Verified against ChatGPT · 2026-08-13
Build a compliance risk register that ranks by actual exposure instead of listing every possible risk equally
Converts a list of compliance areas into a ranked risk register with likelihood, impact, and current mitigation status, so leadership sees where to act first instead of a flat inventory of everything that could go wrong.
The prompt
Ready to copy — highlighted parts are example details you can swap.
Build a compliance risk register from the areas I describe below. The output needs to rank risks by actual exposure, not just list them — a register where everything looks equally urgent is not useful to leadership deciding where to spend limited time.
COMPLIANCE AREAS TO ASSESS
Data privacy handling, workplace safety documentation, and vendor contract compliance.
ORGANIZATION PROFILE
80-person manufacturing company, handles customer PII for e-commerce orders, has a physical warehouse floor.
CURRENT MITIGATIONS IN PLACE
Data encrypted in transit but not at rest; warehouse safety training done annually but not tracked per employee.
WHO REVIEWS THIS REGISTER
Executive leadership team deciding Q3 budget priorities.
BUILDING THE REGISTER
For each compliance area, state the specific risk in concrete terms — not "data privacy risk" as a category, but the actual thing that could go wrong ("customer PII stored without encryption at rest, discovered during a breach"). Rate likelihood and impact separately using a simple scale (Low/Medium/High) based on the organization profile and current mitigations you were given, and explain the rating in one sentence rather than leaving the score unjustified — an unexplained score is not something the audience can push back on or trust. Cross-reference against the mitigations described so a risk with a strong existing control gets rated differently than the same risk with nothing in place — do not rate risks in a vacuum as if no mitigation existed when one was described. Sort the final register by combined exposure (likelihood x impact), highest first, so the audience reads top-to-bottom in priority order rather than having to re-sort a flat list themselves.
WHAT NOT TO DO
Do not assign a specific dollar figure or fine amount to any risk unless one was given to you — invented financial figures in a document leadership might act on are worse than no figure at all. Do not state that a risk is or isn't currently a compliance violation — a risk register describes exposure and priority, not a legal determination of current compliance status.
OUTPUT FORMAT
1. Ranked risk register table: Risk (specific) | Likelihood | Impact | Rating rationale | Current mitigation | Combined exposure.
2. Top 3 priorities called out separately with a one-line "why this first" for each.
3. A closing note stating this register is a prioritization tool built from the information described, not a legal compliance audit or determination — a qualified compliance lawyer or auditor should validate the actual compliance status of each area before this register is used to make final resourcing or disclosure decisions.Customize
Optional — swap in your own details for the highlighted parts above.
Why this works
A risk register that scores every listed item as roughly the same severity fails at its one job, which is telling leadership where to act first — that flattening happens by default because a model given a list of compliance areas without instruction to differentiate will tend to rate most things Medium, the safe middle answer, unless it's explicitly forced to justify each rating against specific organizational facts and sort by combined exposure so the ranking is visible rather than something the reader has to reconstruct themselves. Requiring the risk to be stated as a concrete scenario rather than a category label ("PII stored without encryption at rest" instead of "data privacy risk") matters because a vague category doesn't tell leadership what to actually fix, while a specific failure mode does — and it also makes the likelihood/impact rating checkable, since a reader can look at the specific scenario and judge whether Medium or High makes sense, which a bare category name doesn't allow. Cross-referencing against current mitigations before rating is what keeps the register honest about present-tense risk rather than theoretical risk — the same category (data privacy) is a very different actual risk with encryption at rest in place versus without it, and rating in a vacuum would produce a register that doesn't reflect the organization's actual current exposure, defeating the register's purpose of guiding where new investment is most needed. The prohibitions on inventing dollar figures and on asserting current compliance violation status are both aimed at the same failure: a model will readily produce a specific-sounding number or a definitive compliance verdict because specificity reads as more authoritative, but neither is something the model can actually determine from a short description, and leadership acting on a fabricated fine estimate or an unverified violation claim is a worse outcome than the register simply flagging that a compliance lawyer or auditor needs to confirm it.
What you get back
1. Risk: Customer PII stored without encryption at rest, exposed in a breach scenario. Likelihood: Medium (e-commerce data is a common attack target; no current at-rest encryption). Impact: High (customer PII breach carries notification obligations and reputational cost). Current mitigation: encryption in transit only. Combined exposure: High. Top priority #1: this combines a plausible likelihood with severe impact and only partial mitigation — closing the at-rest encryption gap addresses the largest single exposure on this register. This register is a prioritization tool, not a compliance audit — validate actual compliance status with a qualified lawyer or auditor before final resourcing decisions.
Verified against
ChatGPT GPT-5.1 · 2026-08-13
Changelog
- 2026-08-13 — Initial publish, verified against ChatGPT GPT-5.1.
Need this built into your business?
If a prompt isn't enough — what Scult builds, built and maintained for you — that's Scult's day job.
EXPLORE WHAT SCULT BUILDS
