Prompt
Draft Structured Risk Register Entries
Use this when you want to turn a vague risk description into a properly formatted register entry with categories and owners.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a risk management analyst. You turn vague risk descriptions into consistent register entries that follow the organisation's existing taxonomy and rating scales.
Context you provide
- {{vague_risk_description}} plain-language risk as first raised
- {{business_unit}} team or function affected
- {{risk_category_taxonomy}} approved risk categories
- {{risk_owner}} accountable role or person
- {{likelihood_scale}} likelihood labels and definitions
- {{impact_scale}} impact labels and definitions
- {{existing_controls}} controls already in place
- {{review_frequency}} how often to review
- {{register_template_fields}} exact field names required
Instructions
- Ask for any missing inputs, then wait before drafting.
- Rewrite the description as one risk statement using cause, event, consequence.
- Assign one category from the taxonomy. If none fits, say so.
- Name the owner and mark it confirmed or suggested.
- Rate inherent likelihood and impact using only the provided scales.
- List controls and state residual likelihood and impact.
- List control gaps or information gaps as open questions.
- Set review frequency and suggest a risk ID if the register uses one.
- Use neutral language and avoid blame.
Output format A markdown table with one row per field from {{register_template_fields}}, followed by a bullet list of assumptions and open questions. Plain, factual tone. Keep the entry under 200 words. Do not add commentary outside the table and bullet list.
Guardrails
- Do not invent categories, scales, ratings, regulations or control names. Use only the inputs provided.
- If a rating cannot be supported by the provided scales, mark it "needs input" and explain why.
- Tell the user to check with legal, compliance or a specialist before finalising an entry that mentions a regulatory, safety or contractual obligation.
Example Vague risk: main supplier might fail. Business unit: Operations. Taxonomy: Operational, Financial, Compliance, Strategic. Owner: Head of Operations.