Develop a risk register

Develop a structured risk register and understand impact with scoring, mitigation actions and key indicators.

  • Verified
The approach in this prompt has been verified by the Government Project Delivery Professionals. You must still check the results from this prompt for accuracy, as AI can make mistakes.

 

What this prompt does

This prompt is suitable for any AI assistant (for example, Microsoft Copilot or Gemini). 

The prompt will:

  • create a structured risk register identifying the top project risks
  • align the analysis with official UK government guidance 
  • assess risk severity using a scoring matrix (likelihood and impact)
  • suggest mitigation actions, Key Risk Indicators and ownership details

Before you start

You can also add your project brief and any other relevant information (for example, risk appetite statements or policies) when you submit the prompt.

Before you use this prompt, replace text in square brackets:

  • [PROJECT STAGE] for example [Full Business Case]
  • [INSERT SPECIFIC PROGRAMME DETAILS] for example [multi-department ERP implementation programme]
Do not upload any personal or official information to free tools, or any tool not advised by your department. If you are unsure, check with your digital team.

The prompt

Copy prompt Develop a risk register
                //Goal

Develop a risk register identifying and assessing the top 5 to 10 delivery risks for a programme \[INSERT SPECIFIC PROGRAMME DETAILS].

//Context

You are a senior Risk Manager supporting a UK government programme (for example, ERP programme) involving legacy systems and third-party suppliers. 

The programme spans multiple departments and must align with UK government guidance on project delivery and risk management in \[PROJECT STAGE] of the project lifecycle.

//Source 

Use official UK government guidance from:
* The Teal Book (project delivery) (link Chapter 20. Risk management - Government Project Delivery: https://projectdelivery.gov.uk/teal-book/home/part-e-planning-and-control/chapter-20-risk-management/)
* Project data standard - Government Project Delivery: https://projectdelivery.gov.uk/connect/surveys/provide-feedback-on-the-latest-version-of-the-project-data-standard/project-data-standard/#section-2
* The Orange Book Management of Risk – Principles and Concepts[](http://gov.uk): https://www.gov.uk/government/publications/orange-book/the-orange-book-management-of-risk-principles-and-concepts
* The Green Book: https://assets.publishing.service.gov.uk/media/6645c709bd01f5ed32793cbc/Green_Book_2022__updated\_links\_.pdf
* You can use publicly available data from credible sources on similar UK and International Project to derive this list of risks. However, clearly provided the source where this is used.
* use the project brief or any other project documents the user uploads

//Expected outputs 

Generate a risk register table with the following columns:
* Risk ID
* Risk Type
* Risk Response
* Risk Cause
* Risk Event
* Risk Consequence
* Risk response
* Mitigation Actions
* Risk Score (Inherent risk likelihood, scale 1-5, 5= almost certain and expected to occur in most circumstances, to 1 = Rare and may occur only in exceptional circumstances × impact, 
* scale 1–5, 5= critical and threatens programme success or delivery to 1 = insignificant and minimal impact on time, cost or quality )
* Key Risk Indicators
* Risk owner
* Risk response owner
* Risk response due date
* data risk raised
* risk raised by

Each risk should follow the cause-event-consequence framework and include:
* Risk Score: For each risk score. Provide a brief rationale.
* Risk cause category: Strategic, Operational, Financial, Reputational, or Compliance.
* Risk response category: Avoid, Treat, Transfer, Mitigate, Accept, Share, Enhance, Reject or Exploit.
* Risk consequence: Potential financial impact (in £) of the risk on key project outcomes such as time, cost, benefits.
* Key Risk indicators: Metrics that can be used to gauge whether the risk level is increasing or decreasing and whether mitigations are working as intended
* Risk mitigation description: a description of the types of mitigation actions (preventative and corrective) that can help manage the risk in line with the risk appetite.

Suggest KPIs for monitoring each risk

You should also share prioritisation rationale.
              

Content created: 18 November 2025 | Last updated: 23 November 2025

Support and Resources

Here are the relevant guidance pages for using prompts:

Get in touch

Email ai-knowledge-hub@dsit.gov.uk to share feedback about this prompt.