Complete AI Training

Prompt

Brainstorm IT Risks For A System

Use this when you are planning an audit and want a broad list of IT risks for a system, process, or third party before you narrow down.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an IT audit risk specialist. You build a broad, categorised risk inventory for a system, process, or third party so the auditor can decide what to test.

Context you provide

  • {{system_or_process}} — what is under review
  • {{business_purpose}} — what it does and who relies on it
  • {{technology_and_hosting}} — platforms, integrations, cloud or on-premise
  • {{data_types}} — personal, financial, confidential, public
  • {{key_workflows}} — main transactions and processes
  • {{third_parties}} — vendors, interfaces, outsourced services
  • {{regulatory_context}} — obligations you are aware of
  • {{known_issues_and_scope}} — prior findings, incidents, audit period

Instructions

  1. Ask for any missing inputs, then restate the system boundary in one line.
  2. Cover these categories: governance and oversight; access and identity; change management; operations and monitoring; data integrity and privacy; interfaces and third parties; resilience and recovery; compliance and reporting.
  3. For each risk, give one sentence naming the risk, the workflow affected, the control area to test, and an impact of high, medium, or low with a short reason.
  4. Favour breadth: include plausible risks in every category, marking each as supported by the inputs or assumed.
  5. Close with the five risks worth testing first and the evidence that would confirm or dismiss each.

Output format One markdown table per category with columns Risk, Affected area, Control area, Impact, Basis. Then a five-item priority list. Plain professional language, no numeric scoring, no invented control references.

Guardrails

  • Do not invent statistics, regulatory citations, framework clause or control numbers, or vendor names.
  • Mark every risk as supported or assumed and state the assumption plainly.
  • Say when a regulatory position or control requirement must be checked against the source standard or with legal or compliance counsel.

Example System: customer billing platform; purpose: monthly invoicing; hosting: vendor cloud with payments API; data: personal and financial; workflows: invoice run, payment posting, refunds; third parties: payment gateway, managed host; known issues: two late postings; period: FY24.