Legal Risk Assessment — Risk Assessor
"Flag legal risk"
Turns "this feels risky" into a scored, sorted register with owners and tripwires. Works from a description of the situation plus any documents provided.
When to use
- "What's our exposure if we sign this?" — deal downside read
- "How risky is operating without a signed DPA for a quarter?"
- "Rank the legal risks of this expansion plan"
- Before an exec or board commit on a contested move
- Clause-level contract surgery belongs to
review-contract; this skill scores the whole situation
Workflow
- Frame the situation: the decision at stake, timeline, jurisdictions, counterparties, and what "bad" concretely looks like for the business.
- Enumerate risks across the standard surfaces — contractual, regulatory, IP, privacy and data, employment, litigation, reputational-with-legal-consequence. Each risk is a concrete event ("residuals clause lets the vendor reuse our roadmap"), never a category name ("IP risk").
- Score each risk: impact 1-5 (1 = nuisance cost … 5 = company-changing) × likelihood 1-5 (1 = remote … 5 = expected). Score = impact × likelihood, with a one-line rationale per score — unexplained numbers are guesses.
- Render the heat map sorted by score, descending.
- Attach a mitigation to every risk at or above threshold (default: score ≥ 8, overridable): the action, its owner, and the residual score once done.
- Define escalation criteria — observable conditions that send this to human counsel immediately (e.g., any impact-5 risk, regulator contact, a litigation threat received, press involvement).
- Set monitoring triggers: events that reopen the assessment ("counterparty misses a payment", "new guidance published on X"), each with a named watcher.
- Deliver the dated register and a one-sentence bottom line: proceed, proceed with mitigations, or do not proceed.
Output format
LEGAL RISK REGISTER — <matter> — <date>
Decision at stake: <one line> Mitigation threshold: score ≥ 8
HEAT MAP (sorted by score)
| # | Risk (concrete event) | Impact (1-5) | Likelihood (1-5) | Score | Rationale |
|---|-----------------------|--------------|------------------|-------|------------|
| 1 | <risk> | 4 | 4 | 16 | <one line> |
| 2 | <risk> | 5 | 2 | 10 | <one line> |
| 3 | <risk> | 2 | 3 | 6 | <one line> |
MITIGATIONS (score ≥ threshold)
| Risk # | Mitigation action | Owner | Residual score |
|--------|-------------------|-------|----------------|
| 1 | <action> | <who> | <I × L after> |
ESCALATE TO HUMAN COUNSEL IMMEDIATELY IF
- <observable condition>
- <observable condition>
MONITORING TRIGGERS
- <event> → reassess risk #<n> — watcher: <who>
BOTTOM LINE: <proceed / proceed with mitigations / do not proceed> — <one sentence why>
*Issue-spotting support, not legal advice — engage counsel for binding decisions.*
Quality bar
Example
Invocation: "We're about to sign a 3-year exclusive distribution deal in a market we've never operated in. Exposure?"
Produces: A register of seven risks. Top score 16: exclusivity lock-in with no minimum-performance exit (impact 4 × likelihood 4), mitigated by a termination-for-underperformance clause (residual 8). Escalation fires if the counterparty demands a non-compete covering existing markets; monitoring trigger on quarterly sales versus floor, watched by the deal owner. Bottom line: proceed with mitigations.
Issue-spotting support, not legal advice — engage counsel for binding decisions.
1---2name: legal-risk-assessment3description: Severity-by-likelihood legal risk register for a situation or deal — enumerates concrete risks, scores each one impact 1-5 × likelihood 1-5, renders a heat-map table, attaches mitigations to every risk at or above threshold, defines escalation criteria for immediate human counsel, and sets monitoring triggers. Use when the user says 'what's our exposure', 'how risky is this deal', 'assess the legal risk of this', or before committing to anything with real downside.4---56# Legal Risk Assessment — Risk Assessor78> "Flag legal risk"910Turns "this feels risky" into a scored, sorted register with owners and tripwires. Works from a description of the situation plus any documents provided.1112## When to use1314- "What's our exposure if we sign this?" — deal downside read15- "How risky is operating without a signed DPA for a quarter?"16- "Rank the legal risks of this expansion plan"17- Before an exec or board commit on a contested move18- Clause-level contract surgery belongs to `review-contract`; this skill scores the whole situation1920## Workflow21221. Frame the situation: the decision at stake, timeline, jurisdictions, counterparties, and what "bad" concretely looks like for the business.232. Enumerate risks across the standard surfaces — contractual, regulatory, IP, privacy and data, employment, litigation, reputational-with-legal-consequence. Each risk is a concrete event ("residuals clause lets the vendor reuse our roadmap"), never a category name ("IP risk").243. Score each risk: impact 1-5 (1 = nuisance cost … 5 = company-changing) × likelihood 1-5 (1 = remote … 5 = expected). Score = impact × likelihood, with a one-line rationale per score — unexplained numbers are guesses.254. Render the heat map sorted by score, descending.265. Attach a mitigation to every risk at or above threshold (default: score ≥ 8, overridable): the action, its owner, and the residual score once done.276. Define escalation criteria — observable conditions that send this to human counsel immediately (e.g., any impact-5 risk, regulator contact, a litigation threat received, press involvement).287. Set monitoring triggers: events that reopen the assessment ("counterparty misses a payment", "new guidance published on X"), each with a named watcher.298. Deliver the dated register and a one-sentence bottom line: proceed, proceed with mitigations, or do not proceed.3031## Output format3233```34LEGAL RISK REGISTER — <matter> — <date>35Decision at stake: <one line> Mitigation threshold: score ≥ 83637HEAT MAP (sorted by score)38| # | Risk (concrete event) | Impact (1-5) | Likelihood (1-5) | Score | Rationale |39|---|-----------------------|--------------|------------------|-------|------------|40| 1 | <risk> | 4 | 4 | 16 | <one line> |41| 2 | <risk> | 5 | 2 | 10 | <one line> |42| 3 | <risk> | 2 | 3 | 6 | <one line> |4344MITIGATIONS (score ≥ threshold)45| Risk # | Mitigation action | Owner | Residual score |46|--------|-------------------|-------|----------------|47| 1 | <action> | <who> | <I × L after> |4849ESCALATE TO HUMAN COUNSEL IMMEDIATELY IF50- <observable condition>51- <observable condition>5253MONITORING TRIGGERS54- <event> → reassess risk #<n> — watcher: <who>5556BOTTOM LINE: <proceed / proceed with mitigations / do not proceed> — <one sentence why>5758*Issue-spotting support, not legal advice — engage counsel for binding decisions.*59```6061## Quality bar6263- [ ] Every risk is a concrete event, not a category label64- [ ] Every score carries a one-line rationale — no bare numbers65- [ ] Every risk at or above threshold has a mitigation, an owner, and a residual score66- [ ] Escalation criteria are observable conditions, not judgment calls67- [ ] Register is dated and every monitoring trigger names a watcher68- [ ] Bottom line commits to one recommendation6970## Example7172**Invocation:** "We're about to sign a 3-year exclusive distribution deal in a market we've never operated in. Exposure?"7374**Produces:** A register of seven risks. Top score 16: exclusivity lock-in with no minimum-performance exit (impact 4 × likelihood 4), mitigated by a termination-for-underperformance clause (residual 8). Escalation fires if the counterparty demands a non-compete covering existing markets; monitoring trigger on quarterly sales versus floor, watched by the deal owner. Bottom line: proceed with mitigations.7576*Issue-spotting support, not legal advice — engage counsel for binding decisions.*