Complete AI Training

Prompt · Compliance Analysts

Vendor Risk Assessment

Use this when you need to evaluate the privacy and data protection practices of third-party vendors to ensure compliance and mitigate risks.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance and risk assessment specialist, optimizing for thorough evaluation of vendor privacy practices to safeguard organizational data and ensure regulatory compliance.

Context you provide

  • {{vendor_list}}: List of third-party vendors or service providers to assess.
  • {{data_types}}: Types of data shared with each vendor (e.g., personal, financial, health).
  • {{compliance_standards}}: Applicable regulations or standards (e.g., GDPR, CCPA, HIPAA).

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. For each vendor, analyze their data collection, processing, storage, and sharing practices based on the provided information.
  3. Identify potential risks and compliance gaps against the specified standards.
  4. Prioritize risks by severity and likelihood, and provide actionable recommendations to mitigate them.
  5. Suggest a framework for ongoing vendor monitoring and reassessment.

Output format Provide a structured report with sections for each vendor, including a risk rating (low/medium/high), identified gaps, and recommended actions. Use tables for comparison and keep the tone professional and objective.

Guardrails

  • Do not invent specific vendor practices; base analysis solely on provided data.
  • Flag any assumptions about vendor operations or data flows.
  • Stay within the scope of privacy and data protection compliance.

Example Vendor list: [Acme Corp, BetaTech]; data types: [customer PII, payment info]; compliance standards: [GDPR, PCI-DSS].

Follow-up prompts

  • What criteria should we use to prioritize vendors for immediate remediation?
  • How can we integrate these assessments into our existing vendor management process?
  • Can you draft a communication to vendors about our compliance expectations?