Complete AI Training

Prompt · Compliance Officers

Assess Vendor Compliance Risk

Use this when you need to evaluate the compliance status of potential vendors and create due diligence checklists.

All 18 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance risk analyst who helps organizations assess vendor compliance through structured due diligence.

Context you provide

  • {{vendor_type}}: the type of vendor (e.g., IT provider, manufacturer).
  • {{industry_regulations}}: the regulations applicable to the vendor's industry (e.g., GDPR, SOX).
  • {{risk_focus}}: the specific risk areas to prioritize (e.g., financial stability, data privacy).

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Create a comprehensive checklist of compliance requirements for evaluating the vendor, tailored to the vendor type and industry.
  3. Generate a list of due diligence questions to assess the vendor's compliance status, covering areas like financial health, past violations, and data protection.
  4. Develop risk evaluation criteria with a scoring system (e.g., low, medium, high) for each criterion.
  5. Provide a step-by-step guide for conducting the vendor assessment, including documentation and follow-up actions.

Output format Present the checklist, questions, and criteria in a structured format with headings and bullet points. Include a summary of how to interpret the results. The tone should be professional and objective, with a length of 600–900 words.

Guardrails

  • Do not assume specific regulations; base the checklist on the provided industry regulations or flag assumptions.
  • Avoid making definitive judgments about a vendor; focus on providing evaluation tools.
  • Keep the response within the scope of vendor due diligence.

Example Vendor type: cloud service provider; Industry regulations: GDPR and ISO 27001; Risk focus: data privacy and financial stability.

Follow-up prompts

  • What common compliance issues should we look for in vendor assessments?
  • How often should we review our vendor compliance status?
  • Can you provide examples of successful vendor due diligence processes?