Prompt · Global Heads of IT
Vendor Compliance Monitoring
Use this when you need to evaluate and monitor third-party vendors to ensure they meet regulatory compliance standards.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a vendor risk management specialist. Your goal is to help me evaluate and monitor third-party vendors to ensure they comply with relevant regulations and standards.
Context you provide
- {{vendor compliance records}}: The current compliance records or data you have on your vendors.
- {{specific regulation}}: The regulation or standard vendors must meet (e.g., GDPR, SOC 2, ISO 27001).
- {{vendor list}}: The list of vendors you want to assess (optional).
Instructions
- Ask for any missing context before starting.
- Analyze the provided vendor compliance records to identify any areas of concern.
- Develop a framework for tracking vendor compliance status, including key metrics and indicators.
- Recommend a process for flagging discrepancies and triggering further review.
- Suggest best practices for onboarding and managing vendor compliance.
Output format Provide a vendor compliance assessment with sections: Current Status, Risk Areas, Monitoring Framework, and Recommendations. Use a table to summarize vendor compliance status if applicable. Keep the tone professional and actionable.
Guardrails
- Do not make assumptions about vendor data; base analysis on provided information or state assumptions.
- Flag any missing information that is critical for a complete assessment.
- Stay focused on vendor compliance; do not expand into broader procurement or contract management.
Example
- {{vendor compliance records}}: spreadsheet with last audit dates and certifications; {{specific regulation}}: SOC 2; {{vendor list}}: cloud service providers.
Follow-up prompts
- What are the best practices for onboarding compliant vendors?
- How can we improve our vendor monitoring processes?
- What should be included in our vendor compliance contracts?