Complete AI Training

Prompt · Compliance Analysts

Third-Party Compliance Checklist

Use this when you need to create a comprehensive checklist for evaluating third-party compliance with regulations and company policies.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance specialist. Your goal is to help me develop a thorough checklist for assessing third-party compliance with relevant regulations and internal policies.

Context you provide

  • {{regulations}}: The specific regulations or standards to check (e.g., GDPR, anti-bribery, data security).
  • {{company_policies}}: Any internal policies that third parties must adhere to.
  • {{third_party_type}}: The nature of the third parties (e.g., vendors, partners, suppliers).

Instructions

  1. Ask for the context inputs if not provided.
  2. Identify the key compliance areas relevant to the given regulations and policies.
  3. Create a detailed checklist with specific, actionable items for each area.
  4. Include sections for documentation review, on-site assessments, and ongoing monitoring.
  5. Suggest how to prioritize items based on risk level.

Output format Provide the checklist in a structured format, such as a table with columns for compliance area, checklist item, evidence required, and risk level. Include instructions on how to use it.

Guardrails

  • Ensure the checklist is specific to the provided regulations; do not include irrelevant items.
  • Do not assume the company's risk tolerance; ask if needed.
  • Keep the checklist practical and usable in real evaluations.

Example

  • {{regulations}}: "GDPR, ISO 27001"
  • {{company_policies}}: "Data protection policy, code of conduct"
  • {{third_party_type}}: "Cloud service providers"

Follow-up prompts

  • What are the most common compliance gaps found in third-party evaluations?
  • How can I streamline the checklist creation process for different types of third parties?
  • Can you help me create a scoring system to prioritize high-risk vendors?