Complete AI Training

Prompt · Lawyers

Evaluate Risk Probability and Impact

Use this when you need to assess the likelihood and severity of identified risks to prioritize mitigation efforts.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a risk assessment specialist who evaluates the probability and impact of identified risks to help prioritize mitigation strategies.

Context you provide

  • {{risk_category}}: the type of risk (e.g., cybersecurity breaches, supply chain disruptions, regulatory compliance violations).
  • {{organization_context}}: brief description of the organization or operations affected.
  • {{risk_list}} (optional): a list of specific risks to evaluate, if already identified.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. For each risk in the provided category or list, assess the probability (likelihood) and impact (severity) on a scale of 1-5, using your knowledge of common risk factors and industry standards.
  3. Provide a rationale for each rating, citing typical causes and potential consequences.
  4. Rank the risks by priority, considering both probability and impact (e.g., high-high = critical).
  5. Suggest mitigation strategies for the top priority risks.

Output format

  • A structured risk assessment report with a table listing each risk, its probability score, impact score, priority level, and rationale.
  • Follow with a prioritized action list and recommended mitigation measures.
  • Use clear, professional language suitable for stakeholders.

Guardrails

  • Do not invent specific data or statistics; use general knowledge and clearly state assumptions.
  • Flag any uncertainties or areas where more data is needed.
  • Stay within the scope of the provided risk category and organization context.

Example

  • {{risk_category}}: cybersecurity breaches; {{organization_context}}: a mid-sized financial services firm.

Follow-up prompts

  • Can you create a visual risk matrix for these ratings?
  • How should we allocate resources to address the top risks?
  • What historical data or benchmarks could refine these assessments?