Compliance Gap Analysis Mapper
Maps current controls to a target framework, identifies gaps, and builds a prioritized remediation and evidence plan.
Prompt
ROLE: You are a GRC analyst performing a gap analysis between an organization's current controls and a target compliance framework. CONTEXT: - Target framework: [SOC2_ISO27001_NIST_CSF_HIPAA_PCI_DSS] - Current control state: [PASTE_EXISTING_CONTROLS_AND_PRACTICES] - Scope/boundary: [SYSTEMS_AND_DATA_IN_SCOPE] - Timeline & driver: [AUDIT_DATE_CUSTOMER_REQUIREMENT] TASK: 1. Map each relevant framework requirement/control to the organization's current state: Met / Partially met / Not met / Not applicable (justify N/A). 2. For each gap, describe what's missing and the risk/audit consequence of leaving it. 3. Specify the evidence/artifact an auditor would expect for that control (policy, log, ticket, config). 4. Prioritize remediation by effort vs audit-blocking severity, and group quick wins. 5. Produce a remediation roadmap with owners (roles) and target dates against the audit timeline. OUTPUT FORMAT: - Control mapping table | Requirement/Control ID | Status | Current state | Gap | Required evidence - Gap summary (count by domain) - Prioritized remediation roadmap (control | action | effort | priority | owner role | due) - Evidence collection checklist CONSTRAINTS: Justify every 'Not applicable' — auditors challenge unexplained exclusions. Distinguish 'control absent' from 'control exists but lacks evidence.' Sequence remediation to hit the audit date; flag any gap that cannot realistically close in time.
How to use this prompt
- 1
Copy the prompt above and paste it into ChatGPT, Claude, or Gemini — or open it in the visual Studio to edit each part on a canvas and run it with your own key.
- 2
Replace any bracketed placeholders with your specifics. The more concrete your context and constraints, the sharper the result — see the 5-part prompt structure.
- 3
Run it, then refine. Ask the model to critique and improve its own answer with self-critique prompting.
Techniques in this prompt
Assigns the model an expert persona so it adopts the right vocabulary, depth, and standards for the task.
Learn this techniquePins the response to a defined structure so it drops straight into your workflow.
Learn this techniqueForces explicit intermediate reasoning instead of jumping to a conclusion, which improves accuracy on hard tasks.
Learn this techniqueRecommended models
Build on this prompt
Open it in the visual Studio to wire it into a full workflow with your own API key — or learn the craft behind prompts like this.
More in Cybersecurity & Risk
STRIDE Threat Model For A New Service
Builds a structured STRIDE threat model for a system with trust boundaries, ranked threats, and concrete mitigations.
Security Incident Postmortem Author
Drafts a blameless post-incident review with timeline, root cause, and corrective actions ready for leadership.
CVE Triage And Prioritization Analyst
Triages a list of CVEs by exploitability and business context to produce an actionable patch priority queue.
Phishing Email Forensic Examiner
Analyzes a suspicious email's headers, URLs, and payload to classify intent and recommend SOC response.