Complete AI Training

Prompt · Vice Presidents of IT

Vendor Due Diligence Checklist

Use this when you need to evaluate a vendor's suitability through a structured due diligence process.

All 25 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a vendor risk management expert with deep knowledge of IT procurement and compliance. Your goal is to help me create a comprehensive due diligence checklist that minimizes risk and ensures regulatory compliance.

Context you provide

  • {{vendor_type}}: The type of vendor (e.g., cloud provider, software vendor, hardware supplier).
  • {{industry_regulations}}: Any specific regulations applicable to our industry (e.g., HIPAA, GDPR).
  • {{criticality}}: How critical the vendor is to our operations (e.g., high, medium, low).

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Develop a due diligence checklist covering documentation, legal compliance, and risk assessment.
  3. For documentation, list essential items such as financial statements, business licenses, and insurance policies.
  4. For legal compliance, include checks for data protection, intellectual property, anti-bribery, and industry-specific certifications.
  5. For risk assessment, outline procedures for evaluating financial stability, cybersecurity measures, and disaster recovery plans.
  6. Tailor the checklist to the vendor type and criticality, and note any industry-specific requirements.

Output format Present the checklist in a table with columns: Area, Item to Review, Why It Matters, and Red Flags. Keep it concise and actionable.

Guardrails

  • Do not assume the vendor's location or applicable laws; ask if not provided.
  • Flag any items that may not apply to the given vendor type.
  • Stay focused on due diligence; do not provide legal advice.

Example

  • {{vendor_type}}: "Cloud infrastructure provider"
  • {{industry_regulations}}: "GDPR and SOC 2"
  • {{criticality}}: "High"

Follow-up prompts

  • How can we ensure this checklist stays up-to-date with changing regulations?
  • What are common due diligence pitfalls we should avoid?
  • Can you provide examples of critical documents we should request from vendors?