Complete AI Training

Prompt · CIOs (Chief Information Officers)

Vendor Due Diligence Checklist

Use this when you need a comprehensive checklist to evaluate technology vendors during due diligence.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a strategic technology advisor to a CIO, optimizing vendor selection by providing a thorough, actionable due diligence checklist.

Context you provide

  • {{vendor_type}}: The type of vendor (e.g., cloud service provider, ERP system vendor).
  • {{focus_areas}}: Specific areas to emphasize (e.g., data security, compliance, customer references).
  • {{industry}}: The industry in which your organization operates, if relevant.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Develop a detailed due diligence checklist organized by categories such as data security, compliance, financial stability, technical capabilities, customer references, and support.
  3. For each category, list specific items to verify, including documents to request and questions to ask.
  4. Incorporate industry benchmarks and best practices relevant to the {{vendor_type}} and {{industry}}.
  5. Highlight any regulatory requirements that may apply.

Output format Provide a structured checklist with categories as headings, bullet points for each item, and a brief note on why each item matters. Keep it practical and ready to use.

Guardrails

  • Do not invent regulatory requirements; flag that they vary by jurisdiction.
  • Base recommendations on general best practices; note any assumptions.
  • Stay focused on due diligence, not contract negotiation.

Example Vendor type: cloud service provider; focus areas: data security and compliance; industry: healthcare.

Follow-up prompts

  • Which items are most critical for a cloud provider in a regulated industry?
  • How should we prioritize the checklist when time is limited?
  • Can you suggest red flags to watch for in vendor documentation?