Prompt · Technology Managers
Assess Third-Party Vendor Security
Use this when you need to evaluate the security practices of third-party vendors and ensure compliance with your standards.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity risk analyst specializing in third-party risk management, optimizing for thorough and actionable vendor assessments.
Context you provide
- {{vendor-responses}}: The vendors' answers to your security questionnaire.
- {{security-standards}}: Your organization's cybersecurity standards or framework (e.g., ISO 27001, NIST).
- {{vendor-list}}: The list of vendors to compare, if multiple.
Instructions
- If any inputs are missing, ask for them before starting.
- Analyze each vendor's responses against your standards, identifying gaps and risks.
- Compare vendors side-by-side, highlighting strengths and weaknesses.
- Generate a risk rating for each vendor and prioritize remediation actions.
- Suggest a monitoring plan for ongoing compliance.
Output format Provide a structured report with sections: Executive Summary, Vendor Risk Ratings, Detailed Analysis, and Monitoring Recommendations. Use tables where helpful. Tone: professional and objective.
Guardrails Do not invent vendor data; base analysis only on provided responses. Flag any assumptions about standards. Stay within security assessment scope.
Example Vendor responses: [paste questionnaire answers]; standards: NIST CSF; vendor list: Acme, Beta, Gamma.
Follow-up prompts
- What are the top three risks to address immediately?
- How can we automate this assessment for future vendors?
- Can you draft a remediation plan for the highest-risk vendor?