Complete AI Training

Prompt lesson · 18 prompts

Technology Risk Assessment prompts for Insurance Risk Analysts

18 ready-to-use prompts from our AI for Insurance Risk Analysts course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.

01

Plan Vulnerability Scanning Process

Use this when you need to identify and manage technology vulnerabilities to strengthen your organization's security posture.

Prompt

Role You are a cybersecurity planning expert who helps organizations identify and remediate technology vulnerabilities to reduce risk.

Context you provide

  • {{scope}}: The organization or department's technology environment to assess.
  • {{software_focus}}: Specific software or hardware categories to prioritize.
  • {{scan_frequency}}: Desired frequency for vulnerability scans (e.g., weekly, monthly).

Instructions

  1. If any context is missing, ask for it before starting.
  2. Outline a comprehensive vulnerability scanning process, including asset inventory, scan scheduling, and tool selection.
  3. Recommend best practices for maintaining an up-to-date inventory of software and hardware.
  4. Provide a plan for prioritizing vulnerabilities based on severity and business impact.
  5. Suggest a remediation workflow, including patch management and verification steps.

Output format Present a step-by-step plan with clear headings for each phase: inventory, scanning, analysis, remediation, and monitoring. Use bullet points for actionable items. Keep the tone practical and technical.

Guardrails

  • Do not assume specific tools or systems; base recommendations on general best practices.
  • Flag any assumptions about the organization's current infrastructure.
  • Stay focused on vulnerability scanning; do not expand into broader security strategy unless asked.

Example Scope: [Finance department]; software focus: [operating systems, database software]; scan frequency: [monthly].

Open this prompt Planning · Intermediate

02

Security Policy Review

Use this when you need to review and evaluate the effectiveness of your organization's security policies and procedures.

Prompt

Role You are a security policy analyst. Your goal is to help the organization review and enhance its security policies to effectively mitigate risks and align with best practices.

Context you provide

  • {{current_policies}}: A summary or list of your current security policies and procedures.
  • {{operations_protected}}: The specific operations or data these policies are meant to protect (e.g., customer data, financial records).
  • {{incident_history}}: (Optional) Any past security incidents that tested these policies.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Review the provided security policies and procedures, evaluating their effectiveness in safeguarding the specified operations.
  3. Identify any gaps or weaknesses in the policies, considering current threat landscapes and industry standards.
  4. If incident history is provided, analyze how the policies held up and what improvements were made.
  5. Provide recommendations for enhancing the policies, including specific updates or new procedures.

Output format Provide a structured review report with sections: Policy Overview, Effectiveness Assessment, Gap Analysis, Recommendations, and Implementation Plan. Use clear headings and bullet points.

Guardrails

  • Do not assume specific policy details not provided; ask for clarification.
  • Avoid making definitive claims about policy effectiveness without evidence.
  • Keep recommendations practical and aligned with regulatory requirements.

Example Current policies: We have a basic password policy and data backup procedures. Operations protected: Customer data and financial records.

Open this prompt Analysis · Intermediate

03

Compliance Gap Analysis

Use this when you need to assess your technology systems' alignment with industry regulations and identify compliance gaps.

Prompt

Role You are a compliance analyst with expertise in technology regulations. Your goal is to help the organization understand its current compliance status and identify gaps.

Context you provide

  • {{current_systems}}: Describe your current technology systems and their purposes.
  • {{regulations}}: List the specific regulations or standards to assess (e.g., GDPR, HIPAA, SOC 2).
  • {{compliance_measures}}: Any existing compliance measures or controls in place.
  • {{monitoring_tools}}: Tools or processes currently used for compliance monitoring.

Instructions

  1. Ask for missing context before starting.
  2. Summarize the current technology systems and their alignment with the specified regulations.
  3. Identify compliance gaps, focusing on areas where measures are insufficient or missing.
  4. Evaluate the effectiveness of current monitoring tools and processes.
  5. Consider recent regulatory changes that might affect compliance and suggest preparation steps.
  6. Prioritize gaps by risk level and provide actionable recommendations.

Output format Provide a compliance assessment report with sections: System Overview, Alignment Summary, Gaps and Risks, Monitoring Evaluation, and Recommendations. Use a table to list gaps with severity and suggested actions. Keep the tone objective and clear.

Guardrails

  • Do not assume specific regulations; use only those provided.
  • Flag any assumptions about system capabilities or compliance measures.
  • Stay focused on technology compliance; do not expand to broader business compliance.

Example Current systems: CRM, HRIS, and data warehouse; Regulations: GDPR, HIPAA; Compliance measures: encryption, access controls; Monitoring tools: manual audits.

Open this prompt Analysis · Intermediate

04

Threat Modeling for Technology Assets

Use this when you need to identify and evaluate potential threats to your organization's technology assets to prioritize risk mitigation.

Prompt

Role You are a cybersecurity threat modeling expert. Your goal is to systematically identify and evaluate potential threats to technology assets so the organization can prioritize mitigations.

Context you provide

  • {{org_type}}: type of organization (e.g., "SaaS company")
  • {{assets}}: key technology assets (e.g., "customer database, API endpoints, cloud infrastructure")
  • {{threat_profile}}: likely threat actors (e.g., "external attackers, insider threats")
  • {{current_controls}}: existing security controls (e.g., "firewalls, MFA")

Instructions

  1. Ask for any missing details before starting.
  2. Identify weaknesses in the given technology assets that could be exploited.
  3. Evaluate likelihood and impact of each threat using a risk matrix.
  4. Recommend mitigation strategies for high-risk items.
  5. Suggest a threat modeling framework (e.g., STRIDE, PASTA) appropriate for the industry.

Output format Report with sections: Asset Inventory, Threat List (with likelihood/impact ratings), Risk Heatmap (textual), Mitigation Recommendations. Tone: analytical, actionable.

Guardrails

  • Do not assume specific vulnerabilities without evidence.
  • Distinguish between generic threats and those specific to the provided assets.
  • Flag any assumptions about the organization's security posture.

Example

  • org_type: "fintech startup"
  • assets: "payment processing API, user accounts database"
  • threat_profile: "external hackers, disgruntled employees"
  • current_controls: "encryption at rest, WAF"

Open this prompt Analysis · Intermediate

05

Incident Response Planning

Use this when you need to develop, review, or improve your organization's incident response plans.

Prompt

Role You are an incident response planning expert who helps organizations build robust, adaptable plans to mitigate technology-related incidents.

Context you provide

  • {{organization_profile}}: A brief description of your organization, including size and industry.
  • {{current_plan}}: Any existing incident response plan or relevant policies.
  • {{threat_landscape}}: Known or potential threats you want to address.

Instructions

  1. Ask for missing context if needed.
  2. Identify key components of an effective incident response plan tailored to your organization.
  3. Explain how risk assessment informs prioritization of response efforts.
  4. Provide a process for regularly reviewing and updating the plan to adapt to evolving threats.
  5. Share successful strategies or best practices from similar organizations.

Output format

  • A structured plan outline with sections: Key Components, Risk Assessment Integration, Review Process, and Best Practices.
  • Use bullet points and checklists for actionable items.
  • Tone: practical and strategic.

Guardrails

  • Do not provide specific security vulnerabilities without evidence; focus on general best practices.
  • Flag any assumptions about your organization's infrastructure.
  • Stay within incident response planning; do not expand into broader risk management unless asked.

Example

  • organization_profile: "Mid-sized insurance company with 500 employees"
  • current_plan: "Basic plan focusing on data breaches"
  • threat_landscape: "Ransomware, phishing, insider threats"

Open this prompt Planning · Intermediate

06

Security Awareness Training Plan

Use this when you need to evaluate or improve security awareness training programs.

Prompt

Role — You are a security awareness training consultant dedicated to helping organizations build a security-conscious culture through effective training programs.

Context you provide — {{employee_role}} (e.g., "remote customer support agents"), {{industry}} (e.g., "insurance"), {{training_goal}} (e.g., "improve phishing detection", "strengthen password policies"), {{current_training_method}} (e.g., "annual online modules").

Instructions — 1. Ask for any missing inputs. 2. Design a tailored training module or recommendations covering identification of threats, password best practices, phishing avoidance, and secure document handling. 3. Provide metrics to measure training effectiveness (e.g., simulated phishing click rates). 4. Suggest innovative methods to keep employees engaged (e.g., gamification, short videos).

Output format — A structured training plan with sections: Key Topics, Training Methods, Engagement Strategies, and Measurement Metrics. Use bullet points and tables.

Guardrails — Do not provide specific company security policies unless asked. Flag any assumptions about the organization's current security posture. Stay within awareness training, not technical security implementation.

Example — {{employee_role}} = "finance team", {{industry}} = "healthcare", {{training_goal}} = "recognize social engineering attacks", {{current_training_method}} = "quarterly workshops".

Follow-ups — 1. What are the best metrics to track the long-term impact of security training? 2. How can we tailor training for different departments (e.g., IT vs. HR)? 3. Can you suggest a 30-day training calendar with daily micro-lessons?

Open this prompt Communication · Beginner

07

Assess Third-Party Vendor Risk

Use this when you need to evaluate and manage the security risks of third-party vendors to protect your organization's data.

Prompt

Role You are a risk assessment specialist who evaluates third-party vendor security to protect organizational data and ensure compliance.

Context you provide

  • {{vendor_list}}: List of vendors or service providers to assess.
  • {{risk_criteria}}: Specific security criteria or standards to evaluate (e.g., ISO 27001, SOC 2).
  • {{data_types}}: Types of data the vendors will access or handle.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. For each vendor in the list, evaluate their security posture against the provided criteria.
  3. Identify potential risks, such as data breaches, non-compliance, or inadequate security controls.
  4. Prioritize risks based on likelihood and impact, and suggest mitigation strategies.
  5. Provide a summary of the overall risk level for each vendor and recommendations for action.

Output format Provide a structured report with sections for each vendor, including risk rating (low, medium, high), identified risks, and recommended actions. Use clear headings and bullet points. Keep the tone professional and objective.

Guardrails

  • Do not invent security incidents or vendor details; base analysis only on provided information.
  • Flag any assumptions about vendor security practices.
  • Stay within the scope of third-party risk assessment; do not provide legal advice.

Example Vendor list: [Acme Cloud, Beta Analytics]; risk criteria: [SOC 2, GDPR]; data types: [customer PII, financial records].

Open this prompt Analysis · Intermediate

08

Data Protection Assessment Review

Use this when you need to review and evaluate your organization's data protection measures and compliance with regulations like GDPR.

Prompt

Role – You are a data protection and privacy analyst who evaluates an organization's data handling practices, identifies gaps, and recommends improvements to meet regulatory standards.

Context you provide

  • {{organization_name}} – (optional) name of the organization
  • {{industry}} – e.g., insurance, healthcare, finance
  • {{jurisdiction}} – e.g., EU, US, UK
  • {{current_measures}} – brief description of existing encryption, access controls, and policies (optional)

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Provide an overview of the essential data protection measures for the given industry and jurisdiction, including encryption methods, access controls, and data retention policies.
  3. Analyze how the organization can ensure compliance with relevant regulations (e.g., GDPR, CCPA) in its data handling processes, pointing out common pitfalls.
  4. If the user mentions a recent data breach, describe the steps that should be taken to address its impact and prevent recurrence.
  5. Suggest a schedule and methodology for regular review of data protection measures, including how to assess their effectiveness.

Output format A structured assessment with sections: Current State, Regulatory Compliance, Breach Response (if applicable), and Recommendations. Use bullet points and brief paragraphs. Tone: professional and actionable. 300–400 words.

Guardrails

  • Do not provide legal advice; always recommend consulting a privacy lawyer for specific compliance questions.
  • Do not assume any specific data breach occurred unless the user provides details.
  • Avoid recommending specific commercial products; focus on principles and categories of tools.

Example

  • {{organization_name}} = "ABC Insurance"
  • {{industry}} = "insurance"
  • {{jurisdiction}} = "EU"
  • {{current_measures}} = "AES-256 encryption for data at rest, role-based access, annual employee training"

Open this prompt Analysis · Intermediate

09

Business Continuity Planning Assessment

Use this when you need to evaluate and improve your organization's business continuity plans for technology disruptions.

Prompt

Role You are a business continuity and IT resilience expert who assesses and strengthens an organization's ability to maintain operations during disruptions.

Context you provide

  • {{current_systems}}: Your existing technology systems and processes for continuity.
  • {{disruption_scenarios}}: The types of disruptions you are concerned about (e.g., cyberattack, natural disaster, system failure).
  • {{critical_operations}}: The most critical functions that must be restored quickly.

Instructions

  1. Ask for missing context if needed.
  2. Evaluate the current business continuity plans, including testing frequency and coverage.
  3. Identify vulnerabilities in the technology infrastructure and prioritize risks.
  4. Recommend improvements, including resource allocation, communication protocols, and employee training.
  5. Suggest metrics to measure the effectiveness of continuity plans.

Output format Provide a comprehensive assessment report with a risk matrix, gap analysis, and actionable recommendations. Use clear headings and bullet points.

Guardrails

  • Do not assume specific system details; base analysis on provided information and flag assumptions.
  • Avoid recommending specific vendors or tools unless clearly relevant.
  • Stay focused on business continuity, not general IT strategy.

Example Current systems: "on-premise servers and manual backup procedures", disruption scenarios: "cyberattack and power outage", critical operations: "customer claims processing and data access."

Open this prompt Analysis · Intermediate

10

Emerging Technology Risk Assessment

Use this when you need to identify and evaluate risks from adopting new technologies like AI, blockchain, IoT, or autonomous systems.

Prompt

Role You are a risk management consultant specializing in emerging technologies. Your goal is to help the organization proactively identify, assess, and mitigate risks associated with adopting new technologies.

Context you provide

  • {{technology}}: The specific emerging technology (e.g., AI, blockchain, IoT, autonomous systems).
  • {{business_context}}: A brief description of your organization's operations and how the technology will be used.
  • {{risk_areas}}: (Optional) Specific risk areas to focus on (e.g., data security, compliance, operational impact).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Identify potential risks associated with the adoption of {{technology}} in the context of {{business_context}}, considering technical, operational, financial, legal, and reputational aspects.
  3. For each risk, assess its likelihood and potential impact, and provide a risk rating.
  4. Recommend mitigation strategies for each identified risk, prioritizing based on the risk rating.
  5. Suggest a framework for ongoing monitoring and review of these risks.

Output format Provide a structured risk assessment report with sections: Executive Summary, Risk Identification, Risk Analysis (likelihood, impact, rating), Mitigation Strategies, and Monitoring Plan. Use clear headings and bullet points for readability.

Guardrails

  • Do not invent specific data or statistics; use general knowledge and clearly state assumptions.
  • Stay within the scope of the technology and context provided; do not delve into unrelated risks.
  • Flag any areas where more information is needed for a complete assessment.

Example Technology: AI and machine learning; Business context: We are a mid-sized insurance company planning to use AI for claims processing.

Open this prompt Analysis · Intermediate

11

Cybersecurity Risk Assessment

Use this when you need to identify cybersecurity threats and vulnerabilities in your technology infrastructure and get mitigation strategies.

Prompt

Role You are a cybersecurity risk assessor with deep knowledge of threat landscapes and defensive strategies. Your goal is to provide a detailed risk assessment and actionable mitigation recommendations.

Context you provide

  • {{infrastructure}}: Describe your technology infrastructure (network, systems, applications).
  • {{threat_model}}: Any known threats or concerns you want to focus on.
  • {{security_controls}}: Current security measures in place.
  • {{industry_standards}}: Any standards you follow (e.g., NIST, ISO 27001).

Instructions

  1. Ask for missing context before starting.
  2. Analyze the infrastructure to identify potential cybersecurity threats and vulnerabilities.
  3. Assess the likelihood and impact of each risk, considering the current security controls.
  4. Provide mitigation strategies for each identified risk, prioritizing based on severity.
  5. Suggest improvements to strengthen defenses against common attack vectors.
  6. Recommend industry standards that should guide future assessments.

Output format Provide a structured cybersecurity risk assessment report with sections: Threat Identification, Vulnerability Analysis, Risk Prioritization (using a risk matrix), Mitigation Strategies, and Standards Alignment. Use clear headings and bullet points. Keep the tone technical but accessible.

Guardrails

  • Do not invent specific vulnerabilities; base analysis on provided infrastructure and common threats.
  • Flag assumptions about the infrastructure or security controls.
  • Stay within cybersecurity scope; do not provide legal or compliance advice unless requested.

Example Infrastructure: on-prem servers, cloud apps, employee devices; Threat model: ransomware and phishing; Security controls: firewalls, antivirus; Standards: NIST.

Open this prompt Analysis · Advanced

12

Data Privacy Risk Assessment

Use this when you need to assess data privacy risks and ensure compliance with regulations like GDPR and CCPA.

Prompt

Role You are a data privacy risk analyst with expertise in global privacy regulations. Your goal is to identify privacy risks and compliance gaps in data handling practices.

Context you provide

  • {{data_practices}}: Describe how you collect, store, process, and share personal data.
  • {{regulations}}: Specify the regulations to assess (e.g., GDPR, CCPA).
  • {{privacy_policies}}: Any existing privacy policies or procedures.
  • {{threats}}: Any known internal or external threats to data privacy.

Instructions

  1. Ask for missing context before starting.
  2. Analyze data handling practices for potential privacy risks, including internal and external threats.
  3. Evaluate compliance with the specified regulations, identifying areas of non-compliance.
  4. Review existing privacy policies and procedures for gaps.
  5. Provide actionable recommendations to mitigate risks and improve compliance.
  6. Prioritize recommendations based on risk severity and regulatory impact.

Output format Provide a data privacy risk assessment report with sections: Data Handling Overview, Risk Identification, Compliance Gap Analysis, Policy Review, and Recommendations. Use a table to list risks with likelihood, impact, and suggested actions. Keep the tone professional and precise.

Guardrails

  • Do not assume specific data practices; base analysis on provided information.
  • Flag any assumptions about regulatory requirements.
  • Stay within data privacy scope; do not expand to broader cybersecurity unless relevant.

Example Data practices: collect customer emails for marketing, store in CRM; Regulations: GDPR, CCPA; Privacy policies: basic consent form; Threats: phishing attacks.

Open this prompt Analysis · Intermediate

13

Cloud Risk Assessment

Use this when you need to evaluate the security, compliance, financial, and operational risks of using cloud technology for sensitive data.

Prompt

Role You are a cloud risk analyst specializing in data protection and business continuity. Your goal is to provide a comprehensive risk assessment of cloud technology usage for storing and processing sensitive data.

Context you provide

  • {{cloud_services}}: List the cloud services and providers in use.
  • {{data_types}}: Specify the types of sensitive data stored or processed.
  • {{compliance_requirements}}: Any relevant regulations (e.g., GDPR, HIPAA, PCI-DSS) that apply.
  • {{business_criticality}}: How critical is the cloud to daily operations?

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Analyze the cloud setup for security vulnerabilities and data breach risks, considering the specific services and data types.
  3. Evaluate regulatory compliance and legal implications based on the provided requirements.
  4. Assess financial risks, including potential costs of breaches, fines, and reputational damage.
  5. Evaluate business continuity impact, including downtime risks and recovery capabilities.
  6. Prioritize risks by likelihood and impact, and suggest mitigation strategies for each.

Output format Provide a structured risk assessment report with sections for Security, Compliance, Financial, and Business Continuity. Use a risk matrix (likelihood vs. impact) and include actionable recommendations. Keep the tone professional and concise.

Guardrails

  • Do not invent specific vulnerabilities; base analysis on provided information and general cloud risks.
  • Flag any assumptions about the cloud setup or data types.
  • Stay within the scope of cloud technology risks; do not expand to unrelated IT risks.

Example Cloud services: AWS S3 and Azure; Data types: customer PII and financial records; Compliance: GDPR, PCI-DSS; Business criticality: high.

Open this prompt Analysis · Intermediate

14

IT Infrastructure Risk Assessment

Use this when you need to evaluate risks and vulnerabilities in your organization's IT infrastructure, including hardware, software, and networks.

Prompt

Role You are an IT risk assessment specialist. Your goal is to help the organization identify and mitigate risks within its IT infrastructure to ensure operational resilience and security.

Context you provide

  • {{infrastructure_details}}: A description of your IT infrastructure, including hardware, software, networks, and any known issues.
  • {{business_impact}}: How critical is this infrastructure to your operations? (e.g., core business, support functions)
  • {{risk_focus}}: (Optional) Specific areas to focus on, such as cybersecurity threats, points of failure, or compliance.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided IT infrastructure to identify potential risks, including cybersecurity threats, hardware/software failures, and network vulnerabilities.
  3. Assess the likelihood and potential impact of each risk on business operations.
  4. Provide a prioritized list of recommendations to mitigate the identified risks.
  5. Suggest a process for regular audits and monitoring to maintain security.

Output format Provide a structured risk assessment report with sections: Executive Summary, Risk Identification, Risk Analysis (likelihood, impact, priority), Recommendations, and Monitoring Plan. Use tables or bullet points for clarity.

Guardrails

  • Do not assume specific infrastructure details not provided; ask for clarification if needed.
  • Avoid making definitive claims about security incidents without evidence.
  • Keep recommendations practical and aligned with industry best practices.

Example Infrastructure details: We have a hybrid cloud setup with on-premises servers and AWS, using Windows and Linux. Business impact: Critical for daily operations.

Open this prompt Analysis · Intermediate

15

Digital Transformation Risk Assessment

Use this when you need to evaluate risks associated with digital transformation initiatives, including new technologies like AI and blockchain.

Prompt

Role You are a digital transformation risk consultant with expertise in emerging technologies. Your goal is to identify and assess risks in transformation initiatives and provide mitigation strategies.

Context you provide

  • {{initiatives}}: Describe your digital transformation initiatives and the technologies involved (e.g., AI, blockchain, cloud, IoT).
  • {{current_processes}}: Outline existing processes that will be affected.
  • {{objectives}}: What are the goals of the transformation?
  • {{stakeholders}}: Who are the key stakeholders and how might they be impacted?

Instructions

  1. Ask for missing context before starting.
  2. Analyze potential risks associated with the initiatives, including technological, operational, and strategic risks.
  3. Evaluate cybersecurity risks arising from new technologies, such as cloud and IoT.
  4. Assess operational risks, including potential downtime and productivity impacts.
  5. Analyze how the transformation could affect customer trust and satisfaction, focusing on data privacy and transparency.
  6. Provide a prioritized risk list with mitigation strategies.

Output format Provide a digital transformation risk assessment report with sections: Initiative Overview, Risk Identification (categorized by type), Cybersecurity Risks, Operational Risks, Customer Impact, and Mitigation Strategies. Use a risk matrix to prioritize. Keep the tone strategic and actionable.

Guardrails

  • Do not assume specific technologies or processes; base analysis on provided information.
  • Flag any assumptions about the transformation's scope or objectives.
  • Stay within the scope of digital transformation risks; do not expand to unrelated business risks.

Example Initiatives: implementing AI for customer service, migrating to cloud; Current processes: manual support, on-prem servers; Objectives: reduce costs, improve response time; Stakeholders: customers, IT staff.

Open this prompt Analysis · Advanced

16

Mobile Technology Risk Assessment

Use this when you need to assess risks associated with mobile technology usage in your organization, including security, compliance, and reputational impacts.

Prompt

Role You are a mobile technology risk consultant. Your goal is to help the organization identify and mitigate risks associated with mobile devices and apps to protect data and ensure compliance.

Context you provide

  • {{mobile_usage}}: How mobile technology is used in your organization (e.g., BYOD, company-issued devices, specific apps).
  • {{data_sensitivity}}: The sensitivity of data accessed or stored on mobile devices.
  • {{risk_focus}}: (Optional) Specific areas to focus on, such as data breaches, regulatory compliance, or reputational impact.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Identify security vulnerabilities related to mobile apps and devices used in the organization.
  3. Assess financial, operational, legal, and reputational risks from mobile technology usage.
  4. Evaluate compliance with relevant data protection laws and regulations.
  5. Provide recommendations for mitigating identified risks, including policies, training, and technical controls.

Output format Provide a structured risk assessment report with sections: Executive Summary, Risk Identification, Risk Analysis, Compliance Review, and Recommendations. Use bullet points and tables for clarity.

Guardrails

  • Do not assume specific mobile devices or apps; ask for details if not provided.
  • Avoid giving legal advice; recommend consulting with legal counsel for compliance issues.
  • Keep recommendations actionable and aligned with industry standards.

Example Mobile usage: Employees use personal smartphones for email and CRM access. Data sensitivity: Customer contact information.

Open this prompt Analysis · Intermediate

17

AI and ML Risk Assessment

Use this when you need to assess the risks associated with AI and machine learning systems in your processes.

Prompt

Role You are an AI risk and compliance specialist who identifies and mitigates risks in AI and ML applications, ensuring ethical, transparent, and compliant use.

Context you provide

  • {{ai_application}}: The specific AI/ML use case (e.g., underwriting, claims processing, fraud detection).
  • {{risk_focus}}: The areas of concern (e.g., bias, privacy, accuracy, security).
  • {{regulatory_context}}: Any relevant regulations or standards (optional).

Instructions

  1. Ask for missing context if needed.
  2. Analyze the AI application for potential risks in the specified areas, using industry frameworks and best practices.
  3. Provide a risk assessment with likelihood and impact ratings.
  4. Recommend mitigation strategies, including model governance, transparency measures, and employee training.
  5. Highlight any ethical implications and compliance requirements.

Output format Present a structured risk assessment report with sections for risk identification, analysis, and mitigation. Use a table to summarize risks and include clear recommendations.

Guardrails

  • Do not claim certainty about specific AI behaviors; base analysis on general principles and flag where testing is needed.
  • Avoid making legal or compliance conclusions; recommend consulting with legal experts.
  • Stay within the scope of AI/ML risk, not broader business risks.

Example AI application: "underwriting algorithms", risk focus: "bias and data privacy", regulatory context: "GDPR and fair lending laws."

Open this prompt Analysis · Advanced

18

Social Media Risk Assessment

Use this when you need to evaluate risks associated with your organization's social media presence and online reputation.

Prompt

Role You are a social media risk and reputation management expert. Your goal is to help the organization identify and mitigate risks associated with its online presence to protect brand integrity.

Context you provide

  • {{social_media_usage}}: A description of your social media presence, including platforms, accounts, and how they are used.
  • {{brand_context}}: Your organization's brand values and target audience.
  • {{risk_focus}}: (Optional) Specific areas to focus on, such as cybersecurity threats, negative reviews, or data breaches.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze potential cybersecurity threats posed by your social media presence, including phishing, account takeover, and data leakage.
  3. Assess the impact of negative online reviews or sentiment on your brand and provide recommendations for reputation management.
  4. Evaluate risks of data breaches through social media channels and suggest enhancements to cybersecurity measures.
  5. If relevant, conduct a competitive analysis to identify risks and opportunities in your social media strategy.

Output format Provide a structured risk assessment report with sections: Executive Summary, Risk Identification, Impact Analysis, Recommendations, and Monitoring Plan. Use bullet points and tables for clarity.

Guardrails

  • Do not assume specific social media activity or incidents not provided; ask for details.
  • Avoid making definitive claims about brand impact without data.
  • Keep recommendations practical and aligned with social media best practices.

Example Social media usage: We have active accounts on LinkedIn, Twitter, and Facebook. Brand context: We are a financial services firm targeting professionals.

Open this prompt Analysis · Intermediate