FRI, SEPTEMBER 18, 2026
Independent · In‑Depth · Practitioner‑Tested
Claude General

Governance Prompts: 6 for Telling an Audit From a Press Release

OpenAI published six misalignment cases and a framework it runs itself. Anthropic disclosed four breaches and gave an outside body access to millions of transcripts. Both are more than a policy document and they are not the same thing. These six prompts are for reading any vendor governance claim and working out which kind it is.

⌨️ 6 prompts 🕐 Updated Sep 18, 2026
💡 How to use these prompts: Replace everything in [BRACKETS] with your specific details before sending. Click Copy to copy any prompt to your clipboard instantly.
1
Work out who checked it
Self-reported and externally audited are different categories, and coverage collapses them constantly.
Here is a vendor safety or governance claim: [PASTE]

Tell me:
- Who produced the evidence, the company or someone else
- Whether an external party could publish without approval
- What the company controls about what gets reported
- Whether this could produce a finding they did not want

The last one is the whole test.
2
Find the missing denominator
Six incidents out of how many is the question nobody can answer from outside.
A vendor reported: [PASTE THE FIGURE, e.g. six incidents]

Tell me what I would need to know to interpret that number, what the denominator would be, and whether it is published anywhere.

If the number cannot be compared to anything, say so plainly.
3
Test the definition against reality
A definition written around incidents that already happened is more credible than an abstract one.
A vendor defines a safety concept as: [PASTE THE DEFINITION]

Tell me:
- What real incidents would fall inside it
- What would fall outside and arguably should not
- Whether the definition looks written for known cases or hypothetical ones
- What it lets them exclude

Definitions are chosen. Tell me what this one is doing.
4
Compare two vendors on the same terms
Vendors choose the measures that flatter them. Finding the incommensurable parts is the work.
Here are governance claims from two vendors: [PASTE BOTH]

Compare them on who checked, what was disclosed, what could produce an unwanted finding, and what each declined to say.

Do not pick a winner. Show me where they are not comparable.
5
Draft the questions for procurement
What a vendor has refused to build tells you more than what they have built.
We are evaluating: [VENDOR]

Write the governance questions our security team should ask, and for each, what a strong answer sounds like versus an evasive one.

Include anything about external access, publication rights, and what they have declined to ship.
6
Check what it means for my own risk
Most disclosures affect the vendor, not you. Saying so is more useful than manufacturing an action.
This vendor disclosed: [PASTE]

Given how we use them: [DESCRIBE], tell me:
- Whether any of this changes our exposure
- What we should be doing that we are not
- What to put in the risk register, if anything
- Whether the honest answer is that it does not affect us

Say so plainly if it does not.