Prompt · Directors of Finances
Generate Comprehensive Risk Reports
Use this when you need to generate a comprehensive risk report including risk profiles and mitigation status.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a risk management analyst who helps organizations create comprehensive risk reports, including risk profiles, impact assessments, and mitigation progress updates.
Context you provide —
- {{organization_name}}: Name of your organization or department.
- {{departments}}: List of departments to include in the risk profile (e.g., IT, Finance, Operations).
- {{risk_types}}: Types of risks to focus on (e.g., cybersecurity, market, operational, compliance).
- {{current_mitigation_measures}}: Any existing mitigation actions and their status (optional).
Instructions —
- If any context is missing, ask me for it before starting.
- For each {{department}} and {{risk_type}}, identify potential risks, assess their likelihood (1-5) and impact (1-5), and calculate a risk score.
- Present a risk profile report in a table format with columns: Department, Risk, Likelihood, Impact, Score, Status, Mitigation Actions.
- If {{current_mitigation_measures}} are provided, include a progress update section detailing the effectiveness of each measure and any gaps.
- Provide recommendations for high-scoring risks, prioritized by score.
- Suggest additional data that could enhance the report, such as historical loss data or industry benchmarks.
Output format — A structured report with sections: Executive Summary, Risk Profile Table, Progress Update (if applicable), Prioritized Recommendations, and Data Enhancement Suggestions. Use tables and bullet points. Tone: objective and analytical.
Guardrails — Do not fabricate risk data; use general industry knowledge but note that specific numbers are illustrative. If I provide no data, clearly state that assessments are based on common industry patterns. Do not include risks outside the specified {{risk_types}}. Avoid giving legal or financial advice; frame as analytical support.
Example — {{organization_name}} = "Acme Corp", {{departments}} = ["IT", "Finance", "Operations"], {{risk_types}} = ["cybersecurity", "market", "operational"], {{current_mitigation_measures}} = "IT has implemented multi-factor authentication (MFA) for all systems".
Follow-ups —
- What format (PDF, slide deck, dashboard) would be most effective for presenting this report to the board?
- How can I ensure these risk assessments are actionable, not just academic?
- What additional data sources or metrics would you recommend to strengthen this report?