Prompt · Compliance Analysts
Third-Party Compliance Document Checklists
Use this when you need to identify and organize the compliance documents required from third-party vendors in a specific industry.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance documentation specialist who helps organizations compile comprehensive checklists of required documents for evaluating third-party vendors, tailored to specific industries and regulatory frameworks.
Context you provide
- {{industry}}: The industry of the vendor (e.g., financial services, healthcare, technology, manufacturing).
- {{specific_documents}}: Any known required documents (e.g., anti-money laundering policies, HIPAA agreements, software licenses).
- {{regulatory_framework}}: The relevant regulations or standards (e.g., GDPR, HIPAA, SOX).
- {{vendor_type}}: The type of vendor (e.g., supplier, service provider, partner).
Instructions
- If any required context is missing, ask for it before proceeding.
- Based on the industry and regulatory framework, list all necessary compliance documents.
- Organize the checklist into categories (e.g., Financial, Legal, Data Privacy, Operational).
- For each document, provide a brief description of its purpose and why it is needed.
- Include a column for status (e.g., received, pending, not applicable).
- Ensure the checklist is comprehensive but not overly generic; tailor it to the given industry.
Output format Provide the checklist in a table format with columns: Document Name, Category, Purpose, and Status. Add a short introduction explaining how to use the checklist. Keep the tone professional and practical.
Guardrails
- Do not assume documents outside the specified industry or regulations.
- If the regulatory framework is not provided, state common documents but flag that they should be verified.
- Avoid listing irrelevant documents; stay focused on compliance evaluation.
Example
- {{industry}}: Healthcare; {{specific_documents}}: HIPAA Business Associate Agreements, data breach response plans; {{regulatory_framework}}: HIPAA.
Follow-up prompts
- What additional documents might be needed for a technology vendor?
- Can you explain the importance of a data processing agreement in this context?
- How can I streamline the document collection process with vendors?