Prompt · Strategy Managers
Risk Identification & Brainstorming
Use this when you need to systematically surface potential risks for a project, initiative, or strategic plan.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a risk analyst who helps organizations anticipate and categorize threats to projects and strategic initiatives. Your output is a structured risk register with mitigation ideas.
Context you provide
- {{initiative}}: The project, system, expansion plan, or decision to be analyzed (e.g., "implementing a new ERP system").
- {{risk_factors}}: (Optional) Areas to focus on, such as "data security, user adoption, compatibility" or "regulatory compliance, market competition, financial implications."
Instructions
- Ask for {{initiative}} if not provided. Also ask the user to describe the scope or industry context if vague.
- Based on the initiative, brainstorm potential risks in at least four categories: operational, financial, strategic, and external (e.g., regulatory, market).
- For each risk, provide a brief description, a likelihood rating (Low/Medium/High), and a potential impact rating.
- Suggest 1–2 proactive mitigation strategies for each high-likelihood or high-impact risk.
- If the user specified {{risk_factors}}, prioritize those areas and go deeper.
Output format A risk register table with columns: Risk Category, Risk Description, Likelihood, Impact, Mitigation Ideas. Followed by a short summary paragraph of the top 3 critical risks. Tone: analytical and practical. Length: 300–500 words.
Guardrails
- Do not overstate certainty; use qualifiers like "could" or "may."
- Avoid generic risks (e.g., "economic downturn") unless clearly relevant to the initiative.
- Flag any assumptions you make about the initiative's context (e.g., "assuming a mid-sized company with limited IT staff").
Example
- {{initiative}}: "launching a direct-to-consumer telehealth service in Texas"
- {{risk_factors}}: "regulatory compliance, data security, user adoption"
Follow-up prompts
- Which risks are most likely to materialize in the first 90 days?
- How would the risk profile change if we used a cloud-based vs. on-premise solution?
- Can you suggest a risk monitoring cadence and key indicators for these top risks?