
01 Find a record
Find the record you need, then follow its linked systems, risks and evidence.
“Find the risks linked to [system].”
A PRACTICAL GUIDE
Practical prompts for finding, reviewing and updating records.
MCP connects your AI client to the CSFaaS records you are allowed to use. Ask for what you need in your own words.

Find the record you need, then follow its linked systems, risks and evidence.
“Find the risks linked to [system].”

Ask your AI client what the available evidence supports and what is still missing.
“Which parts of this control lack evidence?”

Propose a specific update or comment. Saving requires write access for your workspace and connection.
“Add this comment to [record].”
An AI review is an analysis to check. It does not itself certify compliance, change an assessment or save a record.
Start with a record, a business question or an upcoming review. Follow the existing connections to build a fuller picture.
Understand exposure, challenge an assessment and clarify the scope of a risk demand.
See what is overdue and whether the evidence supports the planned action.
Explore your recorded posture and find where implementation or assessment work is missing.
Read the actual policy content and review it in the context of your organization.
Prepare reviews with the questions, responses and supporting proof in one conversation.
Go beyond the attachment name: read supported documents and assess what they demonstrate.
Trace recorded dependencies and find gaps in your asset and supplier risk coverage.
Prepare follow-ups using review schedules, available submissions and business context.
Catch up on changes and build a focused list of work that needs your attention.
Reuse your team’s review instructions with the context of the task in front of you.
50 copyable examples. Choose an area, find a task and make the prompt your own.
Replace [bracketed text] with your own names or references, then paste into your connected AI client. These examples do not run on this page.
50 examples to make your own
What needs my attention in this workspace today? Focus on work I own or follow, overdue items and unread updates. Give me the ten most useful next actions with their record references.
A prioritized list based on the records and updates visible to you.
Show the highest-priority open risks in my workspace using its current risk scores and rating scale. Include the affected systems, owners and remediation status where available.
A risk shortlist using your workspace’s own scores and labels.
List overdue remediation plans visible to me. Include their owners, due dates, linked risks and any recorded explanation for a delay. Prioritize the plans connected to the most significant risks.
A follow-up list based on existing plans and their recorded context.
Summarize the recorded posture and gaps for [framework name] in our workspace. Distinguish assessed weaknesses from items with no assessment and respect Not Applicable items.
A framework overview that preserves the meaning of missing assessments.
Review [policy name] against our business context and its linked controls and framework requirements. Identify vague statements, missing responsibilities and inconsistencies. Draft suggested changes without saving them.
A policy critique and proposed wording grounded in the workspace.
Help me prepare for [audit name]. Review its scope, visible framework elements, questions, responses and evidence. Give me a checklist of gaps to address before the next review.
An audit preparation checklist grounded in the audit’s records.
Find the evidence attached to [record name or reference]. List its names, types and recorded status, and explain which documents are most relevant to [review question].
An index of available evidence linked to a specific record.
Which systems and third parties visible to me have no recorded risk assessment? List them separately with their names and owners where available. Do not treat the absence of an assessment as a risk score.
A coverage gap list for the visible asset inventory.
Keep the same conversation open. Use each answer to shape the next question, and check the sources along the way.
Build context first, challenge the assessment, then prepare a useful handoff.
Start with the actual record and its relationships.
Read [risk name or reference]. Summarize its scenario, affected systems, assigned owners, controls and remediation plans using the available records.
Check coherence against your own risk scale.
Review this risk assessment against our workspace’s rating scale and available evidence. Identify unclear assumptions, inconsistencies and missing information. Keep recommendations separate from recorded facts.
Turn the review into something an owner can act on.
Turn this review into a short owner briefing: what is recorded, what remains uncertain and the next three proposed actions. Do not change the risk or its scores.
You do not need technical syntax. A clear target, a task and an expected output are usually enough.
A record name, reference or scope.
Find, compare, explain or propose.
Your records, evidence and constraints.
A table, checklist or short briefing.
Review [policy name] against our recorded business context and linked controls. Use the available policy content and evidence, identify missing information, and return a table of observations, supporting sources and proposed improvements. Keep all changes as a draft in this conversation.
Name the record. Use the name or reference you see in CSFaaS. If several records match, ask the client to clarify.
Ask for sources. Request record references and evidence pages where available, and separate missing information from findings.
Preserve the recorded numbers. Ask for CSFaaS metrics and your workspace’s rating scale, with suggestions clearly labeled.
Be explicit about changes. “Draft it here” and “save this update” are different requests. Ask to review the proposal before saving.
Available work depends on your permissions, enabled workspace features and the records you can access.
MCP needs workspace approval and an enabled account. A connection is scoped to one workspace and the roles you authorize; it does not reveal records outside that access.
Read-only connections can retrieve data for analysis. Changes also need a connection authorized to write and the workspace write setting. Supported workflow rules still apply.
Supported PDFs and images can be read. Scans depend on available page images and your client’s image support. Ask for a narrower page range on long documents. An inaccessible document is not proof of anything.
You can request a supported evidence URL attachment with write access. Upload files through CSFaaS. A link alone does not mean your client can read the document behind it.
AI can help explain, compare and draft. Review its sources and conclusions before using them in an assessment or a decision. No results can mean no matching records within your access.
Supported writes save to your workspace; some views may need a refresh. Check the reported result. Deletion over MCP is deliberately disabled.