30 Claude Prompts for Auditors
Prompts that turn risk assessments, test procedures, and workpaper narratives into a first draft you can review and file, not generic audit fluff.
In short: This page contains 30 copy-paste ready prompts, organized into 6 categories with a description and pro tip for each. The first 5 prompts are free instantly, no signup needed. Hand-curated and tested by the AI Academy team.
Audit Planning and Risk Assessment
5 promptsEngagement Risk Assessment Memo
1/30✨ What it does
Claude writes a ranked risk assessment memo for [CLIENT NAME] in [INDUSTRY], tied to the engagement details you provide. Edit the ranking with last year's findings, then file it before fieldwork starts.
You are a senior audit manager preparing the risk assessment phase of an engagement. <context> I am scoping a new audit engagement and need to document the risk areas before fieldwork starts. </context> <inputs> - Client or business unit: [CLIENT NAME] - Industry: [INDUSTRY] - Prior year findings: [PRIOR YEAR FINDINGS SUMMARY] - Known changes since last audit: [SYSTEM OR PROCESS CHANGES] - Materiality threshold: [MATERIALITY AMOUNT] </inputs> <task> Draft a risk assessment memo that ranks the top five risk areas for this engagement, explains why each one matters this cycle, and recommends where to concentrate testing hours. </task> <constraints> Keep it to one page. Write in plain language a client committee could read without an accounting background. Do not repeat generic risk categories, tie each one to the specific inputs above. </constraints> <format> Return a short memo with a one paragraph summary followed by a numbered list of the five risk areas, each with a one sentence rationale and a suggested testing focus. </format>
Pro tip: Paste in last year's actual findings, a vague prior year summary produces a generic risk list.
Audit Program Scope Outline
2/30✨ What it does
Claude turns [TOP RISK AREAS] into a scoped audit program for [AUDIT AREA] with clear boundaries and team assignments. Check the [START DATE] to [END DATE] window against your calendars, then assign the work.
You are an audit engagement lead. <context> I need to turn a risk assessment into a scoped audit program before assigning work to the team. </context> <inputs> - Audit area: [AUDIT AREA] - Risk areas identified: [TOP RISK AREAS] - Team size: [NUMBER OF AUDITORS] - Fieldwork window: [START DATE] to [END DATE] </inputs> <task> Produce a scoped audit program that lists the objectives, the processes in scope, the processes explicitly out of scope, and how work will be divided across the team. </task> <constraints> Be specific about what is out of scope and why, vague scoping causes rework later. Keep language direct, no filler sentences. </constraints> <format> Return sections titled Objectives, In Scope, Out of Scope, and Team Assignments, each as short bullet lists. </format>
Pro tip: List the out of scope items first in your head, that section prevents the most disputes with the client later.
Materiality Calculation Walkthrough
3/30✨ What it does
Claude writes the materiality calculation narrative using [BENCHMARK, REVENUE OR PRE-TAX INCOME] and [BENCHMARK AMOUNT] so a reviewer can follow the math. Attach your source figures, then drop it in the planning file.
You are an audit senior responsible for planning materiality. <context> I need to explain how I set planning materiality so a reviewer can follow the logic without asking me to redo it. </context> <inputs> - Benchmark used: [BENCHMARK, REVENUE OR PRE-TAX INCOME] - Benchmark amount: [BENCHMARK AMOUNT] - Percentage applied: [PERCENTAGE] - Qualitative factors: [QUALITATIVE FACTORS] </inputs> <task> Write a short explanation of how planning materiality and performance materiality were calculated, including why the benchmark and percentage were chosen given the qualitative factors. </task> <constraints> Keep it under 200 words. State the actual dollar figures, do not just describe the method in the abstract. </constraints> <format> Return three short paragraphs: benchmark selection, calculation with figures, and qualitative adjustment rationale. </format>
Pro tip: List every qualitative factor even minor ones, reviewers ask why a percentage moved and want the full list on record.
Fraud Risk Brainstorm for a New Engagement
4/30✨ What it does
Claude generates fraud scenarios for [ENTITY OR PROCESS] under [FINANCIAL OR OPERATIONAL PRESSURES], each paired with a concrete test. Use those talking points in your required team brainstorm before fieldwork.
You are an audit manager conducting the required fraud risk discussion. <context> I am preparing talking points for the engagement team fraud brainstorming session required before fieldwork. </context> <inputs> - Entity or process: [ENTITY OR PROCESS] - Known pressures: [FINANCIAL OR OPERATIONAL PRESSURES] - Prior fraud history: [PRIOR FRAUD HISTORY, OR NONE] - Key personnel with override ability: [ROLES WITH OVERRIDE ACCESS] </inputs> <task> List realistic fraud scenarios specific to this entity, covering management override, revenue recognition, and asset misappropriation, and suggest one test for each scenario. </task> <constraints> Only include scenarios plausible given the inputs, skip generic textbook fraud triangles. Each scenario needs a concrete test, not just a description of the risk. </constraints> <format> Return a table with columns Scenario, Why It Is Plausible Here, and Suggested Test. </format>
Pro tip: Name the actual roles with override access, generic titles like manager produce generic override scenarios.
Prior Year Findings Follow-Up Tracker
5/30✨ What it does
Claude assesses whether [FINDING DESCRIPTION] was actually remediated against [REMEDIATION COMMITMENT] and lists evidence that would confirm it. Request that evidence from management before you close last year's item.
You are an audit senior preparing for a repeat engagement. <context> I am starting this year's audit and need to check whether last year's findings were actually fixed. </context> <inputs> - Prior year finding: [FINDING DESCRIPTION] - Management's remediation commitment: [REMEDIATION COMMITMENT] - Target completion date: [TARGET DATE] - Current status as reported by client: [STATUS UPDATE FROM CLIENT] </inputs> <task> Draft a follow-up tracker entry that assesses whether the remediation appears complete based on the status update, and specify what evidence would be needed to confirm it during fieldwork. </task> <constraints> Be skeptical of vague status updates like in progress or substantially complete, call that out directly. Do not assume remediation happened just because the deadline passed. </constraints> <format> Return a short table row style entry with fields: Finding, Commitment, Status Assessment, Evidence Needed to Close. </format>
Pro tip: Paste the client's exact wording for the status update, hedge words like substantially are worth flagging verbatim.
Testing Procedures and Sampling
5 promptsSample Selection Methodology Writeup
6/30✨ What it does
Claude writes the sample selection methodology for [POPULATION DESCRIPTION, ALL VENDOR INVOICES] of [POPULATION SIZE], with a justified sample size. File that write-up so your workpaper stands on its own in review.
You are an audit senior designing substantive testing. <context> I need to document how I selected my sample so the workpaper stands on its own for review. </context> <inputs> - Population: [POPULATION DESCRIPTION, ALL VENDOR INVOICES] - Population size: [POPULATION SIZE] - Sampling method: [RANDOM, HAPHAZARD, OR STATISTICAL] - Sample size: [SAMPLE SIZE] - Confidence level if statistical: [CONFIDENCE LEVEL] </inputs> <task> Write the sample selection methodology section of a testing workpaper, explaining why this method fits the population and how the sample size was determined. </task> <constraints> Justify the sample size with a real reason tied to risk or population characteristics, not just a round number. Keep it factual, no hedging language. </constraints> <format> Return a short paragraph followed by a bullet list of the key parameters used. </format>
Pro tip: State the population size as a real number, a reviewer will ask for it if it is missing from the writeup.
Test of Controls Attribute Sheet
7/30✨ What it does
Claude builds an attribute testing sheet for [CONTROL DESCRIPTION] with pass and fail criteria for each attribute at [DAILY, WEEKLY, MONTHLY] frequency. Pull your sample only after those criteria look right.
You are an internal audit tester. <context> I am testing a control and need an attribute sheet before I pull the sample. </context> <inputs> - Control description: [CONTROL DESCRIPTION] - Control frequency: [DAILY, WEEKLY, MONTHLY] - Population period: [PERIOD, JANUARY TO DECEMBER] - Attributes to test: [KEY ATTRIBUTES, APPROVAL SIGNATURE PRESENT] </inputs> <task> Build an attribute testing sheet that lists each attribute to check, the source document to pull it from, and what counts as an exception. </task> <constraints> Define exceptions precisely, an attribute that is ambiguous about pass or fail will produce inconsistent results across testers. Keep each attribute to one clear yes or no test. </constraints> <format> Return a table with columns Attribute, Source Document, Pass Criteria, Fail Criteria. </format>
Pro tip: Give the actual source document names, not just the process name, so testers pull from the same place.
Substantive Analytical Procedure Design
8/30✨ What it does
Claude designs a substantive analytical procedure for [ACCOUNT NAME] with a precise expectation from [EXPECTED RELATIONSHIP, TIED TO HEADCOUNT] and an investigation threshold. Run it before you fall back to full sampling.
You are an audit senior performing substantive analytics. <context> I want to use analytics instead of full sampling for this account and need to document an acceptable procedure. </context> <inputs> - Account: [ACCOUNT NAME] - Expected relationship or driver: [EXPECTED RELATIONSHIP, TIED TO HEADCOUNT] - Threshold for investigation: [THRESHOLD PERCENTAGE OR AMOUNT] - Data source: [DATA SOURCE] </inputs> <task> Design a substantive analytical procedure that states the expectation, the threshold that triggers further investigation, and the follow-up steps if the actual result exceeds the threshold. </task> <constraints> The expectation must be precise enough to actually test, not just directionally reasonable. State the threshold as a specific number. </constraints> <format> Return four short sections: Expectation, Data Used, Threshold, Follow-Up Steps. </format>
Pro tip: Set the threshold before you look at actual results, moving it after the fact defeats the purpose of the procedure.
Walkthrough Narrative for a Business Process
9/30✨ What it does
Claude turns your raw walkthrough notes on [PROCESS NAME, PROCURE TO PAY] with [INTERVIEWEE NAME AND TITLE] into a numbered narrative with control points flagged. Read it once for missed steps, then file it.
You are an auditor documenting a process walkthrough. <context> I just finished a walkthrough interview and need to turn my notes into a clean narrative for the file. </context> <inputs> - Process name: [PROCESS NAME, PROCURE TO PAY] - Interviewee and role: [INTERVIEWEE NAME AND TITLE] - Raw notes: [PASTE RAW WALKTHROUGH NOTES] - Systems involved: [SYSTEM NAMES] </inputs> <task> Turn the raw notes into a clear step by step process narrative, identifying where controls occur and flagging any step that sounded manual or informal. </task> <constraints> Preserve the actual sequence described, do not reorder steps to look tidier than what was described. Flag gaps or unclear points as open questions rather than guessing. </constraints> <format> Return a numbered step by step narrative, with control points marked using the label CONTROL and open questions listed at the end. </format>
Pro tip: Paste the notes exactly as taken, cleaning them up yourself first tends to erase the informal steps worth flagging.
Exception Investigation Summary
10/30✨ What it does
Claude summarizes exceptions from a sample of [SAMPLE SIZE] with [EXCEPTION COUNT] items in [PASTE EXCEPTION DETAILS], calculates the rate, and recommends on control effectiveness. Take that recommendation into your client discussion.
You are an audit tester who found sample exceptions. <context> My testing turned up exceptions and I need to summarize them before discussing with the client. </context> <inputs> - Sample size tested: [SAMPLE SIZE] - Number of exceptions: [EXCEPTION COUNT] - Exception details: [PASTE EXCEPTION DETAILS] - Root cause if known: [ROOT CAUSE OR UNKNOWN] </inputs> <task> Summarize the exceptions found, calculate the exception rate, and state whether this rate suggests the control is operating effectively, needs extended testing, or should be considered failed. </task> <constraints> Show the exception rate as a percentage. Do not soften a clear failure into ambiguous language just to avoid a difficult conversation. </constraints> <format> Return a short summary paragraph followed by a recommendation line stating one of: Effective, Extend Sample, or Not Effective. </format>
Pro tip: Paste every exception detail even ones that seem minor, a pattern across small exceptions is often the real finding.
Workpapers and Documentation
5 promptsWorkpaper Index and Cross-Reference Sheet
11/30✨ What it does
Claude builds a workpaper index for [AUDIT AREA] mapping [LIST OF WORKPAPER NAMES] to purpose and the [LINE ITEMS] each one supports. Put the index at the front of your file before the reviewer opens it.
You are an audit senior organizing the file. <context> I am assembling the workpaper file for this section and need a clean index before the reviewer opens it. </context> <inputs> - Audit area: [AUDIT AREA] - List of workpapers prepared: [LIST OF WORKPAPER NAMES] - Related financial statement line items: [LINE ITEMS] </inputs> <task> Create a workpaper index that lists each workpaper, its purpose in one line, and which financial statement assertion or line item it supports. </task> <constraints> Use the standard assertion names such as existence, completeness, valuation, rights and obligations, and presentation. Keep the purpose line under fifteen words each. </constraints> <format> Return a table with columns Workpaper Reference, Purpose, Assertion or Line Item Supported. </format>
Pro tip: List the actual workpaper file names you use internally, so the index matches the file without renaming anything.
Tickmark Legend and Conclusion Paragraph
12/30✨ What it does
Claude writes the conclusion paragraph and formats the tickmark legend from [PROCEDURE PERFORMED] and [RESULTS SUMMARY]. Paste both onto your finished workpaper, then mark the paper done.
You are audit staff finishing a testing workpaper. <context> I finished my testing and need a proper conclusion paragraph plus a tickmark legend before I mark this workpaper done. </context> <inputs> - Procedure performed: [PROCEDURE PERFORMED] - Items tested and result: [RESULTS SUMMARY] - Tickmarks used: [LIST OF TICKMARKS AND MEANINGS] </inputs> <task> Write the standard conclusion paragraph stating what was tested, what was found, and whether the objective of the procedure was met, plus format the tickmark legend. </task> <constraints> The conclusion must explicitly state whether the objective was achieved, do not leave that implied. Keep the tickmark legend to short phrases, not full sentences. </constraints> <format> Return a Conclusion paragraph followed by a Tickmark Legend as a simple list of symbol and meaning pairs. </format>
Pro tip: State the objective met or not met in the first sentence, reviewers scan for that line first.
Review Note Response Draft
13/30✨ What it does
Claude drafts a review-note response to [PASTE REVIEW NOTE] that points the reviewer to [WHAT YOU DID TO ADDRESS IT]. Link the new evidence, then resubmit the workpaper.
You are an audit senior responding to reviewer comments. <context> My reviewer left comments on my workpaper and I need to draft responses before resubmitting. </context> <inputs> - Review note text: [PASTE REVIEW NOTE] - Additional work performed or evidence found: [WHAT YOU DID TO ADDRESS IT] - Workpaper reference: [WORKPAPER REFERENCE NUMBER] </inputs> <task> Draft a clear response to the review note explaining what additional work was done and where the reviewer can find the supporting evidence. </task> <constraints> Reference the exact workpaper or page where new evidence lives. If the note cannot be fully resolved, say so directly instead of implying it is closed. </constraints> <format> Return a short response formatted as Note, Response, Evidence Location, Status (Resolved or Open). </format>
Pro tip: Paste the reviewer's exact wording, responding to a paraphrase instead of the real note gets bounced back.
Supporting Schedule Narrative
14/30✨ What it does
Claude writes a short narrative for [SCHEDULE PURPOSE] explaining [DATA SOURCE] and how [KEY FIGURES] tie out to the general ledger. Attach it to the spreadsheet before you put the schedule in the file.
You are audit staff preparing a supporting schedule. <context> I built a supporting schedule in a spreadsheet and need a short narrative to accompany it in the workpaper. </context> <inputs> - Schedule purpose: [SCHEDULE PURPOSE] - Source of data: [DATA SOURCE] - Key totals or figures: [KEY FIGURES] - Tie out to general ledger: [TIE OUT AMOUNT OR REFERENCE] </inputs> <task> Write a narrative explaining what the schedule shows, where the data came from, and how the totals were tied to the general ledger. </task> <constraints> State the exact tie out figure and reference. Keep the narrative under 150 words. </constraints> <format> Return a single narrative paragraph, no headers needed. </format>
Pro tip: Give the exact general ledger reference number, a schedule without a stated tie out gets kicked back in review.
File Completion Checklist
15/30✨ What it does
Claude produces a file-completion checklist for [AUDIT AREA] that treats [LIST OF OPEN ITEMS, IF ANY] as explicit blockers before archive. Clear those blockers, then send your file to the partner.
You are an audit manager closing out a file before archiving. <context> Fieldwork is done and I need a checklist to confirm the file is ready to close before it goes to the partner. </context> <inputs> - Audit area: [AUDIT AREA] - Outstanding items: [LIST OF OPEN ITEMS, IF ANY] - Sign off requirements: [WHO MUST SIGN OFF] </inputs> <task> Produce a file completion checklist covering documentation completeness, open item resolution, and required sign offs before archiving. </task> <constraints> Call out any outstanding item as a blocker, do not bury it in a general note. Keep each checklist item actionable and specific. </constraints> <format> Return a checklist with checkbox style items grouped under Documentation, Open Items, and Sign Off. </format>
Pro tip: List every open item even small ones, a checklist that hides one open item defeats its own purpose.
These prompts give you the what. Tutorials give you the why.
Learn when to use extended thinking, how to build Claude Projects, and workflows that compound. 300+ tutorials and growing.
Findings and Issue Write-Ups
5 promptsAudit Finding Statement in Condition Cause Effect Format
16/30✨ What it does
Claude writes a finding from [WHAT WAS OBSERVED] against [CRITERIA OR POLICY REFERENCE] in condition, criteria, cause, effect form, plus a recommendation. Edit the effect line for real impact, then send it to your partner.
You are an audit senior writing up a control deficiency. <context> I identified a control gap during testing and need to write it up in a format the client and partner will both accept. </context> <inputs> - Condition observed: [WHAT WAS OBSERVED] - Criteria or standard expected: [CRITERIA OR POLICY REFERENCE] - Root cause: [ROOT CAUSE] - Potential effect: [POTENTIAL EFFECT OR EXPOSURE] </inputs> <task> Write the finding using the condition, criteria, cause, and effect structure, ending with a recommendation. </task> <constraints> Keep each section to two or three sentences. State the effect in concrete terms such as dollar exposure or compliance risk, not vague language like could be an issue. </constraints> <format> Return four labeled sections: Condition, Criteria, Cause, Effect, followed by a Recommendation section. </format>
Pro tip: Quantify the effect wherever you can, a finding without a number is the first one a partner sends back for more detail.
Finding Severity Rating Justification
17/30✨ What it does
Claude recommends one severity rating for [FINDING SUMMARY] with a justification tied to [IMPACT ESTIMATE] and likelihood. Keep that rating unless your partner has a different impact number.
You are an audit manager rating a finding before it goes into the report. <context> I need to justify why I rated this finding as high, medium, or low severity before the partner review. </context> <inputs> - Finding summary: [FINDING SUMMARY] - Financial or operational impact: [IMPACT ESTIMATE] - Likelihood of recurrence: [LIKELIHOOD] - Compensating controls if any: [COMPENSATING CONTROLS OR NONE] </inputs> <task> Recommend a severity rating and justify it based on impact, likelihood, and any compensating controls, using a consistent rating scale. </task> <constraints> Pick one rating, do not hedge between two levels. Explicitly address whether compensating controls lower the rating and why. </constraints> <format> Return a Recommended Rating line followed by a short justification paragraph. </format>
Pro tip: State whether compensating controls exist even if the answer is none, silence on that point reads as an oversight.
Management Response Request Email
18/30✨ What it does
Claude drafts a management-response request to [PROCESS OWNER NAME] on [FINDING SUMMARY] with [DUE DATE] stated up front. Send it the same day, then calendar your follow-up on the due date.
You are an audit senior requesting a formal response to a finding. <context> I need to send the finding to the process owner and ask for their management response and remediation plan. </context> <inputs> - Process owner name: [PROCESS OWNER NAME] - Finding summary: [FINDING SUMMARY] - Response due date: [DUE DATE] </inputs> <task> Draft a professional email that presents the finding, asks for a management response and remediation timeline, and sets the due date. </task> <constraints> Keep the tone direct but not accusatory. State the due date explicitly in the first paragraph, not buried at the end. </constraints> <format> Return a subject line and email body, under 180 words. </format>
Pro tip: Put the due date in the subject line too, that is what actually gets it onto a busy process owner's calendar.
Root Cause Analysis for a Recurring Issue
19/30✨ What it does
Claude separates the surface story of [ISSUE DESCRIPTION] from the systemic cause, using [PRIOR YEAR DETAILS] against this year's recurrence. Put the deeper cause in your write-up so the fix is not cosmetic.
You are an audit manager investigating a repeat finding. <context> This same type of issue showed up last year and again this year, and I need to dig into why it keeps happening. </context> <inputs> - Issue description: [ISSUE DESCRIPTION] - Prior year occurrence: [PRIOR YEAR DETAILS] - Current year occurrence: [CURRENT YEAR DETAILS] - Process changes attempted: [WHAT MANAGEMENT TRIED, IF ANYTHING] </inputs> <task> Analyze why the same issue recurred despite prior remediation, distinguishing a surface cause from the underlying systemic cause. </task> <constraints> Do not accept the prior remediation plan's stated cause at face value if the issue recurred, dig one level deeper. Be specific about what evidence supports the deeper cause. </constraints> <format> Return two sections: Surface Cause and Underlying Cause, each with a short explanation, followed by one sentence on why the prior fix did not hold. </format>
Pro tip: Include what management actually tried last time, a fix that never addressed the underlying cause usually shows in that detail.
Executive Summary of Findings for the Audit Committee
20/30✨ What it does
Claude writes a committee-ready executive summary from [LIST OF FINDINGS AND RATINGS] that leads with the conclusion and groups by severity. Drop it into your audit committee packet, then rehearse the opening line.
You are an audit director preparing the committee presentation. <context> I need to summarize all findings from this engagement into a short section for the audit committee packet. </context> <inputs> - List of findings with severity: [LIST OF FINDINGS AND RATINGS] - Overall audit opinion or conclusion: [OVERALL CONCLUSION] - Number of high severity items: [COUNT] </inputs> <task> Write an executive summary that gives the overall conclusion first, then summarizes findings grouped by severity, written for people who will not read the detailed workpapers. </task> <constraints> Lead with the overall conclusion, not a list of findings. Keep it to one page equivalent, plain language, no jargon without explanation. </constraints> <format> Return an Overall Conclusion paragraph followed by three short sections: High Severity, Medium Severity, Low Severity, each a brief bullet list. </format>
Pro tip: Give the exact high severity count, committee members scan for that number before reading anything else.
Internal Control Matrices
5 promptsRisk and Control Matrix Builder
21/30✨ What it does
Claude builds a risk and control matrix for [PROCESS NAME] from [LIST OF RISKS] and [LIST OF CONTROLS], and flags any risk with no mapped control. Assign [CONTROL OWNER ROLE] on the gaps before your testing starts.
You are an internal audit senior building a control matrix. <context> I am documenting the risk and control matrix for a process before testing begins. </context> <inputs> - Process name: [PROCESS NAME] - Risks identified: [LIST OF RISKS] - Controls in place: [LIST OF CONTROLS] - Control owner: [CONTROL OWNER ROLE] </inputs> <task> Build a risk and control matrix that pairs each risk with its mitigating control, the control owner, and whether the control is preventive or detective. </task> <constraints> Every risk must map to at least one control, flag any risk with no mapped control instead of leaving it blank. Classify each control as preventive or detective, not both. </constraints> <format> Return a table with columns Risk, Control Description, Control Owner, Type (Preventive or Detective). </format>
Pro tip: List every risk you found, even minor ones, an unmapped risk left out of the matrix is easy to lose track of later.
Control Design Effectiveness Assessment
22/30✨ What it does
Claude assesses whether [CONTROL DESCRIPTION] is even designed well enough to catch the risk, separate from whether it operates. Fix design gaps before you waste hours testing a weak control.
You are an audit senior assessing control design before testing operating effectiveness. <context> Before I test whether a control operates, I need to assess whether it is even designed well enough to prevent the risk. </context> <inputs> - Control description: [CONTROL DESCRIPTION] - Risk it addresses: [RISK ADDRESSED] - Frequency and who performs it: [FREQUENCY AND PERFORMER] </inputs> <task> Assess whether the control as designed would actually prevent or detect the risk if operating as described, and identify any design gaps. </task> <constraints> Separate a design gap from an operating gap, this assessment is about design only. If the control would not catch the risk even when working perfectly, say so plainly. </constraints> <format> Return a short assessment stating Design Adequate or Design Gap, followed by a one paragraph explanation. </format>
Pro tip: Describe the control exactly as performed, not as written in the policy, design gaps often live in that difference.
Segregation of Duties Conflict Map
23/30✨ What it does
Claude maps segregation-of-duties conflicts from [PASTE ROLES AND ACCESS RIGHTS] against incompatible function pairs. Send the conflicts to your system owner, then ask which ones they will actually split.
You are an audit senior reviewing access and role assignments. <context> I have a list of who can perform which functions in the system and need to check for segregation of duties conflicts. </context> <inputs> - Roles and access list: [PASTE ROLES AND ACCESS RIGHTS] - System or application: [SYSTEM OR APPLICATION NAME] - Incompatible function pairs to check: [PAIRS TO CHECK, CREATE VENDOR AND APPROVE PAYMENT] </inputs> <task> Identify any individual or role holding both sides of an incompatible function pair, and note the risk each conflict creates. </task> <constraints> Only flag actual conflicts based on the access list given, do not assume a conflict exists without evidence in the inputs. State the specific risk for each conflict found. </constraints> <format> Return a table with columns Person or Role, Conflicting Functions Held, Risk Created. </format>
Pro tip: Paste the full raw access list rather than a summary, a summarized list hides the exact conflicts you need caught.
Key Control Rationalization for a Process
24/30✨ What it does
Claude ranks [PASTE FULL CONTROL LIST] down to key controls justified against [TOP RISKS] and the hours you have. Test only the key set, and tell the process owner why the rest are not key.
You are an internal audit manager reducing an oversized control list. <context> The process owner listed twenty controls for this process and I need to identify which ones are actually key controls worth testing. </context> <inputs> - Full control list: [PASTE FULL CONTROL LIST] - Top risks for the process: [TOP RISKS] - Testing budget or hours available: [HOURS AVAILABLE] </inputs> <task> Rank the controls by how directly each one mitigates a top risk, and recommend which controls should be classified as key controls given the testing budget. </task> <constraints> Justify each key control selection by tying it to a specific top risk, not just its position on the original list. State clearly which controls are being excluded and why. </constraints> <format> Return two lists: Key Controls Recommended For Testing, and Controls Excluded With Reason. </format>
Pro tip: State your real hours available honestly, an inflated budget number produces a key control list you cannot actually test.
Control Matrix Update After a Process Change
25/30✨ What it does
Claude updates the matrix from [OLD CONTROLS SUMMARY] to match [NEW SYSTEM DESCRIPTION] and flags any risk left without a control. Review those gaps with the client before you start this year's testing.
You are an audit senior updating documentation after a system change. <context> The client rolled out a new system for this process and my existing control matrix is now out of date. </context> <inputs> - Old control matrix summary: [OLD CONTROLS SUMMARY] - New system or process description: [NEW SYSTEM DESCRIPTION] - Controls confirmed still in place: [CONTROLS CONFIRMED] - Controls confirmed removed or changed: [CONTROLS CHANGED OR REMOVED] </inputs> <task> Update the control matrix to reflect the new system, flagging which controls carried over unchanged, which changed, and which are new gaps needing a control. </task> <constraints> Do not assume an old control still works the same way in the new system unless it was confirmed. Flag any risk that now has no control as a priority item. </constraints> <format> Return a table with columns Risk, Old Control Status, New Control Status, Action Needed. </format>
Pro tip: Confirm each carried over control with the process owner before listing it as unchanged, assumptions here create blind spots.
Most people use 10% of Claude. Tutorials unlock the rest.
AI Academy: 300+ hands-on tutorials on Claude, ChatGPT, Midjourney, and 50+ AI tools. New tutorials added every week.
Reporting and Follow-Up
5 promptsDraft Audit Report Executive Summary
26/30✨ What it does
Claude drafts a report executive summary from [AUDIT OBJECTIVE] and [OVERALL CONCLUSION] that leads with the conclusion in the first two sentences. Check your findings count, then drop this draft into the report.
You are an audit manager drafting the final report. <context> Fieldwork and review are complete and I need a first draft of the executive summary section of the report. </context> <inputs> - Audit objective: [AUDIT OBJECTIVE] - Overall conclusion: [OVERALL CONCLUSION] - Number and severity of findings: [FINDINGS COUNT AND SEVERITY] - Scope period: [SCOPE PERIOD] </inputs> <task> Draft an executive summary stating the objective, scope, overall conclusion, and a brief count of findings by severity. </task> <constraints> State the overall conclusion in the first two sentences. Keep the entire summary under 200 words. </constraints> <format> Return a single executive summary section, no subheadings needed. </format>
Pro tip: Write the overall conclusion yourself before prompting, Claude will draft around whatever conclusion you give it.
Remediation Plan Review Checklist
27/30✨ What it does
Claude evaluates [PASTE REMEDIATION PLAN] against [FINDING SUMMARY] and flags missing ownership or timelines. Send those gaps back to the process owner before you accept the plan.
You are an audit senior reviewing a client's remediation plan. <context> The process owner sent back a remediation plan for a finding and I need to check it is actually adequate before I accept it. </context> <inputs> - Finding it addresses: [FINDING SUMMARY] - Remediation plan as submitted: [PASTE REMEDIATION PLAN] - Target completion date: [TARGET DATE] </inputs> <task> Evaluate whether the remediation plan actually addresses the root cause of the finding, has a realistic timeline, and names a responsible owner. </task> <constraints> If the plan only addresses symptoms and not the root cause, say so directly and explain what is missing. Do not accept a plan with no named owner as adequate. </constraints> <format> Return an Adequate or Needs Revision decision line, followed by a short explanation of what is missing if applicable. </format>
Pro tip: Paste the remediation plan exactly as the process owner wrote it, rewording it yourself hides where it is actually vague.
Quarterly Audit Status Update for Leadership
28/30✨ What it does
Claude summarizes [LIST OF AUDITS IN PROGRESS] and [LIST OF COMPLETED AUDITS] for leadership, leading with overdue or at-risk high-severity items. Send your short update, and be ready to speak to the overdue list.
You are an internal audit director reporting to executive leadership. <context> I need to give leadership a short quarterly update on where all open audits and findings stand. </context> <inputs> - Audits in progress: [LIST OF AUDITS IN PROGRESS] - Audits completed this quarter: [LIST OF COMPLETED AUDITS] - Open high severity findings across the department: [LIST OF OPEN HIGH SEVERITY ITEMS] </inputs> <task> Summarize the quarter's audit activity and highlight any open high severity finding that is approaching or past its remediation deadline. </task> <constraints> Lead with anything overdue or at risk, not with a general activity recap. Keep the whole update to a half page equivalent. </constraints> <format> Return three short sections: In Progress, Completed This Quarter, Attention Needed. </format>
Pro tip: List the actual remediation deadlines next to each high severity item, a date makes the overdue ones obvious at a glance.
Post-Audit Lessons Learned Summary
29/30✨ What it does
Claude captures specific lessons from [AUDIT AREA] and [CHALLENGES FACED], split between next year's planning and the team's process. Share it in your close-out, then put one change on next year's kickoff agenda.
You are an audit manager closing out an engagement. <context> The engagement just wrapped and I want to capture what went well and what should change before the next audit of this area. </context> <inputs> - Audit area: [AUDIT AREA] - Challenges encountered during fieldwork: [CHALLENGES FACED] - Team feedback: [TEAM FEEDBACK NOTES] </inputs> <task> Summarize lessons learned from this engagement, separating process improvements for the audit team from observations to carry into next year's planning. </task> <constraints> Be specific enough that next year's planner could act on it, avoid generic statements like communication could improve. Name the actual friction point. </constraints> <format> Return two sections: For Next Year's Planning, and For the Audit Team's Process. </format>
Pro tip: Paste the raw team feedback notes rather than a summary, the specific complaints are what turn into actionable lessons.
Overdue Remediation Escalation Note
30/30✨ What it does
Claude drafts a factual escalation on [FINDING SUMMARY] that is [DAYS OVERDUE] past [ORIGINAL DUE DATE], with no update from the process owner. Send it one level up the same day, and attach your original commitment.
You are an audit senior tracking overdue findings. <context> A finding's remediation deadline has passed with no update from the process owner and this needs to go up a level. </context> <inputs> - Finding summary: [FINDING SUMMARY] - Original due date: [ORIGINAL DUE DATE] - Days overdue: [DAYS OVERDUE] - Process owner and their manager: [PROCESS OWNER AND MANAGER NAMES] </inputs> <task> Draft an escalation note to the process owner's manager explaining the overdue status and requesting a firm new commitment date. </task> <constraints> State the days overdue as a specific number in the first sentence. Keep the tone professional and factual, not confrontational. </constraints> <format> Return a short escalation note under 150 words, addressed to the manager. </format>
Pro tip: Confirm the exact days overdue before sending, a rounded or wrong number undercuts the note's credibility.
Free tool
Prompt Optimizer
Turn a rough idea into a structured, professional AI prompt.
Frequently Asked Questions
Prompts are the starting line. Tutorials are the finish.
A growing library of 300+ hands-on tutorials on ChatGPT, Claude, Midjourney, and 50+ AI tools. New tutorials added every week.
7-day free trial. Cancel anytime.
Related guides