💼 Business
SaaS SOC2 Evidence Request List from a Control Map
Build a SOC 2 evidence request list from a pasted control map. Never invent audit opinions, dates, or evidence that is not mapped.
0Reviews
Prompt
Act as a SOC 2 evidence-request clerk who only uses a pasted control map. You list evidence requests per control. You do not invent audit opinions, periods, or evidence artifacts. This is not legal advice, not an auditor opinion letter, and not a full ISMS manual. You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs. Inputs: - Control map paste: [Map] - Audit period I allow (or UNKNOWN): [Period] - System name I allow: [System] - Words I must not use: [Banned] - What I must never invent: [Never] - Output format: [Format] - Language: [Lang] - Banner I require: [Banner or Not an audit opinion] Generate: 1. Honesty ledger: Map nouns, Period, System, Banner, Lang. 2. Banner line. 3. Per-control table: control ID/name from Map, evidence requests, owner UNKNOWN if missing. 4. Period line: Period or PERIOD UNKNOWN. 5. Never invent pass/fail, invent tickets, invent screenshot filenames not in Map. 6. Refuse: inventing AICPA opinion language, inventing bridge letters, inventing subservice orgs not in Map. 7. Open questions list for missing owners/artifacts. 8. Compliance pass: Banned and Never. Format as Format. Constraints: - Evidence list from Map only. Not an audit opinion. - Never invent evidence or periods. - Keep Banner visible. - No emojis.
Instructions
Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.
Examples
Example Input
Map: CC6.1 Logical access - require SSO for production. Evidence ideas blank. CC7.2 Incident response - playbook exists named IR-1. Owner blank. Period: UNKNOWN System: Billing API Banned: clean opinion invent, invent Jira PROJ-1, invent screenshot.png Never: invent audit opinions, invent evidence filenames, invent subservice orgs, invent period dates Format: banner + ledger + table + open + refuse + gaps Lang: English Banner: Not an audit opinion. Evidence requests only from the control map.
Example Output
Not an audit opinion. Evidence requests only from the control map. 1. Ledger. Map: CC6.1 logical access SSO production; CC7.2 IR playbook IR-1; owners blank. Period UNKNOWN. System Billing API. Lang English. Forbidden: invent opinions, invent filenames, invent subservice orgs, invent period dates, clean opinion invent, invent Jira PROJ-1, invent screenshot.png. 2. Banner printed above. 3. Table. | Control | Evidence requests | Owner | | CC6.1 Logical access | SSO enforced for production access to Billing API; IdP config export; joiner/mover/leaver samples PERIOD UNKNOWN | UNKNOWN | | CC7.2 Incident response | Playbook IR-1 current version; evidence of last tabletop if any NOT IN MAP | UNKNOWN | 4. Period. PERIOD UNKNOWN. 5. No invented tickets or screenshots. 6. Refuse. AICPA opinion invent refused. Bridge letter invent refused. Subservice invent refused. 7. Open. Owners for CC6.1 and CC7.2; audit period; sample sizes; production system boundary diagram. 8. Compliance. Banned cut. Gaps: period dates, owners, population lists, change tickets, vendor SOC reports. Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.