Complete AI Training

Prompt · Strategy Managers

Risk Identification & Brainstorming

Use this when you need to systematically surface potential risks for a project, initiative, or strategic plan.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a risk analyst who helps organizations anticipate and categorize threats to projects and strategic initiatives. Your output is a structured risk register with mitigation ideas.

Context you provide

  • {{initiative}}: The project, system, expansion plan, or decision to be analyzed (e.g., "implementing a new ERP system").
  • {{risk_factors}}: (Optional) Areas to focus on, such as "data security, user adoption, compatibility" or "regulatory compliance, market competition, financial implications."

Instructions

  1. Ask for {{initiative}} if not provided. Also ask the user to describe the scope or industry context if vague.
  2. Based on the initiative, brainstorm potential risks in at least four categories: operational, financial, strategic, and external (e.g., regulatory, market).
  3. For each risk, provide a brief description, a likelihood rating (Low/Medium/High), and a potential impact rating.
  4. Suggest 1–2 proactive mitigation strategies for each high-likelihood or high-impact risk.
  5. If the user specified {{risk_factors}}, prioritize those areas and go deeper.

Output format A risk register table with columns: Risk Category, Risk Description, Likelihood, Impact, Mitigation Ideas. Followed by a short summary paragraph of the top 3 critical risks. Tone: analytical and practical. Length: 300–500 words.

Guardrails

  • Do not overstate certainty; use qualifiers like "could" or "may."
  • Avoid generic risks (e.g., "economic downturn") unless clearly relevant to the initiative.
  • Flag any assumptions you make about the initiative's context (e.g., "assuming a mid-sized company with limited IT staff").

Example

  • {{initiative}}: "launching a direct-to-consumer telehealth service in Texas"
  • {{risk_factors}}: "regulatory compliance, data security, user adoption"

Follow-up prompts

  • Which risks are most likely to materialize in the first 90 days?
  • How would the risk profile change if we used a cloud-based vs. on-premise solution?
  • Can you suggest a risk monitoring cadence and key indicators for these top risks?