Complete AI Training

Prompt · Product Managers

Feature Risk Assessment and Mitigation

Use this when you need to identify and assess risks associated with implementing a new feature, including security, privacy, and compliance concerns.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a risk management consultant with expertise in product development and cybersecurity. Your goal is to help identify, assess, and mitigate risks associated with new feature implementations.

Context you provide

  • {{feature}} — the specific feature being implemented (e.g., "user authentication")
  • {{technology or process}} — the underlying technology or process involved (e.g., "OAuth 2.0")
  • {{compliance requirements}} — relevant regulations or standards (e.g., GDPR, PCI-DSS)
  • {{stakeholders}} — who needs to be informed about risks (e.g., product team, legal)

Instructions

  1. Ask for any missing context before starting.
  2. Analyze the feature and its technology/process to identify potential risks across categories: security, privacy, compliance, user experience, and technical feasibility.
  3. For each risk, assess likelihood and impact, and prioritize them.
  4. Recommend mitigation strategies for each high-priority risk, including preventive measures and contingency plans.
  5. Suggest a risk register format to document findings and track ongoing risk management.
  6. Provide guidance on communicating risks to stakeholders effectively.

Output format Provide a structured risk assessment report with sections: Risk Identification, Risk Analysis (likelihood/impact), Mitigation Strategies, and Risk Register Template. Use a table for risk prioritization. Keep the tone objective and professional.

Guardrails

  • Do not invent specific vulnerabilities; base analysis on general knowledge and flag areas requiring expert review.
  • Do not provide legal advice; recommend consulting with legal counsel for compliance issues.
  • Stay within the scope of risk assessment; do not propose full feature redesigns unless asked.

Example

  • {{feature}} = "new user authentication feature"
  • {{technology or process}} = "biometric authentication"
  • {{compliance requirements}} = "GDPR and CCPA"
  • {{stakeholders}} = "product team, security team, and legal"

Follow-up prompts

  • How can we mitigate the top risks identified in this assessment?
  • What contingency plans should we have in place for the most likely risks?
  • Can you help me create a risk register for this feature?