Risk Maestro prompt library

Use this library when you're working with Risk Maestro in Task Manager. Each prompt is a template you can customize and enter into Risk Maestro to ask it to perform specific tasks. Organize your prompts by the work you're doing—project setup, risk assessment, control mapping, and so on. As new capabilities are added, this library will expand.

To open Risk Maestro, go to Task Manager > Menu > Risk Maestro.

For best results, be specific about your engagement details. Replace placeholder text like [audit name] with your actual project name, dates, and process information. Add more context to get targeted, useful results from Risk Maestro.

Project setup and engagement scoping

Use these prompts when you need to set up a new audit project, define scope, draft objectives, or identify key stakeholders.

Capability Task to be completed Example prompts

Project setup and engagement scoping Use these prompts when you need to set up a new audit project, define scope, draft objectives, or identify key stakeholders.

Define engagement scope

  • Define the scope for an internal audit of the procure-to-pay process at a mid-size manufacturing company.

  • What should be included in the scope for an IT general controls audit covering access management and change management?

  • Draft an engagement scope statement for a review of third-party vendor compliance with our data privacy policy.

Draft audit objectives

  • Write three audit objectives for a financial controls review of the accounts receivable process.

  • Draft clear audit objectives for an operational audit of the warehouse inventory management process.

  • Generate audit objectives for a compliance review of our anti-bribery and anti-corruption (ABAC) program.

Identify stakeholders and key process owners

  • Who are the typical stakeholders to engage for an audit of the payroll process?

  • List the key process owners and departments involved in an order-to-cash audit.

Risk identification and assessment

Use these prompts when you need to identify risks, describe and rate them, or prioritize which risks to focus on. Risk Maestro does not automatically surface new risks, so prompt it to identify potential risks and then review the output.

Capability Task to be completed Example prompts

Risk identification and assessment Use these prompts when you need to identify risks, describe and rate them, or prioritize which risks to focus on.

Identify risks

  • What are the top risks associated with the vendor onboarding process?

  • Identify key risks in a cloud migration project from an IT audit perspective.

  • List the primary fraud risks in an expense reimbursement process.

  • What are the operational, financial, and compliance risks for a retail company's supply chain?

Describe and rate risks

  • Write a risk description for unauthorized access to financial reporting systems. Include likelihood, impact, and inherent risk rating.

  • Describe the risk of inaccurate financial reporting due to manual journal entries. Rate likelihood and impact on a scale of 1–5.

  • Provide a risk statement and risk rating for data loss caused by inadequate backup and recovery procedures.

Refine and prioritize risks

  • We have identified 12 risks for this engagement. Rank them by inherent risk level and recommend the top 5 to prioritize.

  • Are there any risks we may have overlooked for an audit of the employee offboarding process?

  • How does the risk of [risk name] compare to industry benchmarks for [industry]?

Risk-to-control mapping

Use these prompts when you need to link risks to controls, assess whether your control framework covers identified risks, or draft control descriptions.

Capability Task to be completed Example prompts

Risk-to-control mapping Use these prompts when you need to link risks to controls, assess whether your control framework covers identified risks, or draft control descriptions.

Map risks to controls

  • What controls should be in place to mitigate the risk of duplicate payments in the accounts payable process?

  • Map the top three risks identified in our IT change management audit to relevant IT general controls (ITGC).

  • What preventive and detective controls are typically used to address the risk of unauthorized system access?

Assess control coverage

  • We have the following controls in place for segregation of duties: list controls. Are there any gaps?

  • Review the control framework below and identify which risks lack adequate mitigation, then paste the control list.

  • What compensating controls could we implement if a manual review control cannot be fully automated?

Draft control descriptions

  • Write a control description for a monthly bank reconciliation performed by the finance team.

  • Draft a control objective and description for an automated system access review performed quarterly.

Project setup workflow example

The following prompts walk through a sample audit setup flow from initial setup to handover. Enter them into Risk Maestro in sequence, substituting your own project name, dates, and details.

Step Task to be completed Example prompts

1

Set up and roll-forward audit files

Set up a new audit called audit name as an Internal Audit ,Controls Audit with number testing rounds, a start date of start date, and an end date of end date, covering regions.

Required: project name, project type, number of testing rounds, start date, and end date. Use these exact phrases.

2

Add audit objective and generate description

Create a new objective to assess process name for the audit project, include a short description, and assign it to auditor name.

Required: project name, reference, assigned to, and description.

3

Add new risk and generate description

Add a new risk to the audit project related to risk scenario.

Required: risk name, objective, and description.

4

Recommend and add control to mitigate risk

What control would you recommend to mitigate this risk? Generate and add the control with a short description on how it mitigates the risk.

Required: control name, objective, and description.

5

Link control to risk

Link control name to risk name in the audit name audit file.

Required: project name, control name, and risk name.

6

Add new request

Create a new request called request name with you as the requestor and assign to auditor name due date. Toggle on weekly notification reminders.

Note

Risk Maestro can create only a single request at a time. It cannot push email notifications to the client but can toggle the notification schedule.

7

Transfer controls to a new auditor

An auditor has left the team. Go into the audit file and transfer all of their controls to new owner name.

Required: project name and control owner name. Review and approve the transfer before finalizing changes.

Findings and reporting

Use these prompts when you need to report findings and propose remediation after testing activities are complete.

Capability Task to be completed Example prompts

Findings and reporting

Add finding and remediation plan

Create a new audit finding associated with audit name: control name that finding description. Suggest and add remediation plan for signoff prior to payments.

Required: project name, finding description, risk severity, date identified, and description.

Follow-up and refinement

When you want to iterate on a previous response or drill into a specific output, use these prompts. Risk Maestro retains context within a session, so you can refine results through follow-up questions.

Capability Task to be completed Example prompts

Follow-up and refinement

Iterate on previous responses

  • Simplify the risk description you just provided so it can be understood by a non-technical stakeholder.

  • Reformat the risks above as a table with columns for risk name, description, likelihood, impact, and inherent rating.

  • Make the audit objectives you drafted more specific to a financial services company operating in a regulated environment.

  • Add two more risks to the list you generated, focusing on technology and data governance.

  • Summarize the key findings from this session as a draft executive summary.

Tips for writing effective prompts

Follow these guidelines when composing prompts in Risk Maestro to get the most accurate and useful output.

Capability Task to be completed Example prompts

Tips for writing effective prompts

Be specific

Include the process, industry, company size, or regulatory environment when relevant. Vague prompts produce generic results.

Provide context

Paste in relevant background information, such as a process description, existing risk list, or control framework to get more targeted output.

Iterate

Follow up on any response to refine, expand, or reformat the output.

Specify the format

Ask for output as a table, bullet list, paragraph, or numbered list depending on how you plan to use it.

Review all output

AI-generated content may contain inaccuracies. Apply your professional judgment before using any output in an engagement.

The AI-generated content is intended to be informative and may include inaccuracies. It is not a substitute for independent research. By using this content, you acknowledge you understand this disclaimer.