ISO 27001 Internal Audit Readiness Plan Builder

Prepare for an ISO 27001 internal audit with scope, control ownership, evidence requests, interview plans, gap tracking, and corrective actions.

Prompt Template

You are an ISO 27001 compliance program manager. Build an internal audit readiness plan for:

Organization type: [SaaS, fintech, healthcare, agency, enterprise, nonprofit]
Certification goal/status: [first certification, surveillance audit, recertification, internal readiness only]
Standard version/scope: [ISO/IEC 27001:2022 scope, locations, products, systems, teams]
ISMS maturity: [new, partially documented, mature, inherited controls]
Controls in focus: [access control, risk management, supplier security, incident response, asset inventory, HR security]
Evidence tools: [GRC platform, ticketing, HRIS, cloud console, SIEM, policy repo, spreadsheets]
Control owners: [security, IT, HR, engineering, legal, procurement, finance]
Timeline: [weeks until audit, milestones, blackout dates]
Known gaps: [missing risk register, stale policies, incomplete vendor reviews, weak evidence]
Auditor/interview needs: [internal auditor, external consultant, leadership interviews, sample requests]

Create:
1. Audit scope and objective statement
2. Control owner responsibility matrix
3. Evidence request list by control area
4. Interview schedule and question bank
5. Sampling strategy for tickets, access reviews, vendors, incidents, and training
6. Gap log template with severity and owner
7. Corrective action plan workflow
8. Readiness timeline with weekly milestones
9. Executive summary template for leadership
10. Common ISO audit pitfalls and prevention steps

Example Output

Week 1: confirm ISMS scope, freeze policy owners, export asset inventory, and assign Annex A control owners.

Evidence request: last two quarterly access reviews, risk treatment plan, incident drill record, supplier review samples, security awareness completion report.

Gap severity: High if evidence is missing for a control in scope; Medium if evidence exists but owner or date is unclear.

Tips for Best Results

  • 💡List your control owners and tools so the plan becomes an executable evidence chase list.
  • 💡Include known gaps honestly; the output can convert them into corrective actions.
  • 💡Ask for a lightweight version if you are preparing for a startup-scale first audit.

Frequently Asked Questions

What is the ISO 27001 Internal Audit Readiness Plan Builder prompt?

Prepare for an ISO 27001 internal audit with scope, control ownership, evidence requests, interview plans, gap tracking, and corrective actions. It's a free ChatGPT prompt template from our Business collection — copy it, fill in the bracketed variables, and paste it into your AI tool.

Which AI tools work with this prompt?

It's written and tested for ChatGPT, Claude and Gemini. Any AI assistant that accepts free-form text prompts will handle it well.

How do I customize this ChatGPT prompt?

Adjust the details in the template to match your own context before running it. List your control owners and tools so the plan becomes an executable evidence chase list.

Is this prompt free to use?

Yes. Every prompt on PromptAtlas is free to copy, customize, and use — no signup required.