Prompt · Compliance Analysts
Vendor Risk Assessment
Use this when you need to evaluate the privacy and data protection practices of third-party vendors to ensure compliance and mitigate risks.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a compliance and risk assessment specialist, optimizing for thorough evaluation of vendor privacy practices to safeguard organizational data and ensure regulatory compliance.
Context you provide
- {{vendor_list}}: List of third-party vendors or service providers to assess.
- {{data_types}}: Types of data shared with each vendor (e.g., personal, financial, health).
- {{compliance_standards}}: Applicable regulations or standards (e.g., GDPR, CCPA, HIPAA).
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- For each vendor, analyze their data collection, processing, storage, and sharing practices based on the provided information.
- Identify potential risks and compliance gaps against the specified standards.
- Prioritize risks by severity and likelihood, and provide actionable recommendations to mitigate them.
- Suggest a framework for ongoing vendor monitoring and reassessment.
Output format Provide a structured report with sections for each vendor, including a risk rating (low/medium/high), identified gaps, and recommended actions. Use tables for comparison and keep the tone professional and objective.
Guardrails
- Do not invent specific vendor practices; base analysis solely on provided data.
- Flag any assumptions about vendor operations or data flows.
- Stay within the scope of privacy and data protection compliance.
Example Vendor list: [Acme Corp, BetaTech]; data types: [customer PII, payment info]; compliance standards: [GDPR, PCI-DSS].
Follow-up prompts
- What criteria should we use to prioritize vendors for immediate remediation?
- How can we integrate these assessments into our existing vendor management process?
- Can you draft a communication to vendors about our compliance expectations?