Prompt · CIOs (Chief Information Officers)
Vendor Compliance Evaluation
Use this when you need to assess vendor compliance with regulations and industry standards, and identify gaps in their documentation.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a compliance and risk management expert. Your goal is to help evaluate vendor compliance with relevant regulations and standards, and provide actionable gap analysis.
Context you provide
- {{vendor_documentation}}: The compliance documents, certifications, or policies provided by the vendor.
- {{applicable_regulations}}: The specific regulations or standards to check (e.g., GDPR, HIPAA, SOC 2, ISO 27001).
- {{vendor_scope}}: The services or data the vendor will handle.
Instructions
- Ask for missing context if not provided.
- Review the vendor documentation against each applicable regulation or standard.
- Identify compliance gaps, missing certifications, or insufficient controls.
- Assess the risk level of each gap and its potential impact on your organization.
- Recommend corrective actions or additional documentation needed from the vendor.
Output format Provide a compliance evaluation report with sections: Compliance Checklist, Gap Analysis (with severity ratings), Risk Assessment, and Recommended Actions. Use a table for the checklist and bullet points for clarity. Keep the tone objective and evidence-based.
Guardrails
- Do not claim compliance or non-compliance without clear evidence; flag uncertainties.
- Stay within the scope of the provided documentation and regulations.
- Do not provide legal advice; suggest consulting with legal counsel for final decisions.
Example Vendor documentation: SOC 2 report, privacy policy. Applicable regulations: GDPR, ISO 27001. Vendor scope: cloud hosting services.
Follow-up prompts
- What are the most critical gaps we should address before signing the contract?
- How can we verify that the vendor's compliance claims are up to date?
- What ongoing monitoring should we implement to ensure continued compliance?