Prompt Details
Model
Chat - (gpt-5.6)
Token size
450
Example input
[INDUSTRY]: Space Exploration & Off-World Mining
[PROJECT_DESCRIPTION]: Construction and operation of the first automated water-ice and mineral mining facility on Mars to produce rocket propellant (methalox) and resources for a permanent colony.
[SCALE_OR_BUDGET]: Multi-billion USD, 10-year deployment timeline, utilizing Starship fleet payload capacity.
[CONSTRAINTS]: Extreme environmental conditions, 3-22 minute communication delay with Earth, high launch costs, zero immediate human intervention on-site, strict planetary protection standards.
Example output
Below is a **project-level enterprise risk register** for the Mars automated mining and propellant-production program. I have treated the risks as **inherent risks at the current planning/deployment stage**, before assuming that proposed mitigations have been fully implemented.
Risk scoring follows the requested formula:
**Overall Risk Score = Likelihood × Severity**
* **Low:** < 6
* **Medium:** 6–14
* **High:** 15–19
* **Critical:** 20–25
| # | Risk Category | Risk Title / Risk Description | Internal / External Risk | Active Risk? | Root Causes | Impact / Consequences | Preventive Actions | Contingency Response | Likelihood / Probability (1–5) | Severity / Impact (1–5) | Overall Risk Level | Risk Response Strategy | Dependencies / Interconnected Risks | Risk Mitigation Plan |
| ------- | ------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------ | ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -----------------------------: | ----------------------: | ------------------ | ----------------------- | ----------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **R1** | **Business Continuity / Operational / Technical** | **Failure of the autonomous mining and ISRU system** — The mining, excavation, water-ice extraction, purification, electrolysis, hydrogen/oxygen production, methanation and liquefaction systems may fail or degrade without the possibility of immediate physical intervention. | Internal | **Yes** | Immature technology; extreme temperature cycles; abrasive Martian dust; mechanical wear; insufficient redundancy; unexpected soil/ice composition; autonomous-control limitations; inability to perform hands-on maintenance; long qualification cycles; limited operational experience on Mars. | Loss or substantial reduction of water and propellant production; inability to refuel incoming spacecraft; delayed colony deployment; stranded assets; additional launches required; major schedule and CAPEX overruns; potential abandonment of the site. The failure of a single critical subsystem could create a cascading production failure. | High-reliability component selection; qualification under representative Martian conditions; redundant critical subsystems; modular architecture; autonomous fault detection and isolation; extensive Earth-based digital twins; hardware-in-the-loop testing; predictive maintenance; spare-part inventory; graceful degradation modes; multiple independent production trains. | Switch to redundant production train; reduce production targets to preserve critical systems; remotely reconfigure failed equipment; use onboard spares and robotic maintenance where possible; prioritize oxygen/water over non-critical minerals; defer subsequent missions until system recovery; activate contingency propellant reserves. | **4** | **5** | **Critical – 20** | **Mitigate** | **Loss of Availability + Loss of Integrity**; linked to R2, R3, R5, R7 and R8. | Establish a formal **ISRU Reliability & Recovery Program**. Define single-point-of-failure register, minimum redundancy requirements, Mean Time Between Failure/Mean Time To Repair targets, autonomous recovery procedures and mission-level recovery scenarios. Conduct full-system qualification before deployment and maintain independent backup production capability. |
| **R2** | **Business Continuity / Logistics / Supply Chain** | **Loss of launch, transportation or delivery capability** — The project depends on a Starship-based transportation architecture and a sequence of launches to deliver mining equipment, power systems, spares and supporting infrastructure to Mars. Failure of the launch system or a significant reduction in launch cadence could interrupt the entire deployment program. | External | **Yes** | Launch failures; vehicle grounding; regulatory restrictions; production bottlenecks; launch-site infrastructure constraints; weather; supply-chain shortages; loss of a vehicle; changing launch economics; insufficient fleet availability; interplanetary launch-window constraints. | Missing a Mars launch window may create a delay of many months or potentially the next available transfer opportunity. Equipment already manufactured may remain stranded on Earth. Construction sequence may become invalid, creating idle assets, contract penalties and multi-billion-dollar schedule impacts. | Multiple launch vehicles/flight units where feasible; high-value payload redundancy; launch campaign buffers; qualification of critical hardware before launch window; strategic inventory of spares; alternative launch providers where technically and economically feasible; contractual launch capacity reservations; launch-window contingency planning. | Reprioritize payload manifests; defer non-critical payloads; use remaining launch capacity for critical spares/power/communications; reschedule deployment architecture; maintain Earth-based production readiness; use previously delivered redundant equipment. | **4** | **5** | **Critical – 20** | **Mitigate / Transfer** | **Loss of Availability**; linked to R6, R8, R9 and R10. | Create a **Launch & Interplanetary Logistics Resilience Plan** with minimum launch cadence, backup manifests, launch-window decision gates, spare-payload strategy and contractual risk allocation. Maintain predefined "minimum viable Mars deployment" configurations for delayed campaigns. |
| **R3** | **Technical / Environmental / Business Continuity** | **Incorrect assessment of water-ice and mineral resources** — The selected site may contain insufficient accessible water ice, excessive overburden, unsuitable mineral composition or substantially different physical properties from remote sensing estimates. | External | **Yes** | Limited geological data; uncertainty in subsurface structure; inaccurate orbital remote sensing; spatial variability of ice deposits; dust/regolith characteristics; inadequate ground-truthing; unexpected contamination or mineralogy. | Mining may be technically feasible but economically non-viable. Excavation energy requirements may exceed design assumptions; propellant output may be below required levels; equipment may require redesign; site abandonment or relocation could be necessary. | Multi-source orbital data; high-resolution site characterization; robotic prospecting missions; drilling/test wells; probabilistic resource estimation; conservative resource assumptions; selection of multiple candidate sites; pre-deployment validation criteria. | Relocate extraction operations within the site; reduce production target; redesign excavation depth; exploit secondary deposits; deploy additional prospecting assets; modify resource-production mix; postpone colony expansion until resource certainty improves. | **4** | **5** | **Critical – 20** | **Mitigate / Avoid** | **Loss of Availability + Loss of Integrity**; linked to R1, R4 and R6. | Establish a **Resource Assurance Program** requiring statistically defensible estimates of recoverable ice/minerals and defined confidence levels before final site commitment. Do not proceed to full-scale infrastructure deployment unless minimum recoverable-resource thresholds are demonstrated. |
| **R4** | **Financial / Commercial** | **Major cost overrun and economic infeasibility** — Actual development, launch, operations, redundancy and failure-recovery costs may materially exceed the multi-billion-dollar business case. | Internal / External | **Yes** | Technology development uncertainty; low initial production scale; launch delays; inflation; redesign; low equipment reliability; expensive redundancy; unplanned missions; regulatory requirements; financing costs; insufficient contingency reserves. | Significant increase in CAPEX/OPEX; inability to secure further funding; reduced project scope; cancellation of later deployment phases; negative ROI; impairment of assets; investor confidence loss; inability to finance permanent-colony infrastructure. | Stage-gated investment; independent cost estimation; Monte Carlo cost modelling; management reserve; earned-value management; design-to-cost principles; contractual cost controls; technology-readiness gates; sensitivity analysis; explicit cost of failure/recovery in business case. | Freeze non-critical scope; defer expansion phases; renegotiate supplier contracts; seek additional financing; redesign toward minimum viable production; prioritize revenue-generating resources; postpone colony infrastructure until economics recover. | **4** | **5** | **Critical – 20** | **Mitigate** | **Loss of Availability**; linked to virtually all technical, schedule and market risks. | Implement a **Financial Risk & Investment Gate Framework**. Establish P50/P80/P95 cost forecasts, contingency reserves, escalation triggers and stop/go criteria for each deployment phase. Recalculate the business case after every major technical or launch milestone. |
| **R5** | **Cybersecurity / Information Security** | **Cyberattack or compromise of autonomous Mars infrastructure** — Attackers could compromise command systems, software updates, communications infrastructure, navigation or industrial-control systems. Due to communication latency, Earth operators cannot respond interactively to an incident. | External | **Yes** | Remote connectivity; large software attack surface; supply-chain compromise; insecure update mechanisms; credential compromise; vulnerabilities in industrial-control systems; insufficient network segmentation; malicious insiders; dependency on Earth-based infrastructure. | Unauthorized commands could damage equipment, interrupt mining, corrupt production data or cause irreversible hardware failures. A successful attack against propulsion or life-support-related infrastructure could have catastrophic consequences once humans arrive. | Zero-trust architecture; strong cryptographic authentication; hardware security modules; command authorization; network segmentation; offline/immutable recovery images; secure boot; signed software; least privilege; vulnerability management; supply-chain security; continuous monitoring; independent security validation. | Isolate compromised systems; revoke command authority; switch to safe autonomous mode; restore verified software image; disable non-essential external connectivity; use predefined autonomous recovery procedures; preserve forensic evidence; transition to redundant control infrastructure. | **4** | **5** | **Critical – 20** | **Mitigate** | **Loss of Confidentiality + Loss of Integrity + Loss of Availability**; linked to R1, R7, R8 and R10. | Establish a dedicated **Mars OT/ICS Cybersecurity Program** covering IT/OT segmentation, command authentication, secure update infrastructure, cyber incident response, supply-chain assurance and autonomous cyber-safe modes. Cybersecurity must be treated as a safety-critical engineering discipline rather than conventional corporate IT security. |
| **R6** | **Compliance / Regulatory / Planetary Protection** | **Violation of planetary protection requirements** — Mining activities may contaminate scientifically significant Martian environments or introduce terrestrial biological material, potentially violating applicable planetary-protection requirements and international obligations. | External / Internal | **Yes** | Inadequate sterilization; biological contamination during manufacturing/transport; uncontrolled drilling; release of terrestrial material; insufficient environmental characterization; inadequate compliance governance; unclear regulatory interpretation for commercial exploitation. | Regulatory intervention; mission suspension; reputational damage; inability to operate in protected regions; redesign and sterilization costs; potential legal disputes; loss of scientific credibility; restrictions on future missions and commercial activities. | Planetary-protection management system; contamination-control engineering; sterilization and cleanliness requirements; chain-of-custody controls; environmental impact assessment; site exclusion zones; independent compliance assurance; documented evidence throughout manufacturing and launch. | Suspend operations in affected area; isolate contaminated equipment; activate environmental monitoring; notify relevant authorities/stakeholders; shift activity to approved zones; conduct remediation where technically possible; revise mission authorization. | **3** | **5** | **High – 15** | **Mitigate / Avoid** | **Loss of Integrity + Loss of Availability**; linked to R3, R8 and R10. | Create a **Planetary Protection Compliance Plan** integrated into systems engineering. Establish prohibited zones, contamination thresholds, audit evidence, approval gates and independent compliance reviews before launch and before initiating extraction. |
| **R7** | **Information Security / Communications / Operational** | **Loss or degradation of communications and command capability** — The facility operates with a 3–22 minute one-way communication delay, intermittent connectivity and potentially limited bandwidth. | External / Technical | **Yes** | Solar interference; relay failure; antenna degradation; orbital geometry; network congestion; power loss; equipment failure; radiation damage; insufficient communication redundancy. | Earth operators may be unable to issue corrective commands or receive telemetry in time. A seemingly minor fault could escalate into irreversible equipment damage. Mission-critical decisions may need to be executed autonomously without human confirmation. | Multi-path communications; redundant relay satellites; store-and-forward architecture; autonomous decision logic; local health management; predictive fault detection; communication-loss safe states; extensive delayed-communications testing. | Enter autonomous safe mode; execute pre-authorized recovery sequence; prioritize essential telemetry; reduce system activity; use alternative relay paths; wait for communication restoration while preserving equipment. | **4** | **5** | **Critical – 20** | **Mitigate** | **Loss of Availability + Loss of Integrity**; strongly linked to R1, R5 and R8. | Establish a **Communications Loss Operating Concept** defining exactly what the system does after 1 hour, 6 hours, 24 hours and longer communication outages. Critical operations must be autonomous and deterministic, with pre-approved command envelopes. |
| **R8** | **Business Continuity / Energy / Infrastructure** | **Power-generation or energy-storage failure** — The mining and propellant facility requires reliable power for excavation, water extraction, electrolysis, gas processing, liquefaction, heating and communications. | Internal / Environmental | **Yes** | Insufficient solar availability; dust accumulation; extreme temperatures; battery degradation; nuclear-system failure if applicable; power electronics failure; inadequate energy storage; unexpected production-energy requirements. | Mining and ISRU operations may stop. Repeated power interruptions could damage equipment and reduce production capacity. Extended outages could prevent spacecraft refueling and make subsequent missions impossible. | Hybrid power architecture; substantial energy storage; redundant generation; power prioritization; dust mitigation; nuclear backup where technically appropriate; thermal management; energy-demand modelling; black-start capability. | Shut down non-critical loads; preserve thermal conditions; maintain communications and control systems; restart production in stages; use reserve power; prioritize water, oxygen and critical thermal systems. | **4** | **5** | **Critical – 20** | **Mitigate** | **Loss of Availability**; linked to R1, R2 and R7. | Develop a **Mars Energy Resilience Architecture** with N+1 generation, defined energy reserves, black-start procedures, load-shedding priorities and minimum power levels required for safe survival of the facility. |
| **R9** | **Environmental / Technical** | **Radiation and extreme environmental degradation** — Radiation, thermal cycling, vacuum, low atmospheric pressure and Martian dust may progressively degrade electronics, materials, seals, sensors and mechanical systems. | External | **Yes** | Harsh environment; insufficient shielding; radiation-sensitive components; thermal expansion/contraction; electrostatic dust adhesion; abrasive dust; inadequate long-duration testing. | Accelerated equipment degradation; sensor errors; electronics failures; reduced operating life; increased maintenance requirements; unexpected downtime; potential catastrophic failure of irreplaceable equipment. | Radiation-hardened components; shielding; thermal cycling tests; dust-resistant designs; redundant sensors; environmental qualification; conservative component derating; health monitoring; replaceable modular components. | Switch to redundant components; reduce operating loads; isolate degraded equipment; recalibrate sensors; use alternative control modes; deploy robotic replacement modules if available. | **4** | **4** | **High – 16** | **Mitigate** | **Loss of Availability + Loss of Integrity**; linked to R1, R7 and R8. | Establish an **Environmental Qualification & Lifetime Assurance Program** using representative radiation, dust and thermal-cycle testing. Define component end-of-life criteria and maintain degradation models throughout the mission. |
| **R10** | **Schedule / Program Management** | **Failure to meet the 10-year deployment timeline** — Technical maturity, launch windows, regulatory approvals, manufacturing capacity and interdependencies may cause cumulative schedule slippage. | Internal / External | **Yes** | Optimistic estimates; technology development delays; serial dependencies; launch failures; testing delays; supply-chain constraints; redesign; regulatory approval delays; insufficient schedule reserve. | Delay of revenue generation and colony support; increased financing costs; idle assets; contractual penalties; loss of strategic first-mover advantage; increased exposure to technological obsolescence; potential mismatch between infrastructure deployment and crewed missions. | Integrated master schedule; critical-path management; schedule risk analysis; probabilistic Monte Carlo scheduling; schedule contingency; parallel engineering activities; long-lead procurement; independent schedule assurance. | Rebaseline schedule; prioritize critical-path components; defer non-critical capabilities; increase production resources; redesign deployment sequence; use additional launch opportunities; revise crewed-mission dependency dates. | **4** | **4** | **High – 16** | **Mitigate** | **Loss of Availability**; linked to R2, R3, R4, R6 and R8. | Create a **Program Schedule Risk Management Framework** with P50/P80 completion dates, critical-path buffers, milestone health indicators and predefined escalation thresholds. No major milestone should depend on a single unprotected predecessor. |
| **R11** | **Market / Strategic / Commercial** | **Insufficient economic demand for Martian-produced resources** — The business case may assume future demand from spacecraft, logistics or a permanent colony that develops more slowly than expected. | External | **Yes** | Slower-than-expected Mars settlement; alternative propellant architectures; lower launch cadence; competing ISRU technologies; falling Earth launch costs; technological substitution; geopolitical restrictions on Mars commercialization. | Production assets may be underutilized. Revenue assumptions may fail, reducing project valuation and investor appetite. The facility could become technically successful but commercially uneconomic. | Multiple revenue scenarios; conservative demand forecasts; phased capacity expansion; modular production; long-term customer commitments; flexible resource production; scenario analysis against alternative transportation architectures. | Reduce production capacity; postpone expansion; target different resources; sell capacity/service contracts; repurpose infrastructure for scientific/logistics missions; renegotiate financing based on revised demand. | **3** | **4** | **High – 12?** | **Mitigate** | **Loss of Availability**; linked to R2, R4 and R10. | **Note:** 3 × 4 = **12**, therefore this is **Medium** under the specified scoring thresholds. Develop a **Market Demand Validation Plan** with minimum contracted/committed demand, trigger points for capacity expansion and downside scenarios where colony development is delayed by 5–10 years. |
| **R12** | **Human Factors / Safety / Autonomous Systems** | **Autonomous decision-making failure** — The facility may encounter conditions not anticipated by its software and make an incorrect decision without real-time human intervention. | Internal / Technical | **Yes** | Incomplete training data; edge cases; software defects; sensor disagreement; inadequate autonomy architecture; unexpected environmental conditions; incorrect assumptions embedded in control algorithms. | Incorrect excavation, pressure control, thermal management or chemical processing could damage equipment or create hazardous conditions. Once humans arrive, latent autonomous-system failures could threaten crew safety. | Formal verification of safety-critical software; fault-tree analysis; scenario-based simulation; digital twins; independent software validation; fail-safe states; bounded autonomy; sensor fusion; human-on-the-loop architecture where latency permits. | Stop affected process; revert to deterministic safe-state control; isolate subsystem; execute pre-authorized recovery sequence; disable autonomous optimization; await Earth instructions when the system remains stable. | **4** | **5** | **Critical – 20** | **Mitigate** | **Loss of Integrity + Loss of Availability**; linked to R1, R5 and R7. | Implement a **Safety-Critical Autonomy Assurance Program**. Classify autonomous functions by criticality, establish verification requirements and prohibit unrestricted AI/autonomous control of safety-critical systems without deterministic boundaries and validated fallback states. |
| **R13** | **Supply Chain / Procurement / Strategic** | **Failure of critical-component supply chain** — Specialized radiation-hardened electronics, high-performance valves, pumps, sensors, power electronics and propulsion/chemical-processing components may have limited suppliers. | External | **Yes** | Single-source suppliers; long manufacturing lead times; export controls; geopolitical tensions; component obsolescence; quality failures; supplier bankruptcy; low production volumes. | Production delays; inability to replace failed components; redesign costs; launch-window losses; increased procurement costs; potentially stranded infrastructure. | Dual sourcing; strategic stockpiles; component standardization; lifecycle management; supplier financial monitoring; qualification of alternatives; long-lead procurement; domestic/controlled supply where appropriate. | Use certified alternative component; cannibalize non-critical systems; redesign affected module; prioritize remaining inventory for mission-critical systems; postpone non-critical deployment. | **4** | **4** | **High – 16** | **Mitigate / Transfer** | **Loss of Availability + Loss of Integrity**; linked to R2, R4 and R9. | Establish a **Critical Supply Chain Resilience Plan** identifying all single-source components, maximum tolerable lead times, alternate suppliers and minimum strategic stock levels. |
| **R14** | **Project Governance / Strategic / Compliance** | **Program governance failure and excessive system complexity** — A multi-billion-dollar, multi-decade program involving spacecraft, robotics, mining, energy, chemical processing, software and regulatory domains may develop uncontrolled interfaces and fragmented accountability. | Internal | **Yes** | Organizational silos; unclear system ownership; weak configuration management; uncontrolled requirements; inadequate change control; competing stakeholder objectives; insufficient independent assurance. | Interface failures, duplicated investment, inconsistent technical decisions, uncontrolled scope, late defects and poor accountability. Governance failures could amplify otherwise manageable technical risks into program-level failures. | Integrated program governance; clear RACI; systems engineering authority; configuration control board; requirements traceability; independent technical assurance; integrated risk register; formal change control; stage gates. | Escalate critical decisions to program governance board; freeze affected configuration; conduct independent review; re-baseline requirements; establish temporary centralized technical authority. | **3** | **4** | **Medium – 12** | **Mitigate** | **Loss of Integrity + Loss of Availability**; interconnected with virtually every program risk. | Establish a **Program Management & Systems Engineering Governance Framework** with one accountable System-of-Systems Architect, formal interface control documents, integrated change control and independent assurance at each major gate. |
### Executive risk profile
The **highest-priority risks** are the ones that can independently prevent the entire Mars business model from functioning:
1. **Autonomous ISRU failure — R1: Critical (20)**
2. **Launch/transportation failure — R2: Critical (20)**
3. **Incorrect resource assessment — R3: Critical (20)**
4. **Economic/cost overrun — R4: Critical (20)**
5. **Cyberattack on autonomous infrastructure — R5: Critical (20)**
6. **Communications failure — R7: Critical (20)**
7. **Power-system failure — R8: Critical (20)**
8. **Autonomous decision-making failure — R12: Critical (20)**
The key management observation is that these risks **cannot be managed independently**. The program is a tightly coupled system: for example, a communications outage can prevent recovery from an ISRU fault; an ISRU failure can make a launch campaign economically useless; an incorrect resource assessment can invalidate the entire site; and a power failure can simultaneously disable mining, communications and thermal protection.
### Recommended top-level risk architecture
For a program of this scale, I would therefore establish **five major risk portfolios** rather than managing all risks as isolated entries:
| Risk Portfolio | Principal Risks | Management Objective |
| --------------------------------------------- | ------------------- | -------------------------------------------------------------------------------------------------------------------------------- |
| **Mars System Reliability** | R1, R7, R8, R9, R12 | Ensure the facility can survive and recover autonomously without Earth intervention. |
| **Mission & Supply Chain Resilience** | R2, R10, R13 | Ensure that one failed launch, supplier or schedule dependency does not collapse the deployment program. |
| **Resource & Technical Viability** | R3, R1, R9 | Establish with sufficient confidence that the selected site can actually support the planned production model. |
| **Financial & Commercial Viability** | R4, R11 | Ensure the program remains fundable and economically rational throughout the 10-year deployment. |
| **Cyber / Regulatory / Governance Assurance** | R5, R6, R14 | Protect the autonomous infrastructure while maintaining planetary-protection compliance and strong system-of-systems governance. |
**One particularly important distinction:** for this project, **Business Continuity should not be interpreted as simply "restore operations after an incident."** Because there may be no humans available for immediate intervention, the primary continuity objective should be **autonomous survivability**: the system must be capable of entering a safe state, maintaining minimum critical functions, diagnosing failures and recovering or degrading gracefully for potentially weeks or months without Earth intervention. This should become a fundamental architectural requirement rather than merely a contingency-plan requirement.
By purchasing this prompt, you agree to our terms of service
GPT-5.6
Instantly build thorough, ISO-standard risk management frameworks for any project or business scenario. This prompt generates a detailed 14-field Risk Register including risk classification, internal/external triggers, active status, severity ratings, response strategies (Avoid, Mitigate, Transfer, Accept), and comprehensive action plans. Ideal for PMs, startup founders, and enterprise teams looking for audit-ready risk reports without spending hours on spreadsheets.
...more
Added 6 days ago
