5W1H
Two thousand years old, and still the fastest way to find the hole in a brief.
What is 5W1H?
5W1H is six questions: Who, What, When, Where, Why and How. It is the oldest framework on this site by roughly two millennia, it is the only one that predates writing about business entirely, and it is the one most often used the wrong way round.
The wrong way round is treating it as an output structure — six headings, six paragraphs, one per question. That produces a document nobody wants to read and an incident report no security team will accept. 5W1H is a checklist for the input, not a shape for the output. The six questions are what your prompt must already answer before you ask for anything; the output can then be a press release, a report, a set of minutes or a spec, in whatever shape that genre actually takes. Used that way it does something no other framework here does: it finds the missing fact before the model invents one, because an unanswered W is exactly where fabrication goes.
Where 5W1H Came From
Hermagoras of Temnos, 1st century BC
The ancestor is a rhetorical device. Hermagoras of Temnos set out seven "elements of circumstance" — quis, quid, quando, ubi, cur, quem ad modum, quibus adminiculis: who, what, when, where, why, in what way, by what means — building on Aristotle's treatment of circumstances. Note the last two: what we compress into "How", the ancients split into manner and means, which is a distinction worth keeping when the method and the tooling are different answers.
Kipling gave it the form everyone remembers
In Just So Stories (1902), in "The Elephant's Child", Rudyard Kipling wrote: "I keep six honest serving-men (They taught me all I knew); Their names are What and Why and When And How and Where and Who." That verse is why the set is sometimes called the Six Honest Serving Men, and it is the reason a rhetorical doctrine survived into ordinary use — it was easier to remember as a rhyme than as a list of Latin.
The newsroom made it a standard, then industry did
The five Ws became the working test of a complete news lead in the early twentieth century and were being taught formally in American high-school journalism by 1917. Manufacturing and quality management later adopted 5W1H as an analysis tool, which is how it reached root-cause work and process documentation. Three separate traditions, one checklist, and no owner — nobody invented 5W1H, which is unusual for something this durable.
The 6 Slots, One at a Time
Each slot is a decision. Leave it out and the model still makes it — just without you.
Split the actor from the affected — they are almost never the same list and prompts routinely answer only the first. In an incident, "who" is the attacker and the customers whose records were read; in a project, the owner and the people whose work changes.
The negative half is the part people skip and the part readers want most. "No writes, no deletions, no card numbers" is the sentence that decides how a customer feels about the first paragraph, and a model will not supply it unless you do.
Give start, end, detection and response as separate times. The gap between the end and the detection is usually the most scrutinised number in an incident report, and the one an unspecified prompt quietly rounds away.
Where is the slot that bounds the blast radius, so say what was in scope and, where it matters, what was not. "The reporting replica" tells a reader something "our systems" never will.
Five of these are observable and Why is an inference. Who, what, when, where and how can be evidenced; why is a claim about causation, and it is the one that gets a report retracted. Answer it, but mark it: state whether the cause is established or still under review, and forbid the model from presenting a hypothesis as a finding.
Hermagoras' distinction earns its keep here. "How" as manner is the sequence of events; "how" as means is what made it possible. A reused password is the means; the absence of MFA is what turned the means into an entry.
One Task, Before and After
The task: A customer-facing incident report after a credential-reuse breach. Both prompts below are scored by our free prompt checker — paste either in and you will get the same number, because the scoring is deterministic.
Write an incident report about the security breach.
Seven words. The model will fill all six Ws itself — inventing a timeline, a record count and a root cause — and every invented one is a statement your security team has to retract in public.
Who: An attacker using valid credentials belonging to a contractor account that was not disabled at the end of the engagement. Affected: 4,100 customer records in the billing export table. What: Read access to the billing export table. No writes, no deletions, and no card numbers - the table holds names, email addresses, company names and invoice totals only. When: First access 03:14 UTC on 12 August, last access 04:02 UTC. Detected 09:40 UTC on 13 August by an analyst reviewing anomalous export volumes. Credentials revoked 09:55 UTC. Where: The reporting replica, reachable from the internet through a VPN endpoint that did not enforce device posture checks. How: The contractor's password appeared in a third-party breach corpus and was reused. MFA was not enforced on that account. Why: NOT ESTABLISHED. Offboarding did not revoke the account, but whether that was process or tooling is still under review - state this as an open question, not a cause. Write the customer-facing incident report for a security incident, 500 to 600 words, using exactly these five headed sections: What happened, What data was involved, What we have done, What you should do, What happens next. Write for enterprise customers whose own security teams will read this and ask follow-up questions. They already know an incident occurred because we emailed a holding notice. Ensure every one of the six sections above is either answered completely or explicitly marked not yet known - a silent gap is the failure this framework exists to prevent. Work through the facts before you write, settling for each whether it is observed or inferred - not while drafting. Label every statement as either observed or inferred. Do not present the Why as settled: the report must distinguish what we measured from what we believe. For example: ``` Observed: the account authenticated from a single IP address between 03:14 and 04:02 UTC. Inferred: the credential was obtained from a public breach corpus. We have not confirmed this. ``` Do not use the phrase 'we take security seriously'. Do not describe the incident as sophisticated. Do not state a root cause we have not confirmed, and do not invent times, record counts or systems beyond those given above.
Ninety-two — and note what the six labelled answers are not doing: they are not the shape of the report. The output has five different headings, because "What happens next" is what a customer needs and "Where" is not a section anybody wants to read.
Ninety-two, and the score cannot see the mistake most people make
One check is unreachable, and one much larger risk is not checked at all:
No persona slot — 5W1H is six questions, not a brief. Unlike the sales frameworks, where a copywriter persona actively damages the output, here a role is simply outside the acronym: harmless, available, and worth eight points if you want them.
A prompt can score in the nineties and still produce the wrong document. Answer all six questions, then ask for six headed sections, and you get a report structured like a form. No rubric will penalise it. The six answers are the input; the output takes the shape its genre takes.
The whole point of the framework — whether every question is actually answered — is invisible to any scorer, because a confident invented answer and a real one look identical. Only you can tell.
So the instruction that matters most here earns nothing: "either answer it or mark it not yet known." An unanswered W is precisely where a model improvises, and improvisation in an incident report, a press release or a root-cause document is the kind that gets corrected in public.
Copy-Paste Prompt Template
Replace the bracketed placeholders with your specific details.
Who: [Both the actor and the affected — they are rarely the same list] What: [What happened, and equally what did NOT happen] When: [Start, end, detection and response as separate times] Where: [The system, place or scope — and its boundary] Why: [The cause, marked ESTABLISHED or NOT ESTABLISHED. Never a hypothesis in the voice of a finding] How: [The mechanism, and separately what made it possible] [Then the ACTUAL deliverable — its genre, length and real headings, which are almost never the six questions] [Answer every question above or mark it not yet known; a silent gap is where invention enters]
When 5W1H Fits — and When It Does Not
- Incident reports, post-mortems and anything a second organisation will scrutinise.
- Press releases and announcements, where a missing W is what the first reply asks about.
- Root cause analysis and investigations — the tradition industry borrowed it for.
- Process documentation and handovers written for someone who was not there.
- Meeting minutes and requirements documents, where the gaps become next month's argument.
- Any prompt you suspect is underspecified — run the six questions over it as an audit.
- Creative and persuasive writing. Six factual questions will not move anyone.
- Work where the facts are the thing you are trying to discover, not to record.
- Short deliverables — six answers is a heavy preamble for a two-line request.
- As an output structure. Six headings is almost never the right shape for a reader.
- Analysis and recommendation. 5W1H establishes what happened; SWOT or OODA decide what to do.
10 Ready-Made 5W1H Prompts
Every prompt below was produced by the Frompting generator with 5W1H selected — not written by hand for this page. Each is scored by our prompt checker; the median is 81/100. Click one to open it, then copy.
A project kickoff brief 80
You are a project kickoff brief author. Create a concise briefing document that introduces the new project and covers all essential basics. First, identify the primary individuals or groups involved in the project and their roles. Next, describe the core purpose and key deliverables of the project. Then, specify the planned start date and major milestones, including any critical deadlines. After that, indicate the primary location(s) where the project work will be performed or coordinated. Following this, explain the main reasons for undertaking the project and the expected business impact. Finally, outline the high‑level approach, including major phases, methods, and any required resources. The brief should be written for [AUDIENCE: e.g., senior leadership, project team, external partners] and be no longer than 300 words. Quality criteria: - Clear, jargon‑free language that can be quickly scanned. - Each section provides a complete answer to its focus area. - The overall tone is professional and motivating. Exclude any detailed technical specifications, budget figures, or risk assessments. If any of the above details are unknown, insert a placeholder in the format **[PLACEHOLDER: description of needed information]**. State any assumptions you make and ask up to three clarifying questions before finalizing the brief.
A security incident report 80
You are an incident report writer for a security breach. Your task is to produce a concise, professional incident report that follows a logical investigative structure, covering the responsible parties, the nature of the breach, the timing, the location, the underlying reasons, and the response actions. The report is intended for **[AUDIENCE: e.g., senior management, compliance team, external auditors]** and should be no more than **400 words**. **Content requirements** 1. Identify the individual(s) or team(s) involved in detecting or handling the breach. 2. Describe the breach event, including what data or systems were compromised. 3. State the exact date and time (or approximate period) when the breach occurred or was discovered. 4. Specify the physical or network location(s) affected. 5. Explain the primary cause or contributing factors that led to the breach. 6. Outline the steps taken to contain, remediate, and prevent future incidents. **Quality criteria** - Factual and objective tone, avoiding speculation beyond the provided information. - Clear, chronological flow that a non‑technical reader can follow. - Include any relevant identifiers (e.g., incident ID) if known. **Boundary** Do not include speculative legal conclusions, liability statements, or recommendations for policy changes beyond the immediate response actions. If any of the above details are unknown, insert a placeholder in the format **[PLACEHOLDER: description of needed information]**. Otherwise, state any assumptions you are making and ask up to three clarifying questions before finalizing the report.
Discovery questions for a customer call 77
You are a seasoned customer‑research specialist. Your task is to craft a concise set of discovery questions for a research call that will uncover deep insights about the customer’s situation. First, consider who you will be speaking with and tailor the questions to that role. Next, develop questions that explore what the customer currently does, the challenges they face, and the outcomes they seek. Then, include prompts that uncover when key events or decisions occur in their workflow. After that, ask about where (physical locations, digital environments, or organizational units) the relevant activities happen. Follow with inquiries that reveal why the customer behaves as they do, their motivations, and the problems they aim to solve. Finally, generate questions that probe how they currently address these issues, the processes they follow, and any tools or methods they employ. Produce **12–15** open‑ended questions, grouped in the order described above, each on a separate line. Ensure every question is neutral, avoids leading language, and can be answered in a conversational interview. Do not include any sales or promotional content. If any of the following details are unknown, insert a placeholder in the format **[PLACEHOLDER: brief hint]**: - [TARGET_ROLE: the interviewee’s job title or function] - [PRODUCT_OR_SERVICE: the product or service being researched] - [INDUSTRY: the industry sector of the customer] - [CALL_DURATION: expected length of the interview] State any assumptions you make and, if needed, ask up to three clarifying questions before finalizing the list. Write this for [AUDIENCE: who will read the output, and how much they already know]. Match the depth, vocabulary and examples to that reader. Before writing the final answer, work through the problem step by step and weigh the main trade-offs; present only the reasoned conclusion, not your working notes.
A product launch press release 81
You are a seasoned public‑relations specialist tasked with drafting a concise, news‑worthy press release announcing a new product launch. The release must be written for a general media audience and follow a logical flow that naturally covers the essential details in this order: the organization issuing the announcement, the product being introduced, the scheduled launch date, the location or market where it will be available, the core reason this product matters to its intended users, and the method by which the launch will be executed (e.g., rollout phases, distribution channels, or promotional activities). Provide the press release in plain text, no longer than 250 words. Ensure it: - Opens with a compelling headline and sub‑headline that capture the news value. - Includes a clear, factual lead paragraph that answers the key details. - Uses an engaging quote from a senior executive that reinforces the product’s significance. - Ends with a concise boilerplate about the company. [PRODUCT_NAME: supply the official name of the product] [COMPANY_NAME: supply the full legal name of the issuing organization] [LAUNCH_DATE: supply the exact date (day, month, year) of the launch] [LAUNCH_LOCATION: supply the primary market or geographic region] [KEY_BENEFIT: supply the main value proposition or problem solved] [TARGET_AUDIENCE: supply the primary customer segment] State any assumptions you make about the missing details, and ask up to three clarifying questions before finalizing the release.
Process documentation for a new starter 92
You are a business process documentation specialist. Create a clear, step‑by‑step guide that a newly hired team member can follow to perform the designated workflow. First, identify the individual or role that will use this guide. Next, describe the exact workflow to be documented, including all tasks and decision points. Then, indicate the typical timing or sequence in which each step should occur. Specify the environment, tools, and systems where the workflow is executed. Explain the purpose of the workflow and the outcomes it supports for the organization. Finally, detail how the new member should carry out each step, including any required inputs, outputs, and best‑practice tips. The guide should be written for a [ROLE: e.g., “new software engineer”] and cover the [PROCESS NAME: e.g., “customer onboarding”] workflow. Deliver the guide in markdown with numbered steps, sub‑steps as needed, and a brief “Key Points” summary at the end. Keep the total length between 300 and 450 words. Quality criteria: 1. Completeness – every major task and decision point is included. 2. Clarity – instructions are concise, use active verbs, and avoid ambiguous language. 3. Usability – includes practical tips and highlights common pitfalls. Exclude any company‑specific confidential details unless they are provided. If any of the placeholders above are unknown, state your assumption and proceed, or ask up to three clarifying questions before finalizing the guide.
Meeting minutes with decisions and owners 73
You are a professional meeting‑minutes writer tasked with producing clear, concise records that capture every decision made and assign responsibility to the appropriate owners. First, identify the meeting participants and their roles. Next, list each decision that was reached during the session. Then, note the date and time the meeting took place. After that, specify the location or virtual platform where the meeting was held. Following this, describe the primary purpose or agenda that drove the discussion. Finally, format the minutes so that each decision is followed by the name of the owner responsible for implementation and a brief deadline if mentioned. Produce the minutes in plain text, using headings for each section and bullet points for decisions. Keep the total length between 200 and 300 words. Ensure the output is easy to scan, with decisions bolded and owners highlighted in parentheses. Do not include personal commentary or speculative content. [MEETING TITLE]: Provide the official title of the meeting. [ATTENDEES]: List names and roles of all participants. [DATE & TIME]: Specify when the meeting occurred. [LOCATION/PLATFORM]: State where the meeting was held (physical room or virtual link). [PURPOSE]: Summarize the main objective or agenda of the meeting. Write this for [AUDIENCE: who will read the output, and how much they already know]. Match the depth, vocabulary and examples to that reader. If any bracketed detail above is left unfilled, choose a sensible value from the context, state that assumption in one line before you begin, and continue — do not ask for it and stop. Before writing the final answer, work through the problem step by step and weigh the main trade-offs; present only the reasoned conclusion, not your working notes.
Why a marketing campaign underperformed 86
You are a marketing analyst tasked with diagnosing the reasons a recent campaign fell short of expectations. First, identify the primary audience the campaign was intended to reach. Next, describe the core message, offer, or call‑to‑action the campaign promoted. Then, specify the launch date, duration, and any key milestones or phases. After that, outline the primary channels (e.g., email, social media, paid search) and geographic markets where the campaign was deployed. Analyze the underlying causes of the shortfall, considering factors such as audience relevance, creative execution, timing, channel performance, budget allocation, and external influences. Finally, propose a detailed remediation plan with actionable steps, prioritization, and metrics to monitor improvement. [CAMPAIGN_GOAL: brief description of what the campaign aimed to achieve] [TARGET_AUDIENCE: description of the intended consumer segment] [CHANNELS_USED: list of marketing channels employed] [KPIs_TRACKED: key performance indicators measured] [BUDGET_ALLOCATED: total spend or budget range] If any of the above details are unknown, state your assumptions clearly and ask up to three clarifying questions before delivering the analysis. Deliver a concise report of 300–400 words, organized with clear headings for each section, and ensure recommendations are specific, feasible, and tied to measurable outcomes. Before writing the final answer, work through the problem step by step and weigh the main trade-offs; present only the reasoned conclusion, not your working notes.
A requirements document for a new feature 81
You are a requirements analyst tasked with drafting a comprehensive requirements document for a new feature. The document must be organized to cover all essential dimensions in a logical sequence: identify the primary stakeholder(s) and user persona, describe the feature’s functionality and scope, specify the target delivery timeframe, indicate the intended deployment environment, explain the business rationale and expected benefits, and outline the implementation approach and constraints. Produce a markdown‑formatted document of approximately 800–1000 words, including the following sections in order: 1. Stakeholder(s) and user persona 2. Feature description and functional scope 3. Delivery schedule and milestones 4. Deployment environment and platform considerations 5. Business justification and success criteria 6. Implementation approach, technical constraints, and acceptance criteria Quality criteria: - Clarity: each section should be concise yet complete, using plain language and defining any technical terms on first use. - Traceability: link each requirement to the relevant stakeholder or business goal. - Feasibility: include realistic constraints and assumptions. Exclude any speculative market analysis, pricing details, or legal compliance statements unless explicitly provided. If any of the following details are unknown, insert a placeholder in the format **[PLACEHOLDER: brief hint]** and proceed with the rest of the document: - [FEATURE_DESCRIPTION: brief summary of the new feature] - [PRIMARY_STAKEHOLDER: name or role of the main stakeholder] - [TARGET_TIMELINE: expected delivery date or sprint length] - [DEPLOYMENT_ENVIRONMENT: production system or platform] - [BUSINESS_GOAL: key objective the feature supports] State any assumptions you make and ask up to three clarifying questions before finalizing the requirements. Write this for [AUDIENCE: who will read the output, and how much they already know]. Match the depth, vocabulary and examples to that reader.
An offsite plan with every detail captured 89
You are an experienced corporate event planner. Your task is to design a complete off‑site program for a company, covering every logistical and experiential detail. Identify the participants and their roles, then define the purpose and desired outcomes of the off‑site. Specify the agenda, including all sessions, activities, and breaks, with estimated durations for each. Determine the exact dates and overall timeline, noting any constraints on availability. Select a venue and any additional locations, describing capacity, facilities, and travel requirements. Explain the strategic reasons for the off‑site and how it supports the company’s goals. Outline the step‑by‑step execution plan, covering pre‑event preparation, on‑site coordination, and post‑event follow‑up, including responsibilities, communication channels, and contingency measures. Produce the plan as a structured markdown document with clear headings for each section, using bullet points or tables where appropriate. Keep the total length to approximately 800–1000 words. Quality criteria: 1. All elements are concrete, actionable, and internally consistent. 2. The plan anticipates common risks and includes mitigation steps. 3. The language is professional yet concise, avoiding unnecessary jargon. Exclude any assumptions about budget, company size, industry, or specific location unless provided. If any critical information is missing, state your assumptions clearly and ask up to three clarifying questions before finalizing the plan. [COMPANY_SIZE]: number of employees attending [OFFSITE_BUDGET]: total budget available for the off‑site [DESIRED_OUTCOMES]: primary goals the company wants to achieve [VENUE_PREFERENCES]: any specific venue types or locations desired [TRAVEL_RESTRICTIONS]: limitations on travel or accommodations Write this for [AUDIENCE: who will read the output, and how much they already know]. Match the depth, vocabulary and examples to that reader. Before writing the final answer, work through the problem step by step and weigh the main trade-offs; present only the reasoned conclusion, not your working notes.
A root cause analysis of a repeat failure 96
You are a seasoned root cause analyst. Your task is to produce a concise, structured root cause analysis of a repeated production failure. Identify the individuals or roles impacted by the failure. Describe the specific failure event, including its symptoms and observable effects. Specify the time patterns or intervals when the failure recurs. Indicate the production environment, location, or system where the failure occurs. Explore the underlying reasons that could be driving the recurrence, considering process, equipment, human, and material factors. Outline the investigative steps and methods you would use to confirm the true cause and recommend corrective actions. The analysis should be no more than 500 words, presented in clear sections following the order above, each section titled with a brief heading. Quality criteria: - Each section provides concrete, factual details without speculation beyond what is stated. - The reasoning links observed symptoms to potential causes logically. - Recommendations are actionable and measurable. Exclude any discussion of unrelated processes or speculative future scenarios. If any of the required details are unknown, insert a placeholder in the format **[PLACEHOLDER: brief hint]** (e.g., [IMPACTED ROLE: who experiences the failure]). Before delivering the analysis, state any assumptions you are making and ask up to three clarifying questions needed to complete the assessment. Write this for [AUDIENCE: who will read the output, and how much they already know]. Match the depth, vocabulary and examples to that reader. Before writing the final answer, work through the problem step by step and weigh the main trade-offs; present only the reasoned conclusion, not your working notes.
Scores range from 73 to 96. They are shown as generated rather than cherry-picked — a library where every entry scores in the nineties tells you it was curated, not measured.
5W1H vs the Alternatives
The narrative counterpart. 5W1H gathers the facts; SCQA arranges them into an argument that goes somewhere. Use 5W1H to make sure nothing is missing, then SCQA to make it readable.
The briefing framework. TRACE tells someone what to produce; 5W1H makes sure you know the facts before you brief anybody.
Where 5W1H stops. 5W1H is a complete Observe step and nothing else — OODA adds the orientation and the decision that turn facts into a move.
The same completeness instinct made rigorous. MECE asks whether your categories cover everything without overlapping; 5W1H just gives you six categories that usually do.
The machine-facing equivalent of "answer everything before you ask". ICIO structures a prompt for a parser; 5W1H structures the facts for a person.
Five Ways People Get 5W1H Wrong
The defining 5W1H failure. Six questions in, six headings out — and a press release that reads like a police report. The six answers belong in the prompt; the output takes whatever shape the genre demands.
Five of the six are observable and one is a claim about causation. Presenting an unconfirmed Why in the same voice as a timestamp is how a report gets retracted. Mark it.
Every situation has people it happened to. The affected party is the half readers care about and the half prompts routinely omit.
A silent gap is an instruction to improvise, and models improvise plausibly. Write "not yet known" explicitly — it is a fact, and it stops the invention.
Hermagoras split them for a reason. The sequence of events and the thing that made it possible are different answers, and in a root cause analysis only the second one is actionable.
The negative What — no writes, no card data, no customers affected outside the EU — is the most reassuring content in any report and never appears unless you supply it.
5W1H Questions
What does 5W1H stand for?
Who, What, When, Where, Why and How. It is a completeness checklist: six questions that between them cover the facts of a situation.
Where does 5W1H come from?
Rhetoric, not journalism. Hermagoras of Temnos set out seven "elements of circumstance" in the 1st century BC, building on Aristotle. Kipling gave it its memorable form in Just So Stories (1902), and newsrooms had made it a standard test of a complete lead by 1917.
Should my output have six sections, one per question?
Almost never. That is the most common misuse. Answer the six questions in the prompt, then ask for the shape the deliverable actually takes — a press release, a report, a set of minutes.
What if I do not know one of the answers?
Say so, in the prompt, in those words. "Not yet known" is a fact and it prevents the model from supplying a plausible substitute. A blank slot is where fabrication enters.
Why is Why treated differently?
Because it is the only one of the six that is an inference rather than an observation. The other five can be evidenced; Why is a causal claim, and stating an unconfirmed one with the confidence of a timestamp is the characteristic failure of incident writing.
Is 5W1H the same as the Five Ws?
The same tradition with How made explicit. The five Ws come from the news lead; 5W1H is the form that quality and process work adopted, where the mechanism matters as much as the facts.
Generate a 5W1H Prompt Instantly
Skip the manual template — Frompting applies 5W1H to your topic in one click.
Try it FreeFramework Details
| Name | 5W1H |
| Stands for | Who-What-When-Where-Why-How |
| Domain | Strategy & Planning |
| Steps | 6 |
| Access | Pro |