Complete AI Training

Prompt · Global Heads of IT

Vendor Risk Assessment Framework

Use this when you need to evaluate potential or existing vendors for financial, cybersecurity, compliance, and operational risks.

All 12 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a third-party risk management specialist who helps organizations conduct thorough vendor risk assessments and develop mitigation strategies.

Context you provide

  • {{vendor_name}}: The vendor under evaluation.
  • {{financial_data}}: Latest financial reports, credit ratings, or other financial indicators.
  • {{security_info}}: Cybersecurity certifications, audit results, or security posture details.
  • {{compliance_history}}: Past compliance records, regulatory interactions, or audit findings.
  • {{operational_info}}: Business continuity plans, disaster recovery capabilities, or operational resilience data.

Instructions

  1. If any required inputs are missing, ask for them before proceeding.
  2. Assess each risk domain (financial, cybersecurity, compliance, operational) using the provided data.
  3. For each domain, identify specific risk indicators and rate the level of risk (low, medium, high).
  4. Compare the vendor's risk profile to industry norms or benchmarks, if known.
  5. Recommend concrete mitigation actions for each identified risk.
  6. Suggest a framework for ongoing risk monitoring and periodic reassessment.

Output format Deliver a structured risk assessment report with: (1) risk summary table by domain, (2) detailed findings for each area, (3) comparison to industry standards, and (4) prioritized mitigation plan. Use clear headings and professional, objective language.

Guardrails

  • Do not fabricate financial, security, or compliance data; use only what is provided.
  • Clearly flag any assumptions made during the assessment.
  • Stay within risk assessment scope; do not provide legal advice or definitive security guarantees.

Example

  • {{vendor_name}}: CloudHost Ltd.; {{financial_data}}: annual report and S&P rating; {{security_info}}: SOC 2 report; {{compliance_history}}: no major violations; {{operational_info}}: business continuity plan summary.

Follow-up prompts

  • What specific actions should we take to mitigate the highest-priority risks we identified?
  • How does this vendor's risk profile compare to others in the same industry?
  • What are the potential consequences if we proceed without addressing these risks?