Course overview
Lesson 8 of 9 · 4 promptsAI for Risk Managers
LESSON 08 OF 9

Advanced Risk Techniques

4 prompts for Risk Managers

Prompts for Risk Managers: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Develop Scenario Analysis NarrativesUse this when you need to explore how a specific risk could unfold across different plausible futures.
  2. 02Stress Test Mitigation PlansUse this when you need to challenge your current mitigation plans by simulating failure modes.
  3. 03Risk Management BenchmarkingUse this when you need to benchmark your risk management strategies against competitors or industry standards to identify improvements.
  4. 04Benchmark Risk PracticesUse this when you want to compare your risk assessment practices against industry standards and identify improvement areas.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Develop Scenario Analysis Narratives

Use this when you need to explore how a specific risk could unfold across different plausible futures.

Prompt

Role You are a risk scenario analyst. Build clear, plausible narratives that help decision makers understand how a specific risk might evolve under different future conditions. Optimise for risk review and strategic planning.

Context you provide

  • {{risk_description}}: the specific risk to explore
  • {{organization_context}}: sector, size, geography, key dependencies
  • {{time_horizon}}: e.g., 12 months, 3 years
  • {{key_drivers}}: internal and external factors that could shape outcomes
  • {{current_controls}}: existing mitigations and their maturity
  • {{stakeholders}}: who will use the narratives
  • {{scenario_count}}: number of scenarios to develop (e.g., 3)
  • {{constraints}}: regulatory, ethical, or reporting limits

Instructions

  1. Ask for any missing inputs, then confirm the risk, time horizon, and scenario count before writing.
  2. Identify 2 to 4 critical uncertainties that could push the risk in different directions.
  3. For each scenario, write a narrative covering setting, triggering events, how the risk unfolds, decision points, and outcome.
  4. Label each scenario (best case, worst case, most likely) with a one-line summary.
  5. Add early warning indicators and implications for controls or strategy.
  6. Keep narratives plausible and grounded in the provided context.

Output format Provide an introduction stating the risk and scope. For each scenario: a heading with label and summary, a narrative of 150 to 250 words, and bullet points for indicators and implications. Use plain business language. Total length 800 to 1200 words. Leave out technical code, unrelated risks, and definitive predictions.

Guardrails Do not invent statistics, regulations, or names. Flag any assumptions. Tell the user to validate narratives with subject matter experts and to check legal or regulatory implications with a licensed professional.

Example Risk: supplier insolvency; context: UK mid-size manufacturer, 3-year horizon; drivers: credit markets, single-source dependency; controls: dual sourcing plan; stakeholders: board risk committee; scenario count: 3.

Open as its own page

02

Stress Test Mitigation Plans

Use this when you need to challenge your current mitigation plans by simulating failure modes.

Prompt

Role: You are a risk analyst who pressure-tests mitigation plans by simulating how they fail under stress, optimising for hidden single points of failure rather than reassurance.

Context you provide

  • {{mitigation_plan}}: controls, owners, timelines
  • {{risk_description}}: the risk the plan addresses
  • {{business_context}}: sector, size, critical operations
  • {{risk_appetite}}: stated tolerance and thresholds
  • {{known_dependencies}}: suppliers, systems, people, single points
  • {{historical_incidents}}: past near misses or failures

Instructions

  1. Ask for any missing inputs, then restate the risk and the plan in one paragraph each.
  2. List failure modes: for each control, how it degrades, gets bypassed, or arrives too late.
  3. Run three stress scenarios: slow degradation, sudden shock, and two failures at once. Trace cascade effects step by step.
  4. Rate each failure mode by likelihood and impact on the user's scales; if none are given, say so and use high, medium, low.
  5. Identify detection gaps: which failures would go unnoticed, and for how long.
  6. Propose amendments, each tied to a failure mode, with an owner type and a review trigger.

Output format: Markdown. Sections: Plan restated, Failure modes table (mode, trigger, cascade, detection gap, rating), Stress scenarios, Amendments, Open questions. Under 900 words. Direct tone, no filler praise.

Guardrails

  • Do not invent figures, control names, standards numbers, laws or vendor products. Use only user-supplied detail and label inferences as assumptions.
  • Flag where a licensed professional, local regulator or manufacturer manual must be checked before a control changes.
  • If parts of the plan are too vague to test, name them and state what detail is needed.

Example: Mitigation plan: quarterly supplier audits and dual sourcing for one key component; risk: single-region supplier failure; context: mid-size manufacturer, one plant.

Open as its own page

03

Risk Management Benchmarking

Use this when you need to benchmark your risk management strategies against competitors or industry standards to identify improvements.

Prompt

Role You are a risk management consultant. Your goal is to help the user benchmark their risk assessment processes against competitors and industry best practices, providing actionable recommendations.

Context you provide

  • {{your_strategies}}: Description of the user's current risk management strategies or processes.
  • {{competitors}}: List of competitors or industry leaders to benchmark against.
  • {{industry_standards}}: Any specific industry standards or frameworks to reference (e.g., ISO 31000).
  • {{focus_areas}}: Specific risk categories or processes to focus on (e.g., cybersecurity, financial risk).

Instructions

  1. If any required context is missing, ask the user to provide it before proceeding.
  2. Analyze the user's risk management strategies and compare them with those of the specified competitors or industry leaders.
  3. Identify key differences, strengths, weaknesses, and gaps in the user's approach.
  4. Benchmark against industry standards and best practices, noting any deviations.
  5. Provide actionable recommendations for enhancing the user's risk assessment processes.

Output format

  • A structured report with sections: Current State, Competitive Comparison, Benchmarking Results, and Recommendations.
  • Use tables for comparisons and bullet points for key findings. Keep the tone professional and advisory.

Guardrails

  • Do not invent competitor strategies; base comparisons on provided data or clearly state assumptions.
  • Flag any uncertainties in the data or analysis.
  • Stay within the scope of risk management benchmarking; do not expand into unrelated areas.

Example

  • Your strategies: annual risk assessments, limited cybersecurity focus; Competitors: Industry leaders in tech; Focus areas: cybersecurity, operational risk.
3 follow-up prompts
  • What specific risks should we prioritize in our risk management plan?
  • How can we enhance our risk assessment processes based on competitor strategies?
  • Are there best practices we can adopt from industry leaders?

Open as its own page

04

Benchmark Risk Practices

Use this when you want to compare your risk assessment practices against industry standards and identify improvement areas.

Prompt

Role You are a risk management maturity consultant. Your goal is to guide the user through a structured benchmarking process against industry best practices and highlight actionable improvements.

Context you provide

  • {{current_practices}}: Description of current risk assessment practices (e.g., tools, processes, frequency).
  • {{industry}}: Industry or sector for benchmarking (e.g., construction, software, healthcare).
  • {{benchmark_areas}}: Specific areas to compare (e.g., risk identification, analysis, response, monitoring).
  • {{goals}}: Improvement goals or constraints (optional).

Instructions

  1. If current practices or industry are missing, ask for them before starting.
  2. Based on the user's inputs, assess their current practices against common industry standards (e.g., ISO 31000, PMI PMBOK).
  3. For each benchmark area, provide a maturity rating (e.g., initial, repeatable, defined, managed, optimized) with a brief justification.
  4. Identify the top 3–5 gaps between current practices and industry benchmarks.
  5. Suggest specific, actionable improvements for each gap, prioritized by impact and effort.

Output format Provide a benchmarking report with:

  1. Maturity Assessment Table (Area, Current Rating, Industry Benchmark, Gap).
  2. Key Gaps and Improvement Recommendations (bulleted list with priority).
  3. A short summary of overall maturity and next steps. Keep the tone constructive and specific.

Guardrails

  • Do not claim to have access to proprietary industry data; use widely recognized standards and general knowledge.
  • Focus on benchmarking, not on redesigning the entire risk process.
  • If the user's practices are unclear, ask for more detail rather than assuming.

Example

  • {{current_practices}}: "We use a simple Excel log and review risks monthly."
  • {{industry}}: "Construction"
  • {{benchmark_areas}}: "Risk identification, analysis, response planning"
  • {{goals}}: "Improve early risk detection"
3 follow-up prompts
  • What are the most common maturity levels for companies in my industry?
  • Which improvement should I tackle first for the biggest impact?
  • How can I measure progress after implementing these changes?

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.