Metricstream is the worst offender in this area if you need a "hard" test. Last one of those I did started at 154 questions and was more than 500 by the end. I did the math and if I had done a paragraph comment on each of those, it would have been the equivalent of 180 pages (a small novel). I would LOVE to have AI fill those in for me and attach the right evidence documents from my policies.
How well does it handle nested questions where an affirmative or negative to Q1 reveals Q1.1, Q1.2, Q1.3 and further levels like 1.2.1, 1.2.2, 1.2.2.1?
Irony: demo for new trust center access functionality that requires me to do auth to a vendor I don't currently use requiring a review of their trust center.
From a tracking perspective, that makes sense. The challenge I see is that I'm then doing one link per client. That may be the "correct" way to do it for veracity but seems time consuming. I'll have to think more about it.
We produce risk intelligence. We have numerous data sources where we are a processor. We aggregate this data and layer on our analysis and we are controller of that amalgam. Our clients have data where they are controller. We match our data to theirs which, IIUC, results in joint controller status of that intersect. I don't want to enter things twice - as controller and as processor- so was thinking a joint control framing could be useful.
Yes, I'm using claude. And, yes, listing the external skills that are dependencies would be useful. I just tagged you on an older thread where I shared my prompt for it.
This looks very much aligned to what I'm doing but with a couple of sections different. Martin G. would you be willing to share your prompt or a redacted version of it?