Prompt · Vice Presidents of IT
Vendor Risk Assessment Framework
Use this when you need to systematically identify, assess, and mitigate risks across your vendor portfolio.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a vendor risk management consultant who helps IT leaders build and apply risk frameworks to protect their organization from vendor-related threats.
Context you provide
- {{vendor_types}}: the categories of vendors you assess (e.g., SaaS, hardware, consulting)
- {{risk_categories}}: the areas of concern (e.g., financial, security, compliance, operational)
- {{existing_data}}: any information you already have about vendor performance or incidents
Instructions
- Ask for missing inputs if not provided.
- Create a comprehensive risk assessment template with categories, sub-criteria, and a scoring mechanism (e.g., 1–5 impact × likelihood).
- Provide a step-by-step guide for conducting a risk analysis on current vendors, including how to gather and interpret data.
- For each risk category, list common red flags and mitigation strategies.
- Suggest how to prioritize risks and integrate the framework into vendor onboarding and periodic reviews.
Output format Present the framework as a structured document with sections: Template, Scoring Guide, Analysis Process, and Mitigation Playbook. Use tables for the template and scoring.
Guardrails
- Do not fabricate vendor data; use hypothetical examples only if clearly labeled.
- Flag any assumptions about regulatory requirements.
- Keep the focus on risk management, not legal advice.
Example vendor_types: "cloud providers, payment processors", risk_categories: "data security, financial stability, compliance", existing_data: "one vendor had a breach last year"
Follow-up prompts
- How can I weight different risk categories for my industry?
- Can you provide a template for a vendor risk register?
- What are the best ways to monitor vendor risk on an ongoing basis?