---
title: 'Set up Microsoft 365 Copilot for GRC practice'
slug: grc-microsoft-copilot
pillar: grc
profession: 'GRC practitioners'
platform: 'Microsoft 365 Copilot'
builtAgainst: 'Microsoft 365 Copilot Chat with a Microsoft Entra work account, August 2026'
sourcesVerifiedAt: '2026-08-14'
publishedAt: '2026-08-14T00:00:00Z'
summary: 'A ready-to-paste Microsoft 365 Copilot set-up for GRC practice: the standing instruction block, the files to keep beside it, the first three prompts, and what never goes into the platform.'
seo:
  seoTitle: 'Microsoft 365 Copilot set-up for GRC'
  seoDescription: 'A ready-to-paste Microsoft 365 Copilot configuration for GRC practitioners: standing instructions, file pack, first prompts, and verified never-paste rules.'
---

## What this sets up

Microsoft 365 Copilot does not have a persistent project-instructions field the way Claude Projects does, so this configuration works with what Copilot actually gives you: a standing instruction block you paste as the first message of a working session (or save as a reusable prompt where your tenant offers Copilot prompt saving), and a file pack you keep in one dedicated OneDrive or SharePoint folder so Copilot can ground its answers in your own templates through the files you reference or attach. The result is the same discipline as a project space: fixed rules, fixed templates, repeatable chains for control testing summaries, obligation mapping and board papers. The method comes from the [AI Setup module LM-S01](/learning-hub/modules/lm-s01-set-up-your-ai-command-centre); this page packages the GRC playbook for Copilot specifically.

## What never goes in

Work only ever happens in the work experience: signed in with your Microsoft Entra work account, with the enterprise data protection shield showing. The consumer Microsoft Copilot app on a personal account is a different product with different terms, and Microsoft's Purview documentation files it alongside other consumer AI apps, not with the work experience. Microsoft's documentation then sets these boundaries:

- Training: "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft 365 Copilot." For Copilot Chat, Microsoft's FAQ answers the training question "No, prompts and responses aren't used to train foundation models under enterprise data protection" - the qualifier "under enterprise data protection" travels with the claim, which is another reason the Entra sign-in is non-negotiable.
- Everything you type is retained and discoverable: stored Copilot interactions include "the user's prompt and Copilot's response, including citations", held in a hidden folder of your mailbox that "compliance administrators can search with eDiscovery tools". Deleting activity in the app is not deletion from the record, and Microsoft warns that "Messages visible in your AI apps are not an accurate reflection of whether they are retained or permanently deleted". Write every prompt as if it were a work email, because for retention purposes it is one.
- Do not paste customer records, incident detail or personal information into prompts at all: named individuals in a breach file, whistleblower identities and unredacted complaint detail have no place in a discoverable prompt history, whatever the platform's protections. Use role labels such as [CUSTOMER_A] and [STAFF_MEMBER_A] instead.
- Web grounding leaves the tenant: when Copilot queries Bing, Microsoft is "an independent data controller" for those queries and they sit outside the Data Protection Addendum. Microsoft also notes short prompts can reach Bing largely intact, so keep regulated identifiers and confidential matter names out of any prompt you run with web grounding on.
- Copilot "only surfaces organizational data to which individual users have at least view permissions". That protects you, but it also means Copilot inherits any oversharing in your tenant; if Copilot surfaces a document you did not expect to see, report the permissions gap rather than using the content.
- Residency: "Customers outside the EU may have their queries processed in the US, EU, or other regions." Australian processing is not the default; if your data-residency obligations require it, confirm your tenant's arrangements with your administrators before use.
- Third-party agents in Copilot are governed by their own privacy statements, not automatically by the enterprise data protection terms. Treat any agent your tenant has added as a separate vendor decision.

Sources, all verified 14 August 2026: [Data, Privacy, and Security for Microsoft 365 Copilot](https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy), [Enterprise data protection in Microsoft 365 Copilot](https://learn.microsoft.com/en-us/microsoft-365/copilot/enterprise-data-protection), [Retention policies for Copilot](https://learn.microsoft.com/en-us/purview/retention-policies-copilot), [Copilot privacy and protections](https://learn.microsoft.com/en-us/copilot/privacy-and-protections), [Copilot FAQ](https://learn.microsoft.com/en-us/copilot/faq).

## The instruction text

Start each working session by pasting this as your first message, adjusting the folder name to yours:

```text
You support a governance, risk and compliance practitioner. My
context files live in my "GRC command centre" folder:
writing-style.md, obligation-register-extract.md,
control-testing-template.md, board-paper-skeleton.md,
regulator-watchlist.md, glossary.md. When I reference or attach
one, follow it exactly.

Rules for this session:
1. Precision over polish. Every reference to an obligation,
   standard or clause must be specific. If you cannot ground a
   claim in a file I provide or in material I paste, mark it
   "unverified" and list what would confirm it.
2. Never invent regulator positions, citations, dates or quotes.
   This is a hard rule with no exceptions.
3. Control testing summaries follow control-testing-template.md:
   objective, method, sample, results, exceptions, rating,
   remediation.
4. Board papers follow board-paper-skeleton.md: recommendation
   first, then the minimum reasoning a director needs, then
   appendices. Plain English; assume an intelligent reader with
   limited time.
5. Distinguish design effectiveness from operating effectiveness
   whenever controls are discussed.
6. End drafts with "For human review:" naming the claims a
   reviewer must verify against source systems.
```

## The files to attach

Write these six markdown files, keep them in one OneDrive or SharePoint folder, and reference or attach them as each task needs. Each links to a published artefact to build it from:

- **writing-style.md**: your voice profile, built with the voice-profile interview in [module LM-S01, Part 1](/learning-hub/modules/lm-s01-set-up-your-ai-command-centre).
- **obligation-register-extract.md**: a de-identified slice of the register: obligation, source, owner, controls. The register-as-evidence discipline in [the AI use case register article](/grc/ai-use-case-register-board-evidence) sets the shape.
- **control-testing-template.md**: objective, method, sample, results, exceptions, rating, remediation, informed by [AI in internal audit](/grc/ai-in-internal-audit).
- **board-paper-skeleton.md**: your board's structure and send-back triggers. The [board paper recipe](/recipes/produce-a-board-paper-in-ninety-minutes) shows a working skeleton, downloadable as [raw markdown](/recipes/produce-a-board-paper-in-ninety-minutes.md).
- **regulator-watchlist.md**: which regulators you track and what each has signalled recently, maintained with the [Monday regulatory sweep recipe](/recipes/run-the-monday-regulatory-sweep).
- **glossary.md**: your organisation's terminology; the site's [CPS 230](/glossary/apra-cps-230) and [CPS 234](/glossary/apra-cps-234) entries are starting points.

## The first three prompts

```text
Interview me one question at a time so you can support my GRC
practice. Ask:
1. Which obligations and prudential standards does my team own,
   and which regulators do we answer to?
2. What does my control testing methodology look like: sampling,
   evidence standards, rating scale?
3. Who reads my reporting: line management, risk committees, the
   board?
4. What does a strong board paper look like in my organisation,
   and what gets papers sent back?
5. Which registers do I maintain: obligations, controls,
   incidents, attestations?
6. Which source documents should you treat as authoritative, and
   in what order?
Then summarise my answers as folder-ready context notes for my GRC
command centre folder.
```

```text
I am pasting de-identified extracts from control testing working
papers. Structure them against control-testing-template.md:
objective, method, sample, results, exceptions, rating,
remediation. Justify every rating from the evidence provided, mark
anything you cannot ground as "unverified", and end with "For
human review:" naming the claims to verify against source systems.
```

```text
I am pasting an extract from obligation-register-extract.md. Map
each obligation to the business processes and controls that
address it, distinguishing design effectiveness from operating
effectiveness, then draft a gap table with owners and suggested
next steps for my review.
```

## Governance guardrails

- The standing rules travel with every session: if a chat starts without the instruction block, paste it before any substantive work.
- Nothing leaves the draft stage without the "For human review:" list resolved by a human against source systems; ratings, breach characterisations and anything destined for a regulator or the board are human decisions.
- Verify every clause and standard reference against the current instrument before it is relied on; Copilot citations point at your tenant's documents, which may themselves be stale.
- Remember the prompt history is discoverable: keep prompts professional, de-identified and free of speculation you would not put in an email.
- Check your organisation's Copilot rollout guidance first; some tenants restrict web grounding, agents or file attachment, and those restrictions are part of your control environment.

## About this configuration

Built against: Microsoft 365 Copilot Chat with a Microsoft Entra work account, August 2026. Platform behaviour, licensing and terms change; re-check the sources above before relying on any data-handling claim. TheAICommand is independent: no platform vendor paid for, reviewed or influenced this configuration, and we accept no payment for coverage. See [ownership and funding](/editorial-standards#funding).
