ROLE You are assisting an internal auditor in India. The work relates to the procure-to-pay cycle of a company [state the industry]. The books are kept in [Tally / SAP / other: state the system]. I am the auditor: you draft and structure, I verify every fact and I decide every rating and conclusion. TASK Draft a risk and control matrix for the procure-to-pay cycle from the process narrative in my input. Record only the controls my input describes, and show me where an expected control is missing. STARTING POINTS FOR PROCURE-TO-PAY Use these as a checklist. A risk or control from this list that my input does not confirm must not be written as if it exists. - Sub-processes: vendor onboarding and vendor master changes; purchase requisition and purchase order; goods receipt and service acceptance; invoice booking and matching; payment release; advances, debit notes and vendor reconciliation. - Risk themes: fictitious or duplicate vendors in the vendor master; purchases made without approval, or split to stay under an approval limit; goods or services paid for but not received; duplicate, inflated or early payment of invoices; vendor bank details changed shortly before a payment; advances not adjusted and old debit balances on vendor accounts. - Controls usually expected: independent check of vendor identity, tax registration and bank details before the vendor is created; approval under the delegation of authority before the company is committed; three-way match of purchase order, receipt and invoice before booking; maker-checker on payment release, with the approver seeing the invoices being paid; review of the vendor master change log, bank account changes in particular; periodic vendor balance confirmation and review of open advances and receipts not yet invoiced. OUTPUT FORMAT - One table. Columns: Sub-process | Risk | Control (as described in my input) | Control objective | Control type and frequency | Test of design | Test of operating effectiveness | Evidence. - Control objective: choose from existence, validity, occurrence, accuracy, completeness, authorisation, valuation, compliance. - Control type and frequency: preventive or detective; manual, automated or IT-dependent manual; then how often it runs. - Where my input describes no control for a risk, write CONTROL NOT EVIDENCED IN INPUT in the Control column and leave the test columns blank. - After the table, list under EXPECTED BUT NOT DESCRIBED any control from the checklist that my input does not mention. RULES 1. Use only the facts in MY INPUT. The starting points above are general, not facts about this company; anything you take from them that my input does not confirm must be marked [ASSUMPTION]. 2. Mark every other assumption as [ASSUMPTION] at the place where you make it. 3. Do not invent section numbers, rule numbers, standards paragraphs, thresholds, rates, due dates, circulars or case law. Where law, a standard or a company policy seems relevant, describe the topic in words and write TO BE VERIFIED. 4. If a fact you need is missing, do not fill it in. List what you need under QUESTIONS FOR THE AUDITOR before the output, and write NOT PROVIDED where the fact would have gone. 5. One control per row. Do not merge two controls into one sentence. 6. Write each test so that a second auditor could repeat it: what to obtain, what to compare, what counts as a failure. 7. Do not mark any control as key and do not rate any control. I will. 8. Do not name reports, menu paths, tables or fields of the accounting system unless my input gives them. Describe the data in words. MY INPUT Process narrative or SOP with names replaced by roles, the relevant part of the delegation of authority, and any existing RCM: [paste here]
To set the rules for a whole department or firm, start with the internal audit AI strategy template. To record AI assistance on a file, use the AI governance working paper. What the data protection law expects of anyone holding personal data in audit files is set out in DPDP for CA firms.
The checked answer belongs in a working file, not in a chat window: the RCM builder, the walkthrough memo generator, the sampling plan generator, the observation report generator and the ATR tracker.
An internal audit prompt fails for three ordinary reasons. It does not say what the answer should look like, so the tool returns an essay where a table was needed. It does not say what the tool may and may not use, so the answer mixes your facts with general knowledge and you cannot tell which is which. And it says nothing about citations, so a section number or a threshold appears that nobody has checked. The prompts in this library are written to close those three gaps every time.
Each prompt is assembled from two parts. The stage part carries the task and the output format: the columns of a risk and control matrix, the five parts of an observation (Condition, Criteria, Cause, Effect/Risk, Recommendation, then management response, owner and target date), the columns of a data request list or an action taken report. The cycle part carries what is particular to procure-to-pay, order-to-cash, record-to-report, cash and bank, hire-to-retire, fixed assets, inventory, treasury, statutory compliance or IT general controls: the sub-processes, the risk themes, the controls usually expected, the records to ask for and the exceptions commonly found.
Four rules are the same in every prompt. Use only the facts given. Mark every assumption. Do not invent section numbers, standards paragraphs, thresholds or case law, and write TO BE VERIFIED in their place. Ask for a missing fact instead of filling it in. The stage then adds its own rules: the RCM prompt will not mark a control as key, the sampling prompt will not suggest a sample size, the observation prompt will not rate the finding, and the follow-up prompt will not mark an item closed. Those decisions stay with the auditor.
The prompts work in any general AI assistant, including ChatGPT, Claude, Microsoft Copilot and Gemini. They ask for descriptions, counts and masked references, never for names, bank accounts or raw ledgers. What comes back is a draft to be checked against your own evidence and then moved into the working file for that stage.
Illustrative only. An internal auditor at a mid-size manufacturing company is starting a procure-to-pay review for FY 2026-27. She has a two-page process note from the accounts payable team and the purchase section of the delegation of authority. She picks stage 03 (RCM), the procure-to-pay cycle, Manufacturing and Tally, copies the prompt, replaces names in the process note with roles and pastes it under MY INPUT.