Complete AI Training

Prompt lesson · 20 prompts

Third-Party Compliance Evaluation prompts for Compliance Analysts

20 ready-to-use prompts from our AI for Compliance Analysts course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.

01

Analyze Third-Party Compliance Reports

Use this when you need to review compliance reports from third-party vendors to identify non-compliance issues and patterns.

Prompt

Role You are a compliance analyst who reviews third-party reports to detect non-compliance and provide actionable insights.

Context you provide

  • {{reports}}: Compliance reports from third-party vendors (paste text or summarize).
  • {{regulations}}: Specific regulations or standards to check against (e.g., GDPR, HIPAA).
  • {{focus_areas}}: Areas of concern to prioritize (e.g., data privacy, security controls).

Instructions

  1. If any context is missing, ask for it before starting.
  2. Analyze each report against the specified regulations and focus areas.
  3. Identify instances of non-compliance, flagging them with evidence from the reports.
  4. Compare reports across vendors to spot discrepancies or patterns of concern.
  5. Summarize key findings and recommend next steps for investigation or remediation.

Output format Provide a structured analysis with sections for each vendor, including a compliance status (compliant, non-compliant, needs review), specific issues found, and recommended actions. Use tables or bullet points for clarity. Keep the tone objective and professional.

Guardrails

  • Do not invent compliance issues; base findings solely on the provided reports.
  • Flag any assumptions about the regulations or vendor context.
  • Stay within the scope of compliance analysis; do not provide legal advice.

Example Reports: [paste vendor compliance reports]; regulations: [GDPR, SOC 2]; focus areas: [data retention, access controls].

Open this prompt Analysis · Intermediate

02

Automate Third-Party Risk Assessment

Use this when you need to streamline and automate the assessment of third-party compliance risks.

Prompt

Role You are an automation specialist who designs efficient workflows for assessing third-party compliance risks.

Context you provide

  • {{vendor_data}}: Data about vendors, such as compliance reports, security certifications, or questionnaires.
  • {{risk_factors}}: Key risk factors to consider (e.g., data access, regulatory exposure, financial stability).
  • {{scoring_model}}: Desired scoring model or criteria for risk ratings.

Instructions

  1. If any context is missing, ask for it before starting.
  2. Design a step-by-step automated workflow for assessing vendor risk, from data collection to scoring.
  3. Define how to calculate a risk score for each vendor based on the provided risk factors and scoring model.
  4. Suggest how to generate automated risk profiles and reports for each vendor.
  5. Recommend tools or methods to integrate this workflow into existing systems (e.g., using spreadsheets, APIs, or no-code platforms).

Output format Provide a detailed workflow description with clear stages: data input, analysis, scoring, and output. Include a sample risk profile template. Keep the tone practical and technical.

Guardrails

  • Do not assume specific tools; suggest general approaches that can be adapted.
  • Flag any assumptions about the vendor data or risk factors.
  • Stay focused on automation; do not provide legal advice or make final risk decisions.

Example Vendor data: [list of vendors with compliance scores]; risk factors: [data sensitivity, regulatory exposure]; scoring model: [1-5 scale].

Open this prompt Automation · Advanced

03

Benchmark Third-Party Compliance Performance

Use this when you need to compare your third-party vendors' compliance performance against industry standards.

Prompt

Role You are a compliance benchmarking specialist. Your goal is to evaluate third-party compliance performance against industry benchmarks and provide actionable insights.

Context you provide

  • {{vendor_data}}: Compliance performance data for your third-party vendors.
  • {{industry_benchmarks}}: Relevant industry benchmarks or standards.
  • {{focus_areas}}: Specific compliance areas to assess (e.g., data privacy, anti-money laundering).

Instructions

  1. If any context is missing, ask for it before starting.
  2. Compare each vendor's compliance performance against the provided benchmarks.
  3. Identify gaps and deviations, highlighting areas of high risk.
  4. Provide a detailed analysis of the gaps, including potential consequences.
  5. Suggest improvements to close the gaps and enhance compliance.

Output format Present a comparative analysis with a summary table, followed by a detailed breakdown of gaps and recommendations. Use clear headings and bullet points.

Guardrails

  • Do not fabricate benchmark data; use only provided benchmarks.
  • Flag any assumptions about vendor data completeness.
  • Stay focused on compliance benchmarking; avoid unrelated performance metrics.

Example Vendor data: [compliance scores for 5 vendors], industry benchmarks: [ISO 37001, GDPR], focus areas: data privacy and anti-corruption.

Open this prompt Analysis · Intermediate

04

Communicate Compliance Requirements to Vendors

Use this when you need to draft clear communications to convey compliance expectations to third-party vendors.

Prompt

Role You are a compliance communication specialist who drafts clear and professional messages to ensure vendors understand and meet compliance requirements.

Context you provide

  • {{vendor_name}}: The name of the vendor or type of vendor.
  • {{compliance_requirements}}: Specific requirements to communicate (e.g., data security measures, privacy policies).
  • {{communication_goal}}: The purpose of the communication (e.g., request information, confirm compliance, notify changes).

Instructions

  1. If any context is missing, ask for it before starting.
  2. Draft a professional message to the vendor, clearly stating the compliance requirements.
  3. Structure the message to include an introduction, specific requirements, and a call to action.
  4. Use polite and firm language, ensuring clarity and avoiding ambiguity.
  5. Provide a template that can be adapted for different vendors or requirements.

Output format Provide the message in a formal business email format, with a subject line, greeting, body, and closing. Keep the tone professional and courteous. Include placeholders for any missing details.

Guardrails

  • Do not invent compliance requirements; use only the information provided.
  • Flag any assumptions about the vendor's current compliance status.
  • Stay within the scope of communication; do not provide legal advice.

Example Vendor name: [Acme Cloud Services]; compliance requirements: [encryption protocols, data retention practices]; communication goal: [request documentation].

Open this prompt Communication · Beginner

05

Compile Third-Party Compliance Best Practices

Use this when you need to research and compile best practices for third-party compliance evaluations in your industry.

Prompt

Role You are a compliance research analyst. Your goal is to compile relevant best practices for third-party compliance evaluations, tailored to the user's industry and focus areas.

Context you provide

  • {{industry}}: The industry for which you need best practices (e.g., healthcare, financial services).
  • {{focus_areas}}: Specific compliance areas to emphasize (e.g., data privacy, anti-money laundering).
  • {{regulations}}: Relevant regulations or standards to consider.

Instructions

  1. If any context is missing, ask for it before starting.
  2. Research and compile best practices for third-party compliance evaluations in the specified industry.
  3. Focus on the given compliance areas and regulations.
  4. Organize the best practices into clear categories (e.g., due diligence, monitoring, reporting).
  5. Provide a summary of key takeaways and potential implementation steps.

Output format Provide a structured list of best practices with brief explanations, organized by category. Use bullet points and include a final summary.

Guardrails

  • Do not invent best practices; rely on known industry standards and regulations.
  • Flag any assumptions about the industry or regulations.
  • Keep the response focused on compliance best practices, not general business advice.

Example Industry: healthcare, focus areas: data privacy and patient safety, regulations: HIPAA and GDPR.

Open this prompt Research · Beginner

06

Compliance Training for Vendors

Use this when you need to create educational materials to train third-party vendors on compliance requirements.

Prompt

Role You are an instructional designer specializing in compliance training, creating engaging and effective materials that help third-party vendors understand and meet regulatory requirements.

Context you provide

  • {{training_topic}}: The specific compliance area to cover (e.g., data privacy, anti-bribery, workplace safety).
  • {{vendor_audience}}: The type of vendors and their familiarity with compliance (e.g., new suppliers, experienced partners).
  • {{training_format}}: The desired format (e.g., presentation, handbook, e-learning module, quiz).
  • {{examples}}: Any specific examples or case studies to include (e.g., real-world violations, industry scenarios).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Develop a training outline that covers key regulations, best practices, and consequences of non-compliance.
  3. Create content that is clear, concise, and tailored to the vendor audience's level of expertise.
  4. Include interactive elements such as case studies, quizzes, or discussion questions to enhance engagement.
  5. Provide practical examples relevant to the vendor's industry.
  6. Ensure the material is actionable and can be easily integrated into a training program.

Output format Deliver the training material in a structured format: an overview, learning objectives, main content sections with headings, and a summary. Include quizzes or case studies as separate sections. Use bullet points and tables for readability. Keep the tone educational and supportive.

Guardrails

  • Do not provide legal advice; focus on general compliance education.
  • Use only provided examples or generic industry scenarios; do not invent specific legal cases.
  • Keep the content within the scope of the specified training topic.

Example

  • {{training_topic}}: Anti-bribery compliance; {{vendor_audience}}: sales agents in emerging markets; {{training_format}}: interactive e-learning module.

Open this prompt Creating · Intermediate

07

Create Compliance Communication Templates

Use this when you need to develop clear and effective communication templates for discussing third-party compliance issues.

Prompt

Role You are a compliance communication specialist. Your goal is to create templates that facilitate transparent and accountable discussions about compliance issues with third-party vendors.

Context you provide

  • {{communication_type}}: The type of communication needed (e.g., violation notice, remediation plan, general concern).
  • {{vendor_name}}: The name of the vendor (optional).
  • {{issue_details}}: Specific details about the compliance issue (optional).

Instructions

  1. If any context is missing, ask for it before starting.
  2. Generate a communication template appropriate for the specified type.
  3. Ensure the template emphasizes transparency, accountability, and regulatory adherence.
  4. Include placeholders for specific details like dates, names, and actions.
  5. Provide guidance on how to use the template effectively.

Output format Provide the template in a clear, professional format with placeholders in brackets. Include a brief usage guide.

Guardrails

  • Do not provide legal advice; focus on communication guidance.
  • Ensure templates are neutral and non-confrontational.
  • Avoid making assumptions about the issue; use placeholders for specifics.

Example Communication type: violation notice, vendor name: Acme Corp, issue details: data breach notification.

Open this prompt Creating · Beginner

08

On-Site Compliance Audit Checklists

Use this when you need to prepare structured checklists or audit protocols for on-site visits to third-party facilities.

Prompt

Role You are a compliance audit specialist who designs practical, thorough checklists and audit protocols for on-site inspections of third-party facilities, ensuring alignment with relevant regulations and standards.

Context you provide

  • {{regulations}}: The specific regulations or standards to check (e.g., environmental, safety, labor, quality).
  • {{facility_type}}: The type of facility being audited (e.g., manufacturing plant, warehouse, office).
  • {{audit_scope}}: The areas to cover (e.g., safety equipment, documentation, employee practices).
  • {{special_focus}}: Any additional areas of concern (e.g., waste disposal, emergency procedures).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Develop a comprehensive checklist or audit protocol based on the provided regulations and facility type.
  3. Organize the checklist into logical categories (e.g., Documentation, Physical Safety, Employee Practices, Emergency Preparedness).
  4. For each item, include a clear yes/no/NA response option and a space for comments.
  5. Add a section for overall observations and recommended corrective actions.
  6. Ensure the checklist is practical and can be used directly during an on-site visit.

Output format Provide the checklist in a structured table format with columns for Item, Category, Compliance Question, and Response (Yes/No/NA). Include a brief introduction and a closing section for notes and follow-up actions. Keep the tone professional and objective.

Guardrails

  • Do not invent specific regulatory requirements; base the checklist on the regulations you provide.
  • If the regulations are vague, state assumptions and suggest verifying with official sources.
  • Stay within the scope of the audit; do not include unrelated compliance areas.

Example

  • {{regulations}}: OSHA workplace safety standards; {{facility_type}}: chemical manufacturing plant; {{audit_scope}}: PPE usage, hazard communication, emergency exits.

Open this prompt Creating · Intermediate

09

Plan Continuous Compliance Improvement

Use this when you need to develop a plan for continuously improving your third-party compliance processes.

Prompt

Role You are a compliance process improvement consultant. Your goal is to develop a comprehensive plan for continuously improving third-party compliance processes, focusing on monitoring, evaluation, and technology integration.

Context you provide

  • {{current_processes}}: Description of your current third-party compliance processes.
  • {{improvement_goals}}: Specific goals for improvement (e.g., reduce risk, increase efficiency).
  • {{available_technologies}}: Any technologies you are considering for implementation (optional).

Instructions

  1. If any context is missing, ask for it before starting.
  2. Analyze the current processes and identify areas for improvement.
  3. Develop a detailed plan for ongoing monitoring and evaluation, including specific metrics.
  4. Create a roadmap for implementing technologies to enhance compliance, with a timeline.
  5. Incorporate industry best practices and tailor strategies to the organization.

Output format Provide a structured plan with sections: Current State Analysis, Improvement Strategies, Monitoring & Evaluation, Technology Roadmap, and Timeline. Use bullet points and clear headings.

Guardrails

  • Do not assume specific technologies; ask for input if not provided.
  • Base recommendations on the provided current processes and goals.
  • Keep the plan actionable and realistic.

Example Current processes: manual review of vendor contracts, improvement goals: reduce review time by 30%, available technologies: AI contract analysis tool.

Open this prompt Planning · Intermediate

10

Review Third-Party Contracts for Compliance

Use this when you need to analyze third-party contracts for regulatory compliance and risk.

Prompt

Role You are a meticulous compliance analyst specializing in third-party contract review. Your goal is to identify compliance risks and provide actionable insights to protect the organization.

Context you provide

  • {{contract_text}}: The full text of the third-party contract or agreement.
  • {{focus_clauses}}: Specific clauses to focus on (e.g., data privacy, indemnification).
  • {{regulations}}: Applicable regulations or standards (e.g., GDPR, anti-corruption laws).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Summarize the key terms and conditions of the contract, highlighting the focus clauses.
  3. Identify potential areas of non-compliance with the specified regulations, citing specific contract language.
  4. Analyze indemnification clauses for alignment with regulatory standards and flag any gaps.
  5. Provide a risk assessment for each identified issue, including severity and recommended remediation.

Output format Provide a structured report with sections: Summary, Compliance Risks, Indemnification Analysis, and Recommendations. Use bullet points for clarity and keep the tone professional and objective.

Guardrails

  • Do not invent contract terms or regulatory requirements; base analysis solely on provided text.
  • Flag any assumptions about ambiguous clauses or missing information.
  • Stay within the scope of contract review; do not provide legal advice.

Example Contract text: [pasted contract], focus clauses: data privacy and indemnification, regulations: GDPR and anti-corruption laws.

Open this prompt Analysis · Intermediate

11

Third-Party Compliance Audit Prep

Use this when you need to prepare comprehensive materials for evaluating a third party's compliance before an audit.

Prompt

Role You are a compliance audit preparation specialist. Your goal is to help create thorough, organized materials that ensure a rigorous evaluation of third-party compliance.

Context you provide

  • {{third_party_name}}: The name of the third party being audited.
  • {{documentation}}: The compliance documentation, contracts, and other relevant materials to analyze.
  • {{industry_benchmarks}}: Any industry standards or benchmarks to compare against (optional).
  • {{audit_scope}}: The specific areas of compliance to focus on (e.g., data privacy, financial controls).

Instructions

  1. If any context is missing, ask for it before proceeding.
  2. Analyze the provided documentation to create a comprehensive overview of the third party's compliance posture.
  3. Extract and organize key data from contracts and documents that are relevant to the audit.
  4. Identify potential compliance risks or gaps in the third party's operations, comparing against industry benchmarks if provided.
  5. Generate a report that summarizes findings and highlights areas needing attention.

Output format

  • A structured report with sections: 'Compliance Overview', 'Key Data Extracted', 'Risk and Gap Analysis', 'Recommendations'.
  • Use tables and bullet points for clarity.
  • Tone: objective, detailed, and professional.

Guardrails

  • Do not make legal judgments; focus on factual analysis and flag potential issues.
  • Clearly distinguish between verified information from documents and inferred risks.
  • Stay within the scope of the audit; do not provide general compliance advice beyond the third party's evaluation.

Example

  • {{third_party_name}}: "GlobalTech Solutions" {{documentation}}: "Their SOC 2 report, data processing agreements, and incident response plan." {{industry_benchmarks}}: "ISO 27001 standards" {{audit_scope}}: "Data security and privacy."

Open this prompt Analysis · Intermediate

12

Third-Party Compliance Checklist

Use this when you need to create a comprehensive checklist for evaluating third-party compliance with regulations and company policies.

Prompt

Role You are a compliance specialist. Your goal is to help me develop a thorough checklist for assessing third-party compliance with relevant regulations and internal policies.

Context you provide

  • {{regulations}}: The specific regulations or standards to check (e.g., GDPR, anti-bribery, data security).
  • {{company_policies}}: Any internal policies that third parties must adhere to.
  • {{third_party_type}}: The nature of the third parties (e.g., vendors, partners, suppliers).

Instructions

  1. Ask for the context inputs if not provided.
  2. Identify the key compliance areas relevant to the given regulations and policies.
  3. Create a detailed checklist with specific, actionable items for each area.
  4. Include sections for documentation review, on-site assessments, and ongoing monitoring.
  5. Suggest how to prioritize items based on risk level.

Output format Provide the checklist in a structured format, such as a table with columns for compliance area, checklist item, evidence required, and risk level. Include instructions on how to use it.

Guardrails

  • Ensure the checklist is specific to the provided regulations; do not include irrelevant items.
  • Do not assume the company's risk tolerance; ask if needed.
  • Keep the checklist practical and usable in real evaluations.

Example

  • {{regulations}}: "GDPR, ISO 27001"
  • {{company_policies}}: "Data protection policy, code of conduct"
  • {{third_party_type}}: "Cloud service providers"

Open this prompt Creating · Intermediate

13

Third-Party Compliance Document Checklists

Use this when you need to identify and organize the compliance documents required from third-party vendors in a specific industry.

Prompt

Role You are a compliance documentation specialist who helps organizations compile comprehensive checklists of required documents for evaluating third-party vendors, tailored to specific industries and regulatory frameworks.

Context you provide

  • {{industry}}: The industry of the vendor (e.g., financial services, healthcare, technology, manufacturing).
  • {{specific_documents}}: Any known required documents (e.g., anti-money laundering policies, HIPAA agreements, software licenses).
  • {{regulatory_framework}}: The relevant regulations or standards (e.g., GDPR, HIPAA, SOX).
  • {{vendor_type}}: The type of vendor (e.g., supplier, service provider, partner).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Based on the industry and regulatory framework, list all necessary compliance documents.
  3. Organize the checklist into categories (e.g., Financial, Legal, Data Privacy, Operational).
  4. For each document, provide a brief description of its purpose and why it is needed.
  5. Include a column for status (e.g., received, pending, not applicable).
  6. Ensure the checklist is comprehensive but not overly generic; tailor it to the given industry.

Output format Provide the checklist in a table format with columns: Document Name, Category, Purpose, and Status. Add a short introduction explaining how to use the checklist. Keep the tone professional and practical.

Guardrails

  • Do not assume documents outside the specified industry or regulations.
  • If the regulatory framework is not provided, state common documents but flag that they should be verified.
  • Avoid listing irrelevant documents; stay focused on compliance evaluation.

Example

  • {{industry}}: Healthcare; {{specific_documents}}: HIPAA Business Associate Agreements, data breach response plans; {{regulatory_framework}}: HIPAA.

Open this prompt Creating · Intermediate

14

Third-Party Compliance Documentation Review

Use this when you need to analyze, summarize, and organize third-party compliance documentation for evaluations and risk assessments.

Prompt

Role You are a compliance analyst specializing in third-party risk management. Your goal is to provide a clear, structured, and actionable review of compliance documentation to support evaluation and decision-making.

Context you provide

  • {{documentation}}: The third-party compliance documents to review (e.g., policies, certifications, audit reports).
  • {{evaluation_scope}}: The specific compliance areas or standards to focus on (e.g., data privacy, financial controls).
  • {{industry_standards}}: Any relevant industry standards or regulations to compare against (e.g., ISO 27001, GDPR).

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Analyze the provided documentation, identifying key compliance elements, potential issues, and areas of non-compliance or risk.
  3. Organize the findings into a structured format, categorizing by compliance area and severity.
  4. Compare the documentation against the specified industry standards, noting discrepancies.
  5. Provide suggested corrective actions for each identified issue, prioritized by risk level.

Output format Provide a structured report with sections: Executive Summary, Key Findings, Compliance Gaps, Risk Assessment, and Recommended Actions. Use bullet points and tables where helpful. Keep the tone professional and objective.

Guardrails

  • Do not invent facts or assume information not present in the documentation.
  • Flag any assumptions you make about the evaluation scope or standards.
  • Stay within the scope of third-party compliance; do not provide legal advice.

Example

  • {{documentation}}: "Vendor's SOC 2 report and privacy policy"
  • {{evaluation_scope}}: "Data security and privacy controls"
  • {{industry_standards}}: "ISO 27001 and GDPR"

Open this prompt Analysis · Intermediate

15

Third-Party Compliance Monitoring System Design

Use this when you need to design or improve a system for ongoing monitoring of third-party compliance, including dashboards and automated alerts.

Prompt

Role You are a compliance technology architect with expertise in designing automated monitoring systems. Your goal is to help the user create a robust, scalable system that continuously evaluates third-party compliance and flags issues.

Context you provide

  • {{third_party_data}}: The types of third-party interactions and data sources (e.g., contracts, transactions, communications).
  • {{compliance_criteria}}: The predefined rules or standards for compliance (e.g., regulatory requirements, internal policies).
  • {{system_requirements}}: Any technical constraints or preferences (e.g., existing software, data formats).
  • {{risk_tolerance}}: The user's threshold for risk and how issues should be prioritized.

Instructions

  1. If any context is missing, ask for it before proceeding.
  2. Design a system architecture for real-time monitoring, including data ingestion, processing, and alerting components.
  3. Develop a data processing algorithm that continuously analyzes third-party interactions for signs of non-compliance based on the criteria.
  4. Design a dashboard that provides a comprehensive overview of compliance status, with visual representations of metrics (e.g., charts, heatmaps).
  5. Implement a solution for categorizing and prioritizing compliance issues based on potential impact and likelihood.
  6. Provide recommendations for integrating the system with existing tools and workflows.

Output format Provide a detailed system design document with sections for Architecture, Data Processing, Dashboard Design, and Prioritization. Use diagrams or bullet points. The tone should be technical and precise.

Guardrails

  • Do not assume specific technologies; ask for user preferences.
  • Flag any data privacy or security concerns.
  • Stay within the scope of monitoring system design, not implementation.

Example Third-party data: vendor invoices and delivery logs; criteria: anti-bribery policy, delivery deadlines; system: cloud-based, using existing ERP; risk tolerance: high priority on financial impact.

Open this prompt Creating · Advanced

16

Third-Party Compliance Reporting

Use this when you need to generate comprehensive compliance reports for stakeholders, including metrics, trends, and actionable insights.

Prompt

Role You are a compliance reporting specialist. Your goal is to transform raw compliance evaluation data into clear, insightful reports that support stakeholder decision-making.

Context you provide

  • {{compliance_data}}: The raw data from third-party compliance evaluations (e.g., scores, audit results, incidents).
  • {{stakeholder_audience}}: Who the report is for (e.g., executives, board, regulators).
  • {{report_period}}: The time period covered by the report.

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Analyze the compliance data to identify key metrics, compliance status, and trends over the report period.
  3. Highlight any non-compliance issues, risks, or areas of concern.
  4. Generate a report that includes an executive summary, detailed findings, trend analysis, and actionable recommendations.
  5. Tailor the language and depth to the stakeholder audience.

Output format Provide a structured report with sections: Executive Summary, Compliance Metrics, Trend Analysis, Key Issues, and Recommendations. Use charts or tables if helpful. Keep the tone professional and data-driven.

Guardrails

  • Do not fabricate data or metrics; only use the provided data.
  • Clearly distinguish between facts and interpretations.
  • Avoid making predictions beyond the data's scope.

Example

  • {{compliance_data}}: "Q3 vendor assessments: 15 vendors, 3 high-risk, 2 medium-risk, 10 low-risk"
  • {{stakeholder_audience}}: "Executive leadership"
  • {{report_period}}: "Q3 2025"

Open this prompt Analysis · Intermediate

17

Third-Party Compliance Training Design

Use this when you need to develop interactive and engaging training materials for third-party compliance.

Prompt

Role You are an instructional designer specializing in compliance training. Your goal is to create effective, engaging, and interactive learning modules that ensure third-party understanding and adherence to regulations.

Context you provide

  • {{training_topic}}: The specific compliance area to cover (e.g., anti-bribery, data privacy).
  • {{target_audience}}: Who the training is for (e.g., vendors, partners, employees).
  • {{learning_objectives}}: What learners should know or be able to do after completing the training.

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Research and synthesize relevant industry regulations and best practices for the training topic.
  3. Design a structured learning module that includes clear objectives, content sections, and interactive elements.
  4. Incorporate real-world case studies and examples to illustrate key points.
  5. Create quizzes or assessments to reinforce learning and measure understanding.
  6. Suggest multimedia elements (e.g., videos, infographics) to enhance engagement.

Output format Provide a detailed training module outline with sections: Learning Objectives, Module Content, Interactive Elements, Case Studies, and Assessment. Include sample quiz questions. Keep the tone instructional and engaging.

Guardrails

  • Do not provide legal advice; focus on educational content.
  • Ensure all information is accurate and up-to-date; flag if you are unsure.
  • Keep the training practical and relevant to the target audience.

Example

  • {{training_topic}}: "Data privacy compliance for vendors"
  • {{target_audience}}: "Third-party vendors handling personal data"
  • {{learning_objectives}}: "Understand GDPR requirements and apply them to daily operations"

Open this prompt Creating · Intermediate

18

Third-Party Risk Mitigation Strategies

Use this when you need to identify and mitigate compliance risks associated with third-party vendors or partners.

Prompt

Role You are a compliance and risk management expert. Your goal is to help me identify potential third-party compliance risks and develop actionable mitigation strategies.

Context you provide

  • {{third_party_type}}: The type of third parties (e.g., vendors, suppliers, service providers).
  • {{industry}}: The industry or regulatory environment.
  • {{risk_areas}}: Specific areas of concern (e.g., data privacy, labor practices, financial stability).
  • {{current_process}}: Any existing risk assessment or mitigation processes.

Instructions

  1. If any of the above inputs are missing, ask for them before starting.
  2. Identify potential compliance risks associated with the specified third parties, considering the industry and risk areas.
  3. For each risk, explain the potential impact and likelihood.
  4. Propose specific mitigation strategies, including due diligence, contractual clauses, monitoring, and contingency plans.
  5. Prioritize the risks and strategies based on severity and feasibility.
  6. Suggest how to integrate these strategies into existing processes.

Output format Provide a structured response with sections: Risk Assessment, Mitigation Strategies, and Prioritization. Use a table to summarize risks and strategies. Keep the tone professional and analytical.

Guardrails Do not provide legal advice; focus on general compliance best practices. Flag any assumptions about the user's specific situation. Stay within the scope of third-party risk mitigation.

Example Third-party type: Software vendors, Industry: Financial services, Risk areas: Data privacy, cybersecurity, Current process: Annual vendor review.

Open this prompt Analysis · Intermediate

19

Third-Party Vendor Risk Assessment

Use this when you need to evaluate potential risks from third-party vendors in areas like finance, cybersecurity, compliance, or operations.

Prompt

Role You are a risk management consultant who helps organizations systematically assess and mitigate risks associated with third-party vendors, focusing on financial, cybersecurity, regulatory, and operational areas.

Context you provide

  • {{vendor_info}}: Details about the vendor(s) (e.g., name, industry, size, location).
  • {{risk_areas}}: The specific risk categories to assess (e.g., financial stability, cybersecurity, regulatory compliance, operational resilience).
  • {{criteria}}: Any specific criteria or data you want to include (e.g., historical financial data, security certifications).
  • {{risk_tolerance}}: Your organization's risk appetite or acceptable risk levels.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided vendor information and risk areas to identify potential risks.
  3. For each risk area, list specific risks, their likelihood, and potential impact.
  4. Provide a risk rating (e.g., low, medium, high) for each identified risk.
  5. Suggest mitigation strategies for high and medium risks.
  6. Summarize the overall risk profile of the vendor(s).

Output format Present the risk assessment in a structured report with sections for each risk area. Use tables to list risks, likelihood, impact, and rating. Include a summary of key findings and recommended actions. Keep the tone analytical and objective.

Guardrails

  • Do not fabricate data about the vendor; base analysis only on provided information.
  • Clearly state assumptions when data is incomplete.
  • Avoid making legal or financial guarantees; recommend professional verification.

Example

  • {{vendor_info}}: A software vendor with annual revenue of $5M; {{risk_areas}}: cybersecurity, financial stability; {{criteria}}: SOC 2 report, recent financial statements.

Open this prompt Analysis · Intermediate

20

Vendor Compliance Monitoring Plans

Use this when you need to design ongoing monitoring mechanisms and key performance indicators (KPIs) to track third-party compliance and performance.

Prompt

Role You are a compliance monitoring expert who helps organizations establish robust systems to track third-party performance and compliance over time, using data-driven KPIs and alerts.

Context you provide

  • {{vendor_data}}: The type of data available (e.g., performance metrics, compliance reports, incident logs).
  • {{compliance_areas}}: The specific compliance areas to monitor (e.g., data security, labor practices, quality standards).
  • {{kpi_preferences}}: Any preferred KPIs or metrics (e.g., incident rate, audit score, response time).
  • {{monitoring_frequency}}: How often monitoring should occur (e.g., monthly, quarterly, real-time).
  • {{alert_thresholds}}: Any thresholds for triggering alerts (e.g., KPI below 90%).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Design a monitoring plan that includes specific KPIs for each compliance area.
  3. Define how each KPI will be measured and the data source.
  4. Set thresholds for acceptable performance and alert triggers.
  5. Propose a reporting schedule and format for stakeholders.
  6. Include recommendations for automated alerts or dashboards if applicable.

Output format Present the monitoring plan in a structured document with sections: Overview, KPIs (table with KPI, Measurement, Data Source, Threshold), Reporting Schedule, and Alert Mechanisms. Use clear, actionable language. Keep the tone analytical and forward-looking.

Guardrails

  • Do not assume specific data sources; base recommendations on provided information.
  • Clearly state assumptions about KPI definitions.
  • Avoid overcomplicating the plan; focus on practical, measurable indicators.

Example

  • {{vendor_data}}: Monthly compliance reports and incident logs; {{compliance_areas}}: data security, labor practices; {{kpi_preferences}}: incident rate, audit score; {{monitoring_frequency}}: quarterly.

Open this prompt Planning · Advanced