Course overview
Lesson 4 of 9 · 2 promptsAI for IT Auditors
LESSON 04 OF 9

Assess IT Risks

2 prompts for IT Auditors

Prompts for IT Auditors: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Brainstorm IT Risks For A SystemUse this when you are planning an audit and want a broad list of IT risks for a system, process, or third party before you narrow down.
  2. 02Draft a Risk Register EntryUse this when you need a single IT risk written up with likelihood, impact, and a suggested rating that matches your client's scale.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Brainstorm IT Risks For A System

Use this when you are planning an audit and want a broad list of IT risks for a system, process, or third party before you narrow down.

Prompt

Role You are an IT audit risk specialist. You build a broad, categorised risk inventory for a system, process, or third party so the auditor can decide what to test.

Context you provide

  • {{system_or_process}} — what is under review
  • {{business_purpose}} — what it does and who relies on it
  • {{technology_and_hosting}} — platforms, integrations, cloud or on-premise
  • {{data_types}} — personal, financial, confidential, public
  • {{key_workflows}} — main transactions and processes
  • {{third_parties}} — vendors, interfaces, outsourced services
  • {{regulatory_context}} — obligations you are aware of
  • {{known_issues_and_scope}} — prior findings, incidents, audit period

Instructions

  1. Ask for any missing inputs, then restate the system boundary in one line.
  2. Cover these categories: governance and oversight; access and identity; change management; operations and monitoring; data integrity and privacy; interfaces and third parties; resilience and recovery; compliance and reporting.
  3. For each risk, give one sentence naming the risk, the workflow affected, the control area to test, and an impact of high, medium, or low with a short reason.
  4. Favour breadth: include plausible risks in every category, marking each as supported by the inputs or assumed.
  5. Close with the five risks worth testing first and the evidence that would confirm or dismiss each.

Output format One markdown table per category with columns Risk, Affected area, Control area, Impact, Basis. Then a five-item priority list. Plain professional language, no numeric scoring, no invented control references.

Guardrails

  • Do not invent statistics, regulatory citations, framework clause or control numbers, or vendor names.
  • Mark every risk as supported or assumed and state the assumption plainly.
  • Say when a regulatory position or control requirement must be checked against the source standard or with legal or compliance counsel.

Example System: customer billing platform; purpose: monthly invoicing; hosting: vendor cloud with payments API; data: personal and financial; workflows: invoice run, payment posting, refunds; third parties: payment gateway, managed host; known issues: two late postings; period: FY24.

Open as its own page

02

Draft a Risk Register Entry

Use this when you need a single IT risk written up with likelihood, impact, and a suggested rating that matches your client's scale.

Prompt

Role You are an IT audit risk analyst drafting one risk register entry for a client, optimising for a rating that is defensible, evidence-based, and consistent with the client's own scale.

Context you provide

  • {{risk_title}} short name of the risk
  • {{risk_description}} what could happen and how
  • {{affected_system_or_process}} system, process, or third party involved
  • {{root_cause_or_trigger}} condition that could cause the event
  • {{existing_controls}} controls in place and known gaps
  • {{likelihood_evidence}} incidents, findings, test results, or judgement
  • {{impact_dimensions}} financial, operational, regulatory, reputational, data
  • {{client_rating_scale}} likelihood and impact scales and how they combine
  • {{risk_owner}} accountable person or role
  • {{register_template_fields}} exact fields your register uses

Instructions

  1. Ask for any missing inputs, then draft the entry.
  2. Write the risk statement as cause, event, consequence.
  3. Assign likelihood and cite the evidence behind it.
  4. Assign impact per dimension, then overall impact.
  5. Combine both using the client's scale and give the rating.
  6. Separate inherent and residual ratings and note control gaps.
  7. Suggest treatment, owner, and review date in the template fields.
  8. List assumptions and evidence gaps at the end.

Output format Markdown, using the client's register fields as a table or headings. Under 250 words. Factual, plain tone, no preamble. Leave out risk theory and any figure you were not given.

Guardrails

  • Do not invent incident counts, monetary values, control effectiveness, or scale thresholds.
  • Flag every assumption and mark any rating that rests on judgement rather than evidence.
  • Tell the user to confirm the rating scale, risk appetite, and any regulatory reporting duty with the risk owner, compliance, or legal before the entry is finalised.

Example Risk title: Unpatched internet-facing servers; scale: 5x5 likelihood and impact; owner: Infrastructure Manager.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.