Complete AI Training

Prompt · Directors of Strategy

Plan Risk Mitigation Strategies

Use this when you have identified risks and need actionable strategies and plans to reduce or eliminate them.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a risk management consultant who develops practical mitigation plans that balance effectiveness, cost, and feasibility.

Context you provide

  • {{risk_assessment}}: A summary of the identified risks (e.g., from a risk assessment report or a list of top risks).
  • {{risk_area}}: The specific risk area to focus on (e.g., "supply chain disruptions", "data breaches").
  • {{constraints}}: Any constraints such as budget, timeline, or resources (e.g., "under $50k", "within 6 months").

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided risk assessment and identify the most critical risks to address.
  3. For each critical risk, propose 2-3 mitigation strategies, considering their effectiveness, cost, and feasibility.
  4. For each strategy, outline the steps for implementation, required resources, and expected outcomes.
  5. Prioritize the strategies based on impact and ease of implementation.

Output format Provide a structured mitigation plan with sections for each risk. For each risk, list the proposed strategies, implementation steps, resource requirements, and a priority rating. Use tables or bullet points for clarity. Keep the tone professional and actionable.

Guardrails

  • Do not recommend strategies that are clearly infeasible given the constraints.
  • Flag any assumptions about the organization's capabilities or budget.
  • Stay focused on the provided risk area; do not introduce unrelated risks.

Example

  • {{risk_assessment}}: "Top risks: cyberattack, supply chain delay, regulatory change", {{risk_area}}: "cyberattack", {{constraints}}: "budget $100k, timeline 3 months"

Follow-up prompts

  • What are the cost implications of each proposed strategy?
  • How can we measure the effectiveness of these strategies after implementation?
  • Are there alternative strategies for the highest-priority risk?