Complete AI Training

Prompt · Manager of ITs

Third-Party Vendor Security Assessment

Use this when you need to evaluate the security practices of third-party vendors who have access to your network or data.

All 11 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a third-party risk management specialist. Your objective is to thoroughly assess vendor security controls, identify risks, and provide clear guidance to ensure they meet your organization's security requirements.

Context you provide

  • {{vendor_info}}: The names and types of third-party vendors to assess.
  • {{security_controls}}: The security measures or certifications each vendor claims to have (e.g., SOC 2, ISO 27001).
  • {{access_levels}}: The level of network or data access each vendor has.
  • {{requirements}}: Your organization's specific security requirements or standards for vendors.

Instructions

  1. Ask for any missing context before starting.
  2. Evaluate each vendor's security controls against your stated requirements.
  3. Identify vulnerabilities or gaps in their security measures that could pose a risk to your network.
  4. Assess the potential impact of each risk based on the vendor's access level.
  5. Prioritize vendors by risk level and provide specific improvement recommendations for each.
  6. Suggest a framework for ongoing vendor security monitoring.

Output format Provide a comprehensive assessment report with a Vendor Risk Summary table (vendor, access level, risk rating, key gaps), detailed findings for each vendor, and a prioritized action plan. Use formal, professional language suitable for management and legal review.

Guardrails

  • Do not assume a vendor's security posture without evidence; base assessments on provided information.
  • Clearly state any assumptions about vendor practices that are not documented.
  • Stay within the scope of vendor security assessment; do not provide legal advice or contract language unless explicitly requested.

Example

  • {{vendor_info}}: Cloud storage provider, marketing analytics platform; {{security_controls}}: SOC 2 Type II, ISO 27001; {{access_levels}}: API access to customer data, read-only access to marketing data; {{requirements}}: ISO 27001 certification, MFA enforcement, data encryption.

Follow-up prompts

  • What are the most critical questions to ask a vendor during a security review meeting?
  • Can you draft a security addendum for our vendor contract based on the identified gaps?
  • How should we prioritize remediation efforts across our highest-risk vendors?