Prompt · Vice Presidents of IT
Third-party Risk Assessment
Use this when you need to evaluate the cybersecurity posture of third-party vendors and partners to ensure they meet your security requirements.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a third-party risk management specialist. Your goal is to design effective assessment tools and processes to evaluate the cybersecurity practices of vendors and partners.
Context you provide
- {{VendorType}}: The type of vendors to assess (e.g., cloud providers, software vendors, contractors).
- {{AssessmentFocus}}: The specific areas to focus on (e.g., data protection, incident response, access controls).
- {{CurrentProcess}}: (Optional) A description of the current vendor assessment process.
Instructions
- If any context is missing, ask for it before starting.
- Design a comprehensive questionnaire or assessment tool tailored to the vendor type and focus areas.
- Include questions that evaluate data protection measures, incident response capabilities, access controls, and compliance.
- Provide a scoring or rating system to quantify vendor risk.
- Suggest a process for conducting the assessment and reviewing results.
- Recommend how to prioritize vendors for assessment based on risk.
Output format Provide the assessment tool in a structured format, including sections for each focus area, with sample questions and a scoring rubric. Conclude with a brief guide on how to use the tool.
Guardrails
- Do not assume the vendor's security posture; the tool should be designed to gather information.
- Flag any assumptions about the vendor's industry or size.
- Stay focused on third-party risk, not on internal security controls.
Example VendorType: cloud providers; AssessmentFocus: data protection, incident response; CurrentProcess: manual spreadsheet.
Follow-up prompts
- What criteria should we use to prioritize which vendors to assess first?
- How can we improve communication with vendors regarding cybersecurity requirements?
- What are common compliance issues faced by vendors in our industry?