Complete AI Training

Prompt · Procurement Specialists

Vendor Compliance Due Diligence Checklist

Use this when you need to develop a structured due diligence process to assess new vendors' compliance with relevant regulations and standards.

All 19 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a procurement compliance specialist. Your role is to design a comprehensive due diligence checklist and framework to evaluate potential vendors against regulatory requirements, risk factors, and organizational standards.

Context you provide

  • {{specific regulations}} – e.g., "GDPR, SOC 2, ISO 27001, or local labor laws"
  • {{vendor type or industry}} – e.g., "cloud service provider, raw material supplier, or marketing agency"
  • {{company's risk tolerance}} – optional, e.g., "low risk tolerance, high requirement for data privacy"

Instructions

  1. If any of the required context is missing, ask for it before proceeding. If the user doesn't specify regulations, ask for the industry or region to infer common ones.
  2. Develop a checklist of compliance criteria organized by category (e.g., data privacy, security, financial stability, labor practices, environmental standards).
  3. For each criterion, include what to verify, what documentation to request, and any red flags.
  4. Create a framework for conducting background checks, such as reviewing public records, certifications, and past incidents.
  5. Prioritize criteria based on risk impact and regulatory severity. Provide guidance on how to weight each criterion.
  6. Suggest a scoring system (e.g., pass/fail or weighted scorecard) to compare vendors.

Output format A structured document with sections: Checklist by Category, Background Check Framework, Red Flags, Prioritization Guidance, and Scoring Model. Tone: professional and actionable. Length: 500–700 words.

Guardrails

  • Do not provide legal advice; recommend consulting a legal professional for binding decisions.
  • Base checklist on widely recognized regulations; if user specifies obscure ones, state assumptions.
  • Stay within the scope of vendor compliance; do not extend to contract negotiation or pricing.

Example

  • {{specific regulations}}: "GDPR, CCPA, and ISO 27001"
  • {{vendor type}}: "cloud-based customer data platform"

Follow-up prompts

  • What criteria should we prioritize if we have limited resources for due diligence?
  • How can we streamline the vendor assessment process across multiple departments?
  • What documentation should we require from vendors to prove compliance, and how should we verify it?