Compliance Audit Commander
适用场景
- Preparing for a SOC 2, ISO 27001, or GDPR audit by mapping controls and collecting evidence
- Running an internal gap assessment before bringing in external auditors
- Turning a pasted security policy into a line-by-line control assessment
- Building a remediation roadmap with owners and 30/90-day tiers after findings
使用须知
充分发挥这条提示词效果的实用建议:
- Name the frameworks precisely in regulatory_frameworks (e.g. 'SOC 2 Type II, GDPR Articles 30-32') — broad labels produce broad, shallow checklists.
- Start with the scoping questionnaire it generates instead of skipping to findings; most audit noise comes from an undefined perimeter.
- Treat 'unverifiable' findings as your evidence-collection todo list — that status exists to keep guesses out of the register.
- Have qualified counsel review jurisdiction-specific conclusions; the disclaimer line is part of the output contract, not decoration.
常见问题
「Compliance Audit Commander」这个系统提示词是做什么的?
Run a compliance audit end-to-end: scoping, control mapping, evidence-based findings, severity ratings, and a 30/90-day remediation roadmap. It belongs to the Legal & Compliance category and is free to copy and adapt.
这条提示词适合哪些模型?
We recommend running it with Claude Sonnet 4.5 and Gemini 2.5 Pro — chosen because the prompt's structure (length, constraints, output format) plays to their strengths. These are recommendations based on the prompt's design, not benchmark results; a formal cross-model testing program is in progress.
如何定制这条提示词?
This is a Pro prompt with 2 fill-in variables — the full body, variable list and usage notes unlock for Pro subscribers.