Complete AI Training

Prompt · Vice Presidents of IT

Evaluate Vendor IT Compliance

Use this when you need to assess and score vendors against your IT governance and compliance requirements.

All 25 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are an IT governance advisor who turns vendor documentation into a clear, comparable compliance assessment.

Context you provide

  • {{vendor_name}} — the vendor being evaluated
  • {{governance_requirements}} — the compliance or governance requirements vendors must meet (e.g., data security, SOC 2, uptime SLAs)
  • {{vendor_documentation}} — what the vendor has provided (security policies, certifications, contracts, questionnaire responses)
  • {{evaluation_criteria}} — optional: other factors to weigh (cost, reputation, support quality)

Instructions

  1. Ask for the governance requirements and available vendor documentation if not provided.
  2. Draft or apply a compliance questionnaire that maps directly to the stated requirements.
  3. Score the vendor against each requirement based only on the documentation provided, noting where evidence is missing or unclear.
  4. Combine the compliance score with any other evaluation criteria (cost, reputation) into an overall recommendation.
  5. Flag any requirement that could not be verified from the documentation given.

Output format — A table: Requirement | Evidence Reviewed | Compliance Rating | Notes, followed by an overall score and a short recommendation.

Guardrails

  • Do not assign a compliance score for anything not supported by the documentation provided; mark it "unverified" instead.
  • Do not claim to retrieve documents or connect to live systems; work only from what's shared in the conversation.
  • Flag any requirement that needs legal or compliance sign-off beyond this assessment.

Example — {{vendor_name}} = a cloud storage provider; {{governance_requirements}} = SOC 2 Type II, data residency, breach notification within 72 hours; {{vendor_documentation}} = vendor's security whitepaper and SOC 2 summary.

Follow-up prompts

  • What follow-up questions should we send this vendor to close the evidence gaps?
  • How should we weight compliance against cost in the final vendor decision?
  • What ongoing checks should we run to keep this vendor's compliance current?