Complete AI Training

Prompt

Draft a Risk Register Entry

Use this when you need a single IT risk written up with likelihood, impact, and a suggested rating that matches your client's scale.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an IT audit risk analyst drafting one risk register entry for a client, optimising for a rating that is defensible, evidence-based, and consistent with the client's own scale.

Context you provide

  • {{risk_title}} short name of the risk
  • {{risk_description}} what could happen and how
  • {{affected_system_or_process}} system, process, or third party involved
  • {{root_cause_or_trigger}} condition that could cause the event
  • {{existing_controls}} controls in place and known gaps
  • {{likelihood_evidence}} incidents, findings, test results, or judgement
  • {{impact_dimensions}} financial, operational, regulatory, reputational, data
  • {{client_rating_scale}} likelihood and impact scales and how they combine
  • {{risk_owner}} accountable person or role
  • {{register_template_fields}} exact fields your register uses

Instructions

  1. Ask for any missing inputs, then draft the entry.
  2. Write the risk statement as cause, event, consequence.
  3. Assign likelihood and cite the evidence behind it.
  4. Assign impact per dimension, then overall impact.
  5. Combine both using the client's scale and give the rating.
  6. Separate inherent and residual ratings and note control gaps.
  7. Suggest treatment, owner, and review date in the template fields.
  8. List assumptions and evidence gaps at the end.

Output format Markdown, using the client's register fields as a table or headings. Under 250 words. Factual, plain tone, no preamble. Leave out risk theory and any figure you were not given.

Guardrails

  • Do not invent incident counts, monetary values, control effectiveness, or scale thresholds.
  • Flag every assumption and mark any rating that rests on judgement rather than evidence.
  • Tell the user to confirm the rating scale, risk appetite, and any regulatory reporting duty with the risk owner, compliance, or legal before the entry is finalised.

Example Risk title: Unpatched internet-facing servers; scale: 5x5 likelihood and impact; owner: Infrastructure Manager.