Develop a structured risk register and understand impact with scoring, mitigation actions and key indicators.
//Goal
Develop a risk register identifying and assessing the top 5 to 10 delivery risks for a programme \[INSERT SPECIFIC PROGRAMME DETAILS].
//Context
You are a senior Risk Manager supporting a UK government programme (for example, ERP programme) involving legacy systems and third-party suppliers.
The programme spans multiple departments and must align with UK government guidance on project delivery and risk management in \[PROJECT STAGE] of the project lifecycle.
//Source
Use official UK government guidance from:
* The Teal Book (project delivery) (link Chapter 20. Risk management - Government Project Delivery: https://projectdelivery.gov.uk/teal-book/home/part-e-planning-and-control/chapter-20-risk-management/)
* Project data standard - Government Project Delivery: https://projectdelivery.gov.uk/connect/surveys/provide-feedback-on-the-latest-version-of-the-project-data-standard/project-data-standard/#section-2
* The Orange Book Management of Risk – Principles and Concepts[](http://gov.uk): https://www.gov.uk/government/publications/orange-book/the-orange-book-management-of-risk-principles-and-concepts
* The Green Book: https://assets.publishing.service.gov.uk/media/6645c709bd01f5ed32793cbc/Green_Book_2022__updated\_links\_.pdf
* You can use publicly available data from credible sources on similar UK and International Project to derive this list of risks. However, clearly provided the source where this is used.
* use the project brief or any other project documents the user uploads
//Expected outputs
Generate a risk register table with the following columns:
* Risk ID
* Risk Type
* Risk Response
* Risk Cause
* Risk Event
* Risk Consequence
* Risk response
* Mitigation Actions
* Risk Score (Inherent risk likelihood, scale 1-5, 5= almost certain and expected to occur in most circumstances, to 1 = Rare and may occur only in exceptional circumstances × impact,
* scale 1–5, 5= critical and threatens programme success or delivery to 1 = insignificant and minimal impact on time, cost or quality )
* Key Risk Indicators
* Risk owner
* Risk response owner
* Risk response due date
* data risk raised
* risk raised by
Each risk should follow the cause-event-consequence framework and include:
* Risk Score: For each risk score. Provide a brief rationale.
* Risk cause category: Strategic, Operational, Financial, Reputational, or Compliance.
* Risk response category: Avoid, Treat, Transfer, Mitigate, Accept, Share, Enhance, Reject or Exploit.
* Risk consequence: Potential financial impact (in £) of the risk on key project outcomes such as time, cost, benefits.
* Key Risk indicators: Metrics that can be used to gauge whether the risk level is increasing or decreasing and whether mitigations are working as intended
* Risk mitigation description: a description of the types of mitigation actions (preventative and corrective) that can help manage the risk in line with the risk appetite.
Suggest KPIs for monitoring each risk
You should also share prioritisation rationale.
Develop a risk register
Develop a structured risk register and understand impact with scoring, mitigation actions and key indicators.
What this prompt does
This prompt is suitable for any AI assistant (for example, Microsoft Copilot or Gemini).
The prompt will:
Before you start
You can also add your project brief and any other relevant information (for example, risk appetite statements or policies) when you submit the prompt.
Before you use this prompt, replace text in square brackets:
The prompt
Content created: 18 November 2025 | Last updated: 23 November 2025