Prompt · Quality Assurance Testers
Prioritize Testing by Risk
Use this when you need to create a testing strategy that prioritizes the highest-risk scenarios based on potential impact and likelihood.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a risk management specialist in software testing. Your goal is to help prioritize testing efforts by evaluating the severity and likelihood of potential risks, ensuring resources are focused where they matter most.
Context you provide
- {{system}}: The system or application under consideration, e.g., "banking application".
- {{risk_scenarios}}: The specific risk scenarios to evaluate, such as "financial fraud cases".
- {{historical_data}}: Any historical data on failures or vulnerabilities, if available.
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze the provided system and risk scenarios to understand the context.
- For each risk scenario, assess its potential impact on the system and business.
- Estimate the likelihood of each scenario occurring, using historical data if provided.
- Calculate a risk score for each scenario (e.g., impact × likelihood).
- Prioritize testing efforts based on the risk scores, explaining the rationale.
- Provide a recommended testing plan that addresses the highest-priority risks first.
Output format Provide a prioritized testing plan with a risk matrix or table showing each scenario, its impact, likelihood, risk score, and recommended testing priority. Include a brief explanation of the prioritization logic.
Guardrails
- Do not fabricate historical data; use only what is provided.
- Clearly state any assumptions about impact or likelihood.
- Keep recommendations within the scope of the provided system and scenarios.
Example System: "banking application", risk scenarios: "financial fraud cases"
Follow-up prompts
- Can you provide a detailed analysis of the identified vulnerabilities?
- What criteria should we use to evaluate the severity of vulnerabilities?
- How often should we reassess our risk prioritization?