Draft security questionnaires from governed answers
A draft maps each question to current approved evidence, answer owner, and confidence.
The problem
Security teams repeatedly answer similar questionnaires while inconsistent language creates commercial and legal risk.
What you get
A working system with the steps, tools, checkpoints, and expected return made explicit.
- Setup
- 75 minutes
- Back each week
- 3 hours
- Difficulty
- assisted
Expected return
The working case
A planning estimate, not a guaranteed result. Measure the first four weeks against your own baseline.
144
hours returned per year
At 3 hours/week across 48 working weeks.
1
week to earn back setup
Compare the setup estimate with the weekly time returned.
Operating contract
Input
The source material, constraints, and examples a human would need to do this work well.
Checkpoint
A person reviews judgment calls, sensitive content, unfamiliar tools, and irreversible actions.
Success signal
Track time returned, corrections required, and exceptions. Keep it only if the measured result compounds.
Before you start
- ·A named security assurance lead
- ·An approved source-of-truth and review template
The steps
- 01
Name security assurance lead as the accountable owner and define the decision this workflow is allowed to support.
- 02
Collect the questionnaire, approved answer library, security policies, and current certifications; preserve source links, timestamps, and access controls before any synthesis.
- 03
Produce an evidence-linked questionnaire draft using the approved template. Never overstate controls, certifications, testing, or contractual commitments.
Copy this prompt
Create an evidence-linked questionnaire draft from the supplied evidence. Separate facts, assumptions, and missing inputs. Cite every material claim. Never overstate controls, certifications, testing, or contractual commitments. Evidence: [approved inputs]
- 04
security assurance lead reviews the draft, records the decision or next action, and corrects the source system before distribution.
What it runs on
- Google Drive
Google Drive is used as an approved source or review surface in this workflow.
- Google Sheets
Google Sheets is used as an approved source or review surface in this workflow.
Where this goes wrong
- Do not let the model act beyond never overstate controls, certifications, testing, or contractual commitments.
- Keep sensitive fields out of unapproved tools and retain a human-readable evidence trail.
Definition of done
Run it for four weeks. Then make it earn its place.
- □ Baseline the manual time before launch.
- □ Keep a human approval step for consequential output.
- □ Record corrections and exceptions, not just successes.
- □ Expand, revise, or retire it after the first review.
Build the system around it
Related workflows
If this one stops working, tell us. Three reports in a month and it leaves the library until a person has looked at it again.