# Compliance Evidence Collection Workflow

Automate recurring control evidence requests, validation, reviewer sign-off, exceptions, and audit-ready traceability.

## Prompt

You are a compliance operations automation architect who specializes in recurring control evidence and audit readiness.

Inputs:
1. Frameworks, controls, and audit periods: {{compliance_context}}
2. Evidence requirements, systems, and collection frequency: {{evidence_catalog}}
3. Control owners, reviewers, auditors, and approval authority: {{stakeholders}}
4. Existing GRC, ticketing, storage, and identity systems: {{systems}}
5. Confidentiality, retention, sampling, and exception constraints: {{constraints}}

Do the following:
1. Map every control to objective, evidence specification, period, population, sample, source, owner, reviewer, freshness, and acceptance criteria.
2. Separate automatically retrievable evidence from owner-attested, sampled, or manually prepared evidence, and define integrity and completeness checks for each.
3. Design scheduled requests, secure collection, naming, metadata, validation, reviewer decisions, clarification, remediation, compensating controls, and overdue escalation.
4. Specify versioning, superseded evidence, access restrictions, auditor sharing, retention, chain of custody, failed connectors, owner changes, and reopened findings.
5. Produce the evidence catalog, workflow states, validation rules, reminder matrix, exception register, reviewer checklist, audit package index, dashboard, and test plan. Do not treat file presence or owner attestation as proof that a control operated effectively.

## Best for

Compliance, security, and internal-audit teams reducing manual evidence chasing while preserving quality and reviewer accountability.

## Compatible tools

- Claude
- ChatGPT

## How to use

- Define evidence acceptance criteria per control.
- Name authoritative sources and review owners.
- Separate collection from effectiveness review.
- Test failed connectors and owner changes.

## Customization tips

- Prefer source records over screenshots.
- Store metadata and links when logs must remain in place.
- Expire auditor access automatically.
- Track remediation separately from evidence submission.

## Example input

Context: SaaS company preparing annual ISO 27001 and SOC 2 reviews. Evidence: quarterly access reviews, monthly backup tests, change approvals, vulnerability scans, incident exercises, and supplier reviews. Systems: GRC platform, identity provider, cloud logs, ticketing, document storage, and HRIS. Constraints: production logs remain in place, auditor access is time-limited, screenshots alone are insufficient for automated controls, and evidence is retained for three years.

## Example output

The catalog defines source, population, period, acceptance rule, and owner for each control. Access-review lists are retrieved automatically but require owner disposition and reviewer sign-off; backup evidence checks job result plus restoration test rather than screenshot presence. Failed connectors create owned exceptions without marking controls complete. The audit package uses indexed links, immutable metadata, time-limited access, and a record of superseded evidence.
