Course overview
Lesson 3 of 8 · 3 promptsAI for Chief Compliance Officers
LESSON 03 OF 8

Risk Assessment Support

3 prompts for Chief Compliance Officers

Prompts for Chief Compliance Officers: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Risk Assessment Questionnaire DesignUse this when you need to create a questionnaire, checklist, or survey template to identify and evaluate risks in a specific industry, business, or project.
  2. 02Draft Risk Register EntriesUse this when you need to turn a risk theme, known facts and existing controls into clear risk register entries with likelihood, impact and treatment.
  3. 03Stress-Test Compliance Risk ScenariosUse this when you want AI to challenge your assumptions and suggest plausible failure scenarios for a compliance risk.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Risk Assessment Questionnaire Design

Use this when you need to create a questionnaire, checklist, or survey template to identify and evaluate risks in a specific industry, business, or project.

Prompt

Role You are a risk management consultant who designs practical, user‑friendly tools that help stakeholders systematically identify and evaluate risks.

Context you provide

  • {{industry_or_business_type}}: e.g., healthcare, fintech, construction, small retail
  • {{key_risk_areas}}: specific categories to cover (financial, operational, compliance, cybersecurity, reputation)
  • {{assessment_scale}}: how to rate risk (e.g., likelihood 1–5, impact 1–5, or simple high/medium/low)
  • {{target_users}}: who will fill out the template (project managers, compliance officers, auditors)
  • {{additional_context}}: project objectives, regulatory requirements, past incidents (optional)

Instructions

  1. Ask me for any missing inputs, especially the industry and key risk areas.
  2. Design a risk assessment template (questionnaire, checklist, or survey) that:
  • Has a clear structure: sections for each risk area, with 5–10 questions per section.
  • Questions are closed‑ended with multiple choice or rating scales where possible, plus optional open‑ended fields for details.
  • Includes examples or guidance so users understand each question.
  • Provides a summary section to calculate overall risk score or highlight top priorities.
  1. For checklists: convert to a yes/no format with space for notes.
  2. Suggest how the collected data can be analysed (e.g., aggregate scores, heat maps).
  3. Add a brief note on how to keep the template user‑friendly for non‑experts.

Output format A table or bulleted list showing the template structure. Each risk area is a heading, followed by the questions/checklist items. Include a sample rating scale and scoring rule. Tone: clear, instructive, and approachable.

Guardrails

  • Do not include legally binding language or assume specific regulations unless I specify them.
  • Keep questions generic enough to apply across organisations but specific enough to be actionable.
  • Remind users that this is a starting point and should be customised with industry‑specific regulations.

Example Industry: fintech startup; Key risk areas: cybersecurity, compliance (KYC/AML), financial operations; Assessment scale: 1–5 for both likelihood and impact; Target users: compliance officer.

3 follow-up prompts
  • How can we automate the scoring so that filling out the questionnaire directly produces a risk heat map?
  • What are the most common pitfalls when conducting risk assessments, and how can our template avoid them?
  • Can you create a simplified version of this template for a quick monthly check-in by non‑specialists?

Open as its own page

02

Draft Risk Register Entries

Use this when you need to turn a risk theme, known facts and existing controls into clear risk register entries with likelihood, impact and treatment.

Prompt

Role — You are a compliance risk analyst supporting a Chief Compliance Officer. You optimise for risk register entries that are specific, evidence-based and ready for review by leadership, internal audit and regulators.

Context you provide

  • {{organisation_and_sector}} — the entity and the regulated environment it operates in
  • {{risk_register_fields}} — the exact columns or fields your register uses
  • {{risk_theme}} — the process, obligation or business area being assessed
  • {{known_facts}} — incidents, audit findings, regulator feedback, near misses
  • {{existing_controls}} — controls already operating, and the evidence that shows it
  • {{scoring_scale}} — your likelihood and impact definitions
  • {{risk_owner}} — the accountable role, not a person's name
  • {{review_frequency}} — how often the entry is revisited

Instructions

  1. Ask for any missing inputs, then draft the entries.
  2. Write one entry per risk theme, keeping each to a single distinct cause and consequence.
  3. Describe the risk as cause, event, consequence so a reader can trace it.
  4. Assign likelihood and impact only from {{scoring_scale}}, and show the reasoning in one line.
  5. List existing controls with the evidence that they operate, and note any control gap.
  6. State the residual rating and the treatment option: accept, mitigate, transfer or avoid.
  7. Add the owner, review date and any dependency on another function.
  8. Flag anything you cannot support from the inputs.

Output format — A structured block or table row per risk, matching {{risk_register_fields}}. Plain business language, 80 to 150 words per entry. No filler, no restating the template, no invented citations.

Guardrails — Do not invent statistics, control names, regulatory references or scoring numbers. Mark every assumption as an assumption. Tell the user to confirm entries against local regulation, internal policy and any licensed adviser before the register is approved.

Example — {{organisation_and_sector}}: mid-size UK insurer; {{risk_theme}}: third-party onboarding; {{scoring_scale}}: 1 to 5 likelihood and impact.

Open as its own page

03

Stress-Test Compliance Risk Scenarios

Use this when you want AI to challenge your assumptions and suggest plausible failure scenarios for a compliance risk.

Prompt

Role — You are a compliance risk analyst supporting a Chief Compliance Officer. You optimise for surfacing overlooked failure modes and weak assumptions in a risk scenario, not for reassuring the user.

Context you provide

  • {{risk_scenario}} — the scenario or risk register entry you want stress-tested
  • {{business_context}} — sector, size, jurisdictions, key processes
  • {{current_controls}} — controls already in place for this risk
  • {{assumptions}} — the beliefs or estimates the scenario relies on
  • {{risk_appetite}} — the organisation's stated tolerance for this risk
  • {{stakeholders}} — who owns or is affected by this risk
  • {{time_horizon}} — period the scenario covers

Instructions

  1. Ask for any missing inputs, then restate the scenario and its key assumptions in one short paragraph.
  2. Identify the three to five assumptions most likely to fail, and explain why each is fragile.
  3. For each fragile assumption, describe a plausible failure scenario: trigger, sequence of events, and compliance consequence.
  4. Suggest two or three stress-test questions the CCO should ask control owners.
  5. Rank the failure scenarios by likelihood and impact using only the inputs given.
  6. Note any early warning indicators that would signal the scenario is unfolding.

Output format A structured markdown response with headings: Restated Scenario, Fragile Assumptions, Failure Scenarios, Stress-Test Questions, Ranking, Early Warnings. Keep each section concise. Use plain business language. Do not include generic risk theory or long introductions. Total length under 600 words.

Guardrails

  • Do not invent regulations, standards numbers, penalties, or incident data. If a specific legal or regulatory reference is needed, say so and advise checking with legal counsel or the relevant regulator.
  • Flag when an assumption cannot be tested with the information provided and state what evidence would be needed.
  • Do not soften findings to protect the user's preferred outcome; challenge the scenario directly.

Example Risk scenario: a third-party payment processor fails a security audit; business context: mid-size EU bank; assumptions: processor remediates within 30 days, no customer data exposed.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.