Claude Prompt Library

30 Claude Prompts for Risk Assessments

30 copy-paste prompts

Paste in your project or vendor details and Claude builds a scored risk register, mitigation plan, or owner assignment sheet you can drop straight into a status report.

In short: This page contains 30 copy-paste ready prompts, organized into 6 categories with a description and pro tip for each. The first 5 prompts are free instantly, no signup needed. Hand-curated and tested by the AI Academy team.

Louis Corneloup
By Louis Corneloup ยท Founder, Techpresso
Last updated ยทHand-curated & tested by the AI Academy team

Risk Registers and Identification

5 prompts

Build a starting risk register from a project brief

1/30

โœจ What it does

Turns a short project brief into a first-draft risk register of 12+ categorized risks.

You are a senior risk manager who builds first-draft risk registers for new projects. <context> I am kicking off a project and need a starting risk register before the first planning meeting so the team has something concrete to react to. </context> <inputs> - Project name: [PROJECT NAME] - Project summary: [ONE PARAGRAPH DESCRIPTION] - Timeline: [START DATE] to [END DATE] - Budget: [BUDGET AMOUNT] - Key stakeholders: [STAKEHOLDER LIST] - Known constraints: [CONSTRAINTS, e.g. FIXED DEADLINE, LIMITED STAFF] </inputs> <task> Produce a starting risk register of at least 12 risks across categories such as schedule, budget, scope, resourcing, technical, and external factors. For each risk give a short title, a one sentence description, and the category it belongs to. </task> <constraints> Write in plain business language, not academic risk theory. Do not invent stakeholder names beyond what I gave you. Keep each risk description to one sentence. Flag any risk that depends on information I have not provided as [NEEDS CONFIRMATION]. </constraints> <format> Return a table with columns: ID, Risk Title, Category, Description, Needs Confirmation (Yes or No). </format>

๐Ÿ’ก

Pro tip: Run this before the kickoff meeting so the team edits an existing draft instead of staring at a blank register.

Extract hidden risks from a meeting transcript

2/30

โœจ What it does

Pulls unlogged risks out of raw meeting notes and writes them as formal risk statements.

You are a risk analyst who reads project meeting notes to surface risks nobody has formally logged. <context> Our team talks about problems informally in meetings but nobody writes them down as risks, so they resurface later as surprises. </context> <inputs> - Meeting transcript or notes: [PASTE TRANSCRIPT OR NOTES] - Project name: [PROJECT NAME] - Existing risk register (if any): [PASTE EXISTING RISKS OR WRITE NONE] </inputs> <task> Read the transcript and pull out every statement that implies a risk, concern, or unresolved dependency, even if nobody labeled it as a risk. Convert each into a formal risk statement in the format: [EVENT] could cause [IMPACT], leading to [CONSEQUENCE]. </task> <constraints> Only extract risks that are actually implied by the text, do not invent new ones. Skip anything already in the existing register unless the transcript adds new detail. Keep each risk statement under 30 words. </constraints> <format> Return a numbered list of new risk statements, followed by a short section titled Already Covered listing anything that overlaps with the existing register. </format>

๐Ÿ’ก

Pro tip: Paste in Slack threads too, not just formal meeting minutes, since that is often where real risks first surface.

Draft a risk breakdown structure by category

3/30

โœจ What it does

Reorganizes a flat, messy risk list into a categorized risk breakdown structure.

You are a project management consultant who organizes risks into a clean risk breakdown structure. <context> I have a messy flat list of risks and need them organized into a hierarchy so leadership can see which categories carry the most exposure. </context> <inputs> - Flat list of risks: [PASTE LIST OF RISKS] - Project type: [PROJECT TYPE, e.g. SOFTWARE ROLLOUT, CONSTRUCTION, MERGER] - Preferred top-level categories (optional): [CATEGORIES OR WRITE NONE] </inputs> <task> Group the risks into a two-level risk breakdown structure with top-level categories and, under each, the specific risks that belong there. Suggest categories yourself if none were given. </task> <constraints> Use no more than 6 top-level categories. Do not drop any risk from the original list. Note any risk that could reasonably fit two categories and explain the choice in one line under [NOTE]. </constraints> <format> Return an indented outline: top-level category as a heading, risks listed underneath as bullets, with the ambiguous ones flagged inline. </format>

๐Ÿ’ก

Pro tip: Ask for a second pass ranking categories by risk count so you know where to focus review time first.

Compare a risk register against industry-standard categories

4/30

โœจ What it does

Flags gaps in an existing risk register by comparing it to standard categories for the industry.

You are a risk management auditor who checks registers for blind spots against standard risk taxonomies. <context> I want to know what my team's risk register is missing before I present it to leadership, since gaps look worse discovered later than caught now. </context> <inputs> - Current risk register: [PASTE RISK REGISTER] - Industry or domain (for example healthcare IT, logistics, or retail): [INDUSTRY OR DOMAIN] - Project size: [SMALL, MEDIUM, OR LARGE] </inputs> <task> Compare the current register against the standard risk categories typically seen in that industry (such as regulatory, cybersecurity, third-party, operational, financial, reputational) and identify which categories are missing or thin. </task> <constraints> Be specific about which categories are underrepresented, not just a generic checklist. Do not fabricate compliance requirements you are not confident apply to this industry, mark uncertain ones as [VERIFY WITH LEGAL]. Limit the response to the gaps only, not a rewrite of the whole register. </constraints> <format> Return a table with columns: Missing or Thin Category, Why It Matters Here, Suggested Risk to Add. </format>

๐Ÿ’ก

Pro tip: Run this quarterly since new categories like AI vendor risk or data residency rules keep appearing over time.

Turn a customer complaint pattern into logged risks

5/30

โœจ What it does

Converts recurring customer complaint patterns into formal, trackable risk entries.

You are a customer experience risk analyst who converts recurring complaint themes into formal risk entries. <context> We get repeated customer complaints about the same handful of issues and I want those patterns treated as tracked risks instead of one-off tickets. </context> <inputs> - Complaint summary or ticket excerpts: [PASTE COMPLAINT DATA] - Product or service affected: [PRODUCT OR SERVICE NAME] - Volume or frequency, if known: [FREQUENCY, e.g. 40 TICKETS PER MONTH] </inputs> <task> Identify the recurring themes in the complaints and write each as a risk entry describing the trigger, the business impact if it continues unaddressed, and who it likely affects. </task> <constraints> Group near-duplicate complaints into a single risk rather than listing each ticket separately. Do not exaggerate impact beyond what the complaint volume supports. Note where more data is needed with [NEEDS DATA]. </constraints> <format> Return a table with columns: Risk Title, Trigger Pattern, Business Impact, Affected Segment, Confidence (High, Medium, Low). </format>

๐Ÿ’ก

Pro tip: Feed it a full quarter of ticket data rather than a single week so the patterns Claude finds are real, not noise.

Likelihood and Impact Scoring

5 prompts

Score a risk list on a 5x5 likelihood and impact matrix

6/30

โœจ What it does

Scores every risk in a list on likelihood and impact and ranks them by resulting risk score.

You are a quantitative risk analyst who scores risks on a standard 5 by 5 likelihood and impact matrix. <context> I have a list of identified risks and need each one scored consistently so we can rank them and decide what gets attention first. </context> <inputs> - Risk list: [PASTE RISK LIST] - Likelihood scale definition (for example 1 equals rare, 5 equals almost certain): [LIKELIHOOD SCALE DEFINITION] - Impact scale definition (for example 1 equals negligible, 5 equals severe): [IMPACT SCALE DEFINITION] - Project context for judging severity: [BUDGET, USER COUNT, OR CONTRACT VALUE] </inputs> <task> Assign a likelihood score from 1 to 5 and an impact score from 1 to 5 to each risk, calculate the resulting risk score as likelihood times impact, and give a one sentence justification for each score. </task> <constraints> Apply the scales consistently across all risks, do not let scores drift based on how alarming a risk sounds. Where you are genuinely unsure of the score, say so with [LOW CONFIDENCE SCORE] rather than guessing silently. Keep justifications to one sentence each. </constraints> <format> Return a table with columns: Risk Title, Likelihood, Impact, Risk Score, Justification, sorted by Risk Score descending. </format>

๐Ÿ’ก

Pro tip: Give it your own scale definitions rather than a generic one so scores match how your organization already talks about severity.

Recalculate risk scores after a mitigation is applied

7/30

โœจ What it does

Recalculates residual risk scores after mitigations are applied, with reasoning for each change.

You are a risk manager who recalculates residual risk after mitigations are put in place. <context> We have applied mitigations to several risks and I need updated residual scores to show leadership the improvement, not just the original inherent risk. </context> <inputs> - Original risk scores: [PASTE RISK TITLE, LIKELIHOOD, IMPACT PAIRS] - Mitigations applied per risk: [PASTE MITIGATION DESCRIPTIONS] - Scoring scale: [SCALE DEFINITION, e.g. 1 TO 5] </inputs> <task> For each risk, estimate the new residual likelihood and impact after the stated mitigation, explain the reasoning for the change, and calculate the residual risk score alongside the original inherent score. </task> <constraints> Do not reduce a score to zero unless the mitigation fully eliminates the risk, most mitigations only reduce likelihood or impact, not both to nothing. Be explicit when a mitigation only partially addresses the risk. Flag any mitigation that sounds aspirational rather than implemented as [VERIFY IMPLEMENTATION STATUS]. </constraints> <format> Return a table with columns: Risk Title, Inherent Score, Mitigation Summary, Residual Likelihood, Residual Impact, Residual Score, Reasoning. </format>

๐Ÿ’ก

Pro tip: Ask for inherent versus residual scores side by side, since that comparison is what most steering committees actually want to see.

Translate a heat map into a plain-English priority summary

8/30

โœจ What it does

Converts a scored risk matrix into a plain-English narrative summary for non-technical stakeholders.

You are a risk communications specialist who explains a risk heat map to non-technical stakeholders. <context> I have a scored risk matrix but the executives I report to do not want a grid, they want a short written explanation of what matters most. </context> <inputs> - Scored risk list: [PASTE RISK TITLE, LIKELIHOOD, IMPACT, SCORE] - Audience: [BOARD, CLIENT, OR DEPARTMENT HEAD] - Reporting period: [REPORTING PERIOD] </inputs> <task> Write a short narrative summary that groups the risks into red, amber, and green tiers based on their scores, and explain in plain language what the top 3 red risks mean for the business if nothing changes. </task> <constraints> Avoid risk management jargon like inherent, residual, or heat map in the summary itself, write for someone who has never seen a risk matrix. Keep the whole summary under 300 words. Do not soften the top risks just to sound reassuring. </constraints> <format> Return a short memo with a one paragraph overview, then three short paragraphs for the top 3 red risks, then a one line closing statement on overall trend. </format>

๐Ÿ’ก

Pro tip: Send the memo version to executives and keep the raw matrix for the working team, both audiences read risk differently.

Stress test likelihood assumptions with a devil's advocate pass

9/30

โœจ What it does

Challenges optimistic likelihood scores with evidence-based pushback before they reach a steering committee.

You are a skeptical risk reviewer whose job is to challenge overly optimistic likelihood estimates. <context> I worry my team scores likelihood too low because we want the project to look on track, and I want an honest second opinion before this goes to the steering committee. </context> <inputs> - Risk list with current likelihood scores: [PASTE RISK TITLE AND LIKELIHOOD] - Project history or past incidents, if any: [PASTE RELEVANT HISTORY OR WRITE NONE] - Team's general track record (for example often misses deadlines by 2 weeks): [TEAM TRACK RECORD] </inputs> <task> For each risk, argue the case for why the likelihood might actually be higher than scored, citing the history or track record provided. Recommend which scores you think should be revised upward and by how much. </task> <constraints> Only push back where you have a concrete reason from the inputs, do not manufacture doubt for every single risk. Be direct but not alarmist. If a score genuinely looks fair, say so instead of forcing a change. </constraints> <format> Return a table with columns: Risk Title, Current Likelihood, Challenge Argument, Recommended Likelihood, Recommendation Strength (Strong, Moderate, None). </format>

๐Ÿ’ก

Pro tip: Feed it real project history, like a list of past missed deadlines, so the pushback is grounded rather than generic caution.

Build a cost-of-risk estimate from scored risks

10/30

โœจ What it does

Converts qualitative risk scores into rough dollar exposure figures to support a mitigation budget request.

You are a financial risk analyst who converts qualitative risk scores into rough dollar exposure estimates. <context> Leadership wants to know the financial exposure behind our risk register, not just a 1 to 5 score, so I can justify budget for mitigation work. </context> <inputs> - Scored risk list: [PASTE RISK TITLE, LIKELIHOOD, IMPACT] - Financial context: [CONTEXT, e.g. PROJECT BUDGET, CONTRACT VALUE, DAILY REVENUE] - Rough impact-to-dollar mapping if you have one: [MAPPING OR WRITE NONE] </inputs> <task> For each risk, estimate a rough dollar exposure range by combining the likelihood percentage with an estimated cost if the risk occurs, using the financial context provided. Sum the top risks into a total expected exposure figure. </task> <constraints> Be explicit that these are rough order-of-magnitude estimates, not actuarial figures, and label them [ESTIMATE, NOT AUDITED]. Do not present the total as a precise number, round to sensible figures. State your assumptions for each estimate. </constraints> <format> Return a table with columns: Risk Title, Likelihood Percent, Estimated Cost If Occurs, Expected Exposure, Assumption, followed by a one line total expected exposure across all risks. </format>

๐Ÿ’ก

Pro tip: Use the output to open a budget conversation, not to close one, treat the numbers as a starting estimate a finance partner should sanity check.

Mitigation Planning

5 prompts

Draft mitigation options for a single high-priority risk

11/30

โœจ What it does

Generates four concrete mitigation strategy options for one high-priority risk with cost and residual score estimates.

You are a risk mitigation planner who develops concrete response options for high priority risks. <context> I have one risk that scored high on our matrix and need a real set of response options before I meet with the sponsor, not just a vague action item. </context> <inputs> - Risk statement: [PASTE RISK STATEMENT] - Current likelihood and impact scores: [SCORES] - Available budget or resources: [BUDGET OR RESOURCE CONSTRAINT] - Timeline pressure: [TIMELINE, e.g. MUST BE RESOLVED IN 30 DAYS] </inputs> <task> Propose four mitigation strategies covering avoid, reduce, transfer, and accept, each with a short description of what it would actually involve doing, the rough cost or effort, and the expected residual score after applying it. </task> <constraints> Make each option genuinely actionable, not a restatement of the risk. Be honest about tradeoffs, including where accept is the realistic option given the budget stated. Do not recommend transfer options like insurance unless they are plausible for this situation. </constraints> <format> Return a table with columns: Strategy Type, What It Involves, Rough Cost or Effort, Expected Residual Score, followed by a one sentence recommendation on which option to pick. </format>

๐Ÿ’ก

Pro tip: Ask it to also flag which option needs sponsor approval versus which the team can just execute, that split speeds up the actual meeting.

Turn mitigation ideas into an action plan with deadlines

12/30

โœจ What it does

Breaks approved mitigation ideas into a dated, owned action plan ready for a tracker.

You are a program manager who converts approved mitigation ideas into a trackable action plan. <context> We agreed on mitigation approaches in a meeting but nothing has been turned into concrete tasks with dates, so nothing is actually moving. </context> <inputs> - Approved mitigation ideas: [PASTE MITIGATION IDEAS] - Team members available: [NAMES OR ROLES] - Overall deadline for mitigation to be in place: [DEADLINE] </inputs> <task> Break each mitigation idea into 2 to 4 concrete tasks, assign a suggested owner from the team members given, and propose a realistic due date working backward from the overall deadline. </task> <constraints> Do not assign every task to one person, distribute across the roles given based on likely fit. Keep task descriptions action oriented, starting with a verb. Flag any mitigation idea that seems too vague to convert into tasks as [NEEDS CLARIFICATION]. </constraints> <format> Return a table with columns: Mitigation, Task, Suggested Owner, Due Date, Status (Not Started). </format>

๐Ÿ’ก

Pro tip: Paste the output straight into your task tool's CSV import format so the plan does not sit stuck in a document.

Write a contingency plan for a risk that has materialized

13/30

โœจ What it does

Writes an immediate 24-hour contingency plan when a logged risk has actually started to occur.

You are an incident response planner who writes contingency plans for risks that have already started to occur. <context> A risk we logged has started happening and I need an immediate contingency plan, not a theoretical mitigation, because we are already reacting to it. </context> <inputs> - What is happening right now: [DESCRIPTION OF CURRENT SITUATION] - Original risk it relates to: [ORIGINAL RISK STATEMENT] - Stakeholders who need to be informed: [STAKEHOLDER LIST] - Resources currently available to respond: [AVAILABLE RESOURCES] </inputs> <task> Write a contingency plan covering the immediate actions to take in the next 24 hours, who needs to be notified and in what order, and the criteria for declaring the situation resolved. </task> <constraints> Be concrete about the first 24 hours, avoid generic advice like monitor the situation. Order the notification list by urgency, not alphabetically. Do not promise a resolution timeline you cannot support from the inputs given. </constraints> <format> Return three sections: Immediate Actions (numbered list), Notification Order (numbered list with reason), Resolution Criteria (bulleted list). </format>

๐Ÿ’ก

Pro tip: Keep a version of this prompt saved separately from your normal risk workflow so it is ready to fire the moment something breaks.

Estimate the cost-benefit of a proposed mitigation

14/30

โœจ What it does

Compares a mitigation's cost against its expected reduction in financial exposure to support an approval decision.

You are a finance-minded risk advisor who checks whether a proposed mitigation is worth its cost. <context> Someone has proposed a mitigation for a risk and I need to know if the spend is actually justified before I approve the budget. </context> <inputs> - Risk and its estimated financial exposure: [RISK AND EXPOSURE ESTIMATE] - Proposed mitigation and its cost: [MITIGATION DESCRIPTION AND COST] - Expected reduction in likelihood or impact: [EXPECTED REDUCTION] </inputs> <task> Calculate the expected exposure before and after the mitigation, compare that reduction in expected exposure to the mitigation's cost, and give a clear recommendation on whether the spend is justified. </task> <constraints> Show the arithmetic plainly so a non-finance stakeholder can follow it. Do not recommend approval just because the exposure number is large, compare it directly to the cost. State clearly if the inputs are too rough to support a confident recommendation. </constraints> <format> Return a short breakdown: Exposure Before, Exposure After, Reduction in Exposure, Mitigation Cost, Net Benefit, Recommendation (Approve, Reject, Needs More Data). </format>

๐Ÿ’ก

Pro tip: Use this before, not after, a mitigation is approved, it works best as a gate rather than a retrospective justification.

Design a fallback plan if the primary mitigation fails

15/30

โœจ What it does

Defines a measurable failure signal and a ready fallback plan for when a primary mitigation does not work.

You are a contingency planner who designs backup plans in case a primary mitigation does not work as expected. <context> We have a mitigation in progress but I want a fallback ready in case it fails, rather than scrambling to invent one under pressure. </context> <inputs> - Risk being mitigated: [RISK STATEMENT] - Primary mitigation in progress: [MITIGATION DESCRIPTION] - Earliest point we would know the primary mitigation is failing: [TRIGGER OR SIGNAL] - Resources that would be available if we need to fall back: [AVAILABLE RESOURCES] </inputs> <task> Define the specific signal that would tell us the primary mitigation is failing, then propose a fallback plan that could be activated at that point, including the first three actions to take. </task> <constraints> Make the failure signal measurable, not a vague feeling that things are going wrong. Keep the fallback plan realistic given the stated available resources, do not assume unlimited budget or staff. Note any dependency the fallback has on decisions made now. </constraints> <format> Return three sections: Failure Signal (one clear sentence), Fallback Plan Summary (one paragraph), First Three Actions (numbered list). </format>

๐Ÿ’ก

Pro tip: Set a calendar reminder to check the failure signal at the midpoint of the mitigation timeline, not just at the deadline.

These prompts give you the what. Tutorials give you the why.

Learn when to use extended thinking, how to build Claude Projects, and workflows that compound. 300+ tutorials and growing.

Try AI Academy Free

Risk Ownership and Accountability

5 prompts

Assign owners to an unowned risk register

16/30

โœจ What it does

Assigns a clear, justified owner from your team's roles to every risk in an unowned register.

You are an operations manager who assigns clear ownership to risks that currently have none. <context> Our risk register has risks listed but no owners, which means nobody is actually accountable for watching or acting on them. </context> <inputs> - Risk list: [PASTE RISK LIST] - Team roles and responsibilities: [PASTE ROLES, e.g. PM, TECH LEAD, FINANCE PARTNER] - Any risks with existing informal owners: [PASTE IF ANY OR WRITE NONE] </inputs> <task> Assign the most appropriate owner from the given roles to each risk based on who has the authority and visibility to actually manage it, and give a one sentence reason for each assignment. </task> <constraints> Do not default every risk to the project manager, distribute based on actual fit to the role descriptions given. Where no role given clearly fits, flag it as [OWNERSHIP GAP, ESCALATE]. Keep reasons to one sentence. </constraints> <format> Return a table with columns: Risk Title, Assigned Owner, Reason for Assignment. </format>

๐Ÿ’ก

Pro tip: Treat any [OWNERSHIP GAP, ESCALATE] flag as a real finding to bring to the sponsor, it usually means a role is missing on the team.

Write an accountability charter for a risk owner

17/30

โœจ What it does

Writes a short, specific accountability charter clarifying what a risk owner must monitor and decide.

You are a governance specialist who writes clear accountability charters defining what a risk owner is actually responsible for. <context> We assign risk owners but they are not always clear on what the role requires, so risks get logged but not actively managed. </context> <inputs> - Risk owner role or name: [ROLE OR NAME] - Risk they own: [RISK STATEMENT] - Reporting cadence expected: [CADENCE, e.g. WEEKLY, MONTHLY] - Escalation path if the risk worsens: [ESCALATION CONTACT OR PROCESS] </inputs> <task> Write a short accountability charter for this risk owner covering what they must monitor, what decisions they are authorized to make on their own, and when they must escalate rather than decide alone. </task> <constraints> Keep the charter under 200 words. Be specific about the line between what the owner can decide alone and what needs escalation, avoid vague phrases like use good judgment. Reference the actual escalation contact given, not a generic one. </constraints> <format> Return three short sections: What You Monitor, What You Can Decide Alone, When You Must Escalate. </format>

๐Ÿ’ก

Pro tip: Attach this charter to the risk register entry itself so ownership expectations travel with the risk, not in a separate document nobody reopens.

Draft an escalation policy for unresolved risks

18/30

โœจ What it does

Writes an objective escalation policy defining when a stalled risk must move to a higher organizational level.

You are a risk governance consultant who designs escalation policies for risks that stall past their review dates. <context> Risks sit on our register without progress for weeks because nobody is forced to escalate them, and I want a clear rule for when that has to happen. </context> <inputs> - Current review cadence: [REVIEW CADENCE] - Organizational levels available for escalation: [TEAM LEAD, DIRECTOR, OR VP] - Risk severity tiers in use: [HIGH, MEDIUM, OR LOW] </inputs> <task> Write an escalation policy defining, for each severity tier, how many review cycles a risk can go without meaningful progress before it must escalate to the next organizational level, and what counts as meaningful progress. </task> <constraints> Make the trigger conditions objective and countable, such as number of cycles with no status change, not subjective judgment calls. Keep the policy to one page equivalent. Do not create more escalation levels than the ones given. </constraints> <format> Return a table with columns: Severity Tier, Cycles Without Progress Before Escalation, Escalates To, Definition of Meaningful Progress. </format>

๐Ÿ’ก

Pro tip: Pilot the policy on your highest severity tier first for one review cycle before rolling it out to every tier at once.

Prepare talking points for a risk owner who missed a deadline

19/30

โœจ What it does

Prepares direct, non-accusatory talking points for a one-on-one about a missed risk mitigation deadline.

You are a program manager preparing to have a direct but constructive conversation with a risk owner who missed their mitigation deadline. <context> A risk owner missed the deadline for their mitigation task and I need to raise it in our next one-on-one without it turning into a blame session. </context> <inputs> - Risk and mitigation task that was due: [RISK AND TASK] - Original deadline and how late it now is: [DEADLINE AND CURRENT DELAY] - Any context you already know about the delay: [CONTEXT OR WRITE UNKNOWN] - Relationship with this person: [RELATIONSHIP, e.g. PEER, DIRECT REPORT, VENDOR CONTACT] </inputs> <task> Write talking points for the conversation that acknowledge the delay factually, ask an open question about what got in the way, and propose a revised deadline with a specific check-in point before it arrives again. </task> <constraints> Keep the tone direct but not accusatory, avoid words like failed or unacceptable. Do not assume the reason for the delay if it is unknown, ask rather than guess. Keep the talking points to five bullet points or fewer. </constraints> <format> Return a bulleted list of talking points in the order they should be raised in the conversation. </format>

๐Ÿ’ก

Pro tip: Always propose the revised deadline with a check-in point attached, a bare new deadline tends to slip the same way the first one did.

Build a RACI matrix for cross-team risk ownership

20/30

โœจ What it does

Builds a cross-team RACI matrix clarifying responsibility and accountability for a shared set of risks.

You are an operations consultant who builds RACI matrices to clarify risk ownership across multiple teams. <context> A set of risks touches several teams and it is unclear who is responsible, who is accountable, who should be consulted, and who just needs to be informed. </context> <inputs> - Risk list: [PASTE RISK LIST] - Teams involved: [TEAM NAMES, e.g. ENGINEERING, LEGAL, VENDOR MANAGEMENT] - Known team responsibilities: [SHORT DESCRIPTION OF WHAT EACH TEAM HANDLES] </inputs> <task> Build a RACI matrix assigning Responsible, Accountable, Consulted, and Informed roles to the relevant teams for each risk, based on the responsibilities described. </task> <constraints> Each risk should have exactly one Accountable team, do not assign more than one. Do not assign a role to a team with no plausible connection to the risk based on the descriptions given. Flag any risk where no team seems clearly Accountable as [OWNERSHIP GAP]. </constraints> <format> Return a table with rows as risks and columns as team names, with cell values R, A, C, I, or blank. </format>

๐Ÿ’ก

Pro tip: Review the matrix in a joint meeting with all teams present, RACI disagreements are easier to resolve live than over email.

Risk Reporting and Communication

5 prompts

Write a monthly risk summary for a steering committee

21/30

โœจ What it does

Writes a concise, decision-focused monthly risk summary for a time-limited steering committee.

You are a program manager who writes concise monthly risk summaries for a steering committee. <context> I need to report on our risk register status to a steering committee that has limited time and wants the headline, not the full detail. </context> <inputs> - Current risk register with scores and status: [PASTE RISK DATA] - Changes since last report: [NEW RISKS, CLOSED RISKS, OR ESCALATIONS] - Reporting period: [REPORTING PERIOD] </inputs> <task> Write a one page monthly risk summary covering overall risk trend since last period, the top 3 risks needing committee attention, and any risks that were closed or newly opened. </task> <constraints> Keep the entire summary under 350 words. Lead with the trend, not a list, executives want direction before detail. Avoid restating the full register, focus only on what changed and what needs a decision. </constraints> <format> Return a one page memo with sections: Overall Trend, Top 3 Risks Needing Attention, Closed This Period, New This Period. </format>

๐Ÿ’ก

Pro tip: Keep the full register as an appendix link rather than pasting it into the memo, committees skim past long tables.

Translate technical risk into client-facing language

22/30

โœจ What it does

Translates a technical, internal risk into an honest, plain-language client update email.

You are a client relationship manager who translates internal technical risk assessments into language a client can understand. <context> I need to tell a client about a risk affecting their project without alarming them unnecessarily or using internal jargon they will not follow. </context> <inputs> - Internal risk description: [PASTE TECHNICAL RISK DESCRIPTION] - What this means for the client's timeline or deliverable: [IMPACT ON CLIENT] - What we are doing about it: [MITIGATION IN PROGRESS] - Client relationship tone: [TONE, e.g. FORMAL, CASUAL, LONG-TERM PARTNER] </inputs> <task> Write a short client-facing message that explains the situation in plain language, states the impact on their timeline or deliverable honestly, and describes what is being done without overpromising a fix date we cannot guarantee. </task> <constraints> Do not use internal risk management terms like inherent, residual, or risk score. Be honest about the impact, do not minimize it to avoid discomfort. Match the tone specified, do not default to overly formal language if the relationship is casual. </constraints> <format> Return a short email, no more than 150 words, with a clear subject line suggestion above it. </format>

๐Ÿ’ก

Pro tip: Have your account lead review the draft before sending, since only they know exactly how much this specific client tolerates bad news.

Create a risk dashboard narrative from raw scores

23/30

โœจ What it does

Writes the short narrative explanation that should accompany a numeric risk dashboard each reporting period.

You are a data-literate risk reporter who writes the narrative that accompanies a numeric risk dashboard. <context> Our dashboard shows numbers and colors but nobody reads the story behind them, so I want a short narrative to pair with each reporting cycle. </context> <inputs> - Current period risk counts by tier: [CURRENT PERIOD RISK COUNTS] - Previous period counts by tier: [PREVIOUS PERIOD RISK COUNTS] - Notable individual risks worth naming: [RISK NAMES OR WRITE NONE] </inputs> <task> Write a short narrative explaining the change in risk distribution between periods, calling out whether the overall picture improved or worsened, and naming any individual risks worth specific mention. </task> <constraints> Lead with whether things got better or worse in plain terms before giving numbers. Do not claim improvement if high tier count increased even if total count dropped. Keep it under 150 words. </constraints> <format> Return a single short paragraph followed by a one line verdict: Improving, Stable, or Worsening. </format>

๐Ÿ’ก

Pro tip: Pin the Improving, Stable, or Worsening verdict at the top of your dashboard slide, that single word gets read even when nothing else does.

Prepare answers for likely board questions on a risk

24/30

โœจ What it does

Anticipates the five hardest board questions about a risk and drafts honest, direct answers in advance.

You are a governance advisor who prepares executives for hard questions about a specific risk before a board meeting. <context> I am presenting a significant risk to the board and want to anticipate their questions instead of getting caught off guard. </context> <inputs> - Risk summary being presented: [RISK SUMMARY] - Current mitigation status: [MITIGATION STATUS] - Sensitive details to handle carefully: [SENSITIVE DETAILS OR WRITE NONE] - Board's general disposition: [DISPOSITION, e.g. DETAIL-ORIENTED, BIG-PICTURE, RISK-AVERSE] </inputs> <task> List the five most likely questions this board would ask about the risk given their disposition, and draft a direct, honest answer to each that does not overstate confidence in the mitigation. </task> <constraints> Do not write answers that dodge the hard question, boards notice evasiveness. Handle the sensitive details given carefully without omitting material facts. Keep each answer to two or three sentences. </constraints> <format> Return a numbered list of question and answer pairs, five in total. </format>

๐Ÿ’ก

Pro tip: Practice the answers out loud once before the meeting, reading them silently is not the same as saying them under pressure.

Write a risk acceptance memo for sign-off

25/30

โœจ What it does

Documents a formal risk acceptance decision in memo form with a required next review date for the audit trail.

You are a governance officer who documents formal risk acceptance decisions for the record. <context> Leadership has decided to accept a risk rather than mitigate it further, and I need a formal memo documenting that decision for audit purposes. </context> <inputs> - Risk being accepted: [RISK STATEMENT] - Current score and mitigations already in place: [SCORE AND EXISTING MITIGATIONS] - Reason for accepting rather than mitigating further: [REASON, e.g. COST, TIMELINE, LOW RESIDUAL IMPACT] - Approving authority: [NAME AND TITLE] </inputs> <task> Write a formal risk acceptance memo stating the risk, its current score, the reason acceptance was chosen over further mitigation, the approving authority, and the date this will next be reviewed. </task> <constraints> Use formal, precise language appropriate for an audit trail, not casual phrasing. Do not imply the risk has been resolved, acceptance is a decision, not a fix. Include a clear next review date, do not leave it open ended. </constraints> <format> Return a memo with labeled fields: Risk, Current Score, Existing Mitigations, Reason for Acceptance, Approving Authority, Next Review Date, followed by a one paragraph summary statement. </format>

๐Ÿ’ก

Pro tip: Always set the next review date to a real calendar reminder, an accepted risk with no review date tends to be forgotten entirely.

Most people use 10% of Claude. Tutorials unlock the rest.

AI Academy: 300+ hands-on tutorials on Claude, ChatGPT, Midjourney, and 50+ AI tools. New tutorials added every week.

Start Your Free Trial

Vendor and Compliance Risk

5 prompts

Assess risk in a new vendor contract before signing

26/30

โœจ What it does

Reviews new vendor contract terms and data access for risk exposure before the contract is signed.

You are a vendor risk analyst who reviews contracts for risk exposure before a company signs them. <context> We are about to sign a contract with a new vendor and I want the risk exposure identified before legal finalizes it, not after. </context> <inputs> - Vendor name and service provided: [VENDOR NAME AND SERVICE] - Key contract terms: [PASTE RELEVANT TERMS, e.g. LIABILITY CAP, TERMINATION CLAUSE, SLA] - Data or systems the vendor will access: [DATA OR SYSTEM ACCESS] - Our industry's typical regulatory concerns: [REGULATORY CONTEXT] </inputs> <task> Identify the top risks in this vendor relationship covering data access, liability terms, termination and exit difficulty, and regulatory exposure, and rate each as high, medium, or low concern. </task> <constraints> Do not provide legal advice on contract language, flag anything that needs a lawyer's review as [ROUTE TO LEGAL]. Base ratings only on the terms and access described, do not assume standard industry terms if none were given. Be specific about what data or system access drives each concern. </constraints> <format> Return a table with columns: Risk Area, Specific Concern, Concern Level, Recommended Action. </format>

๐Ÿ’ก

Pro tip: Route every [ROUTE TO LEGAL] flag as an actual line item in your review checklist, do not let this output replace a lawyer's read of the contract.

Score third-party vendors on an ongoing risk basis

27/30

โœจ What it does

Scores active vendors on combined data sensitivity and business criticality to set a monitoring tier.

You are a vendor management analyst who scores existing vendors on ongoing risk exposure. <context> We have a list of active vendors and need to know which ones deserve closer monitoring based on what they access and how critical they are. </context> <inputs> - Vendor list with what each provides: [VENDOR NAME AND SERVICE PAIRS] - Data sensitivity each vendor touches: [DATA SENSITIVITY LEVEL PER VENDOR] - Business criticality if the vendor failed: [CRITICALITY PER VENDOR] </inputs> <task> Score each vendor on a combined risk basis using data sensitivity and business criticality, and recommend a monitoring tier of high, medium, or low along with a suggested review frequency for each tier. </task> <constraints> Do not assign high tier to every vendor just because data is involved, weigh both sensitivity and criticality together. Suggest realistic review frequencies, not more frequent than quarterly for medium and low tiers. Flag any vendor missing sensitivity or criticality data as [NEEDS ASSESSMENT]. </constraints> <format> Return a table with columns: Vendor, Data Sensitivity, Business Criticality, Monitoring Tier, Suggested Review Frequency. </format>

๐Ÿ’ก

Pro tip: Re-run this whenever a vendor's contract renews, criticality and data access both tend to expand quietly over time.

Draft a compliance gap risk summary for a new regulation

28/30

โœจ What it does

Compares current practice against a new regulation's requirements and flags likely compliance gaps by risk level.

You are a compliance risk officer who assesses exposure when a new regulation takes effect. <context> A new regulation affecting our industry is coming into effect and I need to understand where our current practices likely fall short before it becomes enforceable. </context> <inputs> - Regulation name and summary: [REGULATION NAME AND WHAT IT REQUIRES] - Our current practice in the relevant area: [CURRENT PRACTICE DESCRIPTION] - Effective date: [EFFECTIVE DATE] - Department most affected: [DEPARTMENT] </inputs> <task> Compare the regulation's requirements against our current practice, identify the specific gaps, and rate each gap by how much risk it carries if unaddressed by the effective date. </task> <constraints> Do not state definitively whether we are compliant or not, that is a legal determination, phrase findings as [LIKELY GAP] or [LIKELY COVERED] with reasoning. Flag anything requiring formal legal review as [ROUTE TO LEGAL]. Base the comparison only on the practice description given, do not assume unstated controls exist. </constraints> <format> Return a table with columns: Requirement, Our Current Practice, Gap Assessment, Risk If Unaddressed, Action Needed. </format>

๐Ÿ’ก

Pro tip: Send the [ROUTE TO LEGAL] items to counsel well before the effective date, gap remediation almost always takes longer than expected.

Build a vendor exit risk plan before a contract ends

29/30

โœจ What it does

Assesses vendor transition risk across data, integrations, and staffing with realistic lead-time estimates before a contract ends.

You are a vendor transition planner who assesses the risk of losing or switching a critical vendor. <context> A vendor contract is ending soon and I need to understand the risk of transition before we decide whether to renew, renegotiate, or switch. </context> <inputs> - Vendor and service being provided: [VENDOR AND SERVICE] - Contract end date: [END DATE] - Dependencies on this vendor: [DEPENDENCIES, e.g. DATA FORMAT, INTEGRATIONS, STAFF TRAINING] - Known alternative vendors, if any: [ALTERNATIVES OR WRITE NONE IDENTIFIED] </inputs> <task> Identify the specific risks of transitioning away from this vendor, covering data migration, integration rework, staff retraining, and service continuity, and estimate how much lead time each risk area realistically needs before the contract end date. </task> <constraints> Be realistic about lead time, do not assume a data migration or integration rework can happen faster than typical for the dependencies described. If no alternative vendors are identified, flag that itself as a top risk. Do not recommend a specific alternative vendor by name unless one was given. </constraints> <format> Return a table with columns: Risk Area, Specific Concern, Estimated Lead Time Needed, Recommended Action, followed by a one line overall recommendation on renew versus switch given the time remaining. </format>

๐Ÿ’ก

Pro tip: Run this at least six months before contract end, most of the lead times it surfaces exceed what a 30-day notice period allows.

Prioritize a backlog of audit findings by risk

30/30

โœจ What it does

Ranks a backlog of audit findings into now, next, and later remediation tiers weighted by severity and regulatory deadlines.

You are an internal audit risk analyst who prioritizes a backlog of audit findings for remediation. <context> We have a backlog of audit findings and limited capacity to fix them all at once, so I need them ranked by actual risk rather than the order they were found. </context> <inputs> - Audit findings list: [PASTE FINDINGS LIST] - Business area each finding affects: [BUSINESS AREA PER FINDING] - Any regulatory deadlines tied to specific findings: [DEADLINES OR WRITE NONE] </inputs> <task> Rank the findings by combined severity and urgency, factoring in any regulatory deadlines, and group them into now, next, and later remediation tiers. </task> <constraints> Findings with a hard regulatory deadline should generally rank above ones without, even if the underlying severity looks similar, unless the deadline is far out. Do not put more than a third of the total findings into the now tier, that defeats the purpose of prioritization. Explain the ranking logic for the top 3 items. </constraints> <format> Return three sections, Now, Next, Later, each listing the findings assigned to it, followed by a short explanation of the top 3 rankings. </format>

๐Ÿ’ก

Pro tip: Revisit the ranking every time a new regulatory deadline is announced, a single new deadline can reshuffle the whole now tier.

Free tool

Prompt Optimizer

Turn a rough idea into a structured, professional AI prompt.

Try it free โ†’

Frequently Asked Questions

Paste your project brief or informal list into the register-building prompt above and Claude will sort the risks into categories, add short descriptions, and flag anything it needs more detail on. You still review and adjust it, but you start from a structured draft instead of a blank page.
Yes, if you give it your scoring scale and enough context about the project, such as budget and user count, it will assign consistent likelihood and impact scores and explain its reasoning. Treat the scores as a strong first pass, not a substitute for your team's judgment on genuinely ambiguous risks.
The more specific your inputs, the better the output. A vague budget figure or a one-word project description forces Claude to guess, which shows up as generic mitigation ideas. Paste real numbers, real stakeholder roles, and real constraints wherever the prompt asks for them.
Use them to draft and organize, not to make the final call. Several prompts above explicitly flag items like contract terms or regulatory gaps for legal or compliance review rather than answering definitively, and you should route those flags to a qualified person before acting on them.
Yes, the structure is designed to be reused, just swap out the bracketed inputs for each new project's details. Many teams save a few of these as templates in a shared doc so risk reviews start from the same format every time.

Prompts are the starting line. Tutorials are the finish.

A growing library of 300+ hands-on tutorials on ChatGPT, Claude, Midjourney, and 50+ AI tools. New tutorials added every week.

7-day free trial. Cancel anytime.