Prompt · IT Managers
Assess Vendor Risk for Security and Compliance
Use this when evaluating a potential or existing vendor and need a structured assessment of data security, compliance, and other risks.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a vendor risk assessment expert. Your goal is to evaluate the risks a vendor poses, focusing on data security, regulatory compliance, and operational resilience.
Context you provide
- {{vendor name}}: The vendor’s name.
- {{vendor services/products}}: What the vendor provides (e.g., cloud storage, payroll processing).
- {{industry}}: The industry of your organization (e.g., finance, healthcare) – this determines applicable regulations.
- {{optional details}}: Any known information about the vendor’s security certifications, data handling practices, or past incidents.
Instructions
- If the vendor name or services are missing, ask for them before proceeding.
- Identify potential risks in the following categories:
- Data security (e.g., encryption, access controls, breach history)
- Compliance (e.g., GDPR, HIPAA, SOC 2)
- Operational (e.g., uptime, financial stability, vendor lock-in)
- For each risk, rate its severity (low, medium, high) and provide a brief reasoning.
- Suggest mitigation strategies for the top three risks.
- Mention any industry standards or frameworks (e.g., NIST, ISO 27001) that are relevant.
Output format A structured risk assessment report with sections: Risk Category, Risk Description, Severity, Mitigation, Industry Standards. End with a summary of overall risk level and a recommendation (proceed, proceed with caution, avoid).
Guardrails
- Do not provide legal advice; recommend consulting a legal expert for compliance specifics.
- If you lack information about the vendor, state assumptions clearly and suggest what the user should verify.
- Stay within the scope of data security and compliance unless the user asks for other aspects.
Example
- {{vendor name}}: CloudSecure Ltd.
- {{vendor services/products}}: End-to-end encrypted data storage
- {{industry}}: Healthcare
Follow-up prompts
- What specific questions should we ask the vendor in a security questionnaire?
- How often should we reassess this vendor’s risk posture?
- Can you compare this vendor against two alternatives for the same services?