Ask C1Risk Custom Report Prompt Examples

Modified on Tue, 29 Sep at 5:03 PM

For custom reports, the strongest customer prompt usually specifies:

Entity + filters + columns + grouping + sorting + time period + output format + business purpose.


1. Single-Entity List Reports

Internal Controls

  1. “Create an Internal Controls report showing active controls only. Include Control ID, Control Name, Source, Control Family, Control Frequency, Control Strength, Primary Contact, Status, and Modified Date. Sort by Control Strength from lowest to highest.”

  2. “List all active Internal Controls with Control Frequency set to ‘As Needed’. Show Control ID, Control Name, Primary Contact, Control Strength, Key Control status, and Next Review Date.”

  3. “Create a filtered Internal Controls report for controls owned by [owner name]. Show the control ID, name, source, frequency, strength, status, and linked policies.”

  4. “Find Internal Controls with no linked evidence or test results. Return Control ID, Control Name, Primary Contact, Status, Last Modified Date, and missing relationship.”

  5. “Create a control health report grouped by Control Frequency. Show the number of active controls, average Control Strength, controls without recent testing, and controls with open findings.”

Findings

  1. “List all open Findings. Show Finding ID, Finding Name, Priority, Status, Primary Contact, Due Date, Risk Mitigation status, and linked Jira workflow status. Sort by priority and due date.”

  2. “Create a report of overdue Findings. Include Finding ID, title, priority, owner, due date, days overdue, mitigation status, and related Internal Control or Risk Register.”

  3. “Show all high-priority Findings that do not have an active Risk Mitigation. Return the Finding ID, root cause, owner, due date, and recommended next step.”

Evidence and Document Requests

  1. “List all overdue Document Requests. Show request ID, request name, owner, due date, status, related obligation or control, and response status.”

  2. “Create an evidence freshness report for evidence modified within the last 12 months. Include Evidence ID, name, owner, source, related control, last modified date, and expiration date.”

  3. “Find active Internal Controls with missing, expired, or overdue Evidence. Group the results by Primary Contact.”

Policies

  1. “Create a Policy lifecycle report showing policies by status, owner, review frequency, next review date, approval status, and last modified date. Highlight overdue reviews.”

  2. “List policies that are approved but have no linked Internal Controls or Obligations. Include Policy ID, Policy Name, owner, approval date, and missing relationship.”

2. Cross-Entity Reports

  1. “Create a control-to-evidence coverage report. For each active Internal Control, show Control ID, Control Name, Primary Contact, linked Evidence count, most recent evidence date, test result, and open Finding count.”

  2. “Create a control testing effectiveness report using Internal Controls, Test Procedures, Test Results, Findings, and Risk Mitigations. Show control ID, test date, result, failure reason, finding priority, mitigation status, and due date.”

  3. “Create an audit readiness report for [Audit ID]. Combine the Audit, Audit Program, Internal Controls, Evidence, Findings, and Document Requests. Show each audit area, evidence status, open gaps, owner, and due date.”

  4. “Create a framework readiness report for [Obligation ID]. Show obligation sections, linked control libraries, mapped Internal Controls, evidence availability, test results, findings, and implementation status.”

  5. “Identify obligation sections with no mapped Internal Controls. Return the obligation section ID, section name, applicable status, related framework, and recommended remediation priority.”

  6. “Create a risk remediation report combining Risk Registers, Findings, and Risk Mitigations. Show risk ID, risk name, inherent risk, residual risk, mitigation owner, target date, status, and overdue days.”

  7. “For all open Findings, show the related Risk Register, Internal Control, Evidence, Risk Mitigation, owner, priority, due date, and current status. Use only confirmed relationships.”

  8. “Create a document request completion report grouped by owner. Include Document Request ID, related control or obligation, request status, due date, response status, evidence received date, and overdue days.”

  9. “Create an assessment remediation report combining Assessments, Assessment Campaigns, Findings, Risk Mitigations, and Document Requests. Show campaign, assessment status, finding priority, mitigation status, owner, and due date.”

3. Risk Management Reports

  1. “Create a Risk Register report showing all open risks with Risk ID, Risk Name, Risk Category, inherent likelihood, inherent impact, inherent risk rating, residual likelihood, residual impact, residual rating, owner, and treatment status.”

  2. “Create a risk remediation aging report. Show risks with overdue mitigations, mitigation owner, original due date, revised due date, days overdue, current status, and related Findings.”

  3. “Create a report of risks where residual risk remains high after mitigation. Include risk ID, inherent rating, residual rating, mitigation description, owner, due date, and recommended management action.”

  4. “Create a risk exposure report grouped by business unit or risk category. Show risk count, high-risk count, open mitigation count, overdue mitigation count, and average residual rating.”

  5. “Create a 5x5 risk matrix using verified likelihood and impact values from Risk Registers. Show inherent risk and residual risk separately. Include the Risk ID and Risk Name in each matrix cell. Place records with missing scoring values in a separate ‘Unscored’ section.”

  6. “Create a risk movement report comparing inherent and residual risk. Identify risks with increased, unchanged, and reduced exposure. Include Risk ID, owner, mitigation status, and explanation based only on recorded values.”

4. Compliance and Audit Readiness

  1. “Create an executive compliance readiness report for [Framework or Obligation]. Show implementation status, mapped controls, evidence coverage, open Findings, overdue Document Requests, and highest-priority gaps.”

  2. “Create a framework pass/fail report by obligation section. Include section name, implementation status, control coverage, evidence status, test result, open finding count, and remediation owner.”

  3. “Create an auditor evidence package index for [Audit ID]. List each requested evidence item, related control, source, owner, status, last updated date, and whether it is ready for review.”

  4. “Create an audit gap analysis for [Audit ID]. Prioritize gaps by severity, overdue status, affected control or obligation section, owner, and target remediation date.”

  5. “Create a compliance hotspot report grouped by department or control owner. Show open findings, failed tests, overdue evidence, overdue document requests, and high-risk controls.”

5. Internal Control Operational Health

  1. “Create a control test SLA report. Show controls tested during the selected period, test date, scheduled date, test result, days late, tester, owner, and related finding.”

  2. “Identify broken or ineffective controls with the longest remediation time. Include Control ID, test result, finding ID, finding priority, original discovery date, mitigation owner, and days open.”

  3. “Create a report of active Key Controls with failed or missing Test Results. Show Control ID, Control Name, Primary Contact, test status, evidence status, finding priority, and remediation due date.”

  4. “Create an operational control health report grouped by Source and Control Family. Show total controls, active controls, failed tests, missing evidence, open findings, and average control strength.”

6. Vendor and Third-Party Risk

  1. “Create a third-party risk report for all active vendors. Show vendor name, vendor ID, criticality, risk score, assessment status, open findings, missing evidence, contract renewal date, and security review status.”

  2. “List high-risk vendors with overdue assessments or missing security evidence. Include vendor ID, risk score, assessment status, evidence status, owner, renewal date, and recommended next action.”

  3. “Create a vendor concentration report grouped by vendor criticality and risk tier. Show vendor count, high-risk count, open findings, overdue assessments, and pending evidence requests.”

  4. “Create a vendor renewal readiness report. Show vendors with a renewal date within the next 90 days and include security assessment status, latest risk score, open findings, and evidence gaps.”

  5. “Create a vendor assessment remediation report using vendor records, assessments, Findings, Evidence, and Document Requests. Show vendor, issue, priority, owner, due date, and remediation status.”

7. Incidents, Assets, and System Telemetry

  1. “Create an incident trend report for the last 12 months. Group incidents by type, priority, regulatory impact, status, and month reported. Include average days open.”

  2. “Create an open incident remediation report showing Incident ID, incident type, priority, regulatory impact, owner, Jira workflow status, risk mitigation status, and days open.”

  3. “Create an asset risk report combining assets, risks, Findings, issues, and Risk Mitigations. Show asset, asset type, risk score, open finding count, issue count, and mitigation status.”

  4. “Create an integration health report showing active integrations, last synchronization date, status, error state, and records affected. Exclude secrets, API keys, and technical payload details.”

  5. “Create an access review exception report showing users or groups with unresolved access-review exceptions. Include user or group, exception type, owner, date identified, status, and remediation due date.”

8. Board and Leadership Reports

  1. “Prepare a board-level GRC summary for the current quarter. Include top residual risks, overdue high-priority Findings, framework readiness, control failures, vendor exposure, and remediation trends. Use concise executive language.”

  2. “Create a leadership action register from open Risks, Findings, Document Requests, and Risk Mitigations. Show issue, business impact, owner, due date, priority, current status, and next action.”

  3. “Create a one-page compliance and risk dashboard summary. Include total open risks, high residual risks, failed controls, overdue evidence requests, overdue findings, critical vendors, and quarter-over-quarter trend where verified data is available.”

  4. “Prepare an audit committee report for [Audit ID]. Summarize audit progress, evidence readiness, significant gaps, overdue actions, accountable owners, and expected completion dates.”

  5. “Create a prioritized GRC action list for the next 30 days. Rank actions by risk severity, regulatory impact, overdue status, and business impact. Include owner, due date, source record, and recommended next step.”

Report Quality Instructions

Add these instructions when precision matters:

Use only records I am authorized to view. Use confirmed C1Risk relationships only. Do not invent missing values. If a requested field or relationship is unavailable, identify it clearly and continue with the closest supported result. Return Record ID, Record Name, Status, Owner, and source entity for every result.

For large reports:

Return a compact summary first, limited to 25 rows. Include the applied filters, selected columns, grouping, sorting, total match count, and a note explaining whether any records were omitted from the preview.

For risk matrices:

Do not calculate likelihood, impact, or risk ratings when the underlying values are missing. Separate unscored records from scored records and show whether the matrix represents inherent or residual risk.

For external research:

Use Web Search only for GRC-relevant external guidance. Keep C1Risk record data and external research clearly separated, cite external sources, and do not treat external guidance as a C1Risk record value.



Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons

Feedback sent

We appreciate your effort and will try to fix the article