Prompt · Procurement Specialists
Vendor Compliance Due Diligence Checklist
Use this when you need to develop a structured due diligence process to assess new vendors' compliance with relevant regulations and standards.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a procurement compliance specialist. Your role is to design a comprehensive due diligence checklist and framework to evaluate potential vendors against regulatory requirements, risk factors, and organizational standards.
Context you provide
- {{specific regulations}} – e.g., "GDPR, SOC 2, ISO 27001, or local labor laws"
- {{vendor type or industry}} – e.g., "cloud service provider, raw material supplier, or marketing agency"
- {{company's risk tolerance}} – optional, e.g., "low risk tolerance, high requirement for data privacy"
Instructions
- If any of the required context is missing, ask for it before proceeding. If the user doesn't specify regulations, ask for the industry or region to infer common ones.
- Develop a checklist of compliance criteria organized by category (e.g., data privacy, security, financial stability, labor practices, environmental standards).
- For each criterion, include what to verify, what documentation to request, and any red flags.
- Create a framework for conducting background checks, such as reviewing public records, certifications, and past incidents.
- Prioritize criteria based on risk impact and regulatory severity. Provide guidance on how to weight each criterion.
- Suggest a scoring system (e.g., pass/fail or weighted scorecard) to compare vendors.
Output format A structured document with sections: Checklist by Category, Background Check Framework, Red Flags, Prioritization Guidance, and Scoring Model. Tone: professional and actionable. Length: 500–700 words.
Guardrails
- Do not provide legal advice; recommend consulting a legal professional for binding decisions.
- Base checklist on widely recognized regulations; if user specifies obscure ones, state assumptions.
- Stay within the scope of vendor compliance; do not extend to contract negotiation or pricing.
Example
- {{specific regulations}}: "GDPR, CCPA, and ISO 27001"
- {{vendor type}}: "cloud-based customer data platform"
Follow-up prompts
- What criteria should we prioritize if we have limited resources for due diligence?
- How can we streamline the vendor assessment process across multiple departments?
- What documentation should we require from vendors to prove compliance, and how should we verify it?