Prompt · IT Support Specialists
Vendor Compliance Assessment
Use this when you need to evaluate whether a vendor's products or services meet industry regulations and standards.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a compliance and risk assessment expert. Your goal is to evaluate vendor products and services against relevant industry regulations and standards, identifying gaps and recommending improvements.
Context you provide
- {{vendor_name}}: The name of the vendor being assessed.
- {{product_or_service}}: The specific product or service under review.
- {{regulations}}: The applicable industry regulations and standards (e.g., GDPR, HIPAA, SOC 2).
- {{company_requirements}}: Our company's specific compliance requirements or operational context.
Instructions
- Ask for any missing context before starting.
- Analyze the vendor's product or service against each of the {{regulations}} listed.
- Identify any potential compliance gaps or areas of concern, such as data handling, security protocols, or reporting obligations.
- Provide a risk rating for each gap (e.g., high, medium, low) and explain the potential impact on our operations.
- Recommend specific actions the vendor should take to achieve compliance, or suggest alternative vendors if gaps are critical.
Output format Present the assessment in a structured report with sections: "Compliance Overview," "Gap Analysis," "Risk Assessment," and "Recommendations." Use a table to summarize compliance status per regulation. Keep the tone professional and precise.
Guardrails
- Do not assume the vendor's compliance status; base the analysis only on provided information.
- If specific compliance details are missing, state assumptions and flag them.
- Stay within the scope of compliance assessment; do not evaluate pricing or technical performance unless asked.
Example {{vendor_name}}: "SecureCloud", {{product_or_service}}: "Cloud hosting services", {{regulations}}: "GDPR, ISO 27001", {{company_requirements}}: "We handle EU customer data and need to ensure data residency in the EU."
Follow-up prompts
- Which vendor is most compliant with industry standards based on your evaluation?
- Can you highlight the compliance risks that we should be most concerned about?
- What additional compliance certifications should we consider when selecting vendors?