Deep GRC Analysis Prompt Examples

Modified on Tue, 29 Sep at 5:17 PM

Deep GRC analysis should ask Ask C1Risk to connect verified records, evaluate risk and control effectiveness, identify gaps, and recommend prioritized next steps.


Recommended Deep Analysis Instruction

Add this to most prompts:

Use only verified and authorized C1Risk records. Follow confirmed relationships between entities. Separate observed facts, analysis, assumptions, data gaps, and recommendations. Do not invent risk ratings, control effectiveness, regulatory requirements, or causal relationships. Include Record IDs for all supporting records. This is a read-only analysis; do not create, update, or delete records.


1. Internal Control Analysis

  1. “For Internal Control [Control ID], perform a deep effectiveness review. Analyze its description, linked policies, control library mappings, evidence, test procedures, test results, findings, and risk mitigations. Identify design gaps, operating gaps, evidence gaps, ownership gaps, and overdue actions.”

  2. “Analyze Internal Control [Control ID] as a GRC analyst. Determine whether the available evidence and test results support the control’s stated objective. Separate verified facts, unresolved questions, and recommended remediation.”

  3. “Review all failed or inconclusive Test Results for Internal Control [Control ID]. Identify recurring failure themes, likely root causes, affected policies or risks, responsible owners, and recommended corrective actions.”

  4. “Compare Internal Controls in Control Family [name]. Identify duplicate controls, overlapping objectives, missing coverage, weak controls, failed tests, and controls without current evidence.”

  5. “Analyze the operating health of controls owned by [owner]. Prioritize controls with failed tests, missing evidence, overdue reviews, open Findings, or high residual risk.”

2. Risk and Mitigation Analysis

  1. “For Risk Register [Risk ID], explain the relationship between inherent risk, residual risk, risk treatment, Findings, and Risk Mitigations. Assess whether the recorded mitigation appears sufficient based only on verified C1Risk data.”

  2. “Analyze all high residual-risk records. Identify common risk categories, affected assets, open Findings, overdue mitigations, accountable owners, and recurring control weaknesses.”

  3. “Review Risk Register [Risk ID] and determine why residual risk remains high. Compare the recorded risk scores, mitigation status, target dates, linked controls, and unresolved Findings.”

  4. “Perform a risk remediation aging analysis. Identify overdue Risk Mitigations, explain the likely blocking factors from available records, and prioritize actions by residual risk, severity, and days overdue.”

  5. “Analyze risk trends for [business unit or risk category]. Identify increasing, decreasing, and unchanged risk exposure and explain the trend using recorded risk scores, Findings, incidents, and mitigation status.”

  6. “Identify conflicts or inconsistencies in Risk Register records, including duplicate risks, conflicting ownership, missing treatment plans, inconsistent status, or mitigation dates that do not align.”

3. Compliance and Framework Analysis

  1. “For Obligation [Obligation ID], perform a framework readiness analysis. Review obligation sections, crosswalks, Internal Controls, Evidence, Test Results, Findings, and Document Requests. Identify implemented, partially implemented, unsupported, and unverified requirements.”

  2. “Analyze the largest compliance gaps for [framework name]. Rank gaps by requirement importance, control coverage, evidence availability, test result, Finding priority, and remediation status.”

  3. “Review all obligation sections with no mapped Internal Controls or Evidence. Explain the potential compliance impact and recommend the next validation or remediation step.”

  4. “Compare the control coverage of [Framework A] and [Framework B]. Identify equivalent coverage, unique requirements, unmapped requirements, duplicate controls, and areas where evidence can be reused.”

  5. “Prepare an audit-readiness assessment for Audit [Audit ID]. Analyze evidence completeness, open Findings, overdue Document Requests, control test results, ownership, and unresolved dependencies.”

  6. “Identify whether each reported compliance gap is caused by missing policy, missing control, failed testing, missing evidence, overdue remediation, or insufficient ownership.”

4. Findings and Root Cause Analysis

  1. “For Finding [Finding ID], perform a root cause analysis using the Finding details, related Internal Controls, Evidence, Test Results, Risk Registers, and Risk Mitigations. Distinguish confirmed facts from analytical hypotheses.”

  2. “Analyze all open high-priority Findings and identify recurring root causes, affected business areas, common control failures, overdue owners, and potential systemic issues.”

  3. “Review Finding [Finding ID] and assess whether the proposed Risk Mitigation addresses the root cause or only the symptom. Recommend improvements to the remediation approach.”

  4. “Analyze Findings that have remained open beyond their target date. Identify common blockers, ownership patterns, Jira workflow status, and actions required to close them.”

  5. “Compare Findings from [period 1] and [period 2]. Identify changes in volume, severity, source, affected controls, remediation speed, and recurring themes.”

5. Evidence and Audit Support

  1. “For Internal Control [Control ID], assess evidence sufficiency. Review evidence type, date, owner, related test result, expiration, and document request response. Identify whether the evidence demonstrates design and operating effectiveness.”

  2. “Identify controls with evidence that is expired, stale, missing, or unrelated to the control objective. Explain the evidence gap and recommend the next evidence request.”

  3. “Analyze overdue Document Requests by owner and business area. Identify the affected obligation, control, audit, or assessment and prioritize follow-up actions.”

  4. “Prepare an evidence-quality review for Audit [Audit ID]. Identify duplicate evidence, missing evidence, outdated evidence, unsupported assertions, and items requiring auditor clarification.”

6. Assessment and Vendor Risk Analysis

  1. “For Assessment [Assessment ID], analyze unanswered questions, high-risk responses, related Findings, missing evidence, and required remediation. Provide a prioritized action plan.”

  2. “Analyze Assessment Campaign [Campaign ID]. Summarize completion status, high-risk responses, open Findings, mitigation progress, overdue participants, and sections with the greatest residual exposure.”

  3. “For Vendor [Vendor ID], perform a third-party risk review using the vendor record, assessments, Evidence, Findings, Document Requests, risk score, and renewal date. Identify material risk drivers and recommended follow-up.”

  4. “Identify vendors with high risk scores, overdue assessments, missing security evidence, open high-priority Findings, or upcoming contract renewals. Explain the combined risk exposure.”

  5. “Compare vendor risk across criticality tiers. Identify whether high-criticality vendors have current assessments, sufficient evidence, acceptable Finding status, and active remediation plans.”

7. Incident and Asset Analysis

  1. “Analyze incidents from the last 12 months. Identify recurring incident types, regulatory impact, affected assets, average time to close, open mitigations, and control or policy weaknesses.”

  2. “For Incident [Incident ID], assess the potential GRC impact. Review affected assets, regulatory impact, related risks, Findings, controls, and mitigation status.”

  3. “Identify assets associated with the highest number of open Findings, Issues, Incidents, or Risk Mitigations. Rank assets by cumulative exposure and remediation urgency.”

8. Executive Deep-Dive Reports

  1. “Prepare a leadership-level GRC risk analysis for the current quarter. Include top residual risks, significant Findings, failed controls, evidence gaps, overdue actions, vendor exposure, and the three most important management decisions.”

  2. “Create an executive analysis of why compliance readiness is below target. Connect framework gaps, control coverage, test failures, missing evidence, overdue Findings, and ownership issues.”

  3. “Prepare a board-ready analysis of the organization’s top GRC exposures. For each exposure, show business impact, supporting C1Risk records, current owner, remediation status, target date, and recommended leadership action.”

  4. “Identify the top five systemic GRC weaknesses across Risks, Internal Controls, Findings, Evidence, Audits, and Assessments. Support each conclusion with verified C1Risk records.”


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons

Feedback sent

We appreciate your effort and will try to fix the article