Build a project risk register

Identify, score, and create mitigation plans for risks before they become project-blocking issues.

Workflow · Project ManagementRole · Risk Manager●●● IntermediateUpdated 2026-07-31

The prompt

Copy and customize

prompt.txt
**Role:** You are a Risk Manager building a proactive risk register for the project {project_name}.

**Context:**
Before execution begins, your team needs a living document that anticipates problems and has pre-approved responses. A good risk register doesn't just list risks — it assigns ownership and defines trigger conditions. You are working in a context where {industry} norms apply and {regulatory_context} is relevant.

**Task:**
Apply step-back thinking: first identify the categories of risk that typically affect projects in this space (people, technology, external, financial, process), then generate specific risks within each category, then score and plan for them.

**Input Available:**
- {project_name}: Project name
- {project_type}: Type of project (product launch, system migration, process redesign, etc.)
- {team_size}: Number of people involved
- {timeline_weeks}: Duration in weeks
- {industry}: Industry or sector
- {known_constraints}: Budget cap, tech limitations, regulatory, etc.

**Output Format:**
Risk Register Table with columns:
- Risk ID | Risk Description | Category | Likelihood (1–5) | Impact (1–5) | Risk Score | Owner | Trigger Signal | Mitigation Strategy | Contingency Plan | Status

Then: Top 3 risks narrative explanation with recommended pre-emptive actions.

**Guardrails & Quality Control:**
- Include at least 12 risks across at least 4 categories
- Risk score = Likelihood × Impact; highlight scores ≥ 15 as critical
- Do not list generic risks — make each one specific to the project context
- Each risk must have a named owner role (not 'the team')
- Provide both mitigation (prevent) and contingency (if it happens) strategies

How to use

Run this prompt in four steps

  1. 1Run before project kickoff and share with the steering committee.
  2. 2Review the register every 2 weeks — update status and add newly discovered risks.
  3. 3Assign a dedicated risk owner for each risk with score ≥ 12.
  4. 4Use the trigger signals as your early warning monitoring checklist.

When to use

When to use this prompt

Use at project initiation and revisit at every major phase gate or when significant change occurs.

Limitations · Worth knowing

This prompt has limitations you must understand.

AI generates probable risks based on the inputs provided. Domain-specific regulatory or market risks may require expert review to validate.