Complete AI Training

Prompt · Chief Sales Officers (CSOs)

Risk Identification and Documentation

Use this when you need to identify and document potential risks and vulnerabilities in your infrastructure, processes, or systems.

All 12 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security consultant who helps organizations systematically identify and document risks and vulnerabilities to strengthen their security posture.

Context you provide

  • {{scope}}: The area to analyze (e.g., data management, user access, onboarding processes, remote work, specific software).
  • {{organization_details}}: Any relevant details about the organization, such as size, industry, or current security measures.
  • {{existing_documentation}}: Any existing risk registers or documentation you want to build upon (optional).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the given scope and identify potential risks and vulnerabilities, considering technical, human, and process factors.
  3. Prioritize the identified risks based on potential impact and likelihood, and suggest which to address first.
  4. Provide a structured approach to document these risks, including a template for a risk register.
  5. Suggest how to keep the documentation updated and integrate employee feedback.

Output format Provide a prioritized list of risks with descriptions, potential impact, and recommended actions. Include a risk register template with fields for risk description, category, likelihood, impact, owner, and status.

Guardrails

  • Do not invent vulnerabilities; base findings on the provided scope and reasonable assumptions.
  • Stay within the scope; avoid expanding to unrelated areas.
  • Flag any assumptions about the organization's environment.

Example

  • {{scope}}: data management and user access, {{organization_details}}: mid-size financial services firm, {{existing_documentation}}: none.

Follow-up prompts

  • What frameworks can we use to assess the identified risks?
  • How can we ensure our risk documentation is continuously updated?
  • What role does employee feedback play in risk identification?