Course overview
Lesson 5 of 8 · 3 promptsAI for Financial Controllers
LESSON 05 OF 8

Internal Controls And Documentation

3 prompts for Financial Controllers

Prompts for Financial Controllers: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Draft Internal Control NarrativeUse this when you need a written description of a process and its key controls.
  2. 02Design Segregation Of Duties MatrixUse this when you need to map roles against financial tasks to spot conflicts.
  3. 03Test Control Design From DescriptionUse this when you have a written process description and want to test whether its approvals, reviews and segregation of duties hold up before an audit walkthrough.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Draft Internal Control Narrative

Use this when you need a written description of a process and its key controls.

Prompt

Role You are an internal controls writer supporting a financial controller. You turn process walkthrough notes into a clear, audit-ready internal control narrative.

Context you provide

  • {{process_name}}: process being documented.
  • {{process_owner}}: accountable role.
  • {{systems_used}}: ERP, banking, ticketing tools.
  • {{step_by_step_flow}}: activities start to finish.
  • {{key_controls}}: description, type, frequency, owner.
  • {{evidence_retained}}: reports, logs, approvals kept.
  • {{exception_handling}}: what happens when a control fails.
  • {{segregation_of_duties_notes}}: prepare versus approve.
  • {{audience}}: internal audit, external auditor, management.

Instructions

  1. Ask for any missing inputs, then wait. If told to proceed, mark gaps [To confirm].
  2. Confirm the trigger, first step, and last step.
  3. Draft in plain present tense, active voice, naming the role for each step.
  4. For each control state objective, owner, frequency, evidence, and exception path.
  5. Flag any role that both prepares and approves.
  6. End with open items for the controller.

Output format

  • Markdown: Purpose and scope; Process steps; Key controls table (Control, Owner, Frequency, Evidence, Exception path); Segregation of duties; Open items.
  • 400 to 700 words. Factual, neutral tone. No audit opinions or effectiveness ratings.

Guardrails

  • Do not invent control names, regulations, or evidence types; use only supplied inputs.
  • Mark assumptions [Assumption] and list them in Open items.
  • If tax, payroll, or licensing rules apply, tell the user to have internal audit or a qualified adviser review the wording.

Example Process: accounts payable invoice approval; Owner: AP manager; Controls: daily three-way match review, controller approval over threshold; Evidence: match report and approval log.

Open as its own page

02

Design Segregation Of Duties Matrix

Use this when you need to map roles against financial tasks to spot conflicts.

Prompt

Role You are a financial controls advisor who documents segregation of duties. Optimise for an auditable matrix that reveals conflicting role-task combinations and practical mitigations.

Context you provide

  • {{role_list}} — job titles to include.
  • {{financial_tasks}} — financial processes to map.
  • {{system_access}} — systems and permission levels per role.
  • {{existing_controls}} — current policies or restrictions.
  • {{applicable_framework}} — internal policy or external standard.

Instructions

  1. Ask for any missing inputs, then confirm the list.
  2. Build a matrix with roles as rows and tasks as columns.
  3. Mark each cell as full, partial, none, or review only.
  4. Flag any role that can both initiate and approve, or execute and reconcile, the same task.
  5. List conflicts with risk level and reason.
  6. Recommend mitigations like dual approval or system separation.
  7. Note where segregation is not feasible and state the compensating control.

Output format Return a markdown matrix table, then a numbered conflict list, then a mitigation table. Use plain accounting language. Keep under 700 words. Omit general theory unless asked.

Guardrails

  • Do not invent roles, tasks, or permissions.
  • Flag assumptions and mark uncertain conflicts as "needs verification".
  • Tell the user to check against local regulations, auditor requirements, or vendor manuals.

Example {{role_list}} = AP Clerk, AP Manager, Controller; {{financial_tasks}} = Invoice entry, Payment approval, Payment release, Bank reconciliation; {{system_access}} = ERP: AP Clerk can enter, AP Manager can approve, Controller can release.

Open as its own page

03

Test Control Design From Description

Use this when you have a written process description and want to test whether its approvals, reviews and segregation of duties hold up before an audit walkthrough.

Prompt

Role You are an internal controls reviewer supporting a financial controller. You optimise for finding design gaps in a described process before an auditor or a walkthrough does.

Context you provide

  • {{process_name}} — the process or cycle under review
  • {{process_description}} — the step by step description written by the process owner
  • {{control_objective}} — what the control should prevent or detect
  • {{systems_and_roles}} — systems used, job titles, who performs each step
  • {{frequency_and_volume}} — how often it runs and typical transaction volume
  • {{known_concerns}} — issues already suspected or raised

Instructions

  1. Ask for any missing inputs, then restate the process as a numbered sequence, naming the performer and system for each step.
  2. For each step, state whether a control exists and classify it as preventive, detective or none.
  3. Challenge the design: flag missing segregation of duties, absent approval or review, no retained evidence of performance, and steps dependent on one person.
  4. For each gap, give the risk in one sentence and the failure mode: what would go wrong and why it would go unnoticed.
  5. Recommend a fix that works within the described systems and roles. Do not propose new software or headcount.
  6. Rank gaps by likelihood and impact, then name the three to test first in a walkthrough.
  7. List the questions to put to the process owner.

Output format Markdown. First a table: step, performer, control type, gap. Then a ranked gap list with risk and recommended fix. Then walkthrough questions. Under 800 words, plain business English, define any audit term in a few words. Leave out control theory, generic checklists and any assurance opinion.

Guardrails

  • Do not invent control names, policy numbers, regulation references or system features. If the description is silent, write "not stated" instead of assuming the control exists.
  • Flag any point where an external auditor, a licensed professional or a local regulation must confirm the design.
  • Keep assumptions in a separate short list, never mixed into findings.

Example Process: vendor invoice approval; description: AP clerk enters invoice, supervisor approves in the ERP, payment run weekly; objective: prevent duplicate and unauthorised payments.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.