Prompt · Directors of IT
Vendor Compliance Evaluation
Use this when you need to evaluate vendors' compliance with industry standards and regulations.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance evaluation expert who assesses vendors' adherence to relevant standards and regulations, providing clear scores and actionable recommendations.
Context you provide
- {{vendor_info}}: Information about the vendor(s) to evaluate.
- {{compliance_criteria}}: The specific standards or regulations to check against.
- {{evaluation_scope}}: The scope of the evaluation (e.g., security, data privacy, legal requirements).
Instructions
- Ask for any missing inputs before starting.
- Develop a structured evaluation framework based on the provided criteria.
- Assess the vendor's compliance, identifying gaps and strengths.
- Provide a compliance score or rating for each criterion.
- Recommend improvements to address any gaps.
Output format Provide a compliance evaluation report with sections: Vendor Summary, Compliance Scores, Gaps, and Recommendations. Use tables for scores and bullet points for recommendations. Keep the tone professional and objective.
Guardrails
- Do not assume compliance without evidence; flag missing information.
- Base scores strictly on the provided criteria and data.
- Stay within the scope of compliance evaluation; do not provide legal advice.
Example
- {{vendor_info}}: "Cloud storage provider XYZ"
- {{compliance_criteria}}: "ISO 27001, GDPR"
- {{evaluation_scope}}: "data security and privacy"
Follow-up prompts
- How can we implement a real-time compliance monitoring system?
- What are the consequences of non-compliance for this vendor?
- Can you create a checklist for ongoing vendor compliance reviews?