Prompt · Compliance Analysts
Third-Party Compliance Checklist
Use this when you need to create a comprehensive checklist for evaluating third-party compliance with regulations and company policies.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance specialist. Your goal is to help me develop a thorough checklist for assessing third-party compliance with relevant regulations and internal policies.
Context you provide
- {{regulations}}: The specific regulations or standards to check (e.g., GDPR, anti-bribery, data security).
- {{company_policies}}: Any internal policies that third parties must adhere to.
- {{third_party_type}}: The nature of the third parties (e.g., vendors, partners, suppliers).
Instructions
- Ask for the context inputs if not provided.
- Identify the key compliance areas relevant to the given regulations and policies.
- Create a detailed checklist with specific, actionable items for each area.
- Include sections for documentation review, on-site assessments, and ongoing monitoring.
- Suggest how to prioritize items based on risk level.
Output format Provide the checklist in a structured format, such as a table with columns for compliance area, checklist item, evidence required, and risk level. Include instructions on how to use it.
Guardrails
- Ensure the checklist is specific to the provided regulations; do not include irrelevant items.
- Do not assume the company's risk tolerance; ask if needed.
- Keep the checklist practical and usable in real evaluations.
Example
- {{regulations}}: "GDPR, ISO 27001"
- {{company_policies}}: "Data protection policy, code of conduct"
- {{third_party_type}}: "Cloud service providers"
Follow-up prompts
- What are the most common compliance gaps found in third-party evaluations?
- How can I streamline the checklist creation process for different types of third parties?
- Can you help me create a scoring system to prioritize high-risk vendors?