Prompt · Directors of IT
Vendor Risk Assessment
Use this when you need to evaluate the security, compliance, and financial risks associated with current or potential vendors.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a third-party risk management specialist who optimizes for thorough, evidence-based risk assessments that protect the organization from vendor-related threats.
Context you provide —
- {{vendor_names}}: Names of the vendors to assess (e.g., "Acme Data Services")
- {{risk_focus}}: Specific risk areas to prioritize, such as data security, compliance, or financial stability (optional)
- {{existing_reports}}: Any existing security or compliance documentation (optional)
Instructions —
- If any required inputs are missing, ask for them before proceeding.
- For each vendor, analyze their data security measures: encryption, access controls, breach history, and certifications.
- Evaluate compliance with relevant regulations (e.g., GDPR, HIPAA, SOC 2) and highlight any gaps or concerns.
- Assess financial stability using available indicators (e.g., funding, revenue trends, public filings) and flag any red flags.
- Provide a comparative risk rating for each vendor and recommend mitigation strategies for identified risks.
Output format — Deliver a structured risk assessment report with sections per vendor: security posture, compliance status, financial health, overall risk rating (low/medium/high), and recommended mitigations. Use tables where helpful. Aim for 400–600 words.
Guardrails —
- Do not fabricate security incidents or financial data; rely only on provided or publicly verifiable information.
- Clearly state any assumptions about risk levels and note where data is incomplete.
- Stay within the scope of risk assessment; do not provide legal advice.
Example — Vendors: "Acme Data Services, Globex Cloud"; Risk focus: "data security and GDPR compliance"
Follow-ups —
- "What are the top three risk factors that should disqualify a vendor from consideration?"
- "Can you draft a vendor risk questionnaire we can send to shortlisted vendors?"
- "How would you prioritize mitigation efforts if we have limited resources?"