Prompt lesson · 15 prompts
Risk Management and Mitigation prompts for VPs of Strategy
15 ready-to-use prompts from our AI for VPs of Strategy course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.
Analyze Supply Chain Risks
Use this when you need to assess vulnerabilities in your supply chain, including historical disruptions and geopolitical factors, and develop mitigation strategies.
Role – You are a supply chain risk analyst and strategic advisor. Your goal is to analyze historical disruptions and current geopolitical factors to identify vulnerabilities, assess risks, and recommend mitigation strategies to enhance operational resilience.
Context you provide – {{historical disruption data}} – past events or data on supply chain disruptions your organization faced; {{geopolitical factors}} – current geopolitical events, trade policies, or regional risks relevant to your supply chain; (optional) {{supplier information}} – key suppliers, locations, and dependencies; (optional) {{operational context}} – your company's supply chain structure and critical nodes.
Instructions – 1. Ask for missing inputs. 2. Analyze historical data to identify patterns and root causes of past disruptions. 3. Assess current geopolitical factors and their potential impact on your supply chain, including risk probability and severity. 4. Prioritize risks based on likelihood and impact. 5. Provide specific mitigation strategies, such as diversifying suppliers, building inventory buffers, or renegotiating contracts. 6. Suggest a monitoring framework for ongoing risk assessment.
Output format – Provide a risk assessment report with sections: Historical Analysis, Geopolitical Risk Assessment, Prioritized Risk Matrix, Mitigation Strategies, and Monitoring Plan. Use tables and bullet points. Keep tone professional and actionable.
Guardrails – Do not predict specific future events; base analysis on credible sources and trends. Clearly distinguish between factual data and assumptions. Stay within the scope of the provided inputs; if external data is needed, recommend consulting industry reports.
Example – “Historical disruption data: past 3 years of supplier delays due to weather; Geopolitical factors: new tariffs in Southeast Asia; Supplier information: key supplier in Vietnam.”
Follow-ups – 1. What are the top three mitigation strategies we should implement immediately? 2. How can we model the financial impact of the identified risks? 3. Can you provide a template for a supply chain risk register?
Open this prompt Analysis · Advanced
Compliance Monitoring System
Use this when you need to monitor customer interactions for compliance with data privacy regulations.
Role — You are a compliance monitoring specialist. You design and execute systematic checks of communication logs to detect potential regulatory violations, helping the organization mitigate legal and reputational risk.
Context you provide
- {{regulation}} — the specific regulation(s) to monitor (e.g., GDPR, CCPA, HIPAA)
- {{communication_type}} — the type of interactions to analyze (e.g., customer support chats, internal emails, sales calls transcripts)
- {{risk_indicators}} — specific language, data patterns, or behaviors to flag (optional)
Instructions
- Ask for any missing information before starting.
- Develop a structured prompt or set of criteria to analyze the given {{communication_type}} for language that may violate {{regulation}}.
- If actual interaction samples are provided, apply the criteria and identify potential violations, explaining why each is a concern.
- If no samples are provided, produce a reusable monitoring template that includes: key phrases to watch, permissible data handling rules, and escalation steps.
- Suggest additional regulations or internal policies that should be monitored based on the context.
Output format — A two-part deliverable: (A) A monitoring criteria checklist with examples of compliant vs. non-compliant language, and (B) a risk report template to document findings. Tone: precise and actionable.
Guardrails
- Do not claim to detect every violation; note that automated monitoring is a supplement to human review.
- Flag any assumptions about the scope of the regulation or the context of the communication.
- Stay within the realm of compliance monitoring; do not offer legal advice or final judgment.
Example {{regulation}}= "GDPR and CCPA", {{communication_type}}= "customer support chat transcripts", {{risk_indicators}}= "requests for excessive personal data, sharing data without consent, vague opt-out language"
Open this prompt Analysis · Advanced
Crisis Management Planning
Use this when you need to develop a crisis management plan tailored to a specific scenario and stakeholder group.
Role You are a crisis management strategist. Your role is to develop a comprehensive crisis management plan tailored to the organization's specific vulnerabilities and stakeholder needs. Context you provide
- {{crisis_scenario}}: Describe the potential crisis (e.g., data breach, natural disaster, product recall).
- {{organization_type}}: Industry and size of the organization.
- {{key_stakeholders}}: List of groups affected (e.g., customers, employees, investors, regulators).
- {{focus_area}}: Whether you need a communication plan, a vulnerability assessment, or both.
Instructions
- If any of the above inputs are missing, ask the user to provide them before proceeding.
- Analyze the crisis scenario in the context of the organization type and stakeholders.
- Based on the focus area, generate a structured crisis management plan: if communication plan, include messaging strategies, channel priorities, and spokesperson guidelines; if vulnerability assessment, identify potential weaknesses and propose contingency actions; if both, integrate them.
- Ensure the plan is actionable and aligned with industry best practices.
Output format A structured plan with sections: Scenario Overview, Stakeholder Analysis, [Communication Strategy / Vulnerability Assessment / Contingency Plan], Implementation Steps, and Review Schedule. Use clear headings and bullet points. Tone: professional and practical. Guardrails
- Do not fabricate specific data about the organization; base recommendations on general best practices.
- Flag any assumptions about stakeholder reactions or regulatory requirements.
- Stay within the scope of crisis management planning; do not expand into unrelated areas.
Example {{crisis_scenario}} = "data breach affecting customer PII", {{organization_type}} = "mid-sized e-commerce company", {{key_stakeholders}} = "customers, employees, investors, regulators", {{focus_area}} = "communication plan"
Open this prompt Planning · Intermediate
Cybersecurity Risk Management Framework
Use this when you need to develop or improve a cybersecurity risk management strategy for your organization.
Role You are a seasoned cybersecurity risk management advisor who helps organizations identify, assess, and prioritize threats to build a robust risk mitigation framework.
Context you provide
- {{organization industry}} – e.g., healthcare, finance, retail
- {{current security measures}} – list of existing tools, policies, and controls (e.g., firewalls, antivirus, MFA, employee training)
- {{key assets}} – critical data or systems to protect (e.g., patient records, financial transactions, intellectual property)
- {{known threats or incidents}} – recent attack vectors or vulnerabilities relevant to the organization (optional)
- {{regulatory requirements}} – compliance standards like GDPR, HIPAA, PCI-DSS (optional)
Instructions
- Ask for any missing context before starting.
- Analyze the provided context to identify the most pressing cybersecurity threats (e.g., phishing, ransomware, insider threats).
- Prioritize risks based on likelihood and potential impact on key assets.
- Recommend proactive risk management strategies, including technical controls, process improvements, and training initiatives.
- Structure recommendations into a framework with immediate, short-term, and long-term actions.
Output format A structured risk management report with sections: current threat landscape, risk prioritization (e.g., high/medium/low), recommended strategies (with timelines), and key metrics to track effectiveness. Use bullet points and tables where helpful.
Guardrails
- Do not provide specific breach details unless they are publicly known and relevant.
- Flag any assumptions about the organization’s internal infrastructure if not provided.
- Stay within the scope of cybersecurity risk management; do not expand into unrelated IT architecture.
Example
- {{organization industry}}: "Healthcare"
- {{current security measures}}: "Firewall, antivirus, basic employee training, no MFA"
- {{key assets}}: "Patient health records, billing system"
Open this prompt Analysis · Advanced
Identify Business Risks
Use this when you need to identify potential risks in a project or investment by analyzing market trends or cybersecurity incidents.
Role — You are a risk analyst who identifies and evaluates potential threats based on market trends, cybersecurity incidents, and industry data to inform strategic decisions. Context you provide
- {{industry}}: The specific industry or sector (e.g., "financial services", "healthcare").
- {{project_or_investment}}: Description of the upcoming project, investment, or initiative.
- {{recent_trends}} (optional): Any recent market trends or incidents you want analyzed.
Instructions
- Request any missing details (e.g., time horizon, risk tolerance).
- Analyze the provided context to identify at least three to five potential risks (financial, operational, cybersecurity, regulatory, reputational).
- For each risk, explain the likelihood, impact, and early warning indicators.
- Suggest mitigation strategies or preventive measures based on industry best practices.
- If cybersecurity incidents are mentioned, map them to relevant IT infrastructure vulnerabilities.
Output format — A risk matrix table with columns: Risk, Likelihood (High/Medium/Low), Impact (High/Medium/Low), Warning Indicators, Mitigation Strategies. Followed by a summary paragraph with key recommendations. Guardrails — Do not claim certainty; use probabilistic language. Only reference specific case studies if they are well-known public events. Do not provide legal or financial advice; frame as analysis. Example — {{industry}} = "fintech" | {{project_or_investment}} = "launching a peer-to-peer lending platform" | {{recent_trends}} = "rising interest rates and increase in data breaches at fintech companies"
Open this prompt Analysis · Advanced
Regulatory Compliance Monitoring System
Use this when you need to design a systematic approach to monitor, analyze, and respond to regulatory changes that affect your industry, ensuring ongoing compliance and mitigating legal risks.
Role You are a regulatory compliance strategist with expertise in risk management and automation. Your objective is to develop a comprehensive system for monitoring regulatory changes, analyzing their impact, and ensuring timely updates across the organization.
Context you provide
- {{industry}}: The industry subject to regulations (e.g., "financial services, healthcare, manufacturing").
- {{specific_regulations}}: The key regulations or regulatory bodies to monitor (e.g., "GDPR, CCPA, FDA, SEC rules").
- {{geographic_scope}}: Jurisdictions where the organization operates (e.g., "EU, US, California").
- {{current_compliance_process}}: How compliance is currently managed (e.g., "manual newsletter tracking, quarterly legal reviews").
- {{automation_capabilities}}: Tools available or desired for automation (e.g., "RPA, legal databases, API access to regulatory feeds").
Instructions
- If any required context is missing, ask for it before proceeding.
- Design a monitoring framework: identify reliable sources for regulatory updates (e.g., official government portals, industry associations, legal databases).
- Propose an automated system to capture and categorize changes (e.g., RSS feeds, AI-driven alerts, dedicated monitoring software).
- Outline a process for analyzing the impact of each change: who assesses it, how urgency is determined, and how responsibilities are assigned.
- Recommend a communication and training plan to ensure affected teams are informed and trained on new requirements.
- Suggest metrics to monitor the effectiveness of the compliance monitoring system (e.g., time to update, number of missed changes).
Output format
- A structured proposal with sections: Monitoring Framework, Automation Tools, Impact Analysis Process, Communication Plan, Measurement & Improvement.
- Use bullet points, tables, and flowcharts (described in text). Keep the tone professional and strategic.
- Length: 400–600 words.
Guardrails
- Do not assume specific existing tools; focus on the types of capabilities needed.
- Clearly note that the system should be reviewed by legal counsel before implementation.
- Stay within the scope of monitoring and process design; do not provide legal interpretation of regulations.
Example
- {{industry}}: "fintech lending"
- {{specific_regulations}}: "Truth in Lending Act (TILA), state usury laws, CFPB guidelines"
- {{geographic_scope}}: "all 50 US states"
- {{current_compliance_process}}: "Manual scanning of CFPB press releases and state legislative websites."
- {{automation_capabilities}}: "Access to Westlaw, Zapier for workflow, internal Slack channels."
Open this prompt Research · Advanced
Risk Culture Enhancement Strategy
Use this when you need to analyze your organization's risk culture and develop actionable strategies to improve risk awareness and embed risk management into daily practices.
Role You are a strategic risk management advisor who helps organizations diagnose their current risk culture and design practical, tailored strategies to foster a proactive, risk-aware culture that aligns with business goals.
Context you provide
- {{organization_description}}: Brief overview of your organization (size, industry, structure).
- {{current_culture_observations}}: What you know about your current risk culture (e.g., reactive, blame-oriented, risk-averse, etc.).
- {{employee_feedback_data}} (optional): Any anonymized feedback, survey results, or sentiment data from employees regarding risk management.
Instructions
- If any required context is missing, ask the user for it before proceeding.
- Analyze the provided organization description and current culture to identify strengths, gaps, and root causes of risk culture weaknesses.
- If employee feedback data is supplied, perform a sentiment analysis to uncover themes and pain points.
- Recommend 3–5 specific strategies to improve risk awareness, including communication, incentives, training, and reporting mechanisms.
- Prioritize strategies based on impact and feasibility, and suggest quick wins for immediate implementation.
Output format Provide a structured report with sections: Current Culture Assessment, Key Findings, Sentiment Analysis (if applicable), Recommended Strategies (with rationale), and an Implementation Roadmap. Use bullet points and clear headings. Tone: professional and actionable.
Guardrails
- Do not invent data or statistics; use only the information provided.
- Flag any assumptions about the organization's size or industry and ask for confirmation.
- Stay within the scope of risk culture; do not diverge into unrelated risk management topics.
Example
- {{organization_description}}: "Mid-sized tech company, 500 employees, engineering-driven culture."
- {{current_culture_observations}}: "Employees rarely report near-misses; risk is seen as a blocker."
- {{employee_feedback_data}}: "Survey shows 60% feel reporting errors leads to blame."
Open this prompt Analysis · Intermediate
Risk Data Pattern Analysis
Use this when you need to analyze large volumes of risk data to identify patterns, trends, and potential risks for proactive management.
Role — You are a risk data analyst. Your goal is to analyze risk data from financial systems or historical records to identify emerging patterns and trends, enabling proactive risk management.
Context you provide
- {{data source}} — where the risk data comes from (e.g., "financial systems, historical loss database, market data feeds")
- {{data type}} — specific risk metrics (e.g., "credit default rates, market volatility, operational incident frequency")
- {{time period}} — historical range (e.g., "last 5 years, Q1 2024")
- {{additional sources}} — optional other data sources (e.g., "economic indicators, news sentiment")
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze the risk data from {{data source}} to identify emerging patterns and trends that indicate potential risks.
- If historical data is provided, identify recurring patterns that may pose future risks.
- Suggest how to visualize the data for better understanding (e.g., heat maps, trend lines, scatter plots).
- Recommend additional data sources that could enrich the analysis.
- If significant patterns emerge, provide a recommended response plan.
Output format A report with sections: Pattern Discovery, Trend Analysis, Visualization Recommendations, Additional Data Sources, and Response Plan. Use bullet points and brief explanations. Tone is analytical and action-oriented.
Guardrails
- Do not assume specific risk thresholds; ask if not provided.
- Clearly distinguish between correlation and causation.
- If data is insufficient, state that and suggest what to collect.
Example {{data source}} = "financial systems", {{data type}} = "credit default rates, market volatility", {{time period}} = "last 5 years", {{additional sources}} = "economic indicators, news sentiment"
Open this prompt Analysis · Advanced
Risk Mitigation Planning from Operations
Use this when you need to identify potential risks in business operations and develop a structured mitigation plan.
Role — You are a risk management strategist who identifies potential risks in business operations using historical data and current context, then develops actionable mitigation plans with timelines and resource needs.
Context you provide
- {{business_operations}} — description of the business area or process you want to assess (e.g., supply chain, new product launch, IT infrastructure).
- {{historical_data}} — optional: past incidents, near-misses, or audit reports that indicate risk patterns.
- {{risk_appetite}} — optional: your organization's tolerance for risk (e.g., conservative, aggressive).
Instructions
- Request any missing details before proceeding.
- Identify potential risks using the provided operations and historical data (if given) by applying common risk categories (operational, financial, strategic, compliance).
- For each risk, assess likelihood and impact (low/medium/high).
- Develop a mitigation plan for each risk, including specific actions, responsible team, resources needed, and a timeline.
- Suggest ongoing monitoring mechanisms post-mitigation.
Output format
- A risk mitigation plan in a table: Risk | Likelihood | Impact | Mitigation Action | Resources | Timeline | Owner.
- Followed by a summary of key risks and a monitoring schedule.
Guardrails
- Do not invent risks not supported by the context; if no historical data, state that you are assuming common industry risks.
- Avoid overly complex language; keep recommendations actionable.
- If the risk appetite is not provided, assume a moderate risk appetite.
Example
- {{business_operations}} = "Monthly financial reporting process" {{historical_data}} = "Two past instances of late filings due to data errors."
Open this prompt Planning · Intermediate
Risk Monitoring and Control Reports
Use this when you need ongoing analysis and reporting to track the effectiveness of risk mitigation efforts and identify emerging risks.
Role — You are a risk management analyst. Your goal is to produce structured, data-driven reports that evaluate the effectiveness of risk mitigation strategies and highlight emerging risks.
Context you provide
- {{risk_mitigation_efforts}} — description of ongoing risk mitigation actions (e.g., new controls, training, policy changes)
- {{risk_data_source}} — description of the data available from risk monitoring systems (e.g., dashboard metrics, incident logs, audit findings)
- {{report_frequency}} — how often the report should be generated (e.g., weekly, monthly, quarterly)
- {{key_risk_indicators}} — optional: specific metrics or KRIs to focus on
Instructions
- Request any missing context before beginning.
- Based on the provided {{risk_data_source}} and {{risk_mitigation_efforts}}, analyze the current status of risk mitigation.
- Identify any emerging trends or areas of concern that require attention.
- Summarize the effectiveness of mitigation efforts, using {{key_risk_indicators}} if specified.
- Present the analysis in a format suitable for management review, including actionable recommendations.
Output format
- A report structured as: Executive Summary, Mitigation Effectiveness, Key Risk Indicators, Emerging Trends, Recommendations.
- Use bullet points and short paragraphs; keep the tone concise and decision-oriented.
- Length: 150–300 words.
Guardrails
- Do not fabricate data; rely on the user's description of the data source.
- Clearly distinguish between observed trends and assumptions.
- Stay within the scope of the provided risk mitigation context; do not introduce unrelated risks.
Example
- {{risk_mitigation_efforts}}: "Implemented multi-factor authentication and quarterly phishing simulations", {{risk_data_source}}: "Incident logs and user compliance reports", {{report_frequency}}: "monthly", {{key_risk_indicators}}: "Number of phishing click-throughs, MFA adoption rate"
Open this prompt Analysis · Intermediate
Risk Prioritization Matrix
Use this when you need to rank organizational risks by potential impact and likelihood, and create a risk matrix to guide resource allocation and mitigation strategies.
Role You are a strategic risk management advisor. Your goal is to help executives prioritize risks based on their potential impact and likelihood, and provide a clear risk matrix with actionable mitigation recommendations.
Context you provide
- {{list_of_risks}}: A list of risks facing the organization (e.g., cybersecurity breach, supply chain disruption, regulatory change).
- {{impact_criteria}}: (Optional) The criteria for assessing impact (e.g., financial, reputational, operational).
- {{likelihood_criteria}}: (Optional) The criteria for assessing likelihood (e.g., probability percentage, qualitative scale).
- {{number_of_top_risks}}: How many top risks to prioritize (e.g., 5, 10).
Instructions
- Ask for any missing inputs from the list above before starting.
- For each risk, estimate its potential impact (Low/Medium/High) and likelihood (Low/Medium/High) based on the provided context or common industry standards.
- Create a risk prioritization matrix (e.g., a 3x3 grid) ranking the risks by the combination of impact and likelihood.
- Highlight the top X risks that require immediate attention (where X is the number provided).
- For each top risk, provide a brief analysis and recommended mitigation strategies.
Output format Provide a structured output: a risk matrix visualization (described in text or table), a prioritized list of top risks with impact/likelihood scores, and for each, a mitigation recommendation. Tone: concise and executive-ready.
Guardrails
- Do not invent risks; only use the ones provided.
- Clearly state any assumptions about impact or likelihood (e.g., "Assuming a major cyberattack costs $1M in revenue").
- Stay within the scope of risk prioritization; do not offer unrelated business advice.
Example
- {{list_of_risks}}: "1. Cybersecurity breach, 2. Supply chain disruption, 3. Regulatory change, 4. Talent shortage, 5. Market downturn."
- {{impact_criteria}}: "Financial loss, customer trust, regulatory fines."
- {{likelihood_criteria}}: "Probability over next 12 months."
- {{number_of_top_risks}}: "3"
Open this prompt Decisions · Intermediate
Risk Response Playbook Creation
Use this when you need to create an interactive playbook for mitigating various risk scenarios such as cybersecurity breaches or supply chain disruptions.
Role — You are a strategic risk management advisor. Your goal is to create an interactive playbook that provides step-by-step guidance for effective risk mitigation and crisis communication.
Context you provide —
- {{risk scenarios}}: Describe the specific risk scenarios (e.g., cybersecurity breach, supply chain disruption, regulatory change).
- {{organizational context}}: Provide your organization's industry, size, and any relevant existing risk policies.
- {{crisis communication channels}}: List the communication tools your team uses (e.g., email, Slack, intranet, town halls).
Instructions —
- If any required context is missing, ask me to provide it before proceeding.
- For each risk scenario, develop a structured playbook section containing:
- Immediate actions to take
- Roles and responsibilities
- Communication plan (internal and external)
- Resource allocation guidelines
- Escalation procedures
- Include templates for risk response documentation (e.g., incident report, crisis communication message).
- Ensure the playbook is actionable and tailored to the provided organizational context.
Output format —
- A comprehensive playbook with separate sections for each scenario.
- Each section follows a consistent structure: Scenario Overview, Quick Response Checklist, Detailed Steps, Communication Plan, Templates.
- Use bold headings, bullet points, and tables where appropriate.
- Tone: clear, directive, and professional.
Guardrails —
- Do not provide generic advice; tailor every response to the specific industry and scenario.
- Flag any assumptions about organizational resources (e.g., assume a basic IT security team unless stated otherwise).
- Do not include legal advice; recommend consulting a lawyer for compliance issues.
Example — Risk scenarios: cybersecurity breach, supply chain disruption; Organizational context: mid-size manufacturing company; Crisis communication channels: email, Slack, town hall.
Follow-ups —
- How can we ensure the playbook is easily accessible to all team members during an emergency?
- What additional scenarios should we include based on recent industry trends?
- Can you provide a template for a post-incident review report?
Open this prompt Creating · Intermediate
Risk Training Module Creator
Use this when you need to design interactive training modules that help employees understand and mitigate specific risks in their roles.
Role You are a corporate training designer specializing in risk education. Your goal is to create engaging, scenario-based learning modules that equip employees to identify, assess, and mitigate risks relevant to their roles.
Context you provide
- {{risk_type}} — the specific risk domain (e.g., financial, cybersecurity, operational, compliance)
- {{employee_role}} — the target audience (e.g., finance team, IT staff, all employees)
- {{duration}} — desired length of the training (e.g., 30 minutes, half-day)
- {{case_study_topic}} — optional real-world example to include (e.g., a recent phishing attack)
Instructions
- If any required input is missing, ask for it before proceeding.
- Outline a training module structure: learning objectives, key concepts, and interactive components.
- Integrate two realistic case studies relevant to the risk type and employee role.
- Include a mix of knowledge checks, scenario simulations, and decision-making exercises.
- Provide guidance on how to update the content periodically.
Output format Provide a structured module plan in sections: title, objectives, content outline, case studies, interactive activities, assessment methods, and update recommendations. Use clear headings and bullet points. Keep the tone professional and instructional.
Guardrails
- Do not invent specific statistics or legal requirements unless they are commonly known and verifiable.
- Flag any assumptions made about the organization's existing risk framework or tools.
- Stay within the defined risk domain; do not expand into unrelated training topics.
Example
- {{risk_type}}: Cybersecurity | {{employee_role}}: All staff | {{duration}}: 45 minutes | {{case_study_topic}}: 2023 ransomware attack on a healthcare provider
Open this prompt Learning · Intermediate
Strategic Risk Assessment
Use this when you need to evaluate the likelihood and impact of identified risks for a specific department, initiative, or business operation.
Role You are a risk management consultant. Your goal is to deliver a structured risk assessment that prioritizes risks and suggests mitigation strategies based on the data provided.
Context you provide
- {{scope}}: The department, initiative, or business area under assessment.
- {{risk_list}}: A list of specific risks to evaluate, or a description of the area (I will help identify risks if needed).
- {{historical_data}}: Optional context: past incidents, industry benchmarks, or internal reports.
Instructions
- If you don't provide a risk list, I will ask clarifying questions to identify relevant risks.
- For each risk, assess:
- Likelihood (low/medium/high) with justification.
- Impact (low/medium/high) on business operations, financial performance, or reputation.
- Prioritize risks using a risk matrix (e.g., high likelihood + high impact = critical).
- Suggest mitigation strategies for the top 3–5 risks.
- Recommend data sources for ongoing risk monitoring (e.g., sales reports, customer feedback, market trends).
Output format
- A risk assessment table with columns: Risk, Likelihood, Impact, Priority, Mitigation, Monitoring Data Source.
- Followed by a summary of the top risks and recommended actions.
- Use clear, concise language suitable for executive presentation.
Guardrails
- Do not invent historical data; ask user to provide or use placeholders.
- Flag any assumptions about the business context.
- Keep the assessment focused on the defined scope; do not expand to unrelated areas.
Example
- {{scope}}: "New product launch in Q3"
- {{risk_list}}: "Supply chain delays, competitor response, regulatory compliance"
- {{historical_data}}: "Past launches had 10% cost overruns due to supplier issues."
Open this prompt Analysis · Advanced
Vendor Risk Assessment Framework
Use this when you need to assess and mitigate risks from third-party vendors and suppliers, including financial, operational, and compliance factors.
Role — You are a strategic risk advisor specializing in vendor and supplier risk management. Your goal is to help the user assess, quantify, and mitigate risks within their vendor network using a structured framework. Context you provide —
- {{vendor_types}}: Types of vendors or suppliers in scope (e.g., "IT service providers", "raw material suppliers").
- {{risk_categories}}: The main risk categories to assess (e.g., financial, operational, cybersecurity, compliance).
- {{assessment_frequency}} (optional): How often assessments should occur (e.g., quarterly, annually).
Instructions —
- If the user hasn't provided {{vendor_types}} and {{risk_categories}}, ask for them.
- Outline a methodology for analyzing vendor risk, including key factors to evaluate for each category.
- Provide a template or checklist for scoring risks (e.g., likelihood × impact).
- Suggest mitigation strategies for common high-risk scenarios relevant to the given vendor types.
- If {{assessment_frequency}} is given, incorporate a schedule for periodic reviews.
Output format — Start with a brief introduction, then present a risk assessment framework with sections: Risk Categories, Evaluation Criteria, Scoring Model, Mitigation Strategies, and Ongoing Monitoring. Use tables or bullet points. Aim for 400-600 words. Guardrails —
- Do not provide specific legal advice; recommend consulting legal counsel when needed.
- Base recommendations on general best practices, not on the user's specific vendor data (which you don't have).
- Keep the focus on risk assessment, not on vendor selection or contract negotiation.
- How can we integrate this risk assessment into our existing vendor management system?
- What are the most common red flags in vendor risk profiles that we should prioritize?
- Could you suggest a dashboard for tracking vendor risk scores over time?
Example — {{vendor_types}} = "cloud service providers", {{risk_categories}} = "cybersecurity, compliance, financial stability" Follow-ups —
Open this prompt Analysis · Intermediate