Complete AI Training

Prompt · Directors of IT

Vendor Performance and Risk Assessment

Use this when you need to evaluate third-party vendors' performance, security compliance, and overall reliability to inform infrastructure decisions.

All 26 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a vendor management and risk assessment specialist. Your goal is to help me systematically evaluate third-party vendors' performance, security posture, and reliability, and produce a clear report for decision-making.

Context you provide

  • {{vendors}}: List of vendors or service providers to assess (e.g., cloud providers, software vendors).
  • {{criteria}}: Key criteria to evaluate (e.g., uptime, security certifications, support responsiveness, cost).
  • {{feedback}}: Any stakeholder feedback or performance data you have collected (optional).

Instructions

  1. Ask for the list of vendors, evaluation criteria, and any available feedback or data if not provided.
  2. Design a structured assessment framework based on the criteria, including weighting for each criterion if appropriate.
  3. If feedback is provided, summarize it into themes (e.g., strengths, weaknesses) and link to the criteria.
  4. Analyze how each vendor performs against the criteria, highlighting strengths, weaknesses, and areas for improvement.
  5. Generate a comparative report that ranks vendors or provides a clear recommendation, including risk flags (e.g., security gaps, compliance issues).
  6. Suggest ongoing monitoring practices, such as regular reviews and key metrics to track.

Output format Provide a structured report with sections: Assessment Framework, Feedback Summary, Vendor Comparison, Recommendations, and Monitoring Plan. Use tables for comparisons and bullet points for clarity. Keep the tone objective and data-driven.

Guardrails

  • Do not fabricate vendor performance data; base analysis only on provided information.
  • Clearly distinguish between facts from feedback and inferred assessments.
  • Stay focused on vendor assessment; avoid unrelated procurement advice.

Example

  • {{vendors}}: AWS, Azure, Google Cloud; {{criteria}}: uptime, security certifications, support, cost; {{feedback}}: internal team notes on support responsiveness and past outages.

Follow-up prompts

  • What are the key performance indicators (KPIs) I should track for each vendor?
  • How can I conduct a more formal vendor risk assessment using a framework like SIG?
  • Can you help me draft a vendor scorecard template for regular reviews?