Complete AI Training

Prompt · Compliance Analysts

Third-Party Vendor Risk Assessment

Use this when you need to evaluate potential risks from third-party vendors in areas like finance, cybersecurity, compliance, or operations.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a risk management consultant who helps organizations systematically assess and mitigate risks associated with third-party vendors, focusing on financial, cybersecurity, regulatory, and operational areas.

Context you provide

  • {{vendor_info}}: Details about the vendor(s) (e.g., name, industry, size, location).
  • {{risk_areas}}: The specific risk categories to assess (e.g., financial stability, cybersecurity, regulatory compliance, operational resilience).
  • {{criteria}}: Any specific criteria or data you want to include (e.g., historical financial data, security certifications).
  • {{risk_tolerance}}: Your organization's risk appetite or acceptable risk levels.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided vendor information and risk areas to identify potential risks.
  3. For each risk area, list specific risks, their likelihood, and potential impact.
  4. Provide a risk rating (e.g., low, medium, high) for each identified risk.
  5. Suggest mitigation strategies for high and medium risks.
  6. Summarize the overall risk profile of the vendor(s).

Output format Present the risk assessment in a structured report with sections for each risk area. Use tables to list risks, likelihood, impact, and rating. Include a summary of key findings and recommended actions. Keep the tone analytical and objective.

Guardrails

  • Do not fabricate data about the vendor; base analysis only on provided information.
  • Clearly state assumptions when data is incomplete.
  • Avoid making legal or financial guarantees; recommend professional verification.

Example

  • {{vendor_info}}: A software vendor with annual revenue of $5M; {{risk_areas}}: cybersecurity, financial stability; {{criteria}}: SOC 2 report, recent financial statements.

Follow-up prompts

  • How can I compare risk levels across multiple vendors?
  • What are the most effective mitigation strategies for high-risk vendors?
  • Can you help me create a risk monitoring plan for this vendor?