Docs
How it works

Compliance - Example prompts

Ten AI Sidekick prompts for compliance work.

These prompts are seed ideas, not a catalogue. Every environment differs, and the ones you end up using should reflect yours — treat these as a starting point to adapt.

Connect your agent first

Each prompt below runs against your own CISO360AI data — your frameworks, controls, evidence, risks and findings — so your agent needs the CISO360AI connector set up before any of them will work. It takes a couple of minutes and is available on every plan, including Free. See Connect your AI agent.

You can also paste any of them straight into the AI Sidekick inside the app, where the connection is already there.

Ten prompts to start from

#PromptWhat it gets you
1"We're ISO 27001 certified and a customer now wants SOC 2 Type II. Using CISO360AI's cross-framework mapping, show me which SOC 2 Trust Services Criteria my existing ISO controls already satisfy, and list only the genuinely new work."Avoids re-doing most of the work. The classic "second framework" problem.
2"Draft a justification for excluding [control] from our ISO 27001 scope in CISO360AI, in language an external auditor will accept."Scoping language is where most first-time certifications get pushed back.
3"Summarise my CISO360AI control coverage by NIST CSF 2.0 category, and tell me which category is weakest and why."A fast posture read for a board or exec paper.
4"List every control in CISO360AI scored 'partial' or worse that maps to more than one framework, ranked by how many frameworks it affects."Finds the high-leverage fixes — one remediation closes gaps in three standards.
5"Which of my failed cloud posture checks in CISO360AI map to ISO 27001 Annex A controls, and what evidence would an auditor expect to see for each?"Connects technical configuration findings to the audit narrative — usually a manual translation job.
6"Convert my top 10 open CISO360AI compliance gaps into risk statements with inherent and residual scores."Turns a gap list into a defensible risk register, ready for you to judge against your own risk appetite.
7"Explain, in plain English for a non-technical audit committee, why risk [ID] in CISO360AI still scores Medium after treatment, and what would be required to bring it to Low."Answers the single question every audit committee asks.
8"Build me a 90-day remediation plan from my open CISO360AI actions, sequenced by risk reduction per unit of effort, with owners and due dates."A defensible prioritisation you can show the auditor as "management response".
9"Which controls in [framework] have no evidence attached yet in CISO360AI, so I know where to focus before the next audit?"Surfaces the gap you'd rather find yourself than have an auditor find for you.
10"Generate an audit readiness report from CISO360AI for [framework]: coverage, open gaps, accepted risks with sign-off, and the top 5 questions the auditor is most likely to ask us."Dress rehearsal before the auditor walks in.

Where they sit in the compliance cycle:

A real-world way to use these: treat 9 → 4 → 6 as your monthly rhythm (what's missing evidence, what's the biggest multi-framework gap, what does that mean in risk terms), and save 1, 2 and 10 for the run-up to an audit or a new customer security questionnaire.

On this page