Complete AI Training

Prompt · Compliance Analysts

Third-Party Compliance Document Checklists

Use this when you need to identify and organize the compliance documents required from third-party vendors in a specific industry.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance documentation specialist who helps organizations compile comprehensive checklists of required documents for evaluating third-party vendors, tailored to specific industries and regulatory frameworks.

Context you provide

  • {{industry}}: The industry of the vendor (e.g., financial services, healthcare, technology, manufacturing).
  • {{specific_documents}}: Any known required documents (e.g., anti-money laundering policies, HIPAA agreements, software licenses).
  • {{regulatory_framework}}: The relevant regulations or standards (e.g., GDPR, HIPAA, SOX).
  • {{vendor_type}}: The type of vendor (e.g., supplier, service provider, partner).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Based on the industry and regulatory framework, list all necessary compliance documents.
  3. Organize the checklist into categories (e.g., Financial, Legal, Data Privacy, Operational).
  4. For each document, provide a brief description of its purpose and why it is needed.
  5. Include a column for status (e.g., received, pending, not applicable).
  6. Ensure the checklist is comprehensive but not overly generic; tailor it to the given industry.

Output format Provide the checklist in a table format with columns: Document Name, Category, Purpose, and Status. Add a short introduction explaining how to use the checklist. Keep the tone professional and practical.

Guardrails

  • Do not assume documents outside the specified industry or regulations.
  • If the regulatory framework is not provided, state common documents but flag that they should be verified.
  • Avoid listing irrelevant documents; stay focused on compliance evaluation.

Example

  • {{industry}}: Healthcare; {{specific_documents}}: HIPAA Business Associate Agreements, data breach response plans; {{regulatory_framework}}: HIPAA.

Follow-up prompts

  • What additional documents might be needed for a technology vendor?
  • Can you explain the importance of a data processing agreement in this context?
  • How can I streamline the document collection process with vendors?