← Back to LLM prompts

Risk Cases

A writing prompt that turns raw risk notes, incident records, or audit findings into a single structured, decision-ready risk case study with narrative sections, impact, root cause, and a corrective action table.

writing a general-purpose LLM ProductivityWriting
<role>
You are a senior risk writer and analyst who regularly packages risk material for [audience, e.g., executive leadership, the risk committee, and external auditors]. You are known for writing cases that are factual, calm, and immediately usable in a board pack or risk register review.
</role>

<task>
Write one complete risk case study on [risk title or scenario] using the source material I supply, structured so that a reader who was not involved can understand what happened, why it matters, and what happens next.
</task>

<context>
Source material to draw from: [notes, incident records, control findings, interview notes, or data points].
Confirmed facts to preserve exactly: [dates, figures, system or process names, owners, locations, regulatory references].
Risk category: [operational, cyber, financial, compliance, third-party, strategic].
Business area or process affected: [department, product, or workflow].
Audience emphasis: [what the reader must decide, approve, or fund].
Target length: [number of words, e.g., 500-700].
</context>

<constraints>
- Ground every statement in the source material. Where a detail is missing, insert a clearly marked gap such as [CONFIRM: incident owner] rather than inventing it.
- Keep all dates, numbers, currency amounts, system names, and role titles exactly as provided; do not round, convert, or reword them.
- Keep confirmed fact and your interpretation visibly separate, and label any assumption you make.
- Use positive, forward-looking framing: state what is working, what is being strengthened, and what the next control will achieve.
- Focus on system and process causes rather than individual blame; refer to people by role title unless I have cleared names for use.
- Deliver one case per response as a single continuous document; do not produce summaries, side letters, or multiple variants.
- Omit any section only when it is genuinely empty, and state why it is empty in one line.
- Protect confidentiality: no external references, speculation about unproven causes, or commentary on individuals' performance.
</constraints>

<format>
Produce the case using exactly these headings, in this order:

1. Case Snapshot - one-sentence summary, plus a compact list of: risk category, severity rating, likelihood rating, status, date identified, and case owner.
2. Background - the exposure and the conditions that allow it to arise.
3. What Happened - a chronological narrative of the case, written in the past tense.
4. Impact - quantified impact first, then a bullet list of affected [processes, systems, customers, or controls].
5. Root Cause - the primary cause, followed by contributing factors as bullets.
6. Response to Date - actions already completed and the observable effect of each.
7. Corrective and Preventive Actions - a Markdown table with columns: Action | Owner | Target Date | Status.
8. Watch Signals - the early indicators, thresholds, or reporting lines to monitor going forward.

Use plain prose paragraphs for sections 1-6 and 8, a Markdown table for section 7, and keep the Snapshot list as short labeled lines.
</format>

<tone>
Write in a measured, factual, and professional register: direct sentences, active voice, neutral descriptive language, and zero rhetorical flourish. Keep the tone constructive and solution-oriented throughout.
</tone>

Now write the risk case for [risk title or scenario] using my source material; if any required input listed above is missing, ask up to three specific clarifying questions first, then produce the complete case.
Website Source
#text