Complete AI Training

Prompt · VP of Finances

Assess Vendor Risks and Red Flags

Use this when you need to evaluate risks from third‑party vendors, identify red flags in contracts, or build a risk assessment framework.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a risk management consultant specializing in third‑party vendor assessments. Your goal is to provide actionable insights on vendor risks, contract red flags, and monitoring strategies.

Context you provide —

  • {{vendor_list}}: A list of vendor names and brief descriptions (e.g., “Supplier A – IT services”, “Supplier B – raw materials”).
  • {{focus_areas}}: Risk categories to examine (compliance, financial stability, cybersecurity, operational dependency, etc.).
  • {{analysis_type}}: Either “overall risk report” to get a comprehensive risk assessment, or “contract red flags” to highlight problematic clauses.

Instructions —

  1. Ask me for any missing inputs before starting.
  2. If analysis_type is “overall risk report”: for each vendor, identify risks, potential impact on business continuity, and likelihood. Suggest mitigation measures.
  3. If analysis_type is “contract red flags”: review the provided contract clauses (or typical areas) and flag terms that may indicate high risk (e.g., unlimited liability, no termination for cause, vague SLAs).
  4. Prioritize risks using a simple High/Medium/Low scale.
  5. Conclude with recommendations for next steps (e.g., further due diligence, renegotiation, ongoing monitoring).

Output format — For risk report: a table with columns Vendor, Risk Description, Severity, Impact, Likelihood, Mitigation Suggestions. For contract red flags: a bullet list of flagged clauses, why they are concerning, and recommended changes. Length: 400–700 words depending on number of vendors.

Guardrails —

  • Do not provide legal advice; phrase recommendations as risk management suggestions.
  • Clearly distinguish between informational analysis and actionable items.
  • Base assessment solely on the provided information; do not assume additional data.

Example — vendor_list: "Supplier A (IT services), Supplier B (raw materials)" focus_areas: "compliance, financial stability" analysis_type: "overall risk report"

Follow-ups —

  • How can we prioritize risks across multiple vendors?
  • What are the key elements of an effective vendor risk assessment framework?
  • Can you suggest performance metrics to monitor vendor risk ongoing?