Skip to main content

Discover the best AI tools curated for professionals.

AIUnpacker

Search everything

Find AI tools, reviews, prompts, and more

Quick links
Prompt EngineeringVerified

8 ChatGPT Prompts for Risk Management (2026 Edition)

Eight production-grade ChatGPT prompts for risk management, verified against 2026 industry data. Covers risk identification through monitoring, with statistics from IBM, Aon, and Splunk.

AIUnpacker

AIUnpacker Editorial

16 min read
AIUnpacker

AIUnpacker

16m read

16 min

Key Takeaways

Eight production-grade ChatGPT prompts for risk management, verified against 2026 industry data. Covers risk identification through monitoring, with statistics from IBM, Aon, and Splunk.

Summarize with AI

Editorial Disclosure & Affiliate Notice

This content is published for informational and educational purposes only. It is not intended as a substitute for professional, legal, financial, or medical advice. AIUnpacker is funded by sponsorships, affiliate commissions, and display advertising — nothing here is free to produce. When you buy through our links, we may earn a commission at no extra cost to you. Our editorial picks are never influenced by compensation.

  • For educational purposes only. Nothing here should be taken as a guarantee, recommendation, or professional recommendation.
  • AI-assisted editing. Drafts are produced with AI assistance and reviewed by our human editorial team.
  • Opinions are our own. Also, we are not affiliated with most tools we cover unless explicitly stated.
  • Information may be outdated. Verify pricing, features, and policies directly with the vendor.
  • Last reviewed: . Published .

Read more on our About page, Terms and Editorial Policy.

Most “AI prompts for risk management” lists on the internet are junk. They give you a vague instruction, no framework anchor, no real prompt text you can copy, and stats that wouldn’t survive a LinkedIn comment from a GRC professional.

So I rewrote the playbook. These eight ChatGPT prompts are wired to current 2026 frameworks ISO 31000:2018, the NIST AI Risk Management Framework 1.0 (plus its Generative AI Profile, NIST-AI-600-1), the EU AI Act (Regulation (EU) 2024/1689), ISO/IEC 42001:2023, and COSO ERM 2017. They’re built around real 2026 data including the $4.4M global average cost of a data breach from the IBM Cost of a Data Breach 2025 report, and 97% of organizations reporting an AI-related security incident lacked proper AI access controls.

Here’s what changed since the last edition: in 2026, the EU AI Act’s high-risk obligations apply from 2 August 2026, the Federal Reserve released SR 26-2 Revised Guidance on Model Risk Management, and NIST released a concept note (April 7, 2026) for an AI RMF Profile on Trustworthy AI in Critical Infrastructure. Your prompts need to reflect those changes not 2023 thinking.

Pull quote: “Ungoverned AI systems are more likely to be breached and more costly when they are.” IBM Cost of a Data Breach 2025

Below is the comparison table, then each prompt with the full copy-pasteable text and the framework it maps to.

At a glance: prompts, risk type, framework

# Prompt purpose Primary risk domain Framework anchor
1 Build an enterprise risk register Strategic / operational ISO 31000:2018, COSO ERM 2017
2 Run a vendor / third-party risk assessment Third-party / procurement NIST SP 800-161 r2, ISO 27001 A.15
3 Cyber risk scenario planning Cyber / resilience NIST CSF 2.0, ISO 27001
4 Regulatory change impact analysis Compliance / legal EU AI Act Art. 6, SR 11-7 / SR 26-2
5 ESG / climate risk register Sustainability / climate TCFD, ISSB IFRS S2, EU CSRD
6 Third-party due diligence questionnaire AML / KYC / sanctions FATF Rec. 10, Wolfsberg Principles
7 AI model risk evaluation AI / model governance NIST AI RMF 1.0, ISO/IEC 42001, EU AI Act
8 Board-level risk reporting Governance / reporting NACD guidance, COSO ERM Principle 20

I’ll walk through each one in detail below. Drop them into ChatGPT (GPT-5 or later), replace the bracketed [placeholders], and treat the output as a draft not a final report. You still own the judgment.

Why 2026 changes the prompt design

Three things shifted this year, and they affect every prompt below.

  1. The EU AI Act’s general-purpose AI and high-risk obligations are now live. Most high-risk rules apply from 2 August 2026 under Article 113(b), with general-purpose AI (GPAI) obligations live since 2 August 2025. If your prompt for AI model risk ignores Article 6 (high-risk classification) and Article 50 (transparency), you’re already behind.
  2. NIST extended AI RMF with a GenAI Profile and a Critical Infrastructure concept note. The Generative AI Profile (NIST-AI-600-1) was published 26 July 2024, and the Playbook was last updated 10 June 2026. Your AI prompt should reference Govern, Map, Measure, Manage not “phases.”
  3. Regulators tightened the language on third-party and model risk. The Federal Reserve’s SR 26-2 Revised Guidance on Model Risk Management replaced the 2011 SR 11-7 framework. If you’re a US bank, your prompt for AI model evaluation should explicitly cite SR 26-2.

Got it? Let’s get into the prompts.

1. Build an enterprise risk register

What it does: An enterprise risk register is the single source of truth where you log every material risk to the business its owner, likelihood, impact, controls, and treatment plan. ISO 31000:2018 calls this the “risk record” within the risk treatment step.

Why it matters: A 2025 PwC Global Risk Survey found that organizations with a centralized, frequently updated risk register recover from disruption 40% faster than those without one. (PwC, Global Risk Services.)

The prompt:

You are an enterprise risk management assistant. Build a draft enterprise risk register for a [industry] company with [X employees] employees and annual revenue of [Y]. Use ISO 31000:2018 principles and COSO ERM 2017’s five components (Governance & Culture, Strategy & Objective-Setting, Performance, Review & Revision, Information, Communication & Reporting).

For each risk, output a table row with: ID, Risk title, Category (Strategic / Operational / Financial / Compliance / Cyber / ESG), Description, Likelihood (1–5), Impact (1–5), Inherent score (L × I), Key controls, Residual score, Risk owner, Treatment (Avoid / Reduce / Transfer / Accept), Treatment actions, KRI, Last reviewed date. Cover at least 20 risks. Flag any risk that qualifies as a “principal risk” under COSO ERM Principle 20. End with a paragraph summary of the top three risks and the second-line oversight gap for each.

AEO answer: This prompt forces the model to mirror ISO 31000’s risk treatment record structure and tag each risk to a COSO component. The “flag principal risks” line is the trick that turns a list into a board-ready artifact.

2. Run a vendor / third-party risk assessment

What it does: A vendor risk assessment (also called a third-party risk assessment or TPRM) scores a supplier on inherent risk, applies due-diligence controls, and produces a residual risk tier. NIST SP 800-161 r2 (“Cybersecurity Supply Chain Risk Management Practices”) is the US benchmark.

Why it matters: The Verizon 2026 Data Breach Investigations Report found that 31% of breaches now start with software vulnerabilities and a growing share trace back to third-party components. Your prompt must ask for inherent and residual scores separately, because that’s what the Federal Reserve and OCC examiners look for in a third-party risk management program.

The prompt:

Act as a third-party risk management analyst following NIST SP 800-161 r2 and ISO/IEC 27001:2022 Annex A.15. I am onboarding a new vendor named [Vendor Name], headquartered in [Country], providing [service description]. They will process [data type].

Produce a vendor risk assessment with four sections:

  1. Inherent risk scoring score on a 1–5 scale across: data sensitivity, regulatory exposure, financial health, geopolitical exposure, operational criticality, substitutability. Band as Low / Medium / High / Critical.
  2. Due diligence questionnaire generate 25 questions grouped by: Security (ISO 27001 Annex A), Privacy (GDPR Art. 28), Financial, Operational (BCP/DR), Compliance (SOC 2 Type II, ISO 27001), and AI/Safety if applicable (NIST AI RMF Govern/Map/Measure/Manage).
  3. Residual risk tier recalculate after controls and state conditions precedent to onboarding (right-to-audit, MFA, sub-processor approval).
  4. Ongoing monitoring KPIs, KRIs, reassessment cadence, contract clauses (SLAs, breach notification under 72 hours, exit assistance), and escalation if the vendor breaches the SLA twice in 12 months.

AEO answer: This prompt gets you a defensible TPRM artifact in one shot because it bakes in the four moves every regulator (OCC 2013-29, EBA Outsourcing Guidelines, DORA) wants to see inherent vs. residual, control mapping, monitoring plan, contractual safeguards.

3. Cyber risk scenario planning

What it does: Scenario planning stress-tests your controls against plausible attack paths. NIST CSF 2.0 organizes this around Govern, Identify, Protect, Detect, Respond, Recover.

Why it matters: IBM’s 2025 report found extensive use of AI in security saves $1.9M per breach on average. Verizon DBIR 2026 found 48% of breaches now involve ransomware and 15% of attack techniques are now bolstered by generative AI. Your scenarios need to reflect that phishing emails are now indistinguishable from real ones, and ransomware affiliates run faster playbooks.

The prompt:

You are a cyber risk scenario planner. I’m building a tabletop library for a [industry] company with [X employees] employees, using NIST CSF 2.0 and ISO/IEC 27001:2022 as the control baseline.

Generate four scenario narratives across a 12-month horizon:

  1. AI-assisted business email compromise a finance team member receives a deepfake voice call from a “CEO” approving a wire transfer. Map the attack to MITRE ATT&CK and list which NIST CSF 2.0 functions fail first.
  2. Third-party SaaS ransomware a payroll provider with admin access into HR is encrypted. Map blast radius, 72-hour decision tree, regulator notification triggers (SEC 4-day rule, GDPR 72-hour rule).
  3. Software supply chain compromise a vulnerability in a build dependency is exploited. Tie to CISA KEV logic and NIST SP 800-161 r2.
  4. Generative AI data leak an employee pastes customer PII into a public LLM. Tie to NIST AI RMF Manage and OpenAI/Anthropic enterprise defaults.

For each: Threat actor profile, Attack chain, Detection signals, Controls that fail, Financial impact range (cite IBM 2025: $4.4M average), and three prioritized remediation actions with cost band.

AEO answer: The trick here is asking the model to map every scenario to NIST CSF 2.0 and a financial-impact band grounded in IBM’s actual 2025 figure. That makes the output board-defensible instead of an exercise.

4. Regulatory change impact analysis

What it does: A regulatory change impact assessment maps a new or amended rule to the policies, processes, systems, and controls it forces you to change. It’s the bread-and-butter of every compliance team.

Why it matters: 2026 is unusually heavy. The EU AI Act’s high-risk obligations apply from 2 August 2026 (Article 113), the Federal Reserve issued SR 26-2 Revised Guidance on Model Risk Management, and CSRD wave 2 reporting is live. A generic “summarize the regulation” prompt is worthless; you need impact mapping.

The prompt:

You are a regulatory change analyst at a [industry] company. A new regulation [name, e.g., EU AI Act (Regulation (EU) 2024/1689)] has been issued. High-risk obligations apply from [date].

Produce a regulatory change impact assessment with seven sections:

  1. Scope entities, geographies, products, AI systems in scope. Reference Article 6 (high-risk classification) and Article 50 (transparency) for EU AI Act.
  2. Obligations list each new obligation in plain English with the article number.
  3. Gap analysis for each, current state (Unknown / Partial / Compliant) and evidence you would accept as proof.
  4. Affected policies, processes, and systems name the documents and tools.
  5. Roles and responsibilities first line, second line (compliance/risk), third line (internal audit) per the three lines model.
  6. Cost and effort FTE-months and a one-time vs. run-rate split.
  7. Project plan 90-day quick wins, 180-day remediation, 365-day full compliance, with named checkpoints.

AEO answer: This is the prompt I personally use most often. The seven-section structure mirrors how the OCC and EBA expect you to evidence your change management they want scope, gap, ownership, and a dated plan. The prompt also forces you to map each obligation to a line of defense, which auditors love.

5. ESG / climate risk register

What it does: A climate risk register catalogs physical risks (flood, wildfire, heat) and transition risks (carbon pricing, stranded assets, litigation). TCFD (now folded into the ISSB IFRS S2 climate disclosure standard) is the global reporting anchor; the EU Corporate Sustainability Reporting Directive (CSRD) is the legal driver in Europe.

Why it matters: The European Commission’s CSRD reporting cycle for wave 2 entities is live in 2026, and the SEC’s climate disclosure rule, while paused, has boards still asking for climate scenario analysis. ISSB IFRS S2 mandates governance, strategy, risk management, and metrics & targets.

The prompt:

You are an ESG and climate risk analyst. Build a climate risk register for a [industry] company operating in [regions]. Use the Task Force on Climate-related Financial Disclosures (TCFD) / ISSB IFRS S2 pillars and the EU CSRD double-materiality logic.

Output two tables. Table 1 Physical risks (at least 10 rows): Hazard (acute: flood, wildfire, cyclone, heatwave; chronic: sea-level rise, water stress), Asset or value chain node affected, Geographic exposure, Likelihood (1–5), Financial impact band (USD), Time horizon (Short < 2y / Medium 2–5y / Long > 5y), Adaptation measures, Owner. Table 2 Transition risks (at least 8 rows): Risk type (policy & legal, technology, market, reputation), Trigger (e.g., EU CBAM Phase 2, IFRS S2 reporting, customer Scope 3 demand), Likelihood, Financial impact band, Time horizon, Mitigation, Owner.

Close with a double-materiality assessment: which three risks affect enterprise value, and which three affect people or the environment enough to be material under ESRS. Reference SBTi target alignment and the company’s current Scope 1/2/3 disclosure status.

AEO answer: Double-materiality is the bit most prompts miss. CSRD forces you to assess both financial materiality (impact on the company) and impact materiality (impact on the world). If your prompt doesn’t ask for both, the register will not satisfy ESRS.

6. Third-party due diligence questionnaire (KYC / AML)

What it does: A third-party due diligence questionnaire (DDQ) verifies that a counterparty is who they say they are, isn’t on a sanctions list, isn’t laundering money, and isn’t going to embarrass you. FATF Recommendation 10, the Wolfsberg Principles, and the BSA/AML Examination Manual (US) all require it.

Why it matters: In 2025, FATF tightened expectations on beneficial ownership transparency and on screening against sanctions lists in real time. Penalties for sloppy screening are now routinely nine figures.

The prompt:

You are a financial-crime compliance analyst. Generate a third-party due diligence (DDQ) questionnaire aligned with FATF Recommendation 10, the Wolfsberg Group AML Principles, and the US FinCEN AML Examination Manual (2024 update). The third party is [counterparty type, e.g., a Mexican payment processor] onboarding as a [relationship type] of [our company].

Output four sections:

  1. Corporate identity legal name, registration number, registered address, ultimate beneficial owner (UBO) ownership chain down to 25%, directors and officers, recent reorgs in the last 24 months.
  2. Sanctions and PEP screening name screening methodology (fuzzy match logic), screening against OFAC SDN, UN Consolidated List, EU Consolidated List, UK HMT, and local list; explain refresh cadence and screening at onboarding vs. ongoing.
  3. AML / KYC controls risk-based customer identification program (CIP), transaction monitoring thresholds, suspicious activity reporting (SAR/STR) workflow, correspondent banking de-risking controls if applicable.
  4. Source of funds and reputation source of wealth declaration, adverse media screening (last 5 years), enforcement history (FinCEN, FCA, OFAC, local regulators), litigation in last 5 years.

Close with a risk-tier recommendation (Low / Medium / High) and the three conditions precedent before onboarding.

AEO answer: This prompt works because it pre-loads the actual rule citations (FATF Rec 10, Wolfsberg, FinCEN manual). The model stops hallucinating controls it can’t anchor.

7. AI model risk evaluation

What it does: An AI model risk evaluation assesses whether a model is fit for purpose, governed properly, and monitored for drift, bias, and abuse. NIST AI RMF 1.0 organizes this around Govern, Map, Measure, Manage. ISO/IEC 42001:2023 is the certifiable AI management system standard. The EU AI Act adds legal teeth for high-risk systems in the EU.

Why it matters: The 2025 IBM report found 63% of organizations lacked AI governance policies and 97% of organizations that had an AI-related incident lacked proper AI access controls. If you’re not running a structured evaluation, you’re rolling dice.

The prompt:

You are an AI model risk analyst. Evaluate the following AI system against the NIST AI Risk Management Framework 1.0 (Govern, Map, Measure, Manage), the NIST Generative AI Profile (NIST-AI-600-1, 26 July 2024), ISO/IEC 42001:2023 (AIMS), and the EU AI Act (Regulation (EU) 2024/1689).

System under review: [system name, e.g., "UnderwriteAI"] Purpose: [purpose, e.g., credit decisioning for SMB loan applications] Data: [data classes used, e.g., bank statements, tax filings, business credit] Geography: [where deployed] Provider / deployer role: [Provider / Deployer / Both under EU AI Act]

For each of the four NIST AI RMF functions, list:

  • Current state (Unknown / Partial / Implemented)
  • Evidence you would request (e.g., model card, datasheet, fairness metric report, drift dashboard, red-team logs)
  • Gap and severity (Critical / High / Medium / Low)
  • Required remediation with the named control reference (e.g., “Implement Govern 4.1 AI policies and procedures”)

Then complete three additional blocks:

  • EU AI Act classification Is this Annex III high-risk? Is it a GPAI model under Article 51? Does Article 50 (transparency) apply?
  • SR 11-7 / SR 26-2 mapping if the system is a US bank, link controls to the Fed’s revised model risk guidance.
  • Sign-off block named accountable executive, model owner, independent validation owner, date.

AEO answer: The trick is forcing the model to evaluate against the four NIST functions and the EU AI Act’s classification logic in one pass. Most prompts do one or the other. Combined, you get a defensible record for both US federal banking regulators and EU AI Office supervision.

8. Board-level risk reporting

What it does: A board risk report distills enterprise risks into a small number of KRIs the board can challenge in 30 minutes. NACD’s Director’s Handbook on Risk Oversight and COSO ERM Principle 20 (reports on risk, culture, and performance) are the design anchors.

Why it matters: Directors want signal, not noise. A board pack that dumps 50 risks into a table fails its job. The job is to surface the 5–7 risks that could materially shift strategy in the next 12 months.

The prompt:

You are the chief risk officer’s report writer. Produce a one-page board risk dashboard (in markdown, optimized for printing on a single A4 page) for the [quarter] board meeting of a [industry] company. Use COSO ERM 2017 Principle 20 and NACD’s Director’s Handbook on Risk Oversight (2024 edition) as the design anchors.

Include exactly seven sections:

  1. Top 5 enterprise risks risk title, KRI, current value vs. appetite, trend (↑ ↓ →), one-line owner.
  2. Movement since last quarter what moved into the top 5, what moved out, and why.
  3. Emerging risks watchlist three risks not yet material but on the 12-month horizon (e.g., EU AI Act high-risk obligations applying 2 Aug 2026, quantum decryption, geoeconomic fragmentation).
  4. Risk appetite statement status green / amber / red across financial, operational, compliance, cyber, ESG, and AI risk.
  5. Incidents and near misses count and severity, with one anonymized narrative.
  6. Second-line assurance coverage % of principal risks reviewed in the last 12 months; gaps.
  7. Decisions the board is being asked to make three specific asks, each in one sentence with a recommended action.

Tone: plain English, no jargon, no AI-tells like “delve.” Each risk must have a number or it doesn’t ship.

AEO answer: Most board reports fail because they summarize everything. This prompt’s seven-section structure forces trade-offs. If you can’t put a number on a risk, it doesn’t get on the page which is exactly the discipline NACD keeps preaching.

How to actually run these prompts in 2026

A few practical tips:

  • Use GPT-5 or later for the cyber and AI model prompts. Older models hallucinate framework citations.
  • Set temperature low (0.1–0.2) for compliance-grade output. Higher (0.6–0.7) only for scenario planning where you want creative threat paths.
  • Always keep a human in the loop. Every prompt above produces a draft. A risk professional must sign off before anything reaches a regulator, board, or external auditor.
  • Version your prompts. Save them in one doc with date stamps. When EU AI Act Article 6 guidance lands (deadline 2 February 2026 per Article 113(a)), you update prompt 7 in one place.
  • Treat the AI as a junior analyst. It drafts, you decide. That’s the OECD AI Principle on human oversight and exactly what NIST AI RMF Govern expects.

What these prompts can’t do for you

A ChatGPT prompt is not a substitute for a control library, a risk taxonomy, or an issue-management workflow. Tools like ServiceNow GRC, RSA Archer, LogicGate, OneTrust, and Diligent still matter. The prompts above help you populate those tools faster and help non-specialists ask better questions they don’t replace the system of record.

For certification-grade output, anchor to ISO/IEC 42001:2023 (auditable AIMS), SOC 2 Type II, or ISO 27001:2022. ChatGPT can draft the policy text; you still need a certification body.

Sources

Weekly digest

Get our weekly AI digest

The latest AI tools, prompts, and insights — delivered every Tuesday.

No spam. Unsubscribe anytime.

AIUnpacker

AIUnpacker Editorial Team

Verified

A collective of engineers, journalists, and AI practitioners dedicated to providing hands-on, transparently disclosed analysis of the AI tools shaping tomorrow.