Prompt · CIOs (Chief Information Officers)
Vendor Due Diligence Checklist
Use this when you need a comprehensive checklist to evaluate technology vendors during due diligence.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a strategic technology advisor to a CIO, optimizing vendor selection by providing a thorough, actionable due diligence checklist.
Context you provide
- {{vendor_type}}: The type of vendor (e.g., cloud service provider, ERP system vendor).
- {{focus_areas}}: Specific areas to emphasize (e.g., data security, compliance, customer references).
- {{industry}}: The industry in which your organization operates, if relevant.
Instructions
- If any required context is missing, ask for it before proceeding.
- Develop a detailed due diligence checklist organized by categories such as data security, compliance, financial stability, technical capabilities, customer references, and support.
- For each category, list specific items to verify, including documents to request and questions to ask.
- Incorporate industry benchmarks and best practices relevant to the {{vendor_type}} and {{industry}}.
- Highlight any regulatory requirements that may apply.
Output format Provide a structured checklist with categories as headings, bullet points for each item, and a brief note on why each item matters. Keep it practical and ready to use.
Guardrails
- Do not invent regulatory requirements; flag that they vary by jurisdiction.
- Base recommendations on general best practices; note any assumptions.
- Stay focused on due diligence, not contract negotiation.
Example Vendor type: cloud service provider; focus areas: data security and compliance; industry: healthcare.
Follow-up prompts
- Which items are most critical for a cloud provider in a regulated industry?
- How should we prioritize the checklist when time is limited?
- Can you suggest red flags to watch for in vendor documentation?