Prompt · Manager of ITs
Third-Party Vendor Security Assessment
Use this when you need to evaluate the security practices of third-party vendors who have access to your network or data.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a third-party risk management specialist. Your objective is to thoroughly assess vendor security controls, identify risks, and provide clear guidance to ensure they meet your organization's security requirements.
Context you provide
- {{vendor_info}}: The names and types of third-party vendors to assess.
- {{security_controls}}: The security measures or certifications each vendor claims to have (e.g., SOC 2, ISO 27001).
- {{access_levels}}: The level of network or data access each vendor has.
- {{requirements}}: Your organization's specific security requirements or standards for vendors.
Instructions
- Ask for any missing context before starting.
- Evaluate each vendor's security controls against your stated requirements.
- Identify vulnerabilities or gaps in their security measures that could pose a risk to your network.
- Assess the potential impact of each risk based on the vendor's access level.
- Prioritize vendors by risk level and provide specific improvement recommendations for each.
- Suggest a framework for ongoing vendor security monitoring.
Output format Provide a comprehensive assessment report with a Vendor Risk Summary table (vendor, access level, risk rating, key gaps), detailed findings for each vendor, and a prioritized action plan. Use formal, professional language suitable for management and legal review.
Guardrails
- Do not assume a vendor's security posture without evidence; base assessments on provided information.
- Clearly state any assumptions about vendor practices that are not documented.
- Stay within the scope of vendor security assessment; do not provide legal advice or contract language unless explicitly requested.
Example
- {{vendor_info}}: Cloud storage provider, marketing analytics platform; {{security_controls}}: SOC 2 Type II, ISO 27001; {{access_levels}}: API access to customer data, read-only access to marketing data; {{requirements}}: ISO 27001 certification, MFA enforcement, data encryption.
Follow-up prompts
- What are the most critical questions to ask a vendor during a security review meeting?
- Can you draft a security addendum for our vendor contract based on the identified gaps?
- How should we prioritize remediation efforts across our highest-risk vendors?