CORAA
CORAA University · Free tool

AI prompts for internal audit prompt library 2026

Pick the audit stage and the process cycle and get a complete prompt you can paste into ChatGPT, Claude, Copilot or Gemini: role, task, output format, and the rules that stop the tool inventing a section number or filling in a fact you never gave it. Under each prompt: what to give the tool, what not to paste, and how to check the answer. The Excel download holds all 110 prompts for FY 2026-27 audit work.

1. Where you are in the audit
2. The process cycle
3. Optional: industry and accounting system
Where the books are kept
These two choices are written into the prompt on screen and into every prompt in the Excel download. Nothing you pick or type on this page leaves your browser.
Stage 03 · Procure-to-pay
Risk and control matrix (RCM)
What you get back: An RCM table from your process narrative, with missing controls and expected-but-absent controls flagged.
ROLE
You are assisting an internal auditor in India. The work relates to the procure-to-pay cycle of a company [state the industry]. The books are kept in [Tally / SAP / other: state the system]. I am the auditor: you draft and structure, I verify every fact and I decide every rating and conclusion.

TASK
Draft a risk and control matrix for the procure-to-pay cycle from the process narrative in my input.
Record only the controls my input describes, and show me where an expected control is missing.

STARTING POINTS FOR PROCURE-TO-PAY
Use these as a checklist. A risk or control from this list that my input does not confirm must not be written as if it exists.
- Sub-processes: vendor onboarding and vendor master changes; purchase requisition and purchase order; goods receipt and service acceptance; invoice booking and matching; payment release; advances, debit notes and vendor reconciliation.
- Risk themes: fictitious or duplicate vendors in the vendor master; purchases made without approval, or split to stay under an approval limit; goods or services paid for but not received; duplicate, inflated or early payment of invoices; vendor bank details changed shortly before a payment; advances not adjusted and old debit balances on vendor accounts.
- Controls usually expected: independent check of vendor identity, tax registration and bank details before the vendor is created; approval under the delegation of authority before the company is committed; three-way match of purchase order, receipt and invoice before booking; maker-checker on payment release, with the approver seeing the invoices being paid; review of the vendor master change log, bank account changes in particular; periodic vendor balance confirmation and review of open advances and receipts not yet invoiced.

OUTPUT FORMAT
- One table. Columns: Sub-process | Risk | Control (as described in my input) | Control objective | Control type and frequency | Test of design | Test of operating effectiveness | Evidence.
- Control objective: choose from existence, validity, occurrence, accuracy, completeness, authorisation, valuation, compliance.
- Control type and frequency: preventive or detective; manual, automated or IT-dependent manual; then how often it runs.
- Where my input describes no control for a risk, write CONTROL NOT EVIDENCED IN INPUT in the Control column and leave the test columns blank.
- After the table, list under EXPECTED BUT NOT DESCRIBED any control from the checklist that my input does not mention.

RULES
1. Use only the facts in MY INPUT. The starting points above are general, not facts about this company; anything you take from them that my input does not confirm must be marked [ASSUMPTION].
2. Mark every other assumption as [ASSUMPTION] at the place where you make it.
3. Do not invent section numbers, rule numbers, standards paragraphs, thresholds, rates, due dates, circulars or case law. Where law, a standard or a company policy seems relevant, describe the topic in words and write TO BE VERIFIED.
4. If a fact you need is missing, do not fill it in. List what you need under QUESTIONS FOR THE AUDITOR before the output, and write NOT PROVIDED where the fact would have gone.
5. One control per row. Do not merge two controls into one sentence.
6. Write each test so that a second auditor could repeat it: what to obtain, what to compare, what counts as a failure.
7. Do not mark any control as key and do not rate any control. I will.
8. Do not name reports, menu paths, tables or fields of the accounting system unless my input gives them. Describe the data in words.

MY INPUT
Process narrative or SOP with names replaced by roles, the relevant part of the delegation of authority, and any existing RCM:
[paste here]
618 words. Replace anything in square brackets, then paste your own input where it says [paste here]. Works in any general AI assistant; if the copy button is blocked by your browser, select the text and copy it.
Before you paste, and before you rely on it
Give the tool
  1. The process narrative or SOP, with names replaced by roles.
  2. The relevant part of the delegation of authority: who approves what, up to what limit.
  3. Any existing RCM for the process, even an old one.
  4. The accounting system, and which steps happen outside it.
Do not paste
  1. Names of employees. Use roles such as AP executive or stores in-charge.
  2. A delegation of authority that lists people by name. Convert it to roles first.
  3. Vendor bank account numbers, PAN and GSTIN of proprietors and individuals, and contact persons with phone numbers.
  4. Names, phone numbers, email addresses, PAN, Aadhaar, bank account numbers or salary of any employee, customer or vendor.
  5. Raw ledgers, registers or extracts. Give descriptions, counts and totals; run the tests in a spreadsheet or a testing tool.
Check the answer
  1. Walk each control with the process owner. A control exists only if someone performs it and it leaves evidence.
  2. Read each test against its control: does the test step test that control, or something next to it?
  3. Treat everything under EXPECTED BUT NOT DESCRIBED as a question for the walkthrough, not as a gap.
  4. Search the answer for [ASSUMPTION], TO BE VERIFIED and NOT PROVIDED. Resolve each one before the text goes into the file.
  5. Any section number, standard paragraph, threshold, rate or due date in the answer: open the source and read it, or delete it.
Working file
The answer is a draft. Put the checked version into the working file for this stage: the RCM builder.
What every prompt in the library contains
Role and task
Who the tool is helping, on which cycle, and the one piece of work wanted. It also says who decides: the tool drafts, the auditor verifies and concludes.
Starting points for the cycle
Sub-processes, risk themes, expected controls, records and common exceptions for the cycle you picked, given to the tool as a checklist and labelled as general, not as facts about the company.
Output format
The exact tables and headings wanted: RCM columns, the five parts of an observation, the columns of a request list. A fixed format is what makes two answers comparable.
Mark every assumption
Anything the tool adds that your input does not confirm carries the tag [ASSUMPTION], so you can find it and remove or confirm it.
No invented citations
No section, rule, standards paragraph, threshold, rate, due date or case law from memory. The tool writes TO BE VERIFIED and you fill it from the source.
Ask, do not fill in
Where a fact is missing the tool lists its questions first and writes NOT PROVIDED in the output, in place of a plausible guess.
The eleven stages, and what each prompt gives you
Risk factors by sub-process, a blank scoring sheet for you to fill, coverage options and a draft paragraph for the plan.
A scope note with objectives, an in-scope and out-of-scope table, approach, deliverables, dependencies and limitations.
An RCM table from your process narrative, with missing controls and expected-but-absent controls flagged.
A question set by step, the document trail for one transaction and a memo skeleton to fill in after the meeting.
A grouped information request list with purpose, period, format and owner, plus a completeness check for each extract.
A test of operating effectiveness for each control, a full-population alternative where data exists, and a sampling rationale with the size left to you.
A structured working-paper note from your rough results, with every count kept as you gave it and the conclusion left to you.
A five-part observation from your verified facts, with the management response, owner and target date left open and a source trail for every sentence.
A gap table on management's response, the closure evidence to ask for and a short neutral reply requesting what is missing.
A one-page summary: coverage, a ratings table, themes across observations, disagreements and matters for the committee.
A follow-up table with closure evidence and re-test steps by rating, a note to action owners and a short summary of overdue items.
Using AI in internal audit without getting into trouble
Authority to use the tool
Use an AI tool on audit work only if the company (for an in-house team) or the engagement terms and your firm's policy (for a CA firm) allow it, and only the tool and account they allow. Check your plan's data-use and retention settings before any work material goes in.
No personal data in consumer tools
Names, PAN, Aadhaar, bank accounts, salary and contact details of employees, customers and vendors stay out. The Digital Personal Data Protection Act applies to that data whoever is holding it. Masked references, counts and totals are enough for every prompt in this library.
The auditor remains responsible
These tools draft, summarise and structure. They do not test a population, and they can state a section, a threshold or a date that is wrong. Evidence, ratings and conclusions are the auditor's, and each prompt here keeps them with you.
Record it in the working paper
Note the tool, what it was used for, what was given to it, what you verified and what you changed, with preparer and reviewer initials. A reviewer should be able to see where the draft came from and what stands behind it.

To set the rules for a whole department or firm, start with the internal audit AI strategy template. To record AI assistance on a file, use the AI governance working paper. What the data protection law expects of anyone holding personal data in audit files is set out in DPDP for CA firms.

The checked answer belongs in a working file, not in a chat window: the RCM builder, the walkthrough memo generator, the sampling plan generator, the observation report generator and the ATR tracker.

Drafting is not testing

A chat assistant can draft the RCM, but it does not test a single transaction

Every prompt here produces words: a matrix, a question list, an observation. Whether the control worked across the year is a question for the data — every voucher, every vendor, every journal, with each exception traced to its entry. That part needs a tool built to test the full population, which is the part CORAA does.

Further reading: AI in internal audit 2026, stage by stage, ChatGPT for internal audit: prompts, uses and limits and Claude for internal audit: Projects, prompts and workflow.

How to use AI prompts for internal audit in 2026

An internal audit prompt fails for three ordinary reasons. It does not say what the answer should look like, so the tool returns an essay where a table was needed. It does not say what the tool may and may not use, so the answer mixes your facts with general knowledge and you cannot tell which is which. And it says nothing about citations, so a section number or a threshold appears that nobody has checked. The prompts in this library are written to close those three gaps every time.

Each prompt is assembled from two parts. The stage part carries the task and the output format: the columns of a risk and control matrix, the five parts of an observation (Condition, Criteria, Cause, Effect/Risk, Recommendation, then management response, owner and target date), the columns of a data request list or an action taken report. The cycle part carries what is particular to procure-to-pay, order-to-cash, record-to-report, cash and bank, hire-to-retire, fixed assets, inventory, treasury, statutory compliance or IT general controls: the sub-processes, the risk themes, the controls usually expected, the records to ask for and the exceptions commonly found.

Four rules are the same in every prompt. Use only the facts given. Mark every assumption. Do not invent section numbers, standards paragraphs, thresholds or case law, and write TO BE VERIFIED in their place. Ask for a missing fact instead of filling it in. The stage then adds its own rules: the RCM prompt will not mark a control as key, the sampling prompt will not suggest a sample size, the observation prompt will not rate the finding, and the follow-up prompt will not mark an item closed. Those decisions stay with the auditor.

The prompts work in any general AI assistant, including ChatGPT, Claude, Microsoft Copilot and Gemini. They ask for descriptions, counts and masked references, never for names, bank accounts or raw ledgers. What comes back is a draft to be checked against your own evidence and then moved into the working file for that stage.

Worked example — an RCM prompt for procure-to-pay on Tally (illustrative)

Illustrative only. An internal auditor at a mid-size manufacturing company is starting a procure-to-pay review for FY 2026-27. She has a two-page process note from the accounts payable team and the purchase section of the delegation of authority. She picks stage 03 (RCM), the procure-to-pay cycle, Manufacturing and Tally, copies the prompt, replaces names in the process note with roles and pastes it under MY INPUT.

Inputs
Stage03 · Risk and control matrix (RCM)
CycleProcure-to-pay
Industry and systemManufacturing · Tally
Pasted under MY INPUTProcess note with roles in place of names; approval limits for purchase orders and payments
Output
Questions firstQUESTIONS FOR THE AUDITOR: who confirms a change of vendor bank account, and is service acceptance recorded anywhere?
RCM tableOne control per row with objective, type and frequency, test of design, test of operating effectiveness and evidence
Where the note is silentCONTROL NOT EVIDENCED IN INPUT against the risk of bank details changed before payment
Checklist items the note does not mentionListed under EXPECTED BUT NOT DESCRIBED: vendor balance confirmation; review of the vendor master change log
What she does nextTakes the two questions and the expected-but-absent items to the walkthrough, confirms each control with the process owner, then enters the checked rows in the RCM
The useful part of the answer is not the table alone. It is the three places where the tool was told to stop: the questions, the rows marked as not evidenced, and the list of expected controls the note never mentioned. Those become the agenda for the walkthrough. Nothing in the answer is a finding until she has seen the control performed and the evidence it leaves.

Common mistakes

Treating the cycle checklist as the company's controls
The starting points in each prompt are general. A control from that list is in your RCM only if the process owner confirms it and it leaves evidence. The prompt tells the tool to keep the two apart; check that it did.
Pasting the ledger to save time
A chat assistant given a large file may read part of it and describe all of it. It also takes personal data out of your control. Give descriptions, counts and totals, and run the test where every result ties to a row.
Letting the tool choose the sample
A selection made in a chat cannot be repeated or reviewed. Decide the size from your methodology, select in a spreadsheet with a method you can show, and use the prompt only for the test design and the rationale note.
Keeping a citation because it looks right
An invented section number looks exactly like a real one. If a number appears despite the rule against it, open the Act, the rule, the standard or the policy. If you cannot find it, delete it.
Accepting a cause the tool supplied
Lack of training and absence of a documented procedure are the causes a model reaches for when it has none. A cause is what the process owner confirms and the evidence supports.
No record that AI assisted
A reviewer should be able to see which working papers began as an AI draft, what was given to the tool and what was verified. The Excel download includes a log for this.

Frequently asked questions

What are the best AI prompts for internal audit in 2026?+
The ones that fix the output format, limit the tool to the facts you supply, and forbid invented citations. For each audit stage that means a different format: RCM columns for control design, a question table for a walkthrough, Condition, Criteria, Cause, Effect/Risk and Recommendation for an observation. This library gives one such prompt for every stage and process cycle.
Can I use these internal audit prompts in ChatGPT?+
Yes. The prompts are plain text and work in ChatGPT, Claude, Microsoft Copilot, Gemini or any general AI assistant your organisation has approved. They do not depend on a particular model, plan or feature.
How do I write an internal audit RCM prompt?+
State the role and the cycle, paste the process narrative with names replaced by roles, and specify the columns: sub-process, risk, control, control objective, control type and frequency, test of design, test of operating effectiveness and evidence. Tell the tool to record only controls your narrative describes, to mark every assumption, and to write a fixed phrase where no control is described. The RCM stage in this tool builds that prompt for you.
Is it safe to paste audit data into an AI tool?+
Not without authority, and never personal data in a consumer tool. Names, PAN, Aadhaar, bank account numbers and salary details of employees, customers and vendors should stay out. Every prompt here is written to work with roles, masked references, counts and totals. Check your plan's data-use and retention settings and your organisation's policy first.
Can AI write an internal audit observation?+
It can structure one from facts you have already verified. The observation prompt asks for Condition, Criteria, Cause, Effect/Risk and Recommendation, leaves management response, owner and target date to be obtained, and adds a source trail so that each sentence points to a fact you supplied. The criteria, the cause and the rating remain yours to confirm.
Will AI give me the sample size for a control test?+
The prompts in this library tell it not to. Sample size comes from your own methodology and the risk of the control, and the selection must be repeatable. The test design prompt gives attributes, exception definitions and a rationale note with the size left for the auditor.
How do I check an AI answer before using it in an audit file?+
Search it for the markers the prompt asked for: [ASSUMPTION], TO BE VERIFIED and NOT PROVIDED. Resolve each one. Agree every number to your own test sheet, read every criterion in its source, and confirm every control and cause with the process owner. Then record in the working paper what was verified.
Do I need to disclose that AI was used in an internal audit?+
Record it in the working paper: the tool, what it was used for, what was given to it, what was verified and who reviewed. Whether it is mentioned in the report is a matter for your methodology and the audit committee or board that approves it.

Authoritative sources

ICAI
ICAI Internal Audit Standards Board — Compendium of Standards on Internal Audit — Check the current compendium for the standards on planning, evidence, documentation, reporting and follow-up before you add any standards wording to a scope note or report.
MCA
Ministry of Corporate Affairs — Companies Act, 2013 and the Companies (Accounts) Rules, 2014 — Section 138 and Rule 13 govern who must appoint an internal auditor and who settles the scope, functioning, periodicity and methodology of internal audit.
Always confirm against the latest version of the source. Regulations evolve and amendments are common.
Related calculators
Internal audit RCM builder →Walkthrough memo generator →Sampling plan generator →Observation report generator →ATR tracker →AI governance working paper →Internal audit AI strategy template →DPDP for CA firms →
Share this tool
Last reviewed: 2026-10-01 · For informational purposes only — not professional advice.