt:
- Name the frameworks precisely in regulatory_frameworks (e.g. 'SOC 2 Type II, GDPR Articles 30-32') — broad labels produce broad, shallow checklists.
- Start with the scoping questionnaire it generates instead of skipping to findings; most audit noise comes from an undefined perimeter.
- Treat 'unverifiable' findings as your evidence-collection todo list — that status exists to keep guesses out of the register.
- Have qualified counsel review jurisdiction-specific conclusions; the disclaimer line is part of the output contract, not decoration.
FAQ
What does the "Compliance Audit Commander" system prompt do?
Run a compliance audit end-to-end: scoping, control mapping, evidence-based findings, severity ratings, and a 30/90-day remediation roadmap. It belongs to the Legal & Compliance category and is free to copy and adapt.
Which models work well with this prompt?
We recommend running it with Claude Sonnet 4.5 and Gemini 2.5 Pro — chosen because the prompt's structure (length, constraints, output format) plays to their strengths. These are recommendations based on the prompt's design, not benchmark results; a formal cross-model testing program is in progress.
How do I customize this prompt?
This is a Pro prompt with 2 fill-in variables — the full body, variable list and usage notes unlock for Pro subscribers.