ISO 27001 Internal Audit Readiness Plan Builder
Prepare for an ISO 27001 internal audit with scope, control ownership, evidence requests, interview plans, gap tracking, and corrective actions.
Prompt Template
You are an ISO 27001 compliance program manager. Build an internal audit readiness plan for: Organization type: [SaaS, fintech, healthcare, agency, enterprise, nonprofit] Certification goal/status: [first certification, surveillance audit, recertification, internal readiness only] Standard version/scope: [ISO/IEC 27001:2022 scope, locations, products, systems, teams] ISMS maturity: [new, partially documented, mature, inherited controls] Controls in focus: [access control, risk management, supplier security, incident response, asset inventory, HR security] Evidence tools: [GRC platform, ticketing, HRIS, cloud console, SIEM, policy repo, spreadsheets] Control owners: [security, IT, HR, engineering, legal, procurement, finance] Timeline: [weeks until audit, milestones, blackout dates] Known gaps: [missing risk register, stale policies, incomplete vendor reviews, weak evidence] Auditor/interview needs: [internal auditor, external consultant, leadership interviews, sample requests] Create: 1. Audit scope and objective statement 2. Control owner responsibility matrix 3. Evidence request list by control area 4. Interview schedule and question bank 5. Sampling strategy for tickets, access reviews, vendors, incidents, and training 6. Gap log template with severity and owner 7. Corrective action plan workflow 8. Readiness timeline with weekly milestones 9. Executive summary template for leadership 10. Common ISO audit pitfalls and prevention steps
Example Output
Week 1: confirm ISMS scope, freeze policy owners, export asset inventory, and assign Annex A control owners.
Evidence request: last two quarterly access reviews, risk treatment plan, incident drill record, supplier review samples, security awareness completion report.
Gap severity: High if evidence is missing for a control in scope; Medium if evidence exists but owner or date is unclear.
Tips for Best Results
- 💡List your control owners and tools so the plan becomes an executable evidence chase list.
- 💡Include known gaps honestly; the output can convert them into corrective actions.
- 💡Ask for a lightweight version if you are preparing for a startup-scale first audit.
Related Prompts
SOC 2 Evidence Collection Plan Builder
Create a practical SOC 2 evidence collection plan that maps controls, owners, artifacts, deadlines, and audit readiness gaps.
One-Page Business Plan
Generate a concise, investor-ready one-page business plan covering all critical aspects of your venture.
SWOT Analysis Framework
Conduct a thorough SWOT analysis with actionable strategies derived from each quadrant.