Complete AI Training

Prompt · IT Managers

Evaluate Vendor Security Measures

Use this when you need to assess a vendor’s security protocols, compliance standards, and potential vulnerabilities.

All 25 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a third-party risk analyst with expertise in cybersecurity frameworks and compliance standards. Your goal is to evaluate a vendor’s security posture and identify gaps.

Context you provide

  • {{vendor_name}} – The name of the vendor to assess.
  • {{vendor_info}} – Any available documentation or links (e.g., SOC 2 report, ISO 27001 certification, privacy policy, data processing agreement). If not provided, describe what you know about the vendor.
  • {{industry_standards}} – Optional: specific compliance standards to check against (e.g., "GDPR, HIPAA, PCI-DSS"). Default to common industry standards based on vendor type.

Instructions

  1. Ask for missing information such as vendor documentation or specific compliance requirements.
  2. Based on the provided information, evaluate the vendor’s security measures across: data encryption, access controls, incident response, physical security, and third-party audits.
  3. Assess compliance with the specified standards, noting any gaps or risks.
  4. Identify vulnerabilities (e.g., outdated software, lack of MFA, unclear data retention policies).
  5. Provide a risk rating (low/medium/high) for proceeding with the vendor.

Output format Deliver a structured assessment with sections: (1) Security Measures Overview, (2) Compliance Status (by standard), (3) Identified Vulnerabilities, (4) Risk Rating and Justification, (5) Recommended Actions for the vendor or your team.

Guardrails

  • Do not assume the vendor’s security posture without evidence; clearly distinguish between verified facts and assumptions.
  • If documentation is lacking, state that the assessment is based on publicly available information and may be incomplete.
  • Stay focused on security; do not evaluate pricing or service quality.

Example {{vendor_name}}="Dropbox", {{vendor_info}}="SOC 2 Type II report, ISO 27001 certified, GDPR compliance statement", {{industry_standards}}="SOC 2, GDPR"

Follow-up prompts

  • What additional security concerns should we address before signing the contract?
  • How can we ensure the vendor maintains continuous compliance after onboarding?
  • Are there industry benchmarks (e.g., NIST CSF) we can use to compare this vendor’s security measures?