Scrut Teammates is an intelligent, AI-powered compliance and risk management assistant embedded right within the Scrut platform. It provides contextual insights for your queries. You can think of it as a compliance and security expert at your fingertips, guiding you through complex requirements as you work on getting compliant.
How to Ask Questions to Scrut Teammates
Heads Up!
Before you begin, please enable Scrut AI for your organization, if not done already.
Once you have logged in to Scrut, look for the Scrut Teammates icon at the bottom right corner of any page.
Click the icon to open the chat interface.

Type your query into the text field and press Enter.

You can also use the sample prompts as inspiration to draft your questions.
Review the answer.

Share your feedback
Your feedback helps us continuously improve Scrut Teammates’ responses and capabilities.
Use the New Chat icon at the top to start a fresh chat.
Click the Search icon to launch a product-wide search across your documents and modules.
Click Raise a Support Ticket to report an issue to the support team.
Click the three-dot icon (More Actions) to access the Help Center, Setup Wizard FAQs, and Product Updates.

What to Ask Scrut Teammates?
Scrut Teammates provides expert answers and actionable insights and can assist you with various tasks in Scrut. Here are a few sample topics and questions to help you get started:
Bring up my Incident Response Plan.
What does our Information Classification Policy say about handling confidential data?
For the evidence item ‘Monthly internal report / MIS for major departments,’ what are we expected to provide?
What does our Privacy Policy say about consent from employees before background verification?
Which roles are listed under the ‘Primitive Role in Use’ section in our Access Control policy?
What are the best practices for assessing a vendor with an ISO 27001 certificate?
When should we schedule our internal audit for ISO 27001?
How often should we conduct a Business Continuity and Disaster Recovery (BCP/DR) drill?
Heads Up!
These are just a few examples to help you get started. Scrut Teammates is built to understand and respond intelligently to a wide range of compliance and security questions based on your organizational data.
Do’s & Don’ts
Do: Use Plain Everyday Language
You don’t have to use special commands or keywords while interacting with Scrut Teammates. Ask questions like you would ask your colleagues. Examples: “Who is responsible for AWS in our company?”, “Which tests are failing for our upcoming ISO 27001 audit?”
Do: Be Specific
Make your questions detailed and specific. The more specific your questions, the more precise the answers.
Examples:
Instead of asking, “What controls am I missing?”, you can ask, “What controls am I missing for ISO 27001 certification?”
Instead of asking, “Is my AWS secure?”, you can ask, “What security issues exist in my AWS S3 bucket across all regions?”
Do: Dive into Details
Scrut Teammates can process complex data within your organization to answer highly specific technical questions about your organization.
Examples:
How many employees have not yet completed the ISMS training?
What’s the encryption status for our RDS instances?
Do: Ask Questions that Require Analyzing Multiple Sources
Scrut Teammates excels at analyzing your organization's data, helping you gain deeper insights into it. Ask broad questions that require synthesizing multiple data points.
Examples:
Review all my policies and let me know what’s missing for HIPAA compliance.
How compliant are we with NIST password requirements?
Don’t: Ask Questions that Require Subjective Judgment
Steer clear of questions asking for opinions or subjective assessments.
Instead of asking, "Is our privacy policy good enough?" you can ask, "What are the gaps in our privacy policy for SOC 2 compliance?"
Don’t: Ask Vague Requests
Questions with clear scope and context get more precise and helpful responses.
Instead of: "Are our vendors secure?”, you can ask: “What are the top 5 risks associated with our vendors?"
Don’t: Ask Multiple Questions at Once
Break down complex queries into small steps for more thorough responses.
Instead of asking, "What are our compliance gaps, how do we fix them, and who should be responsible?", try asking these questions separately.
Best Practices
#1: Be Iterative
Start with an initial question, then narrow down with follow-up questions based on the response.
For example, you can begin by asking, "What are our most critical vulnerabilities?" and then follow up with, "How can we remediate the SQL injection vulnerability you mentioned?"
#2: Build a Conversation
Scrut Teammates performs best when asked open-ended questions that provide context.
Instead of asking, "Do we have MFA enabled?", you can ask, "What is the status of MFA implementation across employee devices?"