risk-assessment

Identify, quantify, and evaluate risks to generate a structured risk register.

Updated Apr 1, 2026
One-click install
npx skills add https://github.com/hpsgd/turtlestack --skill risk-assessment-hpsgd
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: risk-assessment
Source: https://github.com/hpsgd/turtlestack/tree/main/plugins/leadership/grc-lead/skills/risk-assessment
Command: npx skills add https://github.com/hpsgd/turtlestack --skill risk-assessment-hpsgd

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Risk assessments are time-consuming and error-prone without a structured approach to identify, quantify, and prioritise risks for systems, projects, or changes.

Core Features & Use Cases

  • Systematic risk identification across categories (Regulatory, Operational, AI/ML, Data, Financial, Reputational, Vendor) with unique IDs
  • Quantitative risk analysis using probability, impact, and a matrix to establish inherent and residual risk levels
  • Formal risk treatment planning including owner assignment and review triggers, then compiling a risk register
  • Use Case: A product launch faces regulatory and operational risks; run the assessment to produce a prioritized risk list and mitigation plan.

Quick Start

Provide the subject and scope, then run the risk assessment.

Frequently Asked Questions about risk-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create a structured risk assessment for a project launch?

A risk assessment identifies, quantifies, and evaluates risks across categories like regulatory, operational, and financial, using a probability and impact matrix to establish inherent and residual risk levels for systems or projects.

Can I use this to evaluate AI and vendor risks together?

Yes, you can evaluate AI and vendor risks together by applying the assessment across multiple risk categories including AI/ML, data, and vendor scenarios, assigning unique risk IDs to track each distinct threat within a single profile.

How do I calculate residual risk levels after applying controls?

Calculate residual risk by assessing the probability and impact of inherent risks, evaluating existing control measures, and then recalculating the remaining risk levels to generate a formal risk treatment decision and plan.

What is the best way to build a risk register with mitigation plans?

Build a risk register by systematically identifying risks with unique IDs, analyzing them through a risk matrix, assigning formal treatment plans and owners, and capturing review triggers to document both inherent and residual calculations.

Does this risk assessment support regulatory and operational compliance scenarios?

Yes, this risk assessment supports regulatory and operational compliance scenarios by systematically identifying threats across these categories, evaluating control effectiveness, and producing a structured treatment plan to ensure project compliance.