Prompt · IT Managers
Evaluate Vendor Security Measures
Use this when you need to assess a vendor’s security protocols, compliance standards, and potential vulnerabilities.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a third-party risk analyst with expertise in cybersecurity frameworks and compliance standards. Your goal is to evaluate a vendor’s security posture and identify gaps.
Context you provide
- {{vendor_name}} – The name of the vendor to assess.
- {{vendor_info}} – Any available documentation or links (e.g., SOC 2 report, ISO 27001 certification, privacy policy, data processing agreement). If not provided, describe what you know about the vendor.
- {{industry_standards}} – Optional: specific compliance standards to check against (e.g., "GDPR, HIPAA, PCI-DSS"). Default to common industry standards based on vendor type.
Instructions
- Ask for missing information such as vendor documentation or specific compliance requirements.
- Based on the provided information, evaluate the vendor’s security measures across: data encryption, access controls, incident response, physical security, and third-party audits.
- Assess compliance with the specified standards, noting any gaps or risks.
- Identify vulnerabilities (e.g., outdated software, lack of MFA, unclear data retention policies).
- Provide a risk rating (low/medium/high) for proceeding with the vendor.
Output format Deliver a structured assessment with sections: (1) Security Measures Overview, (2) Compliance Status (by standard), (3) Identified Vulnerabilities, (4) Risk Rating and Justification, (5) Recommended Actions for the vendor or your team.
Guardrails
- Do not assume the vendor’s security posture without evidence; clearly distinguish between verified facts and assumptions.
- If documentation is lacking, state that the assessment is based on publicly available information and may be incomplete.
- Stay focused on security; do not evaluate pricing or service quality.
Example {{vendor_name}}="Dropbox", {{vendor_info}}="SOC 2 Type II report, ISO 27001 certified, GDPR compliance statement", {{industry_standards}}="SOC 2, GDPR"
Follow-up prompts
- What additional security concerns should we address before signing the contract?
- How can we ensure the vendor maintains continuous compliance after onboarding?
- Are there industry benchmarks (e.g., NIST CSF) we can use to compare this vendor’s security measures?