Chapter 8 encourages you to run the Pragmatic GRC prompts inside a Project (or your AI tool’s equivalent workspace feature) instead of a loose chat. This kit gives you three things to make that quick: a standing instruction you can copy and fill in, a checklist of what to upload (and what to keep out), and a short data-handling checklist to complete before you upload anything sensitive. It is tool-neutral on purpose, so it works whichever AI tool you use.
Quick Start
Create one Project for your GRC work.
Paste in the standing instruction from Part 1, filled in for your business.
Upload the files from Part 2, and leave out anything on the “do not upload” list.
Complete the checklist in Part 3 before you upload anything sensitive.
Run the Chapter 8 prompts inside that Project.
Part 1: Standing Instruction Template
Paste this into your Project’s instructions field and replace every [bracketed] item. Keep it under a page. Review it during your Monthly GRC Heartbeat™ so it stays current as your business changes.
You are a GRC assistant helping a small or medium-sized business maintain its Pragmatic GRC Methodology™ program.
ABOUT THE BUSINESS: [Company name] is a [number]-person [industry] business based in [location]. Our team works [on-site / remote / hybrid].
KEY SYSTEMS: [For example: Microsoft 365, QuickBooks, a cloud file server, our line-of-business software, our MSP’s name].
WHAT WE PROTECT: [For example: customer records, financial data, client or patient information].
COMPLIANCE DRIVERS: [For example: customer contracts, cyber insurance requirements, HIPAA, PCI DSS, state privacy laws, or “none yet”].
WHO OWNS GRC: [Business Owner / Operations Manager / IT Manager or MSP].
HOW TO WORK WITH US: Our Three Living Documents (Master Asset Register, Enterprise Risk Register, and Unified System Security Plan) are in this Project’s files and are our system of record. Treat them as the source of truth. Write in plain, non-technical language sized for a small team, and keep answers short and actionable. If you are missing information or are unsure, say so and ask instead of guessing. Never invent regulations, citations, or facts about our systems. Flag anything a person should verify. You draft; we review and decide.
Part 2: What to Upload (and What to Keep Out)
Start small. A few current, accurate files beat a large pile of outdated ones.
Upload these
Do not upload these
Housekeeping tips
Replace sensitive names and numbers with placeholders (for example, [Client A], [Server 1]) before uploading.
Put the date in each file name so you can tell which version the Project is using.
When you update a Living Document, remove the old version from the Project and upload the new one.
Part 3: Data-Handling Checklist
Answer these before you upload anything sensitive. Your registers and security plans describe how your business is protected, so treat them accordingly. You can find the answers in your AI tool’s settings, admin console, and the provider’s own terms and privacy documentation.
Important: This checklist is a practical starting point, not legal advice. If you are unsure whether a contract or regulation permits a particular use, ask your attorney or compliance advisor.