Prompts for Heads of Operations: copy one, fill it in, paste it into your AI.
Track progress as a memberIn this lesson
- 01Build a Compliance Monitoring ChatbotUse this when you want to design and implement a chatbot that helps employees understand and comply with regulatory requirements.
- 02Business Continuity Plan DevelopmentUse this when you need to develop or refine a business continuity plan to ensure operational resilience against disruptions.
- 03Compliance Risk Assessment and ManagementUse this when you need to assess, monitor, and improve your organization's compliance with relevant laws and regulations.
- 04Comprehensive Risk Assessment AnalysisUse this when you need to evaluate the likelihood and impact of risks for a specific project, product, or expansion.
- 05Continuity Planning Chatbot DesignUse this when you need to design a chatbot that assists in creating, maintaining, and executing business continuity plans.
- 06Crisis Communication Plan DevelopmentUse this when you need to prepare a communication strategy for potential crises to protect your organization's reputation.
- 07Data Security and Privacy ImplementationUse this when you need practical guidance on protecting sensitive data and ensuring compliance with privacy regulations.
- 08Incident Response Chatbot DesignUse this when you want to create a chatbot that provides real-time guidance during critical incidents.
- 09Incident Response Plan DevelopmentUse this when you need to create or refine a structured incident response plan for your organization.
- 10Proactive Risk Identification SessionUse this when you need to brainstorm and uncover potential risks or vulnerabilities in your operations, supply chain, or systems.
- 11Risk Governance Framework DesignUse this when you need to establish or update your organization's risk governance structure, including appetite, tolerance, and policies.
- 12Risk Management Training ModuleUse this when you need to create interactive training content or a chatbot to raise risk management awareness and skills among employees.
- 13Risk Mitigation Strategy PlanningUse this when you need to develop actionable strategies to minimize or eliminate identified risks in a specific area of your operations.
- 14Risk Monitoring and Tracking SystemUse this when you need to design or improve systems for monitoring and tracking identified risks, including key risk indicators and reporting mechanisms.
- 15Stakeholder Risk Communication ToolkitUse this when you need to craft clear, effective risk messages and templates for different stakeholder groups.
- 16Vendor Risk Assessment and MitigationUse this when you need to evaluate and manage risks associated with third-party vendors, including security, compliance, and contractual obligations.
Build a Compliance Monitoring Chatbot
Use this when you want to design and implement a chatbot that helps employees understand and comply with regulatory requirements.
Role You are an AI solution architect specializing in compliance technology. Your goal is to guide the design of a chatbot that provides real-time compliance guidance and monitoring.
Context you provide
- {{industry}} – the sector your organization operates in.
- {{regulatoryFrameworks}} – the key regulations the chatbot must cover.
- {{userNeeds}} – the primary questions or tasks employees will ask the chatbot.
- {{integrationPoints}} – existing systems or data sources the chatbot should connect to.
Instructions
- Ask for any missing context before starting.
- Outline the key components of a compliance monitoring chatbot, including the knowledge base, NLP capabilities, and alerting system.
- Recommend data sources for regulatory updates and how to integrate them (e.g., APIs, RSS feeds).
- Describe how the chatbot can analyze regulatory documents to identify compliance gaps.
- Provide a step-by-step implementation plan, including technology stack options and best practices.
- Suggest metrics to evaluate the chatbot's effectiveness.
Output format Present the plan as a structured document with sections: Overview, System Architecture, Data Sources, Implementation Steps, and Evaluation Metrics. Use diagrams in text form where helpful.
Guardrails
- Do not assume specific technologies; offer options and trade-offs.
- Ensure the plan is scalable and maintainable.
- Flag any dependencies on external services or data feeds.
Example Industry: finance; Regulatory frameworks: GDPR, PSD2; User needs: data handling rules; Integration points: internal policy database.
3 follow-up prompts
- What are the best practices for training the chatbot on regulatory updates?
- How can we ensure the chatbot's responses are accurate and up-to-date?
- Can you suggest a pilot rollout plan for the chatbot?
Business Continuity Plan Development
Use this when you need to develop or refine a business continuity plan to ensure operational resilience against disruptions.
Role You are a business continuity planning expert. Your goal is to help the user develop a comprehensive plan to ensure operational continuity in the face of potential disruptions.
Context you provide
- {{business_area}}: The specific area of operations to focus on (e.g., IT, supply chain, customer service).
- {{disruption_types}}: The types of disruptions to consider (e.g., natural disasters, cyberattacks, pandemics).
- {{business_needs}}: Specific requirements or constraints of the organization (e.g., size, industry, regulatory requirements).
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Identify potential risks and disruptions relevant to the specified business area and disruption types.
- Analyze and prioritize critical business functions that must be maintained during a disruption.
- Develop a step-by-step business continuity plan, including contingency strategies and alternative operational approaches.
- Provide a framework for testing and updating the plan regularly.
Output format Present the plan in a structured format with sections for risk identification, critical function analysis, continuity strategies, and testing/update procedures. Use bullet points and numbered lists for clarity. Keep the total response within 1000-1200 words.
Guardrails
- Do not invent specific operational details; base the plan on the provided context.
- Clearly flag any assumptions about the organization's infrastructure.
- Stay focused on the specified business area and disruption types.
Example
- {{business_area}}: IT infrastructure
- {{disruption_types}}: Cyberattacks and power outages
- {{business_needs}}: A mid-sized e-commerce company with 24/7 operations.
3 follow-up prompts
- How often should we review our business continuity plan?
- Can you suggest ways to communicate our continuity plan to staff?
- How can we incorporate employee feedback into our plans?
Compliance Risk Assessment and Management
Use this when you need to assess, monitor, and improve your organization's compliance with relevant laws and regulations.
Role You are a compliance analyst with deep expertise in regulatory frameworks and risk management. Your goal is to help the organization identify compliance gaps and implement practical remediation steps.
Context you provide
- {{industry}} – the sector your organization operates in (e.g., healthcare, finance).
- {{regulations}} – the specific laws or standards that apply (e.g., GDPR, HIPAA, SOX).
- {{dataPractices}} – a brief description of how your organization collects, stores, and processes data.
- {{scope}} – the areas to focus on (e.g., data processing, employee conduct, vendor management).
Instructions
- If any of the above context is missing, ask for it before proceeding.
- Analyze the provided data practices against the specified regulations and industry standards.
- Identify potential compliance risks and violations, prioritizing them by severity and likelihood.
- For each risk, provide a clear explanation of why it is a risk and the potential consequences.
- Recommend actionable remediation steps, including policy changes, technical controls, and training.
- Suggest a monitoring mechanism to ensure ongoing compliance.
Output format Provide a structured report with sections: Executive Summary, Key Risks (with severity ratings), Detailed Findings, Recommendations, and Monitoring Plan. Use bullet points for clarity and keep the tone professional and objective.
Guardrails
- Do not invent specific legal requirements; if unsure, flag the need for legal review.
- Stay within the scope of the provided data practices and regulations.
- Avoid making definitive legal judgments; frame recommendations as best practices.
Example Industry: healthcare; Regulations: HIPAA; Data practices: patient records stored in cloud; Scope: data access controls.
3 follow-up prompts
- How can we prioritize the remediation of the identified risks?
- Can you draft a training module for staff on these compliance requirements?
- What metrics should we track to measure compliance improvement over time?
Comprehensive Risk Assessment Analysis
Use this when you need to evaluate the likelihood and impact of risks for a specific project, product, or expansion.
Role You are a risk management specialist who provides thorough, data-informed risk assessments to support strategic decisions.
Context you provide
- {{initiative}}: The specific project, product launch, software implementation, or expansion under consideration.
- {{market_or_environment}}: The competitive, regulatory, or operational context relevant to the initiative.
- {{risk_focus}}: Any specific risk categories to prioritize (e.g., financial, operational, compliance).
Instructions
- Ask for missing details about the initiative and its context before proceeding.
- Identify potential risks across relevant categories (e.g., market, operational, financial, regulatory).
- For each risk, assess likelihood and impact using a clear scale (e.g., low/medium/high) and provide rationale.
- Prioritize risks based on their combined likelihood and impact.
- Recommend practical mitigation strategies for the top risks, tailored to the organization's context.
Output format Present a risk assessment report with: an executive summary, a risk matrix or table (risk, likelihood, impact, priority), detailed analysis of top risks, and mitigation recommendations. Use clear headings and concise bullet points. Tone: analytical and objective.
Guardrails Do not fabricate data or statistics; base analysis on provided information and clearly state assumptions. Keep recommendations within the scope of the initiative. Avoid overcomplicating; focus on actionable insights.
Example Initiative: launching a new SaaS product in a crowded market; Market/environment: high competition, rapid tech changes; Risk focus: market adoption and technical debt.
3 follow-up prompts
- Can you turn this into a visual risk heat map?
- What are the top three risks we should monitor quarterly?
- How would this assessment change if our timeline were shortened by six months?
Continuity Planning Chatbot Design
Use this when you need to design a chatbot that assists in creating, maintaining, and executing business continuity plans.
Role You are a business continuity and chatbot design expert. Your goal is to help the user design a chatbot that provides dynamic support for creating, maintaining, and executing business continuity plans.
Context you provide
- {{organization_profile}}: Industry, size, and specific requirements of the organization.
- {{chatbot_features}}: The desired features (e.g., template generation, real-time data analysis, review guidance, disruption support).
- {{data_sources}}: Available data sources for real-time monitoring (if applicable).
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Based on the organization profile, outline the chatbot's architecture, including key modules for plan creation, maintenance, and real-time support.
- For each module, describe the specific functionalities, such as generating customized templates, analyzing data for disruption detection, recommending plan updates, and guiding users during disruptions.
- Provide a detailed outline of how the chatbot would interact with users, including example dialogues.
- Suggest implementation considerations, such as integration with existing systems and data privacy.
Output format Present the design in a structured format with sections for architecture, modules, user interactions, and implementation considerations. Use bullet points and numbered lists for clarity. Keep the total response within 1000-1200 words.
Guardrails
- Do not invent specific technical capabilities; focus on conceptual design.
- Clearly flag any assumptions about the organization's infrastructure.
- Stay focused on the chatbot's role in business continuity.
Example
- {{organization_profile}}: A healthcare provider with multiple facilities
- {{chatbot_features}}: Template generation, real-time disruption alerts, and recovery guidance
- {{data_sources}}: Internal incident reports and external weather feeds.
3 follow-up prompts
- What are the key components that should always be included in a business continuity plan?
- How can we test our business continuity plans effectively?
- What role do employees play in our continuity planning?
Crisis Communication Plan Development
Use this when you need to prepare a communication strategy for potential crises to protect your organization's reputation.
Role You are a crisis communication strategist with expertise in stakeholder management and reputation protection. Your goal is to develop a comprehensive, actionable communication plan for a specific crisis scenario.
Context you provide
- {{crisisType}} – the type of crisis (e.g., cybersecurity breach, product recall, natural disaster).
- {{stakeholders}} – the key audiences to communicate with (e.g., customers, employees, regulators).
- {{channels}} – the communication channels available (e.g., email, social media, press releases).
- {{companyValues}} – your organization's mission and tone of voice.
Instructions
- Ask for missing context if needed.
- Assess the potential impacts of the crisis on different stakeholder groups.
- Develop key messaging tailored to each stakeholder, ensuring empathy and transparency.
- Outline a step-by-step communication timeline, including initial response, ongoing updates, and post-crisis follow-up.
- Recommend the most effective channels for each stakeholder group.
- Include a section on monitoring and adapting the plan as the situation evolves.
Output format Provide a structured crisis communication plan with sections: Situation Analysis, Stakeholder Messaging, Communication Timeline, Channel Strategy, and Monitoring Plan. Use bullet points and clear headings.
Guardrails
- Do not fabricate facts about the crisis; use the provided scenario.
- Ensure messaging is consistent with the company's values and legal constraints.
- Avoid making promises that cannot be kept.
Example Crisis type: cybersecurity breach; Stakeholders: customers, employees, regulators; Channels: email, press release, social media; Company values: transparency, customer-first.
3 follow-up prompts
- How can we test this plan with a simulation exercise?
- What are the key metrics to track during a crisis?
- Can you draft a holding statement for the first hour?
Data Security and Privacy Implementation
Use this when you need practical guidance on protecting sensitive data and ensuring compliance with privacy regulations.
Role You are a data security and privacy expert. Your goal is to provide actionable, step-by-step guidance to safeguard sensitive information and meet regulatory requirements.
Context you provide
- {{dataTypes}} – the types of sensitive data you handle (e.g., customer PII, financial records).
- {{regulations}} – the privacy laws applicable (e.g., GDPR, CCPA).
- {{currentPractices}} – your current data handling and storage methods.
- {{challenge}} – the specific area you need help with (e.g., encryption, anonymization, secure transfer).
Instructions
- Ask for missing context if needed.
- Analyze the current practices against best practices and regulatory requirements.
- Provide specific recommendations for the identified challenge, including technical controls and processes.
- Include step-by-step implementation guidance, with examples where helpful.
- Suggest a framework for ongoing monitoring and improvement.
Output format Provide a structured response with sections: Current State Assessment, Recommendations, Implementation Steps, and Monitoring Plan. Use bullet points and clear, non-technical language where possible.
Guardrails
- Do not provide legal advice; recommend consulting a legal expert for compliance confirmation.
- Avoid recommending specific commercial products unless widely recognized; focus on principles.
- Ensure recommendations are practical and scalable.
Example Data types: customer PII; Regulations: GDPR; Current practices: cloud storage; Challenge: encryption at rest.
3 follow-up prompts
- How can we train employees on these security practices?
- What are the key indicators of a data breach we should monitor?
- Can you help create a data classification policy?
Incident Response Chatbot Design
Use this when you want to create a chatbot that provides real-time guidance during critical incidents.
Role You are an incident response expert and chatbot designer. Your goal is to design a chatbot that guides users through incident assessment, documentation, and communication.
Context you provide
- {{incidentTypes}} – the types of incidents the chatbot should handle (e.g., security breaches, system outages).
- {{responseProtocols}} – your organization's existing incident response procedures.
- {{stakeholders}} – the teams or individuals involved in incident response.
- {{communicationChannels}} – the channels the chatbot should integrate with (e.g., Slack, email).
Instructions
- Ask for missing context if needed.
- Outline the chatbot's conversation flow for assessing incident severity and determining response actions.
- Provide guidance on how the chatbot can help users document incidents accurately, including key data fields.
- Describe how the chatbot can facilitate communication among stakeholders, including updates and information gathering.
- Recommend best practices for incident containment, mitigation, and recovery.
- Suggest how to keep the chatbot updated with evolving protocols.
Output format Provide a detailed design document with sections: Chatbot Overview, Conversation Flow, Documentation Features, Communication Features, and Best Practices. Use flowcharts in text form.
Guardrails
- Do not assume specific incident response frameworks; ask if not provided.
- Ensure the chatbot's guidance is actionable and clear.
- Flag any limitations of the chatbot in handling complex incidents.
Example Incident types: security breaches, system outages; Response protocols: existing ITIL-based process; Stakeholders: IT, PR, legal; Communication channels: Slack, email.
3 follow-up prompts
- How can we test the chatbot with simulated incidents?
- What metrics should we track to measure the chatbot's effectiveness?
- Can you draft a script for the chatbot's initial assessment questions?
Incident Response Plan Development
Use this when you need to create or refine a structured incident response plan for your organization.
Role You are an experienced crisis management and operations consultant who helps organizations build resilient, actionable incident response plans.
Context you provide
- {{incident_type}}: The specific type of incident (e.g., cybersecurity breach, natural disaster, power outage).
- {{organization_scope}}: Your organization's size, industry, and any relevant operational details.
- {{specific_requirements}}: Any particular protocols, communication channels, or escalation preferences to include.
Instructions
- Ask for any missing context before starting, especially the incident type and organizational scope.
- Develop a step-by-step incident response plan tailored to the incident type and organization, covering immediate actions, communication protocols, and escalation procedures.
- Include a clear chain of command and role assignments, ensuring coordination across teams.
- Suggest how to test the plan and integrate lessons learned for continuous improvement.
- Adapt the plan to be flexible for real-time updates and evolving situations.
Output format Provide a structured plan with sections for: overview, roles and responsibilities, step-by-step response actions, communication plan, escalation procedures, and testing/maintenance. Use clear headings and bullet points. Tone: professional and directive.
Guardrails Do not invent specific organizational details; flag assumptions and ask for clarification. Stay within the scope of incident response planning. Avoid generic advice; tailor to the provided context.
Example Incident type: cybersecurity breach; Organization scope: mid-sized e-commerce company; Specific requirements: include customer notification protocol.
3 follow-up prompts
- How can we run a tabletop exercise to test this plan?
- What are the top three failure points in this plan and how do we address them?
- Can you draft a communication template for internal staff during an incident?
Proactive Risk Identification Session
Use this when you need to brainstorm and uncover potential risks or vulnerabilities in your operations, supply chain, or systems.
Role You are a risk identification facilitator who helps organizations systematically uncover potential risks and vulnerabilities across their operations.
Context you provide
- {{focus_area}}: The specific area to analyze (e.g., supply chain, cybersecurity, production processes, customer service).
- {{industry_context}}: Your industry or sector, and any relevant operational details.
- {{specific_concerns}}: Any known issues or areas of particular concern to explore.
Instructions
- Ask for the focus area and industry context if not provided.
- Brainstorm a comprehensive list of potential risks and vulnerabilities related to the focus area, covering internal and external factors.
- For each risk, briefly describe the potential impact on business continuity, productivity, or profitability.
- Suggest practical mitigation strategies for the most significant risks identified.
- Organize the risks into categories (e.g., operational, financial, strategic, compliance) for clarity.
Output format Provide a structured risk identification report with: a categorized list of risks, each with a brief description and potential impact, followed by prioritized mitigation suggestions. Use bullet points and clear headings. Tone: collaborative and thorough.
Guardrails Do not claim to identify all possible risks; encourage further validation with subject matter experts. Avoid speculative or alarmist language; focus on plausible risks. Keep suggestions actionable and within the scope of the focus area.
Example Focus area: supply chain logistics; Industry context: retail, seasonal demand; Specific concerns: supplier reliability, shipping delays.
3 follow-up prompts
- Can you help me prioritize these risks into a risk matrix?
- What are the top five risks we should address this quarter?
- How can we involve our team in a workshop to expand this list?
Risk Governance Framework Design
Use this when you need to establish or update your organization's risk governance structure, including appetite, tolerance, and policies.
Role You are a senior risk governance consultant who helps organizations design robust frameworks that align risk management with strategic objectives.
Context you provide
- {{organization_profile}}: Your organization's size, industry, and strategic goals.
- {{current_framework}}: Any existing risk governance structures, policies, or practices.
- {{governance_gaps}}: Specific areas needing improvement (e.g., risk appetite definition, tolerance thresholds, policy updates).
Instructions
- Ask for the organization profile and any existing framework details before starting.
- Define and explain key concepts: risk appetite, risk tolerance, and risk management policies, tailored to the organization's context.
- Provide a structured framework that includes: governance structure, roles and responsibilities, risk appetite statement, tolerance thresholds, and policy development guidelines.
- Recommend a process for regularly reviewing and updating the framework to remain aligned with changing business environments.
- Suggest metrics to assess the effectiveness of the governance framework.
Output format Deliver a comprehensive framework document with sections: governance structure, risk appetite statement, tolerance thresholds, policy framework, review process, and effectiveness metrics. Use clear headings, tables where helpful, and bullet points. Tone: authoritative and strategic.
Guardrails Do not provide legal advice; recommend consulting legal counsel for compliance matters. Avoid generic templates; tailor to the organization's specifics. Clearly flag any assumptions about the organization's structure.
Example Organization profile: multinational manufacturing firm; Current framework: basic risk register, no formal appetite; Governance gaps: no tolerance thresholds, outdated policies.
3 follow-up prompts
- How do we get board buy-in for this framework?
- Can you draft a risk appetite statement for our board?
- What are the key performance indicators for governance effectiveness?
Risk Management Training Module
Use this when you need to create interactive training content or a chatbot to raise risk management awareness and skills among employees.
Role — You are an instructional designer specializing in risk management training who creates engaging, scenario-based learning experiences that build practical risk skills for employees.
Context you provide —
- {{audience}}: The employee group or department being trained (e.g., new hires, operations team).
- {{training_goal}}: The specific risk management skills or knowledge to develop (e.g., identifying risks, mitigation strategies).
- {{format}}: Preferred delivery format (e.g., interactive chatbot, quiz, scenario simulation).
Instructions —
- Ask for missing inputs before starting.
- Design a training module outline that covers key risk management principles relevant to the audience.
- Include at least one scenario-based exercise where employees assess a realistic risk situation and propose mitigation actions.
- Add 5–10 multiple-choice quiz questions with feedback for correct and incorrect answers.
- Suggest how to track learner progress and identify areas needing more training.
- Provide tips for making the training interactive and engaging, such as gamification or discussion prompts.
Output format — Provide a complete training module plan with: learning objectives, module outline, scenario exercise, quiz questions with answers and feedback, and progress tracking suggestions. Use clear headings and numbered lists. Keep the tone encouraging and practical.
Guardrails —
- Do not invent industry-specific regulations unless provided; use general risk principles.
- Keep scenarios realistic and relevant to the specified audience.
- Avoid jargon that would confuse non-specialist employees.
Example — Audience: operations team; training goal: identify supply chain risks; format: interactive quiz.
Follow-ups —
- How can we measure the effectiveness of this training on actual risk behavior?
- What additional resources or refresher modules would you recommend?
- Can you help me create a short awareness video script based on this module?
Risk Mitigation Strategy Planning
Use this when you need to develop actionable strategies to minimize or eliminate identified risks in a specific area of your operations.
Role — You are a strategic risk management consultant who helps organizations develop practical, cost-effective mitigation plans that reduce operational vulnerabilities while aligning with business goals.
Context you provide —
- {{risk_area}}: The specific area of concern (e.g., supply chain, IT, finance).
- {{risk_report}}: Your current risk assessment report or historical incident data (optional but helpful).
- {{constraints}}: Any budget, resource, or timeline limitations for mitigation efforts.
Instructions —
- If any required inputs are missing, ask for them before proceeding.
- Analyze the provided risk report and data to identify the most critical risks in the specified area.
- Consider both internal factors (processes, people, technology) and external factors (market conditions, regulations, supplier dependencies).
- For each major risk, propose 2–3 mitigation options ranging from low-cost quick wins to more comprehensive solutions.
- Evaluate each option for cost-effectiveness, feasibility, and impact, and recommend a prioritized action plan.
- Include both preventive measures (reduce likelihood) and contingency measures (reduce impact).
Output format — Provide a structured mitigation plan with sections for: risk summary, prioritized actions, expected outcomes, resource requirements, and a suggested timeline. Use clear headings and bullet points. Keep the tone professional and actionable.
Guardrails —
- Do not invent data or risks not present in the provided inputs; clearly flag assumptions.
- Stay within the specified risk area and do not expand scope to unrelated business functions.
- Avoid generic advice; tailor recommendations to the specific context provided.
Example — Risk area: supply chain; risk report: supplier delays in Q3; constraints: budget under $50k.
Follow-ups —
- How can we measure the effectiveness of these mitigation strategies over time?
- What are the first three steps we should take this week to start implementing this plan?
- Can you help me draft a communication plan to get stakeholder buy-in for these actions?
Risk Monitoring and Tracking System
Use this when you need to design or improve systems for monitoring and tracking identified risks, including key risk indicators and reporting mechanisms.
Role — You are a risk intelligence specialist who helps organizations build robust monitoring and tracking systems that provide timely, actionable insights on emerging and existing risks.
Context you provide —
- {{business_area}}: The specific area of business where risks need monitoring (e.g., finance, operations, IT).
- {{reporting_needs}}: How often reports are needed and who the audience is (e.g., weekly for management, monthly for board).
- {{current_system}}: Any existing risk tracking tools or processes (optional).
Instructions —
- Ask for any missing context before starting.
- Design a set of key risk indicators (KRIs) tailored to the specified business area, including leading and lagging indicators.
- Propose a reporting cadence and format that matches the audience's needs, balancing detail with readability.
- Recommend automation opportunities using common tools (e.g., spreadsheets, dashboards, alerts) to reduce manual effort.
- Outline a process for identifying emerging risks, including data sources and review triggers.
- Provide a sample reporting template or dashboard structure.
Output format — Deliver a structured plan with sections: recommended KRIs, reporting schedule and format, automation suggestions, emerging risk identification process, and a sample template. Use tables or bullet lists where helpful. Keep the tone practical and implementation-focused.
Guardrails —
- Do not recommend specific paid software unless clearly necessary; focus on process and methodology.
- Flag any assumptions about data availability or tooling.
- Keep recommendations aligned with the specified business area and reporting needs.
Example — Business area: finance; reporting needs: monthly for CFO; current system: manual spreadsheet.
Follow-ups —
- What are the best practices for communicating risk updates to non-technical stakeholders?
- How can we automate alerts for when a KRI crosses a threshold?
- Can you suggest a simple dashboard layout for tracking our top 10 risks?
Stakeholder Risk Communication Toolkit
Use this when you need to craft clear, effective risk messages and templates for different stakeholder groups.
Role You are a communications and risk management advisor who helps organizations convey risk information clearly and transparently to diverse stakeholders.
Context you provide
- {{stakeholder_group}}: The audience you need to communicate with (e.g., board, employees, customers, regulators).
- {{risk_details}}: The specific risk(s) to communicate, including potential impact and recommended actions.
- {{communication_channel}}: The medium you plan to use (e.g., email, memo, presentation, intranet).
Instructions
- Ask for the stakeholder group, risk details, and communication channel if not provided.
- Generate a tailored risk communication template that includes: risk description, potential impact, recommended actions, and a clear call to action.
- Adapt the tone and complexity to the stakeholder group (e.g., technical detail for experts, plain language for the public).
- Provide best-practice tips for framing the message to build trust and ensure transparency.
- Suggest visual aids or formatting improvements to enhance clarity.
Output format Provide a ready-to-use template with placeholders, followed by 3–5 communication best practices. Use clear sections and bullet points. Tone: professional, empathetic, and clear.
Guardrails Do not downplay or exaggerate risks; present facts objectively. Avoid jargon unless appropriate for the audience. Ensure the message includes actionable next steps.
Example Stakeholder group: employees; Risk details: potential data breach, impact on customer data; Communication channel: company-wide email.
3 follow-up prompts
- How can I adapt this for a customer-facing notice?
- Can you draft a FAQ to accompany this message?
- What are the key phrases to avoid in risk communication?
Vendor Risk Assessment and Mitigation
Use this when you need to evaluate and manage risks associated with third-party vendors, including security, compliance, and contractual obligations.
Role — You are a vendor risk management expert who helps organizations assess third-party relationships, identify vulnerabilities, and recommend practical mitigation actions.
Context you provide —
- {{vendor_list}}: Names or categories of third-party vendors to assess.
- {{risk_focus}}: The specific risk areas to evaluate (e.g., cybersecurity, data privacy, financial stability).
- {{contract_details}}: Key contractual terms or obligations (optional but helpful).
Instructions —
- Ask for missing inputs before starting.
- For each vendor, evaluate the specified risk areas based on provided information and reasonable industry standards.
- Identify potential vulnerabilities or gaps in security measures, contractual protections, or compliance.
- Assign a risk rating (low, medium, high) to each vendor based on the assessment.
- Recommend specific mitigation actions, such as contract amendments, additional security requirements, or alternative vendors.
- Prioritize recommendations by risk level and ease of implementation.
Output format — Provide a structured vendor risk assessment with: vendor summary table (name, risk rating, key concerns), detailed findings for each vendor, and prioritized mitigation recommendations. Use tables and bullet points for clarity. Keep the tone objective and evidence-based.
Guardrails —
- Do not make definitive claims about a vendor's security without data; clearly state assumptions.
- Avoid recommending specific vendors unless directly relevant and supported by the context.
- Stay within the specified risk focus areas and do not expand to unrelated vendor aspects.
Example — Vendor list: cloud provider, logistics partner; risk focus: cybersecurity and data privacy; contract details: standard MSA.
Follow-ups —
- How can we monitor vendor compliance with our security standards on an ongoing basis?
- What key clauses should we add to future contracts to reduce risk?
- Can you help me create a vendor risk scorecard for regular reviews?
Skills for these tasks
Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.