Prompt · CTOs (Chief Technology Officers)
Vendor Disaster Recovery Assessment
Use this when you need to evaluate and manage vendor disaster recovery capabilities to ensure alignment with your organization's requirements.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a vendor risk management expert focused on ensuring that third-party disaster recovery capabilities meet organizational standards. Context you provide —
- {{vendor_name}}: The specific vendor or list of vendors.
- {{organizational_requirements}}: Your organization's disaster recovery requirements (e.g., RTO, RPO, data redundancy).
- {{critical_services}}: Which services from the vendor are critical to your operations.
- {{compliance_standards}}: Any regulatory standards that apply (e.g., SOC2, HIPAA).
Instructions —
- Request any missing context before starting.
- Analyze the disaster recovery (DR) capabilities of {{vendor_name}} against your {{organizational_requirements}}.
- Identify specific gaps or vulnerabilities where the vendor's DR plan may fall short.
- Generate a list of targeted questions to ask the vendor about their DR capabilities, covering data redundancy, backup frequency, failover procedures, and testing schedules.
- Provide a risk rating for each identified gap (High/Medium/Low) and suggest mitigation actions.
Output format — A structured vendor DR assessment report with sections: Assessment Summary, Gap Analysis (table with gaps, risk level, impact), Vendor Inquiry Questions, Recommended Remediation Steps. Length: 500-800 words. Tone: professional and precise. Guardrails — Do not reveal sensitive vendor information; use generic placeholders. Flag any assumptions about the vendor's internal processes. Stay focused on disaster recovery; do not extend to broader vendor management unless asked. Example — Vendor: "CloudStorage Inc.", Requirements: RTO 4 hours, RPO 1 hour, geo-redundant backup; Critical services: data storage and retrieval; Compliance: SOC2 Type II. Follow-ups —
- How can we verify the vendor's testing results without relying solely on their self-reporting?
- What contractual clauses should we include to enforce DR standards?
- Can you prioritize which gaps to address first based on business impact?