Find AI Prompts
HomeOperations & Supply Chaina Supply Chain Risk Register
Operations & Supply ChainRisk & Resilience

AI Prompts for a Supply Chain Risk Register

A risk register is a living list of what could disrupt supply, how likely and how bad it would be, who owns each risk and what is being done about it. Most registers fail through inconsistency — the same event scored differently by different people — or through neglect, reviewed once and left. A usable register has a taxonomy that makes risks comparable, scoring scales anchored to real consequences, and a review rhythm.

These prompts build the register across the taxonomy, calibrate the scoring so that a 4 means the same thing everywhere, and prepare the periodic review. They cover the whole supply chain; supplier-specific assessment and disruption response have their own pages.

Before you use these

Have these ready to replace the highlighted [variables]:

The prompts

1. Build the risk register

Best forA complete first register organized by taxonomy with owners and current controls.
Inputs needed
  • Supply chain description
  • Known risks and incidents
  • Owners
How to use itGive the model your supply chain in enough detail that risks can be specific (this lane, this supplier, this site) rather than generic. Generic risks are not actionable.
Expected outputRegister with risk ID, category, description, cause, effect, current controls, owner, and initial likelihood/impact scores with rationale.
Act as a supply chain risk manager building a risk register for [company / supply chain].

Supply chain: [sources and suppliers by tier where known, manufacturing/DC sites, logistics lanes and modes, key products and their dependencies, customers/channels]
Known risks, incidents, near misses: [list]
Owners: [roles responsible for procurement, logistics, planning, sites, quality, IT]

1. Using a taxonomy — supply (supplier failure, capacity, quality, sub-tier), demand (volatility, concentration, forecast), process (site, equipment, labor, quality), logistics (lane, port, carrier, customs), external (natural hazard, geopolitical, regulatory, macro), information/cyber, financial (currency, commodity, credit) — identify specific risks for our supply chain. Each must name the specific supplier, site, lane or product exposed.
2. For each risk: ID, category, description (event), cause(s), effect on us (which products/customers, how), current controls, owner, and an initial likelihood (1–5) and impact (1–5) with one line of rationale each.
3. Group risks that share a cause or a mitigation.
4. Identify risks where no owner is natural and propose one.
5. Highlight risks with no current control.
6. Note the risks whose scores are most uncertain and what information would firm them up.

Aim for a register that is complete on the material risks (typically 20–40 entries), not exhaustive. Do not include generic risks with no specific exposure identified.

2. Calibrate likelihood and impact scoring

Best forScoring scales anchored to real consequences so scores are consistent across the register.
Inputs needed
  • Financial and operational context
  • Draft scores
  • Risk appetite
How to use itGive revenue, margin and recovery-cost context. The model builds anchored scales and then re-scores the draft register against them, flagging inconsistencies.
Expected outputAnchored likelihood and impact scales, re-scored register, inconsistencies found, and the risk appetite thresholds.
You are calibrating the scoring for a supply chain risk register.

Context: [annual revenue, revenue by key product/channel, margin, typical recovery costs, service commitments, regulatory exposure]
Draft register scores: [risk, likelihood, impact, rationale]
Risk appetite: [what leadership considers tolerable, if stated]

1. Build an impact scale (1–5) with anchors on multiple dimensions: revenue at risk (absolute and % thresholds), duration of disruption, customer/service effect, cost to recover, regulatory or safety consequence, reputational. A risk scores at its highest dimension.
2. Build a likelihood scale (1–5) anchored to frequency (e.g. 5 = expected within a year; 1 = less than once in 20 years) with guidance for events with no history.
3. Define a velocity or detectability modifier if useful (how fast the risk hits and how much warning we get).
4. Re-score the draft register against the anchors. List every score that changed and why.
5. Identify inconsistencies: similar risks scored differently, scores driven by recency of an incident, and impacts scored on worst case rather than reasonable case (state which convention applies).
6. Set the appetite thresholds on the resulting scale: which score combinations require mitigation, monitoring, or acceptance.

Present the scales as tables and the re-scored register. Keep anchors specific to our numbers.

3. Run the heat-map review

Best forA periodic review that focuses on the risks that moved and the mitigations that are behind.
Inputs needed
  • Current register
  • Changes since last review
  • Mitigation status
How to use itRun quarterly. Give the model the prior scores and the mitigation status; it will produce the heat map, the movers, and the review agenda.
Expected outputHeat map summary, risks that moved with reasons, mitigation status and overdue actions, new and closed risks, and the decisions for the review meeting.
Act as the facilitator of a quarterly supply chain risk review.

Register: [risk, category, likelihood, impact, prior likelihood, prior impact, owner, mitigation actions with status and due dates]
Changes since last review: [incidents, near misses, external events, supply base changes, new products]
Appetite thresholds: [from calibration]

1. Heat map summary: count and list of risks per zone (above appetite / monitor / accept). Show the shift versus last review.
2. Movers: risks whose scores changed, with the reason (event, new information, mitigation effect). Challenge any score that moved without a stated reason.
3. Mitigation status: actions completed, on track, overdue. For overdue actions: consequence and the decision required.
4. New risks proposed from the changes (with initial scores) and risks proposed for closure (with the evidence that they no longer apply).
5. Effectiveness: risks where mitigation has been in place for more than [n] quarters without a score improvement — is the mitigation wrong or the score stale?
6. Review meeting agenda (60 minutes): decisions required, in priority order; the risks not to discuss (unchanged, within appetite).
7. Outputs for the board or executive summary: five lines maximum.

Keep the review focused on change and decisions. Do not re-discuss stable risks.

Related prompts

Logical next step

After this, most operations teams move on to Supplier Risk Assessment.

Get the free Operations & Supply Chain AI Starter Kit → Nine of these prompts as a diagnose → analyze → plan workflow with an intake worksheet, delivered by email. See what's inside

All Operations & Supply Chain prompts · Search the full library