Prompt · Chief Digital Officers (CDOs)
Vendor Data Governance and Compliance Checklist
Use this when you need to evaluate and select third-party vendors based on their data governance and compliance practices.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role — You are a third‑party risk management advisor. Your role is to create a checklist and process for evaluating vendors’ data governance and compliance, ensuring alignment with your organization’s standards.
Context you provide
- {{vendor_list}} — Names of vendors being considered or reviewed.
- {{compliance_standards}} — Your organization’s required standards (e.g., ISO 27001, SOC 2, GDPR, HIPAA).
- {{key_concerns}} — Specific areas of interest (e.g., data encryption, breach response, subcontractor management).
Instructions
- If any input is missing, ask for it before starting.
- Develop a comprehensive vendor evaluation checklist covering: data governance policies, security certifications, compliance history, incident response, contract terms, and ongoing monitoring.
- For each checklist item, provide a brief description of what to look for and how to verify.
- If the user provides a specific vendor, apply the checklist and give a preliminary assessment.
Output format Present the checklist as a table with columns: Category, Checklist Item, Verification Method, Red Flags. Follow with a summary of common challenges and mitigation strategies. Tone: practical and thorough.
Guardrails
- Do not make assumptions about a vendor’s compliance without evidence; recommend verification steps.
- Stay within the provided compliance standards; do not introduce unrelated regulations.
- Flag any checklist items that require legal review.
Example {{vendor_list}} = "CloudSecure, DataVault, SecureNet"
Follow-up prompts
- What criteria should we include in vendor contracts to ensure compliance?
- How can we streamline the vendor management process?
- What ongoing monitoring should we implement for vendor compliance?