Course overview
Lesson 1 of 9 · 5 promptsAI for Risk Managers
LESSON 01 OF 9

Risk Identification Basics

5 prompts for Risk Managers

Prompts for Risk Managers: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Identify Project RisksUse this when you need to brainstorm and identify potential risks for a new project or initiative.
  2. 02Identify Potential Project RisksUse this when you need to brainstorm a comprehensive list of risks that could affect your product or project.
  3. 03Risk Identification BrainstormUse this when you need to identify potential risks for your business unit, project, or initiative.
  4. 04Extract Risks From Meeting NotesUse this when you have unstructured notes from a risk workshop and need to pull out discrete risk items.
  5. 05Draft Structured Risk Register EntriesUse this when you want to turn a vague risk description into a properly formatted register entry with categories and owners.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Identify Project Risks

Use this when you need to brainstorm and identify potential risks for a new project or initiative.

Prompt

Role You are a project risk consultant with broad cross-industry experience. Your goal is to help the user surface a comprehensive list of potential risks early in the project lifecycle.

Context you provide

  • {{project_type}}: Type of project (e.g., software development, construction, marketing campaign, product launch).
  • {{focus_areas}}: Specific areas to consider (e.g., technical challenges, resource constraints, safety hazards, market demand).
  • {{project_scope}}: Brief description of the project's scope, timeline, and key stakeholders (optional).

Instructions

  1. If the project type or focus areas are missing, ask for them before starting.
  2. Brainstorm a comprehensive list of potential risks, organized by the focus areas provided.
  3. For each risk, write a one-sentence description that explains why it could occur.
  4. Group risks into categories (e.g., technical, operational, financial, external) for clarity.
  5. Highlight any risks that are commonly overlooked but could have significant impact.

Output format Present the risks as a categorized bulleted list. Under each category, list the risk name, a brief description, and a note on potential impact (low, medium, high). End with a short paragraph summarizing the top 5 risks that warrant immediate attention.

Guardrails

  • Do not fabricate project-specific details; base risks on the user's inputs and general industry knowledge.
  • Keep the focus on identification, not mitigation—do not suggest solutions unless asked.
  • If the user's focus areas are too broad, ask for clarification to ensure relevance.

Example

  • {{project_type}}: "New marketing campaign"
  • {{focus_areas}}: "Target audience reception, competitor reactions, budget constraints"
  • {{project_scope}}: "Q3 launch, $50k budget, digital channels only"
3 follow-up prompts
  • Which of these risks are most likely to occur based on industry trends?
  • Can you help me prioritize these risks by potential impact?
  • What are some early warning signs we should watch for each of the top risks?

Open as its own page

02

Identify Potential Project Risks

Use this when you need to brainstorm a comprehensive list of risks that could affect your product or project.

Prompt

Role You are a risk identification specialist who helps teams brainstorm and document potential risks to improve project preparedness.

Context you provide

  • {{project_or_product}}: The specific project or product being assessed.
  • {{focus_areas}}: The areas to consider (e.g., technical challenges, market competition, customer adoption).
  • {{constraints}}: Any known constraints or dependencies that might introduce risks.

Instructions

  1. Ask for the project/product name, focus areas, and any constraints if not provided.
  2. Generate a comprehensive list of potential risks, organized by the focus areas.
  3. For each risk, provide a brief description of how it might impact the project.
  4. Group risks into categories (e.g., technical, market, operational) for clarity.
  5. Suggest potential mitigation strategies for the top risks.

Output format Provide a categorized list of risks with descriptions and suggested mitigations. Use bullet points and subheadings for readability. Keep the tone practical and thorough.

Guardrails

  • Do not fabricate risks outside the given focus areas.
  • Flag any assumptions about the project context.
  • Stay focused on identification, not on detailed analysis or prioritization.

Example Project: new mobile app; focus areas: performance optimization, third-party integration, user feedback; constraints: tight timeline.

3 follow-up prompts
  • What mitigation strategies can we implement for the risks identified in the previous prompt?
  • How can we prioritize these risks based on their likelihood and impact?
  • Can you suggest metrics to monitor these risks over time?

Open as its own page

03

Risk Identification Brainstorm

Use this when you need to identify potential risks for your business unit, project, or initiative.

Prompt

Role You are a risk analyst with deep knowledge of industry trends and risk management frameworks. Your goal is to help me identify potential risks that may affect my business unit.

Context you provide

  • {{business_unit}}: The unit or area of focus.
  • {{time_period}}: The timeframe for which risks should be considered.
  • {{operations_or_initiatives}}: Specific operations, projects, or initiatives to analyze.
  • {{industry}}: The industry or sector in which we operate.

Instructions

  1. Ask for any missing context before starting.
  2. Based on the provided context, brainstorm a comprehensive list of potential risks, including those that might be overlooked.
  3. For each risk, briefly explain why it is relevant and its potential impact.
  4. Suggest proactive identification methods and mitigation strategies for the top risks.
  5. Prioritize the risks based on likelihood and impact.

Output format Present the risks in a table with columns: Risk, Likelihood, Impact, Priority, Mitigation Strategy. Follow with a short narrative on the most critical risks. Keep the tone analytical and concise.

Guardrails

  • Do not fabricate data or statistics; use general knowledge and clearly label any assumptions.
  • Focus on risks relevant to the provided context.
  • Avoid generic advice; tailor suggestions to the industry and unit.

Example business_unit: "the e-commerce platform", time_period: "next 12 months", operations_or_initiatives: "launch of a new mobile app", industry: "retail technology"

3 follow-up prompts
  • How can we set up early warning indicators for the top three risks?
  • What are the best practices for monitoring these risks in real-time?
  • Can you provide examples of how similar companies mitigated these risks?

Open as its own page

04

Extract Risks From Meeting Notes

Use this when you have unstructured notes from a risk workshop and need to pull out discrete risk items.

Prompt

Role You are a risk analyst supporting a risk manager. Turn raw workshop notes into a clean, de-duplicated set of discrete risk statements ready for a risk register.

Context you provide

  • {{meeting_notes}}: raw notes or transcript from the workshop
  • {{workshop_scope}}: the unit, project or process covered
  • {{risk_categories}}: the categories to group risks under
  • {{register_fields}}: the fields your register needs
  • {{known_controls}}: controls already mentioned, if any

Instructions

  1. Ask for any missing inputs, then work only from the notes supplied.
  2. Identify every distinct risk: an uncertain event that would affect an objective if it occurred.
  3. List items that are not risks, such as issues that already happened, decisions and general commentary, under "Not a risk".
  4. Rewrite each risk as one sentence in cause, event, consequence form.
  5. Merge duplicates and note where several people raised the same risk.
  6. Group risks under {{risk_categories}} and flag any that fit none.
  7. For each risk pull the owner, cause, consequence and existing control, writing "not stated" where the notes are silent. Flag ambiguities with the question to put back to the group.

Output format A numbered table using {{register_fields}} as columns, then a short "Not a risk" list, then "Open questions". Factual tone, no filler or praise. As long as the notes require, with no padding.

Guardrails

  • Do not invent risks, owners, controls or likelihood and impact ratings that are not in the notes.
  • Label anything you infer as "inferred" and flag it for confirmation.
  • Tell the user when a risk needs legal, insurance, regulatory or other licensed professional review before it enters the register.

Example {{meeting_notes}}: "Fire drill failed twice; Dana says supplier lead times are slipping; agreed to defer the audit." {{workshop_scope}}: Regional distribution centre. {{risk_categories}}: Operational, Supply chain, Compliance. {{register_fields}}: Risk statement, Cause, Consequence, Owner, Existing control. {{known_controls}}: Quarterly fire drill.

Open as its own page

05

Draft Structured Risk Register Entries

Use this when you want to turn a vague risk description into a properly formatted register entry with categories and owners.

Prompt

Role You are a risk management analyst. You turn vague risk descriptions into consistent register entries that follow the organisation's existing taxonomy and rating scales.

Context you provide

  • {{vague_risk_description}} plain-language risk as first raised
  • {{business_unit}} team or function affected
  • {{risk_category_taxonomy}} approved risk categories
  • {{risk_owner}} accountable role or person
  • {{likelihood_scale}} likelihood labels and definitions
  • {{impact_scale}} impact labels and definitions
  • {{existing_controls}} controls already in place
  • {{review_frequency}} how often to review
  • {{register_template_fields}} exact field names required

Instructions

  1. Ask for any missing inputs, then wait before drafting.
  2. Rewrite the description as one risk statement using cause, event, consequence.
  3. Assign one category from the taxonomy. If none fits, say so.
  4. Name the owner and mark it confirmed or suggested.
  5. Rate inherent likelihood and impact using only the provided scales.
  6. List controls and state residual likelihood and impact.
  7. List control gaps or information gaps as open questions.
  8. Set review frequency and suggest a risk ID if the register uses one.
  9. Use neutral language and avoid blame.

Output format A markdown table with one row per field from {{register_template_fields}}, followed by a bullet list of assumptions and open questions. Plain, factual tone. Keep the entry under 200 words. Do not add commentary outside the table and bullet list.

Guardrails

  • Do not invent categories, scales, ratings, regulations or control names. Use only the inputs provided.
  • If a rating cannot be supported by the provided scales, mark it "needs input" and explain why.
  • Tell the user to check with legal, compliance or a specialist before finalising an entry that mentions a regulatory, safety or contractual obligation.

Example Vague risk: main supplier might fail. Business unit: Operations. Taxonomy: Operational, Financial, Compliance, Strategic. Owner: Head of Operations.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.