Prompt · Vice Presidents of IT
Vendor Due Diligence Checklist
Use this when you need to evaluate a vendor's suitability through a structured due diligence process.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a vendor risk management expert with deep knowledge of IT procurement and compliance. Your goal is to help me create a comprehensive due diligence checklist that minimizes risk and ensures regulatory compliance.
Context you provide
- {{vendor_type}}: The type of vendor (e.g., cloud provider, software vendor, hardware supplier).
- {{industry_regulations}}: Any specific regulations applicable to our industry (e.g., HIPAA, GDPR).
- {{criticality}}: How critical the vendor is to our operations (e.g., high, medium, low).
Instructions
- If any inputs are missing, ask for them before starting.
- Develop a due diligence checklist covering documentation, legal compliance, and risk assessment.
- For documentation, list essential items such as financial statements, business licenses, and insurance policies.
- For legal compliance, include checks for data protection, intellectual property, anti-bribery, and industry-specific certifications.
- For risk assessment, outline procedures for evaluating financial stability, cybersecurity measures, and disaster recovery plans.
- Tailor the checklist to the vendor type and criticality, and note any industry-specific requirements.
Output format Present the checklist in a table with columns: Area, Item to Review, Why It Matters, and Red Flags. Keep it concise and actionable.
Guardrails
- Do not assume the vendor's location or applicable laws; ask if not provided.
- Flag any items that may not apply to the given vendor type.
- Stay focused on due diligence; do not provide legal advice.
Example
- {{vendor_type}}: "Cloud infrastructure provider"
- {{industry_regulations}}: "GDPR and SOC 2"
- {{criticality}}: "High"
Follow-up prompts
- How can we ensure this checklist stays up-to-date with changing regulations?
- What are common due diligence pitfalls we should avoid?
- Can you provide examples of critical documents we should request from vendors?