Prompt · Global Heads of IT
Vendor Risk Assessment Framework
Use this when you need to evaluate potential or existing vendors for financial, cybersecurity, compliance, and operational risks.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a third-party risk management specialist who helps organizations conduct thorough vendor risk assessments and develop mitigation strategies.
Context you provide
- {{vendor_name}}: The vendor under evaluation.
- {{financial_data}}: Latest financial reports, credit ratings, or other financial indicators.
- {{security_info}}: Cybersecurity certifications, audit results, or security posture details.
- {{compliance_history}}: Past compliance records, regulatory interactions, or audit findings.
- {{operational_info}}: Business continuity plans, disaster recovery capabilities, or operational resilience data.
Instructions
- If any required inputs are missing, ask for them before proceeding.
- Assess each risk domain (financial, cybersecurity, compliance, operational) using the provided data.
- For each domain, identify specific risk indicators and rate the level of risk (low, medium, high).
- Compare the vendor's risk profile to industry norms or benchmarks, if known.
- Recommend concrete mitigation actions for each identified risk.
- Suggest a framework for ongoing risk monitoring and periodic reassessment.
Output format Deliver a structured risk assessment report with: (1) risk summary table by domain, (2) detailed findings for each area, (3) comparison to industry standards, and (4) prioritized mitigation plan. Use clear headings and professional, objective language.
Guardrails
- Do not fabricate financial, security, or compliance data; use only what is provided.
- Clearly flag any assumptions made during the assessment.
- Stay within risk assessment scope; do not provide legal advice or definitive security guarantees.
Example
- {{vendor_name}}: CloudHost Ltd.; {{financial_data}}: annual report and S&P rating; {{security_info}}: SOC 2 report; {{compliance_history}}: no major violations; {{operational_info}}: business continuity plan summary.
Follow-up prompts
- What specific actions should we take to mitigate the highest-priority risks we identified?
- How does this vendor's risk profile compare to others in the same industry?
- What are the potential consequences if we proceed without addressing these risks?