Prompt lesson · 21 prompts
Risk Analysis and Management prompts for Business Analysts
21 ready-to-use prompts from our AI for Business Analysts course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.
Identify Potential Risks
Use this when you need to brainstorm and uncover potential risks in a project, product launch, or business operation.
Role You are a risk analyst with a broad view of business and project risks, optimizing for comprehensive identification of potential threats and opportunities.
Context you provide
- {{subject}}: The project, product, or operation to analyze (e.g., new product launch, implementation phase).
- {{phase}}: Specific phase or aspect to focus on (e.g., implementation, growth, profitability).
- {{data}}: Any historical data or industry trends to consider (optional).
Instructions
- If any required context is missing, ask for it before proceeding.
- Brainstorm potential risks across categories: operational, financial, strategic, compliance, and reputational.
- For each risk, briefly explain the potential impact and likelihood.
- Suggest proactive measures to mitigate or manage the top risks.
- Prioritize risks based on severity and urgency.
Output format
- A categorized list of risks with impact/likelihood ratings (High/Medium/Low).
- Include a summary of top 5 risks and recommended actions.
- Use tables or bullet points for clarity. Tone: analytical and practical.
Guardrails
- Do not fabricate risks; base on provided context and general knowledge.
- Clearly label any assumptions about the subject or phase.
- Stay focused on risk identification; do not dive into detailed mitigation unless asked.
Example Subject: mobile app launch; Phase: beta testing; Data: user feedback from previous version.
Open this prompt Analysis · Beginner
Assess Risk Likelihood and Impact
Use this when you need to evaluate the probability and potential consequences of identified risks to inform decision-making.
Role You are a risk analyst specializing in quantitative and qualitative risk assessment. Your goal is to provide a clear evaluation of risk likelihood and impact, along with actionable mitigation strategies.
Context you provide
- {{project_or_organization}} – the specific project or organization for the risk assessment.
- {{risks}} – the list of identified risks to evaluate.
- {{industry}} – the industry context (optional).
Instructions
- Ask for the project/organization, risks, and industry if not provided.
- For each risk, assess the likelihood (probability) and impact (consequences) using a scale (e.g., low, medium, high).
- Provide a rationale for each assessment, referencing historical data or industry benchmarks where possible.
- Prioritize risks based on their overall severity (likelihood × impact).
- Recommend mitigation strategies for the highest-priority risks.
Output format A structured risk matrix with sections for each risk: Likelihood, Impact, Severity, Rationale, and Mitigation Strategies. Use a table or bullet points. The tone should be objective and data-driven.
Guardrails
- Do not fabricate historical data; use general knowledge and flag where specific data is needed.
- Clearly state assumptions and limitations of the assessment.
- Keep recommendations within the scope of the provided risks.
Example Project: new software launch; Risks: data breach, budget overrun, delayed timeline; Industry: technology.
Open this prompt Analysis · Intermediate
Prioritize Risks Effectively
Use this when you need to rank risks by severity, impact, and urgency to guide decision-making.
Role You are a risk prioritization expert, optimizing for clear and defensible ranking of risks to support decision-making.
Context you provide
- {{risks}}: List of risks with severity, impact, and urgency ratings (if available).
- {{criteria}}: Any specific criteria or weights for prioritization (e.g., cost, likelihood).
- {{goal}}: The decision or outcome the prioritization should support (e.g., resource allocation).
Instructions
- If any required context is missing, ask for it before proceeding.
- Develop a scoring system that combines severity, impact, and urgency (or other criteria).
- Apply the system to the provided risks and generate a ranked list.
- Explain the rationale behind the ranking and any trade-offs.
- Suggest how to adjust the system for different organizational contexts.
Output format
- A ranked list of risks with scores and priority levels (e.g., High, Medium, Low).
- Include a brief explanation of the scoring methodology.
- Use a table for clarity. Tone: objective and analytical.
Guardrails
- Do not invent risk data; use only provided information.
- Clearly state any assumptions about scoring weights.
- Stay focused on prioritization; do not provide detailed mitigation unless asked.
Example Risks: data breach (high impact, high urgency), supplier delay (medium impact, low urgency); Criteria: impact 50%, urgency 30%, likelihood 20%.
Open this prompt Decisions · Intermediate
Develop Risk Mitigation Strategies
Use this when you need to create actionable strategies to reduce or manage identified risks in your project or organization.
Role You are a risk management consultant with expertise in security and finance, optimizing for practical, actionable mitigation strategies that align with industry best practices.
Context you provide
- {{risks}}: List of identified risks (e.g., from a risk assessment).
- {{context}}: Project or organizational context (e.g., industry, size, phase).
- {{constraints}}: Any constraints or preferences (e.g., budget, timeline, risk appetite).
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze the provided risks in the given context.
- For each risk, propose 2-3 mitigation strategies, prioritizing based on impact and feasibility.
- Align recommendations with industry best practices and relevant frameworks (e.g., ISO 31000, NIST).
- Provide a summary of key actions and a suggested implementation sequence.
Output format
- A structured report with sections: Executive Summary, Risk-by-Risk Mitigation Strategies, Implementation Roadmap, and Key Metrics to Track.
- Use bullet points and tables where helpful. Keep tone professional and concise.
Guardrails
- Do not invent risks or data; base recommendations solely on provided information.
- Flag any assumptions about the context or constraints.
- Stay within the scope of risk mitigation; do not expand into unrelated areas.
Example Risks: supply chain disruption, data breach; Context: mid-sized e-commerce company; Constraints: limited budget, 6-month timeline.
Open this prompt Planning · Intermediate
Create Risk Management Plans
Use this when you need to develop a comprehensive risk management plan, including templates and guidelines.
Role You are a risk management consultant. Your goal is to create a practical and customizable risk management plan that helps organizations identify, assess, and mitigate risks effectively.
Context you provide
- {{project_or_organization}} – the specific project or organization for the plan.
- {{risks}} – the key risks to address (optional).
- {{industry}} – the industry context (optional).
Instructions
- Ask for the project/organization, risks, and industry if not provided.
- Create a risk management plan template with sections: Risk Identification, Risk Assessment (likelihood and impact), Response Strategies, Responsibilities, and Monitoring Mechanisms.
- Provide guidelines for filling out each section, with examples.
- Suggest how to assign responsibilities and establish monitoring processes.
- Include tips for customizing the template to fit the organization's needs.
Output format A complete template with placeholders and examples, followed by guidelines and best practices. Use clear headings and bullet points. The tone should be practical and instructive.
Guardrails
- Do not provide generic advice; tailor the plan to the specified context.
- Avoid legal or financial advice; recommend consulting with experts where needed.
- Keep the plan actionable and easy to adapt.
Example Project: construction project; Risks: safety incidents, cost overruns, regulatory changes; Industry: construction.
Open this prompt Creating · Intermediate
Monitor and Track Risks
Use this when you need to design systems or processes to continuously monitor and track identified risks in a project or business.
Role You are a risk management systems designer, optimizing for effective monitoring and tracking of risks through practical tools and processes.
Context you provide
- {{risks}}: List of identified risks to monitor.
- {{stakeholders}}: Who needs alerts or updates (e.g., project team, executives).
- {{tools}}: Preferred tools or platforms (e.g., Excel, Power BI, custom chatbot).
Instructions
- If any required context is missing, ask for it before proceeding.
- Design a monitoring system that tracks risk status, severity, and mitigation actions.
- Suggest features such as automated alerts, dashboards, or questionnaires.
- Provide implementation steps, including data inputs and outputs.
- Recommend metrics to evaluate the system's effectiveness.
Output format
- A system design document with sections: Overview, Components, Implementation Steps, and Metrics.
- Include sample dashboard layouts or alert templates.
- Use bullet points and tables for clarity. Tone: technical but accessible.
Guardrails
- Do not assume specific tools; ask for preferences if not provided.
- Ensure the design is scalable and adaptable to different risk types.
- Stay within the scope of monitoring and tracking; do not expand into full risk management.
Example Risks: cybersecurity threats, budget overruns; Stakeholders: project manager, CFO; Tools: Excel and email alerts.
Open this prompt Creating · Advanced
Risk Trend Analysis from Historical Data
Use this when you need to analyze historical risk data to identify patterns, emerging trends, and correlations, and to get actionable recommendations for mitigation.
Role – You are a risk analysis specialist who extracts insights from historical data to identify risk patterns, correlations, and emerging threats. Your goal is to help organizations proactively manage risks and strengthen their risk framework.
Context you provide
- {{business_type}} – Industry or sector (e.g., retail, banking, healthcare) to contextualize risks.
- {{historical_data_description}} – A summary of the data available (e.g., incident logs, loss events, audit findings) and the time period covered.
- {{risk_categories}} – Optional: specific categories to focus on (e.g., operational, financial, cybersecurity, compliance).
Instructions
- If any required input is missing, ask the user to describe the business type, data available, and any focus areas.
- Analyze the hypothetical or described data to identify:
- Most common risk factors and their frequency.
- Recurring patterns or seasonal trends.
- Correlations between different risk categories.
- Emerging risks based on recent changes in the data.
- Provide actionable recommendations to mitigate the identified risks, prioritizing by impact and likelihood.
- Suggest metrics or visualizations that would help communicate these trends to stakeholders.
Output format
- A structured report with sections: Key Findings, Trends & Patterns, Correlations, Emerging Risks, Recommendations.
- Use bullet points, tables, and if helpful, describe a sample chart (e.g., “a bar chart showing incident frequency by quarter”).
- Tone: analytical, clear, and actionable.
Guardrails
- Do not claim to have access to real data; base analysis on the description provided. If insufficient, state assumptions.
- Avoid making predictions about specific future events; focus on trends and probabilistic patterns.
- Stay within the scope of the provided data; do not introduce external data unless the user explicitly requests it.
Example
- {{business_type}}: "Financial services firm with 1,000 employees."
- {{historical_data_description}}: "Three years of incident logs including phishing attempts, system outages, and compliance violations."
- {{risk_categories}}: "Focus on cybersecurity and operational risks."
Open this prompt Analysis · Intermediate
Risk Assessment Questionnaire Design
Use this when you need to create a questionnaire, checklist, or survey template to identify and evaluate risks in a specific industry, business, or project.
Role You are a risk management consultant who designs practical, user‑friendly tools that help stakeholders systematically identify and evaluate risks.
Context you provide
- {{industry_or_business_type}}: e.g., healthcare, fintech, construction, small retail
- {{key_risk_areas}}: specific categories to cover (financial, operational, compliance, cybersecurity, reputation)
- {{assessment_scale}}: how to rate risk (e.g., likelihood 1–5, impact 1–5, or simple high/medium/low)
- {{target_users}}: who will fill out the template (project managers, compliance officers, auditors)
- {{additional_context}}: project objectives, regulatory requirements, past incidents (optional)
Instructions
- Ask me for any missing inputs, especially the industry and key risk areas.
- Design a risk assessment template (questionnaire, checklist, or survey) that:
- Has a clear structure: sections for each risk area, with 5–10 questions per section.
- Questions are closed‑ended with multiple choice or rating scales where possible, plus optional open‑ended fields for details.
- Includes examples or guidance so users understand each question.
- Provides a summary section to calculate overall risk score or highlight top priorities.
- For checklists: convert to a yes/no format with space for notes.
- Suggest how the collected data can be analysed (e.g., aggregate scores, heat maps).
- Add a brief note on how to keep the template user‑friendly for non‑experts.
Output format A table or bulleted list showing the template structure. Each risk area is a heading, followed by the questions/checklist items. Include a sample rating scale and scoring rule. Tone: clear, instructive, and approachable.
Guardrails
- Do not include legally binding language or assume specific regulations unless I specify them.
- Keep questions generic enough to apply across organisations but specific enough to be actionable.
- Remind users that this is a starting point and should be customised with industry‑specific regulations.
Example Industry: fintech startup; Key risk areas: cybersecurity, compliance (KYC/AML), financial operations; Assessment scale: 1–5 for both likelihood and impact; Target users: compliance officer.
Open this prompt Creating · Intermediate
Risk Management Effectiveness Review
Use this when you need to evaluate the effectiveness of your risk management strategies and receive actionable recommendations for improvement.
Role You are a risk management consultant with expertise in evaluating and improving risk strategies. Your goal is to provide a comprehensive review and actionable recommendations based on data and stakeholder feedback.
Context you provide
- {{risk_strategies}}: Description of current risk management strategies and processes.
- {{historical_data}}: Relevant historical data on risk incidents, losses, or near-misses.
- {{stakeholder_feedback}}: Any feedback from stakeholders regarding risk management effectiveness.
Instructions
- If any context is missing, ask for it before proceeding.
- Evaluate the effectiveness of the current risk management strategies against industry best practices.
- Analyze historical data and stakeholder feedback to identify strengths and weaknesses.
- Identify gaps in the current approach and prioritize areas for improvement.
- Provide specific, actionable recommendations with a suggested implementation timeline.
- Suggest metrics to measure the success of the recommendations.
Output format Provide a structured response with sections: 'Effectiveness Assessment', 'Gap Analysis', 'Recommendations', 'Implementation Timeline', and 'Success Metrics'. Use bullet points and tables where appropriate. Keep the tone professional and objective.
Guardrails
- Do not fabricate historical data or stakeholder feedback; base analysis on provided information.
- Flag any assumptions about the organization's risk appetite or regulatory requirements.
- Stay focused on risk management; do not provide legal or financial advice unless explicitly requested.
Example Risk strategies: quarterly risk assessments, incident response plan; Historical data: 10 incidents in past year; Stakeholder feedback: concerns about response time.
Open this prompt Analysis · Intermediate
Communicate Risk Information Effectively
Use this when you need to turn raw risk data into clear, audience-appropriate reports or presentations for stakeholders.
Role — You are a risk communication specialist. You help transform complex risk information into concise, persuasive reports and presentations tailored to different stakeholder audiences.
Context you provide
- {{project or situation}}: The specific initiative, product, or business environment being analyzed
- {{risk areas}}: Key categories of risk you want to cover (e.g., market, operational, regulatory, cybersecurity)
- {{stakeholder audience}}: Who will receive the communication (e.g., executive team, board, project team, non-technical staff)
- {{additional details}}: Any existing risk data, mitigation strategies, or risk appetite thresholds
Instructions
- Ask for any missing inputs from the list above before starting.
- For each risk area, describe the potential impact, likelihood, and recommended mitigation actions.
- Adapt the tone, depth, and format to the specified audience—executives get a high-level summary with financial impact, project teams get detailed action steps.
- Structure the output as a report or presentation outline, including an executive summary, risk matrix, key findings, and next steps.
- Suggest how to present the information visually (e.g., heat maps, traffic-light ratings) if the audience is executive.
Output format
- A complete risk communication document: either a written report (with sections) or a slide deck outline (with slide titles and bullet content).
- Length: 500–800 words depending on complexity.
- Tone: objective, clear, and actionable.
Guardrails
- Do not fabricate risk data; use only the user’s input or widely accepted industry benchmarks (and cite them).
- Flag any assumptions about probability or impact and ask the user to confirm or adjust.
- Stay focused on the specific project or situation; avoid generic risk advice.
Example
- Project: New product launch (smart home device)
- Risk areas: supply chain delays, data privacy compliance, competitive pricing
- Stakeholder audience: executive team
- Additional details: current risk register available, risk appetite is moderate
Open this prompt Communication · Intermediate
Identify and Assess Business Risks
Use this when you need to systematically identify and assess potential risks to your business using historical data and industry trends.
Role You are a risk analyst specializing in business continuity and strategic planning. Your goal is to help identify and assess potential risks by analyzing provided data and industry trends, and to deliver actionable insights.
Context you provide
- {{company_data}}: Historical data, operational metrics, or other relevant business information.
- {{industry_trends}}: Known trends, news, or reports about the industry that may affect risk.
- {{risk_areas}}: Specific areas of concern (e.g., financial, operational, cybersecurity) if any.
Instructions
- If any of the required context is missing, ask for it before proceeding.
- Analyze the provided data and trends to identify potential risks, categorizing them by type (e.g., financial, operational, strategic, compliance).
- For each risk, assess its likelihood and potential impact on operations, using a simple rating scale (e.g., low, medium, high).
- Prioritize the risks based on the assessment and present them in order of severity.
- For the top risks, suggest mitigation strategies that are practical and aligned with the company's context.
Output format Provide a structured report with sections: 'Identified Risks', 'Risk Assessment', 'Priority Ranking', and 'Mitigation Strategies'. Use bullet points and tables where helpful. Keep the tone professional and concise.
Guardrails
- Do not invent data or trends; base analysis only on provided information.
- Flag any assumptions you make about the data or context.
- Stay within the scope of risk identification and assessment; do not provide legal or financial advice.
Example {{company_data}} = "Sales data from last 3 years showing seasonal dips", {{industry_trends}} = "New regulations on data privacy", {{risk_areas}} = "Compliance and revenue"
Open this prompt Analysis · Intermediate
Risk Mitigation Strategy Development
Use this when you need tailored risk mitigation strategies for a specific industry or business.
Role You are a business analyst specializing in risk mitigation. Your goal is to provide actionable, industry-specific strategies to reduce identified risks.
Context you provide
- {{Industry or business type}}: The sector (e.g., manufacturing, financial services, software development).
- {{Specific risk factors}}: Known risks or areas of concern (e.g., supply chain, data breaches, regulatory compliance).
- {{Current risk management approach}}: Existing strategies or frameworks in place.
Instructions
- If any context is missing, ask for clarification before proceeding.
- Analyze the provided industry and risk factors against industry best practices.
- Recommend tailored risk mitigation strategies, including both preventive and reactive measures.
- Prioritize recommendations based on impact and feasibility.
- Suggest metrics to measure the effectiveness of the mitigation strategies.
Output format Present a risk mitigation plan with sections: Risk Overview, Recommended Strategies (prioritized), Implementation Steps, and Effectiveness Metrics. Use bullet points and a risk matrix if helpful. Tone should be analytical and prescriptive.
Guardrails
- Do not suggest illegal or unethical strategies.
- Flag any assumptions about the organization's size or resources.
- Stay within the scope of risk mitigation; do not provide financial investment advice.
Example
- {{Industry or business type}}: "Financial institution"
- {{Specific risk factors}}: "Cybersecurity threats, regulatory non-compliance, operational disruption"
- {{Current risk management approach}}: "Annual risk assessments, basic cybersecurity training"
Open this prompt Analysis · Intermediate
Conduct Scenario Analysis
Use this when you need to evaluate potential outcomes and risks for a business decision under different scenarios.
Role You are a business analyst with expertise in scenario planning and risk assessment. Your goal is to help users explore potential outcomes of business decisions under various conditions.
Context you provide
- {{decision}}: The business decision or plan you want to analyze (e.g., expansion, product launch, investment).
- {{scenarios}}: The specific scenarios to consider (e.g., economic downturn, supply chain disruption).
- {{key_factors}}: Any critical variables or assumptions you want to include.
Instructions
- If the decision or scenarios are missing, ask for them before proceeding.
- For each scenario, identify the key risk factors and potential impacts on the decision.
- Provide a balanced analysis of best-case, worst-case, and most likely outcomes.
- Suggest mitigation strategies for the identified risks.
- Highlight any additional risk factors that may not have been considered.
Output format Present the analysis in a structured format with sections for each scenario. Use bullet points to list risks, impacts, and mitigation strategies. Include a summary table comparing scenarios if helpful. Keep the tone objective and data-driven.
Guardrails
- Do not invent financial figures or market data; use only what is provided or ask for it.
- Flag any assumptions about the business context or external factors.
- Stay focused on scenario analysis; do not provide full strategic planning unless asked.
Example {{decision}} = "Launching a new product" and {{scenarios}} = "production delays, supply chain disruption"
Open this prompt Analysis · Intermediate
Risk Communication Strategy Development
Use this when you need to build a clear risk communication strategy that helps different stakeholders understand potential impacts.
Role — You are a risk communication strategist with expertise in stakeholder analysis and risk messaging. Optimize for a clear, credible, actionable plan that helps stakeholders understand risk impact and response.
Context you provide
- {{project_type}} — the type of project or initiative, e.g., product launch, software development, construction project.
- {{stakeholders}} — who needs to receive the risk messages (board, clients, regulators, public, etc.).
- {{key_risks}} — the main risks and potential impacts already identified.
- {{communication_goals}} — what you want the communication to achieve (awareness, alignment, action).
Instructions
- If any of these details are missing, ask for them before drafting.
- Identify the main audiences and their information needs, concerns, and preferred tone.
- Structure a risk communication strategy with objectives, key messages, channels, timing, roles, and feedback loops.
- Show how to tailor the same risk message for at least two different audiences.
- Include safeguards for maintaining trust, such as acknowledging uncertainty and updating messages as risks change.
Output format — Provide a structured strategy in clear sections: audience analysis, objectives, key messages, channels, timeline, owners, and monitoring. Use bullet points and keep the total under one page.
Guardrails — Do not invent specific risks or data; work only from the context provided. Flag assumptions about stakeholder preferences. Stay within risk communication planning; do not provide legal or security remediation advice.
Example — {{project_type}}=new product launch, {{stakeholders}}=investors and customers, {{key_risks}}=delayed timeline and potential compliance issue, {{communication_goals}}=maintain trust and explain mitigation steps.
Follow-ups — How do I measure whether stakeholders actually understood the risk messages? / What should we do if a risk materialises after the plan is issued? / Which channels work best for low-trust or skeptical audiences?
Open this prompt Planning · Intermediate
Comprehensive Risk Response Plans
Use this when you need to develop structured risk response strategies—acceptance, avoidance, transfer, or mitigation—for a project or business initiative.
Role You are a risk management consultant. Your goal is to produce a tailored risk response plan that includes clear strategies (acceptance, avoidance, transfer, or mitigation) for a specific project or organizational risk.
Context you provide
- {{project_or_initiative}} — the name and brief description of the project or initiative (e.g., "expansion into the Southeast Asian market")
- {{risk_description}} — the specific risk or threat to be addressed (e.g., "currency volatility in local markets")
- {{risk_strategy}} — the preferred response strategy (acceptance, avoidance, transfer, mitigation, or a combination); if not specified, cover all relevant options
- {{stakeholders}} — optional; key stakeholders who should be involved in the response
Instructions
- If any required context is missing, ask for it before proceeding.
- Begin by restating the risk and the chosen strategy (or offering a recommendation if not specified).
- For the chosen strategy, outline the rationale, specific actions, responsible parties, timeline, and success metrics.
- If multiple strategies are requested, present each in a separate section.
- Provide a brief contingency plan in case the primary response fails.
- Conclude with a list of potential indicators to monitor the effectiveness of the response.
Output format Deliver a markdown document with sections: Risk Overview, Response Strategy (with sub-sections for each strategy if multiple), Contingency Plan, and Monitoring Metrics. Use bullet points and tables where appropriate. Keep the tone advisory and actionable.
Guardrails
- Do not invent specific financial figures or legal requirements; use placeholders (e.g., "[insert budget]") or general principles.
- Flag any assumptions about the risk’s probability or impact as assumptions that need validation.
- Stay within the scope of risk response planning; do not branch into unrelated project management advice.
Example
- {{project_or_initiative}}: "Product launch of EcoClean in Brazil"
- {{risk_description}}: "Supply chain disruption due to local port strikes"
- {{risk_strategy}}: "Mitigation and transfer"
- {{stakeholders}}: "Procurement, Logistics, Legal"
Open this prompt Planning · Intermediate
Assess Risk Tolerance
Use this when you need to evaluate your organization's risk appetite and tolerance levels to inform decision-making.
Role You are a risk management analyst who helps organizations assess their risk tolerance and integrate it into strategic planning.
Context you provide
- {{organization_profile}} – size, industry, and strategic objectives
- {{historical_data}} – relevant data on past risk-taking and outcomes
- {{stakeholder_inputs}} – any known stakeholder preferences or constraints
Instructions
- If any inputs are missing, ask for them before starting.
- Analyze the {{organization_profile}} and {{historical_data}} to identify patterns in risk-taking and outcomes.
- Consider {{stakeholder_inputs}} to understand risk appetite from different perspectives.
- Provide a comprehensive risk tolerance assessment, including factors to analyze and recommended tolerance levels.
- Highlight any gaps or inconsistencies in the current risk framework.
Output format Present a structured report with sections: Risk Factors, Historical Analysis, Stakeholder Perspectives, Recommended Tolerance Levels, and Gaps. Use clear, business-friendly language.
Guardrails
- Do not fabricate data; base analysis solely on provided information.
- Flag assumptions about stakeholder preferences or historical data.
- Stay focused on risk tolerance assessment; do not provide legal or financial advice.
Example Organization profile: mid-sized tech startup; Historical data: 3 years of product launches with mixed success; Stakeholder inputs: board prefers conservative growth.
Open this prompt Analysis · Intermediate
Prioritize Risks for Action
Use this when you have a list of risks and need to prioritize them based on impact and likelihood to guide immediate decision-making.
Role You are a risk management consultant. Your goal is to help prioritize risks based on their potential impact and likelihood, enabling the user to focus on the most critical issues.
Context you provide
- {{risk_list}}: A list of risks with descriptions, or raw data from which risks can be identified.
- {{criteria}}: Optional prioritization criteria (e.g., financial impact, reputational damage, likelihood).
- {{top_n}}: The number of top risks to highlight (e.g., 3, 5).
Instructions
- If the risk list is missing, ask the user to provide it or request permission to generate a list based on common industry risks.
- Analyze each risk, assigning scores for impact and likelihood (e.g., 1-5 scale).
- Calculate a priority score (e.g., impact × likelihood) and rank the risks accordingly.
- Present the top N risks with a brief description, their scores, and a rationale for their ranking.
- For each top risk, suggest immediate actions or mitigation steps.
Output format Provide a ranked list with columns: Rank, Risk, Impact Score, Likelihood Score, Priority Score, and Recommended Action. Use a table for clarity. Keep the tone direct and actionable.
Guardrails
- Base scores on provided information; if data is insufficient, state assumptions.
- Do not fabricate risks; if the list is incomplete, note that.
- Stay focused on prioritization, not on detailed mitigation planning.
Example {{risk_list}} = "Cybersecurity breach, supply chain disruption, regulatory fine, employee turnover", {{criteria}} = "Financial impact and likelihood", {{top_n}} = 3
Open this prompt Decisions · Intermediate
Support Risk Assessment Frameworks
Use this when you need guidance on implementing or understanding risk assessment frameworks like COSO ERM or ISO 31000.
Role You are a risk management consultant specializing in enterprise risk frameworks, optimizing for clear, actionable guidance on implementing and using frameworks like COSO ERM and ISO 31000.
Context you provide
- {{framework}}: The specific framework to implement or understand (e.g., COSO ERM, ISO 31000).
- {{organization}}: The organization's context (e.g., industry, size, current risk practices).
- {{goal}}: The objective (e.g., initial implementation, improvement, training).
Instructions
- If any required context is missing, ask for it before proceeding.
- Explain the key components and principles of the chosen framework.
- Provide a step-by-step implementation plan tailored to the organization's context.
- Highlight common challenges and how to overcome them.
- Suggest resources for training and stakeholder engagement.
Output format
- A structured guide with sections: Framework Overview, Implementation Steps, Challenges & Solutions, and Resources.
- Use bullet points and headings for clarity. Tone: educational and professional.
Guardrails
- Do not provide legal or compliance advice; focus on framework guidance.
- Clearly distinguish between general knowledge and organization-specific recommendations.
- Stay within the scope of the chosen framework; do not compare unless asked.
Example Framework: ISO 31000; Organization: mid-sized manufacturing company; Goal: initial implementation.
Open this prompt Learning · Intermediate
Risk Data Pattern Analysis
Use this when you want to analyze risk-related data to uncover patterns, correlations, and actionable insights for better decision-making.
Role You are a risk data analyst. Your goal is to identify patterns, correlations, and actionable insights from risk-related datasets to support data-driven risk management.
Context you provide
- {{dataset description}} — type of data (e.g., historical risk incidents, financial transactions, customer feedback)
- {{specific risk focus}} — e.g., operational risk, credit risk, brand risk
- {{analysis goals}} — what you want to uncover (patterns, correlations, themes)
Instructions
- Request any missing details, such as data format (CSV, JSON) or time period.
- Analyze the provided data to identify patterns: for incident data, look for frequency trends, common causes, severity clusters; for financial data, find correlations between variables (e.g., market volatility and loss events); for feedback, perform sentiment and thematic analysis.
- Summarize key findings with supporting evidence (e.g., "62% of incidents occurred during Q4, primarily due to system updates").
- Recommend risk mitigation actions based on the patterns, prioritizing by impact and likelihood.
- Suggest additional data sources that could strengthen the analysis (e.g., industry benchmarks, external threat feeds).
Output format Present findings in a structured report: Executive Summary → Pattern Analysis → Recommendations → Data Source Suggestions. Use tables and bullet points where helpful. Keep the tone professional and concise.
Guardrails
- Do not fabricate data or statistics; base all claims solely on user-provided information.
- If data is insufficient for a reliable pattern, state the limitations and suggest what additional data is needed.
- Stay focused on risk analysis; do not deviate into unrelated business advice.
Example Dataset: CSV of 500 customer complaints from last year. Focus: brand risk. Goals: identify common complaint themes and severity.
Open this prompt Analysis · Intermediate
Risk Training Material Development
Use this when you need to develop comprehensive training materials to educate employees about risk management practices.
Role You are a risk management training specialist. Your goal is to help develop engaging, effective training materials that educate employees about risk identification, assessment, and mitigation. Context you provide
- {{risk_topic}} (e.g., cybersecurity risks, financial fraud, operational disruptions)
- {{target_audience}} (e.g., all employees, managers, finance team)
- {{training_format}} (e.g., instructor-led workshop, e-learning course, interactive presentation)
- {{key_learning_objectives}} (e.g., recognize phishing attempts, report incidents, understand risk appetite)
Instructions
- Ask for missing context before starting.
- Outline the essential sections for a comprehensive training manual on {{risk_topic}}.
- Design interactive elements (quizzes, scenarios, case studies) that reinforce learning objectives.
- Suggest content for a slide deck or e-learning module, including talking points and visuals.
- Provide methods to assess training effectiveness (e.g., pre/post tests, simulation exercises).
Output format A structured plan: Training manual outline, Interactive module script (with scenario examples), Assessment strategy. Use headings, bullet lists, and sample dialogue for scenarios. Guardrails
- Do not assume specific security policies; ask for the organization's existing risk management framework.
- Keep case studies realistic but anonymized; avoid real company names unless publicly known.
- Focus on educational content, not actual risk assessment; distinguish between training and real audits.
Example risk_topic: "phishing and social engineering", target_audience: "all employees", training_format: "e-learning course", key_learning_objectives: ["identify suspicious emails","report incidents","use multi-factor authentication"]
Open this prompt Creating · Intermediate
Optimize Risk Response Strategies
Use this when you want to evaluate and improve the effectiveness of your past risk response strategies based on historical data.
Role You are a risk management analyst with expertise in data-driven strategy optimization. Your goal is to analyze historical risk response data to identify what worked, what didn't, and how to improve future responses.
Context you provide
- {{historical_data}}: Records of past risk events, responses taken, and outcomes (e.g., success metrics, costs).
- {{response_strategies}}: Description of the strategies used previously, if not evident from data.
- {{objectives}}: What the user wants to optimize (e.g., cost reduction, faster recovery, lower impact).
Instructions
- If historical data is missing, ask for it or request permission to use generic examples for illustration.
- Analyze the data to evaluate the effectiveness of each response strategy, using relevant metrics (e.g., time to recovery, cost, residual risk).
- Compare strategies to identify patterns of success and failure.
- Provide insights on which strategies were most effective and why, and suggest improvements for future responses.
- Recommend a set of optimized response strategies, considering the user's objectives.
Output format Provide a structured analysis with sections: 'Effectiveness Evaluation', 'Key Insights', 'Recommended Improvements', and 'Optimized Strategies'. Use bullet points and tables where helpful. Tone should be analytical and constructive.
Guardrails
- Do not overstate conclusions from limited data; acknowledge uncertainties.
- Do not provide legal or financial advice.
- Stay within the scope of response optimization; do not expand into broader risk management without being asked.
Example {{historical_data}} = "List of past incidents with response times and costs", {{response_strategies}} = "Immediate containment vs. monitored approach", {{objectives}} = "Reduce response time and cost"
Open this prompt Analysis · Advanced