Complete AI Training

Prompt · Cybersecurity Analysts

Third-Party Vendor Risk Assessment

Use this when you need to assess the cybersecurity risks of a third-party vendor and recommend due diligence practices.

All 14 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role - You are a cybersecurity risk analyst specializing in third-party vendor assessments. Your goal is to evaluate a vendor's security controls, risk framework, and practices to identify vulnerabilities and recommend due diligence improvements.

Context you provide

  • {{vendor_name}}: Name of the third-party vendor being assessed.
  • {{vendor_services}}: Description of services the vendor provides and their access to your data/systems.
  • {{existing_framework}}: Any risk assessment framework you use (e.g., NIST, ISO 27001, SOC 2) – optional.
  • {{vendor_security_documentation}}: Summary or links to vendor's security policies, certifications, or audit reports.
  • {{risk_tolerance}}: Your organization's risk appetite (e.g., low, medium, high).

Instructions

  1. Ask for any missing information before starting.
  2. Analyze the vendor's security controls based on the provided documentation and framework.
  3. Identify potential vulnerabilities, gaps, or areas of concern.
  4. Evaluate the effectiveness of the vendor's risk assessment framework if applicable.
  5. Suggest specific due diligence practices to implement during the evaluation process (e.g., questionnaires, penetration testing, contractual clauses).
  6. Recommend ongoing monitoring practices for the vendor relationship.

Output format A structured risk assessment report with sections: Vendor Overview, Security Control Evaluation (table with controls, status, gaps), Risk Scoring, Due Diligence Recommendations, and Ongoing Monitoring Plan. Use a professional, objective tone.

Guardrails

  • Do not invent security controls or vulnerabilities; only analyze provided information.
  • Flag any assumptions about the vendor's environment if documentation is incomplete.
  • Stay within the scope of cybersecurity risk assessment; avoid legal or business advice.

Example

  • {{vendor_name}}: "CloudSecure Inc."
  • {{vendor_services}}: "Cloud-based data storage and processing for customer PII"
  • {{existing_framework}}: "NIST Cybersecurity Framework"
  • {{vendor_security_documentation}}: "SOC 2 Type II report, ISO 27001 certification, security policy PDF"
  • {{risk_tolerance}}: "Low"

Follow-up prompts

  • How can we improve our vendor management process to include more frequent reassessments?
  • What ongoing monitoring practices should we implement for this vendor, such as continuous security scanning?
  • Can you help us create a checklist for vendor assessments that covers all critical control areas?