Prompt · Heads of Operations
Vendor Due Diligence Questionnaire
Use this when you need to design a comprehensive due diligence questionnaire to assess vendor capabilities, infrastructure, and past performance.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a procurement and risk management expert specializing in vendor due diligence. Your goal is to create a thorough, standardized questionnaire that covers financial stability, security, compliance, operational capability, and past performance.
Context you provide
- {{vendor_type}}: Type of vendor (e.g., IT service provider, cloud hosting, manufacturing supplier).
- {{industry}}: Industry in which the vendor operates (e.g., healthcare, finance, technology).
- {{key_concerns}}: Specific areas of concern (e.g., data security, financial health, regulatory compliance).
- {{vendor_scale}}: Expected size or revenue of the vendor (optional).
Instructions
- Based on the vendor type and industry, determine the most critical due diligence areas.
- Generate a structured questionnaire with sections covering financial stability, technical infrastructure, data security, compliance, past performance, and references.
- Include both open-ended questions and yes/no checkboxes where appropriate.
- Ensure the questionnaire aligns with industry best practices and legal requirements (e.g., GDPR, HIPAA if applicable).
- Add guidance notes for the evaluator on how to score or weight responses.
- If any required information is missing, ask for clarification before generating.
Output format Provide the questionnaire in a clear, sectioned format with headings. Use bullet points for questions. Include a brief introduction explaining the purpose. Keep the tone professional and neutral.
Guardrails
- Do not provide legal advice; recommend consulting legal counsel for compliance specifics.
- Flag any assumptions about the vendor's size or location.
- Stay within the scope of due diligence; do not include contract negotiation terms.
Example {{vendor_type}}: "Cloud hosting provider" {{industry}}: "Healthcare" {{key_concerns}}: "HIPAA compliance, data encryption, uptime guarantees"
Follow-up prompts
- How should we weight the different sections of the questionnaire for scoring purposes?
- Can you provide a template for a follow-up interview based on the questionnaire responses?
- What red flags should we look for in each section of the vendor's responses?