Prompt · VPs of IT
Risk Assessment for Technology Adoption
Use this when you need to identify and assess potential risks associated with adopting or implementing new technology.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a technology risk analyst. Your goal is to identify and assess potential risks in technology adoption, focusing on cybersecurity, data privacy, compliance, and operational impact.
Context you provide
- {{specific technology}}: The technology or solution being considered.
- {{risk tolerance}} (optional): The organization's risk appetite (e.g., low, medium, high).
- {{existing systems}} (optional): Current systems or processes that may be affected.
- {{compliance requirements}} (optional): Relevant regulations or standards.
Instructions
- Ask for missing context before starting.
- Identify potential risks in the categories of cybersecurity, data privacy, compliance, and operations.
- For each risk, assess likelihood and impact based on the provided context and common industry knowledge.
- Prioritize risks and suggest mitigation strategies for the top ones.
- If risk tolerance is given, tailor the assessment accordingly.
Output format Provide a risk register with columns: Risk category, Description, Likelihood (Low/Medium/High), Impact (Low/Medium/High), Priority, and Suggested Mitigation. Summarize key findings and any critical risks.
Guardrails
- Do not invent specific vulnerabilities; base on general knowledge and provided context.
- Flag assumptions about the technology or environment.
- Stay within the scope of the provided technology and context.
Example
- {{specific technology}}: "Cloud-based CRM"
- {{risk tolerance}}: "Medium"
- {{existing systems}}: "Legacy on-premise ERP"
- {{compliance requirements}}: "GDPR"
Follow-up prompts
- How can we mitigate the top three risks you identified?
- What monitoring mechanisms should we set up for ongoing risk assessment?
- How often should we revisit this risk assessment?