home/roleplay/control-self-assessment-csa-questionnair

Control Self Assessment Csa Questionnair

GPTClaudeGemini··880 copies·updated 2026-07-14
control-self-assessment-csa-questionnair.prompt
# 13. Control Self-Assessment (CSA) Questionnaire

**Domain:** Audit and Assurance
**Level:** Essential

## Use Case

Draft a targeted questionnaire to send to a system owner, process owner, or team lead to confirm that a specific control is actually operating as designed. The practical tool that closes the gap between 'the control exists on paper' and 'the control is being performed.'

## Variables

| Variable | What to Enter | Example |
|----------|--------------|---------|
| `[CONTROL_OR_PROCESS]` | The control or process being self-assessed | e.g. Quarterly user access review for production systems, Monthly AI model performance monitoring, Supplier security due diligence process, Data subject access request handling |
| `[RESPONDENT_ROLE]` | Who will complete this questionnaire | e.g. System Administrator, Head of IT Operations, Data Protection Officer, Line manager, AI system owner |
| `[CONTROL_STANDARD]` | The standard or policy the control must satisfy | e.g. ISO 27001 A.5.18 (access rights), ISO 42001 A.9.4 (performance monitoring), GDPR Article 12 (SAR response timeframes), Internal IT policy Section 6 |
| `[ASSESSMENT_PERIOD]` | The period the questionnaire covers | e.g. Last quarter (1 July - 30 September 2025), Last 12 months, Current state as at today's date |
| `[EVIDENCE_REQUIRED]` | Whether the respondent should attach supporting evidence | e.g. Yes - attach the most recent access review report; Yes - attach a sample of 3 completed process records; No - written confirmation only |

## The Prompt

Copy everything below this line. Replace all `[VARIABLES]` with your specific information. Paste into Claude, GPT-4o, Gemini, or any capable LLM.

---

when to use it

Community prompt sourced from the open-source GitHub repo KunalCyber/GRC-Prompts-Library (MIT). A "Control Self Assessment Csa Questionnair" style prompt — adapt the placeholders and specifics to your task. Imported as-is and not independently retested here, so check the output before relying on it.

tags

roleplaycommunitygeneral

source

KunalCyber/GRC-Prompts-Library · MIT