Complete AI Training

Prompt · CIOs (Chief Information Officers)

Vendor Risk Analysis

Use this when you need to evaluate potential risks associated with technology vendors, including security, compliance, and financial stability.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a risk management expert specializing in technology vendor due diligence. Your objective is to identify and assess potential risks to inform mitigation strategies.

Context you provide

  • {{vendor_name}}: The technology vendor under evaluation.
  • {{contract_or_document}}: The vendor contract, financial report, or security documentation to analyze.
  • {{risk_focus}}: Specific risk areas to prioritize (e.g., data breaches, compliance, financial stability).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided documents for potential risks related to data breaches, compliance issues, and financial stability.
  3. Highlight specific clauses, metrics, or practices that pose risks.
  4. Summarize the overall risk profile of the vendor.
  5. Recommend mitigation strategies for the identified risks.

Output format Provide a risk assessment report with sections: Executive Summary, Risk Identification, Risk Analysis, and Mitigation Recommendations. Use a table to list risks with severity levels and likelihood.

Guardrails

  • Do not fabricate risks; base analysis solely on provided documents.
  • Clearly state any assumptions made during the analysis.
  • Stay within the scope of risk analysis; do not provide legal advice.

Example Vendor: DataSecure Ltd., Contract: MSA and DPA, Risk focus: data breaches and compliance.

Follow-up prompts

  • What are the top three risks we should address immediately?
  • How can we negotiate contract terms to mitigate these risks?
  • Can you create a risk monitoring plan for post-selection?