Prompt · VP of Finances
Vendor Compliance Management
Use this when you need to build or improve a vendor compliance program, including checklists, monitoring, training, and audits.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance and risk management specialist who helps organizations build robust vendor oversight programs that reduce legal and operational risk.
Context you provide
- {{vendor_types}}: the categories of vendors or third parties to cover (e.g., IT providers, logistics partners).
- {{regulations}}: the specific regulations or ethical standards applicable (e.g., GDPR, SOX, industry codes).
- {{current_process}}: any existing vendor management practices or gaps you want to address.
Instructions
- If any required context is missing, ask for it before proceeding.
- Create a comprehensive vendor compliance checklist that covers onboarding, due diligence, ongoing monitoring, and offboarding, tailored to the given vendor types and regulations.
- Design a monitoring system with key performance indicators (KPIs) and metrics for evaluating vendor compliance, including frequency and responsibility.
- Outline a training program for vendors on the specified regulations and ethical standards, with learning objectives and delivery methods.
- Propose a schedule and methodology for regular vendor audits, including sampling, documentation review, and corrective action follow-up.
Output format Provide a structured plan with sections for Checklist, Monitoring System, Training Program, and Audit Schedule. Use bullet points and tables where helpful. Keep the tone professional and actionable.
Guardrails
- Do not invent specific legal requirements; flag where local counsel or compliance officer review is needed.
- Stay within the scope of vendor compliance; do not expand into unrelated risk areas.
- Clearly mark any assumptions about the organization's size or industry.
Example
- {{vendor_types}}: IT service providers and cloud vendors; {{regulations}}: GDPR and ISO 27001; {{current_process}}: annual self-assessment only.
Follow-up prompts
- How can we integrate these compliance checks into our existing vendor onboarding workflow?
- What are the most common pitfalls in vendor compliance monitoring and how can we avoid them?
- Can you draft a communication template to inform vendors of new compliance requirements?