30 Claude Prompts for Risk Assessments
Paste in your project or vendor details and Claude builds a scored risk register, mitigation plan, or owner assignment sheet you can drop straight into a status report.
In short: This page contains 30 copy-paste ready prompts, organized into 6 categories with a description and pro tip for each. The first 5 prompts are free instantly, no signup needed. Hand-curated and tested by the AI Academy team.
Risk Registers and Identification
5 promptsBuild a starting risk register from a project brief
1/30โจ What it does
Claude turns a short brief for [PROJECT NAME] into a first-draft register of a dozen-plus categorized risks. Bring it to your first planning meeting, then let the team add and cut from that list.
You are a senior risk manager who builds first-draft risk registers for new projects. <context> I am kicking off a project and need a starting risk register before the first planning meeting so the team has something concrete to react to. </context> <inputs> - Project name: [PROJECT NAME] - Project summary: [ONE PARAGRAPH DESCRIPTION] - Timeline: [START DATE] to [END DATE] - Budget: [BUDGET AMOUNT] - Key stakeholders: [STAKEHOLDER LIST] - Known constraints: [CONSTRAINTS, e.g. FIXED DEADLINE, LIMITED STAFF] </inputs> <task> Produce a starting risk register of at least 12 risks across categories such as schedule, budget, scope, resourcing, technical, and external factors. For each risk give a short title, a one sentence description, and the category it belongs to. </task> <constraints> Write in plain business language, not academic risk theory. Do not invent stakeholder names beyond what I gave you. Keep each risk description to one sentence. Flag any risk that depends on information I have not provided as [NEEDS CONFIRMATION]. </constraints> <format> Return a table with columns: ID, Risk Title, Category, Description, Needs Confirmation (Yes or No). </format>
Pro tip: Run this before the kickoff meeting so the team edits an existing draft instead of staring at a blank register.
Extract hidden risks from a meeting transcript
2/30โจ What it does
Claude pulls unlogged risks out of [PASTE TRANSCRIPT OR NOTES] and writes them as formal risk statements. Add the new ones to your register before the next stand-up, then drop anything that is just a task.
You are a risk analyst who reads project meeting notes to surface risks nobody has formally logged. <context> Our team talks about problems informally in meetings but nobody writes them down as risks, so they resurface later as surprises. </context> <inputs> - Meeting transcript or notes: [PASTE TRANSCRIPT OR NOTES] - Project name: [PROJECT NAME] - Existing risk register (if any): [PASTE EXISTING RISKS OR WRITE NONE] </inputs> <task> Read the transcript and pull out every statement that implies a risk, concern, or unresolved dependency, even if nobody labeled it as a risk. Convert each into a formal risk statement in the format: [EVENT] could cause [IMPACT], leading to [CONSEQUENCE]. </task> <constraints> Only extract risks that are actually implied by the text, do not invent new ones. Skip anything already in the existing register unless the transcript adds new detail. Keep each risk statement under 30 words. </constraints> <format> Return a numbered list of new risk statements, followed by a short section titled Already Covered listing anything that overlaps with the existing register. </format>
Pro tip: Paste in Slack threads too, not just formal meeting minutes, since that is often where real risks first surface.
Draft a risk breakdown structure by category
3/30โจ What it does
Claude reorganizes [PASTE LIST OF RISKS] into a categorized breakdown so leadership can see which groups carry the most exposure. Present the hierarchy, not the flat list, then focus your meeting on the heaviest category.
You are a project management consultant who organizes risks into a clean risk breakdown structure. <context> I have a messy flat list of risks and need them organized into a hierarchy so leadership can see which categories carry the most exposure. </context> <inputs> - Flat list of risks: [PASTE LIST OF RISKS] - Project type: [PROJECT TYPE, e.g. SOFTWARE ROLLOUT, CONSTRUCTION, MERGER] - Preferred top-level categories (optional): [CATEGORIES OR WRITE NONE] </inputs> <task> Group the risks into a two-level risk breakdown structure with top-level categories and, under each, the specific risks that belong there. Suggest categories yourself if none were given. </task> <constraints> Use no more than 6 top-level categories. Do not drop any risk from the original list. Note any risk that could reasonably fit two categories and explain the choice in one line under [NOTE]. </constraints> <format> Return an indented outline: top-level category as a heading, risks listed underneath as bullets, with the ambiguous ones flagged inline. </format>
Pro tip: Ask for a second pass ranking categories by risk count so you know where to focus review time first.
Compare a risk register against industry-standard categories
4/30โจ What it does
Claude compares your register to standard categories for the industry and flags the gaps. Add the missing categories before you present, then keep a note of what you still chose not to log.
You are a risk management auditor who checks registers for blind spots against standard risk taxonomies. <context> I want to know what my team's risk register is missing before I present it to leadership, since gaps look worse discovered later than caught now. </context> <inputs> - Current risk register: [PASTE RISK REGISTER] - Industry or domain (for example healthcare IT, logistics, or retail): [INDUSTRY OR DOMAIN] - Project size: [SMALL, MEDIUM, OR LARGE] </inputs> <task> Compare the current register against the standard risk categories typically seen in that industry (such as regulatory, cybersecurity, third-party, operational, financial, reputational) and identify which categories are missing or thin. </task> <constraints> Be specific about which categories are underrepresented, not just a generic checklist. Do not fabricate compliance requirements you are not confident apply to this industry, mark uncertain ones as [VERIFY WITH LEGAL]. Limit the response to the gaps only, not a rewrite of the whole register. </constraints> <format> Return a table with columns: Missing or Thin Category, Why It Matters Here, Suggested Risk to Add. </format>
Pro tip: Run this quarterly since new categories like AI vendor risk or data residency rules keep appearing over time.
Turn a customer complaint pattern into logged risks
5/30โจ What it does
Claude converts recurring customer complaint patterns into formal, trackable risk entries. Log those entries this week, then stop treating the same tickets in your queue as one-offs.
You are a customer experience risk analyst who converts recurring complaint themes into formal risk entries. <context> We get repeated customer complaints about the same handful of issues and I want those patterns treated as tracked risks instead of one-off tickets. </context> <inputs> - Complaint summary or ticket excerpts: [PASTE COMPLAINT DATA] - Product or service affected: [PRODUCT OR SERVICE NAME] - Volume or frequency, if known: [FREQUENCY, e.g. 40 TICKETS PER MONTH] </inputs> <task> Identify the recurring themes in the complaints and write each as a risk entry describing the trigger, the business impact if it continues unaddressed, and who it likely affects. </task> <constraints> Group near-duplicate complaints into a single risk rather than listing each ticket separately. Do not exaggerate impact beyond what the complaint volume supports. Note where more data is needed with [NEEDS DATA]. </constraints> <format> Return a table with columns: Risk Title, Trigger Pattern, Business Impact, Affected Segment, Confidence (High, Medium, Low). </format>
Pro tip: Feed it a full quarter of ticket data rather than a single week so the patterns Claude finds are real, not noise.
Likelihood and Impact Scoring
5 promptsScore a risk list on a 5x5 likelihood and impact matrix
6/30โจ What it does
Claude scores every item in [PASTE RISK LIST] on a 5 by 5 likelihood and impact matrix and ranks the results. Use the ranking to decide where you spend time this week, then leave the low scores until the top ones move.
You are a quantitative risk analyst who scores risks on a standard 5 by 5 likelihood and impact matrix. <context> I have a list of identified risks and need each one scored consistently so we can rank them and decide what gets attention first. </context> <inputs> - Risk list: [PASTE RISK LIST] - Likelihood scale definition (for example 1 equals rare, 5 equals almost certain): [LIKELIHOOD SCALE DEFINITION] - Impact scale definition (for example 1 equals negligible, 5 equals severe): [IMPACT SCALE DEFINITION] - Project context for judging severity: [BUDGET, USER COUNT, OR CONTRACT VALUE] </inputs> <task> Assign a likelihood score from 1 to 5 and an impact score from 1 to 5 to each risk, calculate the resulting risk score as likelihood times impact, and give a one sentence justification for each score. </task> <constraints> Apply the scales consistently across all risks, do not let scores drift based on how alarming a risk sounds. Where you are genuinely unsure of the score, say so with [LOW CONFIDENCE SCORE] rather than guessing silently. Keep justifications to one sentence each. </constraints> <format> Return a table with columns: Risk Title, Likelihood, Impact, Risk Score, Justification, sorted by Risk Score descending. </format>
Pro tip: Give it your own scale definitions rather than a generic one so scores match how your organization already talks about severity.
Recalculate risk scores after a mitigation is applied
7/30โจ What it does
Claude recalculates residual scores after mitigations, with a reason for each change. Show your leadership the residual column, not only the original scores, then update the register.
You are a risk manager who recalculates residual risk after mitigations are put in place. <context> We have applied mitigations to several risks and I need updated residual scores to show leadership the improvement, not just the original inherent risk. </context> <inputs> - Original risk scores: [PASTE RISK TITLE, LIKELIHOOD, IMPACT PAIRS] - Mitigations applied per risk: [PASTE MITIGATION DESCRIPTIONS] - Scoring scale: [SCALE DEFINITION, e.g. 1 TO 5] </inputs> <task> For each risk, estimate the new residual likelihood and impact after the stated mitigation, explain the reasoning for the change, and calculate the residual risk score alongside the original inherent score. </task> <constraints> Do not reduce a score to zero unless the mitigation fully eliminates the risk, most mitigations only reduce likelihood or impact, not both to nothing. Be explicit when a mitigation only partially addresses the risk. Flag any mitigation that sounds aspirational rather than implemented as [VERIFY IMPLEMENTATION STATUS]. </constraints> <format> Return a table with columns: Risk Title, Inherent Score, Mitigation Summary, Residual Likelihood, Residual Impact, Residual Score, Reasoning. </format>
Pro tip: Ask for inherent versus residual scores side by side, since that comparison is what most steering committees actually want to see.
Translate a heat map into a plain-English priority summary
8/30โจ What it does
Claude converts a scored heat map into a short plain-English priority summary for non-technical stakeholders. Send the narrative instead of the grid, then keep the matrix in your appendix.
You are a risk communications specialist who explains a risk heat map to non-technical stakeholders. <context> I have a scored risk matrix but the executives I report to do not want a grid, they want a short written explanation of what matters most. </context> <inputs> - Scored risk list: [PASTE RISK TITLE, LIKELIHOOD, IMPACT, SCORE] - Audience: [BOARD, CLIENT, OR DEPARTMENT HEAD] - Reporting period: [REPORTING PERIOD] </inputs> <task> Write a short narrative summary that groups the risks into red, amber, and green tiers based on their scores, and explain in plain language what the top 3 red risks mean for the business if nothing changes. </task> <constraints> Avoid risk management jargon like inherent, residual, or heat map in the summary itself, write for someone who has never seen a risk matrix. Keep the whole summary under 300 words. Do not soften the top risks just to sound reassuring. </constraints> <format> Return a short memo with a one paragraph overview, then three short paragraphs for the top 3 red risks, then a one line closing statement on overall trend. </format>
Pro tip: Send the memo version to executives and keep the raw matrix for the working team, both audiences read risk differently.
Stress test likelihood assumptions with a devil's advocate pass
9/30โจ What it does
Claude challenges optimistic likelihood scores with evidence-based pushback before the steering committee. Raise every score you cannot defend, then take the honest version to the committee.
You are a skeptical risk reviewer whose job is to challenge overly optimistic likelihood estimates. <context> I worry my team scores likelihood too low because we want the project to look on track, and I want an honest second opinion before this goes to the steering committee. </context> <inputs> - Risk list with current likelihood scores: [PASTE RISK TITLE AND LIKELIHOOD] - Project history or past incidents, if any: [PASTE RELEVANT HISTORY OR WRITE NONE] - Team's general track record (for example often misses deadlines by 2 weeks): [TEAM TRACK RECORD] </inputs> <task> For each risk, argue the case for why the likelihood might actually be higher than scored, citing the history or track record provided. Recommend which scores you think should be revised upward and by how much. </task> <constraints> Only push back where you have a concrete reason from the inputs, do not manufacture doubt for every single risk. Be direct but not alarmist. If a score genuinely looks fair, say so instead of forcing a change. </constraints> <format> Return a table with columns: Risk Title, Current Likelihood, Challenge Argument, Recommended Likelihood, Recommendation Strength (Strong, Moderate, None). </format>
Pro tip: Feed it real project history, like a list of past missed deadlines, so the pushback is grounded rather than generic caution.
Build a cost-of-risk estimate from scored risks
10/30โจ What it does
Claude converts qualitative scores into rough dollar exposure so you can justify a mitigation budget. Attach those dollar ranges to the budget request, then be ready to explain the rough math.
You are a financial risk analyst who converts qualitative risk scores into rough dollar exposure estimates. <context> Leadership wants to know the financial exposure behind our risk register, not just a 1 to 5 score, so I can justify budget for mitigation work. </context> <inputs> - Scored risk list: [PASTE RISK TITLE, LIKELIHOOD, IMPACT] - Financial context: [CONTEXT, e.g. PROJECT BUDGET, CONTRACT VALUE, DAILY REVENUE] - Rough impact-to-dollar mapping if you have one: [MAPPING OR WRITE NONE] </inputs> <task> For each risk, estimate a rough dollar exposure range by combining the likelihood percentage with an estimated cost if the risk occurs, using the financial context provided. Sum the top risks into a total expected exposure figure. </task> <constraints> Be explicit that these are rough order-of-magnitude estimates, not actuarial figures, and label them [ESTIMATE, NOT AUDITED]. Do not present the total as a precise number, round to sensible figures. State your assumptions for each estimate. </constraints> <format> Return a table with columns: Risk Title, Likelihood Percent, Estimated Cost If Occurs, Expected Exposure, Assumption, followed by a one line total expected exposure across all risks. </format>
Pro tip: Use the output to open a budget conversation, not to close one, treat the numbers as a starting estimate a finance partner should sanity check.
Mitigation Planning
5 promptsDraft mitigation options for a single high-priority risk
11/30โจ What it does
Claude generates four concrete mitigation options for [PASTE RISK STATEMENT], with cost and residual score estimates. Pick one option with your sponsor, then stop treating monitor as the plan.
You are a risk mitigation planner who develops concrete response options for high priority risks. <context> I have one risk that scored high on our matrix and need a real set of response options before I meet with the sponsor, not just a vague action item. </context> <inputs> - Risk statement: [PASTE RISK STATEMENT] - Current likelihood and impact scores: [SCORES] - Available budget or resources: [BUDGET OR RESOURCE CONSTRAINT] - Timeline pressure: [TIMELINE, e.g. MUST BE RESOLVED IN 30 DAYS] </inputs> <task> Propose four mitigation strategies covering avoid, reduce, transfer, and accept, each with a short description of what it would actually involve doing, the rough cost or effort, and the expected residual score after applying it. </task> <constraints> Make each option genuinely actionable, not a restatement of the risk. Be honest about tradeoffs, including where accept is the realistic option given the budget stated. Do not recommend transfer options like insurance unless they are plausible for this situation. </constraints> <format> Return a table with columns: Strategy Type, What It Involves, Rough Cost or Effort, Expected Residual Score, followed by a one sentence recommendation on which option to pick. </format>
Pro tip: Ask it to also flag which option needs sponsor approval versus which the team can just execute, that split speeds up the actual meeting.
Turn mitigation ideas into an action plan with deadlines
12/30โจ What it does
Claude breaks [PASTE MITIGATION IDEAS] into a dated, owned action plan you can drop into a tracker. Assign the owners in the same meeting, then put the dates on the calendar that day.
You are a program manager who converts approved mitigation ideas into a trackable action plan. <context> We agreed on mitigation approaches in a meeting but nothing has been turned into concrete tasks with dates, so nothing is actually moving. </context> <inputs> - Approved mitigation ideas: [PASTE MITIGATION IDEAS] - Team members available: [NAMES OR ROLES] - Overall deadline for mitigation to be in place: [DEADLINE] </inputs> <task> Break each mitigation idea into 2 to 4 concrete tasks, assign a suggested owner from the team members given, and propose a realistic due date working backward from the overall deadline. </task> <constraints> Do not assign every task to one person, distribute across the roles given based on likely fit. Keep task descriptions action oriented, starting with a verb. Flag any mitigation idea that seems too vague to convert into tasks as [NEEDS CLARIFICATION]. </constraints> <format> Return a table with columns: Mitigation, Task, Suggested Owner, Due Date, Status (Not Started). </format>
Pro tip: Paste the output straight into your task tool's CSV import format so the plan does not sit stuck in a document.
Write a contingency plan for a risk that has materialized
13/30โจ What it does
Claude writes an immediate 24-hour contingency plan for a logged risk that has already started happening. Follow the first-day steps now, then brief the sponsor on what you are doing.
You are an incident response planner who writes contingency plans for risks that have already started to occur. <context> A risk we logged has started happening and I need an immediate contingency plan, not a theoretical mitigation, because we are already reacting to it. </context> <inputs> - What is happening right now: [DESCRIPTION OF CURRENT SITUATION] - Original risk it relates to: [ORIGINAL RISK STATEMENT] - Stakeholders who need to be informed: [STAKEHOLDER LIST] - Resources currently available to respond: [AVAILABLE RESOURCES] </inputs> <task> Write a contingency plan covering the immediate actions to take in the next 24 hours, who needs to be notified and in what order, and the criteria for declaring the situation resolved. </task> <constraints> Be concrete about the first 24 hours, avoid generic advice like monitor the situation. Order the notification list by urgency, not alphabetically. Do not promise a resolution timeline you cannot support from the inputs given. </constraints> <format> Return three sections: Immediate Actions (numbered list), Notification Order (numbered list with reason), Resolution Criteria (bulleted list). </format>
Pro tip: Keep a version of this prompt saved separately from your normal risk workflow so it is ready to fire the moment something breaks.
Estimate the cost-benefit of a proposed mitigation
14/30โจ What it does
Claude compares a proposed mitigation's cost against the exposure it would reduce. Approve the spend only if the reduction is worth it to you, then send that comparison with the budget request.
You are a finance-minded risk advisor who checks whether a proposed mitigation is worth its cost. <context> Someone has proposed a mitigation for a risk and I need to know if the spend is actually justified before I approve the budget. </context> <inputs> - Risk and its estimated financial exposure: [RISK AND EXPOSURE ESTIMATE] - Proposed mitigation and its cost: [MITIGATION DESCRIPTION AND COST] - Expected reduction in likelihood or impact: [EXPECTED REDUCTION] </inputs> <task> Calculate the expected exposure before and after the mitigation, compare that reduction in expected exposure to the mitigation's cost, and give a clear recommendation on whether the spend is justified. </task> <constraints> Show the arithmetic plainly so a non-finance stakeholder can follow it. Do not recommend approval just because the exposure number is large, compare it directly to the cost. State clearly if the inputs are too rough to support a confident recommendation. </constraints> <format> Return a short breakdown: Exposure Before, Exposure After, Reduction in Exposure, Mitigation Cost, Net Benefit, Recommendation (Approve, Reject, Needs More Data). </format>
Pro tip: Use this before, not after, a mitigation is approved, it works best as a gate rather than a retrospective justification.
Design a fallback plan if the primary mitigation fails
15/30โจ What it does
Claude defines a measurable failure signal and a ready fallback for when the primary mitigation on [RISK STATEMENT] does not work. Agree the signal with the owner, then keep the fallback written down before you need it.
You are a contingency planner who designs backup plans in case a primary mitigation does not work as expected. <context> We have a mitigation in progress but I want a fallback ready in case it fails, rather than scrambling to invent one under pressure. </context> <inputs> - Risk being mitigated: [RISK STATEMENT] - Primary mitigation in progress: [MITIGATION DESCRIPTION] - Earliest point we would know the primary mitigation is failing: [TRIGGER OR SIGNAL] - Resources that would be available if we need to fall back: [AVAILABLE RESOURCES] </inputs> <task> Define the specific signal that would tell us the primary mitigation is failing, then propose a fallback plan that could be activated at that point, including the first three actions to take. </task> <constraints> Make the failure signal measurable, not a vague feeling that things are going wrong. Keep the fallback plan realistic given the stated available resources, do not assume unlimited budget or staff. Note any dependency the fallback has on decisions made now. </constraints> <format> Return three sections: Failure Signal (one clear sentence), Fallback Plan Summary (one paragraph), First Three Actions (numbered list). </format>
Pro tip: Set a calendar reminder to check the failure signal at the midpoint of the mitigation timeline, not just at the deadline.
These prompts give you the what. Tutorials give you the why.
Learn when to use extended thinking, how to build Claude Projects, and workflows that compound. 300+ tutorials and growing.
Risk Ownership and Accountability
5 promptsAssign owners to an unowned risk register
16/30โจ What it does
Claude assigns a justified owner from your team's roles to every item in [PASTE RISK LIST]. Confirm each person accepts the watch, then publish the owned register.
You are an operations manager who assigns clear ownership to risks that currently have none. <context> Our risk register has risks listed but no owners, which means nobody is actually accountable for watching or acting on them. </context> <inputs> - Risk list: [PASTE RISK LIST] - Team roles and responsibilities: [PASTE ROLES, e.g. PM, TECH LEAD, FINANCE PARTNER] - Any risks with existing informal owners: [PASTE IF ANY OR WRITE NONE] </inputs> <task> Assign the most appropriate owner from the given roles to each risk based on who has the authority and visibility to actually manage it, and give a one sentence reason for each assignment. </task> <constraints> Do not default every risk to the project manager, distribute based on actual fit to the role descriptions given. Where no role given clearly fits, flag it as [OWNERSHIP GAP, ESCALATE]. Keep reasons to one sentence. </constraints> <format> Return a table with columns: Risk Title, Assigned Owner, Reason for Assignment. </format>
Pro tip: Treat any [OWNERSHIP GAP, ESCALATE] flag as a real finding to bring to the sponsor, it usually means a role is missing on the team.
Write an accountability charter for a risk owner
17/30โจ What it does
Claude writes a short accountability charter stating what a risk owner must monitor and decide. Hand it to your new owner, then review it with them at the next risk meeting.
You are a governance specialist who writes clear accountability charters defining what a risk owner is actually responsible for. <context> We assign risk owners but they are not always clear on what the role requires, so risks get logged but not actively managed. </context> <inputs> - Risk owner role or name: [ROLE OR NAME] - Risk they own: [RISK STATEMENT] - Reporting cadence expected: [CADENCE, e.g. WEEKLY, MONTHLY] - Escalation path if the risk worsens: [ESCALATION CONTACT OR PROCESS] </inputs> <task> Write a short accountability charter for this risk owner covering what they must monitor, what decisions they are authorized to make on their own, and when they must escalate rather than decide alone. </task> <constraints> Keep the charter under 200 words. Be specific about the line between what the owner can decide alone and what needs escalation, avoid vague phrases like use good judgment. Reference the actual escalation contact given, not a generic one. </constraints> <format> Return three short sections: What You Monitor, What You Can Decide Alone, When You Must Escalate. </format>
Pro tip: Attach this charter to the risk register entry itself so ownership expectations travel with the risk, not in a separate document nobody reopens.
Draft an escalation policy for unresolved risks
18/30โจ What it does
Claude writes an objective escalation policy for when a stalled risk must move to a higher level. Publish the rule with your review cadence, then follow it the first time a date slips.
You are a risk governance consultant who designs escalation policies for risks that stall past their review dates. <context> Risks sit on our register without progress for weeks because nobody is forced to escalate them, and I want a clear rule for when that has to happen. </context> <inputs> - Current review cadence: [REVIEW CADENCE] - Organizational levels available for escalation: [TEAM LEAD, DIRECTOR, OR VP] - Risk severity tiers in use: [HIGH, MEDIUM, OR LOW] </inputs> <task> Write an escalation policy defining, for each severity tier, how many review cycles a risk can go without meaningful progress before it must escalate to the next organizational level, and what counts as meaningful progress. </task> <constraints> Make the trigger conditions objective and countable, such as number of cycles with no status change, not subjective judgment calls. Keep the policy to one page equivalent. Do not create more escalation levels than the ones given. </constraints> <format> Return a table with columns: Severity Tier, Cycles Without Progress Before Escalation, Escalates To, Definition of Meaningful Progress. </format>
Pro tip: Pilot the policy on your highest severity tier first for one review cycle before rolling it out to every tier at once.
Prepare talking points for a risk owner who missed a deadline
19/30โจ What it does
Claude prepares direct, non-accusatory talking points for a one-on-one about a missed mitigation deadline. Use them in the next meeting, then leave with a new date you both accept.
You are a program manager preparing to have a direct but constructive conversation with a risk owner who missed their mitigation deadline. <context> A risk owner missed the deadline for their mitigation task and I need to raise it in our next one-on-one without it turning into a blame session. </context> <inputs> - Risk and mitigation task that was due: [RISK AND TASK] - Original deadline and how late it now is: [DEADLINE AND CURRENT DELAY] - Any context you already know about the delay: [CONTEXT OR WRITE UNKNOWN] - Relationship with this person: [RELATIONSHIP, e.g. PEER, DIRECT REPORT, VENDOR CONTACT] </inputs> <task> Write talking points for the conversation that acknowledge the delay factually, ask an open question about what got in the way, and propose a revised deadline with a specific check-in point before it arrives again. </task> <constraints> Keep the tone direct but not accusatory, avoid words like failed or unacceptable. Do not assume the reason for the delay if it is unknown, ask rather than guess. Keep the talking points to five bullet points or fewer. </constraints> <format> Return a bulleted list of talking points in the order they should be raised in the conversation. </format>
Pro tip: Always propose the revised deadline with a check-in point attached, a bare new deadline tends to slip the same way the first one did.
Build a RACI matrix for cross-team risk ownership
20/30โจ What it does
Claude builds a matrix of who is responsible, accountable, consulted, and informed for a shared set of risks. Walk it with each of your teams, then post it where those risks are reviewed.
You are an operations consultant who builds RACI matrices to clarify risk ownership across multiple teams. <context> A set of risks touches several teams and it is unclear who is responsible, who is accountable, who should be consulted, and who just needs to be informed. </context> <inputs> - Risk list: [PASTE RISK LIST] - Teams involved: [TEAM NAMES, e.g. ENGINEERING, LEGAL, VENDOR MANAGEMENT] - Known team responsibilities: [SHORT DESCRIPTION OF WHAT EACH TEAM HANDLES] </inputs> <task> Build a RACI matrix assigning Responsible, Accountable, Consulted, and Informed roles to the relevant teams for each risk, based on the responsibilities described. </task> <constraints> Each risk should have exactly one Accountable team, do not assign more than one. Do not assign a role to a team with no plausible connection to the risk based on the descriptions given. Flag any risk where no team seems clearly Accountable as [OWNERSHIP GAP]. </constraints> <format> Return a table with rows as risks and columns as team names, with cell values R, A, C, I, or blank. </format>
Pro tip: Review the matrix in a joint meeting with all teams present, RACI disagreements are easier to resolve live than over email.
Risk Reporting and Communication
5 promptsWrite a monthly risk summary for a steering committee
21/30โจ What it does
Claude writes a concise, decision-focused monthly risk summary for a time-limited steering committee. Lead with the ask, then send the page the day before your meeting.
You are a program manager who writes concise monthly risk summaries for a steering committee. <context> I need to report on our risk register status to a steering committee that has limited time and wants the headline, not the full detail. </context> <inputs> - Current risk register with scores and status: [PASTE RISK DATA] - Changes since last report: [NEW RISKS, CLOSED RISKS, OR ESCALATIONS] - Reporting period: [REPORTING PERIOD] </inputs> <task> Write a one page monthly risk summary covering overall risk trend since last period, the top 3 risks needing committee attention, and any risks that were closed or newly opened. </task> <constraints> Keep the entire summary under 350 words. Lead with the trend, not a list, executives want direction before detail. Avoid restating the full register, focus only on what changed and what needs a decision. </constraints> <format> Return a one page memo with sections: Overall Trend, Top 3 Risks Needing Attention, Closed This Period, New This Period. </format>
Pro tip: Keep the full register as an appendix link rather than pasting it into the memo, committees skim past long tables.
Translate technical risk into client-facing language
22/30โจ What it does
Claude translates an internal technical risk into an honest, jargon-free client update email. Tone-check it for unnecessary alarm, then send it once the facts are ones you would stand behind.
You are a client relationship manager who translates internal technical risk assessments into language a client can understand. <context> I need to tell a client about a risk affecting their project without alarming them unnecessarily or using internal jargon they will not follow. </context> <inputs> - Internal risk description: [PASTE TECHNICAL RISK DESCRIPTION] - What this means for the client's timeline or deliverable: [IMPACT ON CLIENT] - What we are doing about it: [MITIGATION IN PROGRESS] - Client relationship tone: [TONE, e.g. FORMAL, CASUAL, LONG-TERM PARTNER] </inputs> <task> Write a short client-facing message that explains the situation in plain language, states the impact on their timeline or deliverable honestly, and describes what is being done without overpromising a fix date we cannot guarantee. </task> <constraints> Do not use internal risk management terms like inherent, residual, or risk score. Be honest about the impact, do not minimize it to avoid discomfort. Match the tone specified, do not default to overly formal language if the relationship is casual. </constraints> <format> Return a short email, no more than 150 words, with a clear subject line suggestion above it. </format>
Pro tip: Have your account lead review the draft before sending, since only they know exactly how much this specific client tolerates bad news.
Create a risk dashboard narrative from raw scores
23/30โจ What it does
Claude writes the short narrative that should sit next to your numeric risk dashboard each period. Pair it with the dashboard before you circulate numbers, then keep the same structure next month.
You are a data-literate risk reporter who writes the narrative that accompanies a numeric risk dashboard. <context> Our dashboard shows numbers and colors but nobody reads the story behind them, so I want a short narrative to pair with each reporting cycle. </context> <inputs> - Current period risk counts by tier: [CURRENT PERIOD RISK COUNTS] - Previous period counts by tier: [PREVIOUS PERIOD RISK COUNTS] - Notable individual risks worth naming: [RISK NAMES OR WRITE NONE] </inputs> <task> Write a short narrative explaining the change in risk distribution between periods, calling out whether the overall picture improved or worsened, and naming any individual risks worth specific mention. </task> <constraints> Lead with whether things got better or worse in plain terms before giving numbers. Do not claim improvement if high tier count increased even if total count dropped. Keep it under 150 words. </constraints> <format> Return a single short paragraph followed by a one line verdict: Improving, Stable, or Worsening. </format>
Pro tip: Pin the Improving, Stable, or Worsening verdict at the top of your dashboard slide, that single word gets read even when nothing else does.
Prepare answers for likely board questions on a risk
24/30โจ What it does
Claude anticipates the five hardest board questions about [RISK SUMMARY] and drafts honest answers. Rehearse the weakest answer, then take those replies into your board meeting.
You are a governance advisor who prepares executives for hard questions about a specific risk before a board meeting. <context> I am presenting a significant risk to the board and want to anticipate their questions instead of getting caught off guard. </context> <inputs> - Risk summary being presented: [RISK SUMMARY] - Current mitigation status: [MITIGATION STATUS] - Sensitive details to handle carefully: [SENSITIVE DETAILS OR WRITE NONE] - Board's general disposition: [DISPOSITION, e.g. DETAIL-ORIENTED, BIG-PICTURE, RISK-AVERSE] </inputs> <task> List the five most likely questions this board would ask about the risk given their disposition, and draft a direct, honest answer to each that does not overstate confidence in the mitigation. </task> <constraints> Do not write answers that dodge the hard question, boards notice evasiveness. Handle the sensitive details given carefully without omitting material facts. Keep each answer to two or three sentences. </constraints> <format> Return a numbered list of question and answer pairs, five in total. </format>
Pro tip: Practice the answers out loud once before the meeting, reading them silently is not the same as saying them under pressure.
Write a risk acceptance memo for sign-off
25/30โจ What it does
Claude documents a formal acceptance of [RISK STATEMENT] in memo form, with a required next review date. Get the signature on that memo, then file it in your audit trail.
You are a governance officer who documents formal risk acceptance decisions for the record. <context> Leadership has decided to accept a risk rather than mitigate it further, and I need a formal memo documenting that decision for audit purposes. </context> <inputs> - Risk being accepted: [RISK STATEMENT] - Current score and mitigations already in place: [SCORE AND EXISTING MITIGATIONS] - Reason for accepting rather than mitigating further: [REASON, e.g. COST, TIMELINE, LOW RESIDUAL IMPACT] - Approving authority: [NAME AND TITLE] </inputs> <task> Write a formal risk acceptance memo stating the risk, its current score, the reason acceptance was chosen over further mitigation, the approving authority, and the date this will next be reviewed. </task> <constraints> Use formal, precise language appropriate for an audit trail, not casual phrasing. Do not imply the risk has been resolved, acceptance is a decision, not a fix. Include a clear next review date, do not leave it open ended. </constraints> <format> Return a memo with labeled fields: Risk, Current Score, Existing Mitigations, Reason for Acceptance, Approving Authority, Next Review Date, followed by a one paragraph summary statement. </format>
Pro tip: Always set the next review date to a real calendar reminder, an accepted risk with no review date tends to be forgotten entirely.
Most people use 10% of Claude. Tutorials unlock the rest.
AI Academy: 300+ hands-on tutorials on Claude, ChatGPT, Midjourney, and 50+ AI tools. New tutorials added every week.
Vendor and Compliance Risk
5 promptsAssess risk in a new vendor contract before signing
26/30โจ What it does
Claude reviews contract terms and data access for [VENDOR NAME AND SERVICE] and flags exposure before you sign. Send the findings to legal before finalization, then do not sign until the high items are closed.
You are a vendor risk analyst who reviews contracts for risk exposure before a company signs them. <context> We are about to sign a contract with a new vendor and I want the risk exposure identified before legal finalizes it, not after. </context> <inputs> - Vendor name and service provided: [VENDOR NAME AND SERVICE] - Key contract terms: [PASTE RELEVANT TERMS, e.g. LIABILITY CAP, TERMINATION CLAUSE, SLA] - Data or systems the vendor will access: [DATA OR SYSTEM ACCESS] - Our industry's typical regulatory concerns: [REGULATORY CONTEXT] </inputs> <task> Identify the top risks in this vendor relationship covering data access, liability terms, termination and exit difficulty, and regulatory exposure, and rate each as high, medium, or low concern. </task> <constraints> Do not provide legal advice on contract language, flag anything that needs a lawyer's review as [ROUTE TO LEGAL]. Base ratings only on the terms and access described, do not assume standard industry terms if none were given. Be specific about what data or system access drives each concern. </constraints> <format> Return a table with columns: Risk Area, Specific Concern, Concern Level, Recommended Action. </format>
Pro tip: Route every [ROUTE TO LEGAL] flag as an actual line item in your review checklist, do not let this output replace a lawyer's read of the contract.
Score third-party vendors on an ongoing risk basis
27/30โจ What it does
Claude scores active vendors on data sensitivity and business criticality so you know who needs closer monitoring. Put the high-tier vendors on a review cadence, then leave the low-tier ones on a lighter check.
You are a vendor management analyst who scores existing vendors on ongoing risk exposure. <context> We have a list of active vendors and need to know which ones deserve closer monitoring based on what they access and how critical they are. </context> <inputs> - Vendor list with what each provides: [VENDOR NAME AND SERVICE PAIRS] - Data sensitivity each vendor touches: [DATA SENSITIVITY LEVEL PER VENDOR] - Business criticality if the vendor failed: [CRITICALITY PER VENDOR] </inputs> <task> Score each vendor on a combined risk basis using data sensitivity and business criticality, and recommend a monitoring tier of high, medium, or low along with a suggested review frequency for each tier. </task> <constraints> Do not assign high tier to every vendor just because data is involved, weigh both sensitivity and criticality together. Suggest realistic review frequencies, not more frequent than quarterly for medium and low tiers. Flag any vendor missing sensitivity or criticality data as [NEEDS ASSESSMENT]. </constraints> <format> Return a table with columns: Vendor, Data Sensitivity, Business Criticality, Monitoring Tier, Suggested Review Frequency. </format>
Pro tip: Re-run this whenever a vendor's contract renews, criticality and data access both tend to expand quietly over time.
Draft a compliance gap risk summary for a new regulation
28/30โจ What it does
Claude compares current practice to a new regulation and flags likely compliance gaps by risk level. Brief the owners of your high gaps, then start those fixes before the rule is enforceable.
You are a compliance risk officer who assesses exposure when a new regulation takes effect. <context> A new regulation affecting our industry is coming into effect and I need to understand where our current practices likely fall short before it becomes enforceable. </context> <inputs> - Regulation name and summary: [REGULATION NAME AND WHAT IT REQUIRES] - Our current practice in the relevant area: [CURRENT PRACTICE DESCRIPTION] - Effective date: [EFFECTIVE DATE] - Department most affected: [DEPARTMENT] </inputs> <task> Compare the regulation's requirements against our current practice, identify the specific gaps, and rate each gap by how much risk it carries if unaddressed by the effective date. </task> <constraints> Do not state definitively whether we are compliant or not, that is a legal determination, phrase findings as [LIKELY GAP] or [LIKELY COVERED] with reasoning. Flag anything requiring formal legal review as [ROUTE TO LEGAL]. Base the comparison only on the practice description given, do not assume unstated controls exist. </constraints> <format> Return a table with columns: Requirement, Our Current Practice, Gap Assessment, Risk If Unaddressed, Action Needed. </format>
Pro tip: Send the [ROUTE TO LEGAL] items to counsel well before the effective date, gap remediation almost always takes longer than expected.
Build a vendor exit risk plan before a contract ends
29/30โจ What it does
Claude assesses transition risk across data, integrations, and staffing before a vendor contract ends, with realistic lead times. Use that picture for your renew, renegotiate, or switch call, then start the long-lead items now.
You are a vendor transition planner who assesses the risk of losing or switching a critical vendor. <context> A vendor contract is ending soon and I need to understand the risk of transition before we decide whether to renew, renegotiate, or switch. </context> <inputs> - Vendor and service being provided: [VENDOR AND SERVICE] - Contract end date: [END DATE] - Dependencies on this vendor: [DEPENDENCIES, e.g. DATA FORMAT, INTEGRATIONS, STAFF TRAINING] - Known alternative vendors, if any: [ALTERNATIVES OR WRITE NONE IDENTIFIED] </inputs> <task> Identify the specific risks of transitioning away from this vendor, covering data migration, integration rework, staff retraining, and service continuity, and estimate how much lead time each risk area realistically needs before the contract end date. </task> <constraints> Be realistic about lead time, do not assume a data migration or integration rework can happen faster than typical for the dependencies described. If no alternative vendors are identified, flag that itself as a top risk. Do not recommend a specific alternative vendor by name unless one was given. </constraints> <format> Return a table with columns: Risk Area, Specific Concern, Estimated Lead Time Needed, Recommended Action, followed by a one line overall recommendation on renew versus switch given the time remaining. </format>
Pro tip: Run this at least six months before contract end, most of the lead times it surfaces exceed what a 30-day notice period allows.
Prioritize a backlog of audit findings by risk
30/30โจ What it does
Claude ranks audit findings into now, next, and later tiers by severity and regulatory deadlines. Fix the now pile in your sprint, then schedule the rest against real capacity.
You are an internal audit risk analyst who prioritizes a backlog of audit findings for remediation. <context> We have a backlog of audit findings and limited capacity to fix them all at once, so I need them ranked by actual risk rather than the order they were found. </context> <inputs> - Audit findings list: [PASTE FINDINGS LIST] - Business area each finding affects: [BUSINESS AREA PER FINDING] - Any regulatory deadlines tied to specific findings: [DEADLINES OR WRITE NONE] </inputs> <task> Rank the findings by combined severity and urgency, factoring in any regulatory deadlines, and group them into now, next, and later remediation tiers. </task> <constraints> Findings with a hard regulatory deadline should generally rank above ones without, even if the underlying severity looks similar, unless the deadline is far out. Do not put more than a third of the total findings into the now tier, that defeats the purpose of prioritization. Explain the ranking logic for the top 3 items. </constraints> <format> Return three sections, Now, Next, Later, each listing the findings assigned to it, followed by a short explanation of the top 3 rankings. </format>
Pro tip: Revisit the ranking every time a new regulatory deadline is announced, a single new deadline can reshuffle the whole now tier.
Free tool
Prompt Optimizer
Turn a rough idea into a structured, professional AI prompt.
Frequently Asked Questions
Prompts are the starting line. Tutorials are the finish.
A growing library of 300+ hands-on tutorials on ChatGPT, Claude, Midjourney, and 50+ AI tools. New tutorials added every week.
7-day free trial. Cancel anytime.
Related guides