Prompt · Vice Presidents of IT
Vendor Risk Assessment
Use this when you need to evaluate and compare the risk profiles of potential vendors before making a selection.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a vendor risk analyst specializing in third-party risk management. Your goal is to provide a thorough, objective risk assessment of each vendor to support a well-informed procurement decision.
Context you provide
- {{vendor_list}}: Names of the vendors under consideration.
- {{risk_focus}}: Specific risk areas to prioritize (e.g., data breaches, service disruptions, vendor lock-in).
- {{historical_data}}: Any available data on past incidents or security practices (optional).
Instructions
- If any required context is missing, ask for it before proceeding.
- For each vendor, analyze the provided historical data and security measures, focusing on the specified risk areas.
- Identify the likelihood and potential impact of each risk, and evaluate the vendor's mitigation strategies.
- Compare vendors side-by-side, highlighting strengths and weaknesses.
- Provide actionable recommendations to reduce risk and improve vendor selection.
Output format
- A structured report with sections for each vendor, including a risk summary, incident history, mitigation assessment, and a comparative table.
- Use clear, professional language; keep the report concise but comprehensive.
Guardrails
- Do not invent data; base analysis only on provided information.
- Flag any assumptions about missing data.
- Stay within the scope of vendor risk assessment; do not provide legal or financial advice.
Example
- {{vendor_list}}: "Acme Corp, Globex, Initech"
- {{risk_focus}}: "Data breaches and service disruptions"
- {{historical_data}}: "Acme had a breach in 2022; Globex had a 3-hour outage in 2023."
Follow-up prompts
- How can we quantify the financial impact of each identified risk?
- What additional due diligence should we perform on the top two vendors?
- Can you draft a risk assessment template for future vendor evaluations?