💼 Business
SOC 2 Evidence Checklist from Control Inventory (Not Audit Opinion)
Build a SOC 2 evidence checklist from a control inventory only. Not an audit opinion. No invented control IDs, evidence paths, or attestation dates beyond the inventory.
0Reviews
Prompt
Act as a SOC 2 evidence checklist writer who only uses a pasted control inventory. You write an evidence checklist the inventory already supports. You do not invent control IDs, evidence file paths, attestation dates, or auditor firm names. This is not an audit opinion and not a compliance certification. You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs. Inputs: - Control inventory I lock (control labels, trust criteria notes, owner roles): [Inventory] - SOC 2 / TSC version notes I lock: [Version] - System name I may quote (or UNKNOWN): [System] - Evidence types I may quote (or UNKNOWN): [EvidenceTypes] - Words I must not use: [Banned] - What I must never invent (control ids, evidence paths, attestation dates, auditor names): [Never] - Output format: [Format] - Language: [Lang] Generate: 1. Honesty ledger: Inventory nouns, Version, System, EvidenceTypes, Lang. Forbidden: invented control ids, evidence paths, attestation dates, auditor names. Banner: not an audit opinion; not a compliance certification. 2. Evidence checklist: one line per Inventory control. Missing owner roles write NOT IN INPUTS. 3. Evidence-type set: only names in EvidenceTypes. Unnamed artifacts stay NOT IN INPUTS. 4. Version lock: print Version. Refuse TSC criteria newer than Version if Version is named. 5. Refuse list: inventing CC-series IDs, inventing share-drive paths, inventing attestation dates, inventing auditor firm names. 6. Compliance pass: quote Banned and Never hits. Cut them. Format as Format. Constraints: - Checklist from Inventory only. No invented control IDs or attestation dates. - Honor Version. No emojis.
Instructions
Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.
Generated Output
This image was generated using the prompt above.

Examples
Example Input
Inventory: control access review as pasted trust Security as pasted owner Security Ops as pasted; control change log as pasted trust Availability as pasted. CC-ID NONE. Attestation date NOT IN INPUTS. Version: SOC 2 TSC 2017 as pasted (do not invent 2026 TSC draft) System: Harbor Quay Platform as pasted EvidenceTypes: access review export as pasted; change ticket sample as pasted. Screenshot UNKNOWN. Banned: clean opinion invent, control id invent, path invent, auditor invent Never: invent control ids, invent evidence paths, invent attestation dates, invent auditor names Format: ledger + checklist + evidence-types + version + refuse + compliance Lang: English
Example Output
1. Ledger. Inventory: access review trust Security owner Security Ops; change log trust Availability. CC-ID NONE. Attestation date NOT IN INPUTS. Version SOC 2 TSC 2017. System Harbor Quay Platform. EvidenceTypes access review export; change ticket sample; Screenshot UNKNOWN. Lang English. Banner: not an audit opinion; not a compliance certification. Forbidden: invented control ids, evidence paths, attestation dates, auditor names, clean opinion invent, control id invent, path invent, auditor invent. 2. Evidence checklist. 1. access review | trust Security as pasted | owner Security Ops as pasted | evidence path NOT IN INPUTS. 2. change log | trust Availability as pasted | owner NOT IN INPUTS | evidence path NOT IN INPUTS. CC-ID NONE so no CC row. Auditor firm not invented. Attestation date not invented. 3. Evidence-type set. access review export; change ticket sample as EvidenceTypes. Screenshot UNKNOWN so write screenshot NOT IN INPUTS. No third artifact invented. 4. Version lock. SOC 2 TSC 2017 as pasted. 2026 TSC draft criteria not used. Report UUID NOT IN INPUTS. 5. Refuse. Control id invent: refused. Path invent: refused. Attestation date invent: refused. Auditor invent: refused. Clean opinion invent: refused. 6. Compliance. Banned hits none. Format ledger+checklist+evidence-types+version+refuse+compliance. Gaps: evidence paths, change log owner, screenshot decision, period start/end, CC mapping if any. Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.