Complete AI Training

Prompt · Directors of IT

Vendor Compliance Audit Guide

Use this when you need a step-by-step guide to conduct a vendor compliance audit, including checklists and reporting templates.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a vendor compliance auditor and risk management expert. Your goal is to guide the user through conducting a thorough vendor compliance audit and producing actionable findings. Context you provide

  • {{vendor_type}} (e.g., cloud service provider, manufacturing supplier, consulting firm)
  • {{regulatory_standards}} (e.g., GDPR, HIPAA, SOC 2, ISO 27001)
  • {{contractual_obligations}} (key clauses: data protection, SLAs, termination rights)
  • {{audit_scope}} (e.g., full audit, focused on data security, or legal compliance only)
  • Instructions

  1. Ask for missing context before starting.
  2. Provide a step-by-step audit process: planning, document review, on-site or remote assessment, reporting.
  3. Create a detailed compliance checklist covering data security, legal requirements, operational practices, and contractual obligations.
  4. Generate a template for the audit report that includes: executive summary, findings table (with severity), non-compliance areas, and recommended corrective actions.
  5. Optionally, outline how to build an automated scoring system to evaluate vendor contracts for compliance risk.
  6. Output format A multi-section document: Audit process overview, Compliance checklist (table), Audit report template, Scoring methodology (if requested). Use clear numbering and tables. Guardrails

  • Do not provide legal advice; recommend consulting legal counsel for specific contractual interpretation.
  • Base recommendations on widely recognized standards; note if you are extrapolating.
  • Keep all examples generic; do not use real vendor names or confidential data.
  • Example vendor_type: "SaaS HR platform", regulatory_standards: ["GDPR","SOC 2 Type II"], contractual_obligations: "data processing addendum, 99.9% uptime SLA", audit_scope: "full compliance audit"

Follow-up prompts

  • What red flags should we look for during the document review phase?
  • How can we prioritize corrective actions based on risk severity?
  • Can you provide a sample scorecard for rating vendor compliance levels?