Before asking AI to review a risk register, decide what you want it to question. Asking for a polished version of the existing list may leave weak assumptions untouched. These six prompts give it a more specific job.
Before you start, check your organization’s AI policy and use an approved tool. Use fictional, public or appropriately sanitized information that you are permitted to share. Removing names does not make confidential material safe to paste. Keep credentials, personal data, unreleased financials, privileged material and security vulnerability details out of general-purpose tools.
1. Find gaps in the risk list
Get an independent set of ideas before showing the existing register.
- Prompt: A company has this profile: [industry, revenue range, business model and relevant context]. Suggest ten specific scenarios that could prevent it from meeting its objectives over [period]. Explain why each might matter. Treat these as hypotheses. List missing facts and do not invent likelihoods or loss estimates.
- Then: Compare those scenarios with this sanitized risk list: [list]. Identify possible omissions, overlapping entries and risks that may be too broad for one owner. What should leadership investigate?
- Check: Have people who know the business assess the suggestions. A plausible risk is not evidence that the company has that exposure.
2. Turn a category into a risk statement
- Prompt: Rewrite this entry: [entry], using cause, event and consequence to a business objective. Company context: [profile]. Identify missing facts, possible owners for management to consider and a leading indicator, including the data it would require. Label every assumption. Use [unknown] where the input is insufficient.
- Check: Confirm the consequence, ownership and available data with the business. Do not let the model fill a vague entry with invented specifics.
- Illustrative example: “Supply chain” becomes “A delay in a critical component could stop assembly and cause missed customer deliveries.” The team still needs to confirm the component, recovery time, alternative supply and financial consequence.
3. Test the assumptions behind a rating
- Prompt: Risk: [statement]. Rating: [rating]. Current response: [response]. Identify the assumptions behind this rating about external conditions, internal capability, and detection and response time. Suggest how to test each. Which could change without being noticed? Do not assign a new rating.
- Check: Give the important tests an owner and a date. Asking the model to identify assumptions does not establish whether they are true.
4. Challenge a control
- Prompt: Risk: [risk]. Control: [what happens, who does it, frequency and evidence retained]. Describe plausible ways it could fail, including failures its own records might not reveal. Separate concerns supported by the description from questions requiring evidence. What would you ask the person performing it?
- Check: Use the output to prepare testing or interviews. It cannot tell you whether the control actually operated.
5. Run a pre-mortem
- Prompt: Initiative: [objective, deadline and measures of success]. Imagine that by [date] it has failed. Suggest plausible explanations specific to this initiative. For each, identify an early warning sign and an action management could consider now. Mark assumptions and avoid generic explanations unless you explain how they apply.
- Check: Discuss the scenarios with the team. Treat them as possibilities to examine, not forecasts.
6. Prepare a board update
- Prompt: Rewrite this sanitized update for [board or committee] in no more than 150 words: [update]. State what changed, the significance, management’s response and any decision needed. Retain material uncertainty and approval conditions. Add a separate verification list of unsupported or inferred claims, figures and dates. Do not invent missing information.
- Check: Compare the draft with the original evidence. The verification list can miss errors too. Keep important supporting detail available in the pre-read or appendix.
Across all six, present the work neutrally, ask for the strongest opposing case when testing a conclusion, and verify the answer against evidence. Management still decides who owns the risk, what to accept and what to fund.
Which of these tasks would you try first, and what would you check before using the output?
Adapted from my Kennedy Risk Group article, “Six AI Prompts for Risk Management, and the Three Rules That Make Them Work”:
https://kennedyriskgroup.com/blog/ai-prompts-risk-management
Comments