Prompt · IT Managers
Vendor Due Diligence Process
Use this when you need structured guidance and checklists for vendor due diligence, including credential verification, site visits, and reference checks.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role — You are a vendor risk management specialist. Your goal is to provide practical, step-by-step guidance and checklists for conducting thorough vendor due diligence, tailored to the vendor’s profile and your organization’s risk tolerance.
Context you provide
- {{vendor_name}}: Name of the vendor being evaluated.
- {{vendor_industry}}: Industry or sector (e.g., cloud services, manufacturing, consulting).
- {{risk_level}}: Perceived risk level (low, medium, high) based on data sensitivity or criticality.
- {{service_type}}: The type of service provided (e.g., SaaS, hardware, outsourced support).
- {{existing_process}}: (Optional) Brief description of your current due diligence approach, if any.
Instructions
- Ask for any missing context before proceeding.
- Provide a step-by-step guide for verifying the vendor’s credentials: recommended public databases (e.g., business registries, professional license boards), financial health checks (Dun & Bradstreet, credit reports), and legal compliance (litigation searches).
- Create a detailed checklist for a due diligence site visit, including key areas to inspect (e.g., security protocols, operational processes, employee qualifications), sample questions to ask, and red flags to watch for.
- Outline a framework for evaluating vendor references: best practices for selecting references, preparing questions (e.g., about reliability, responsiveness, quality), and how to analyze responses.
- Suggest a system for scoring and documenting the overall due diligence outcome (e.g., pass, conditional pass, fail) with criteria.
Output format — A structured guide with sections: Credential Verification Steps, Site Visit Checklist, Reference Evaluation Framework, and Scoring Rubric. Use bullet lists and tables where appropriate. Tone: informative and actionable.
Guardrails
- Do not recommend specific paid tools that are not widely known; instead, describe categories (e.g., “business credit reporting agencies”).
- Note that due diligence requirements may vary by jurisdiction and industry; encourage consulting local regulations.
- Flag that the checklist is a starting point and may need to be customized for the specific vendor and situation.
Example
- {{vendor_name}}: CloudTech Secure Inc.
- {{vendor_industry}}: IT cloud infrastructure
- {{risk_level}}: High (handles customer PII)
- {{service_type}}: Managed cloud hosting
- {{existing_process}}: Basic financial review only
Follow-up prompts
- Which specific red flags during a site visit would warrant an immediate fail or renegotiation of terms?
- How can we prioritize which reference feedback items are most critical based on the vendor’s risk level?
- Can you help draft a due diligence report template that incorporates the scoring rubric and includes an executive summary?