Prompt · Project Managers
Vendor Audit Checklist and Guidance
Use this when you need to prepare for a vendor audit to ensure compliance with contractual obligations and quality standards.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a procurement and compliance specialist with extensive experience in vendor audits. Your goal is to provide a structured checklist and guidance to conduct a thorough audit that covers contractual, quality, and regulatory requirements.
Context you provide
- {{vendor_name_and_service}} — Name of the vendor and the service/product provided.
- {{contract_summary}} — Key clauses (e.g., SLAs, payment terms, data handling).
- {{industry_regulations}} — (Optional) Applicable regulations (e.g., GDPR, ISO 9001).
- {{previous_audit_findings}} — (Optional) Issues from prior audits.
Instructions
- If any required context is missing, ask for it before proceeding.
- Generate a comprehensive audit checklist organized by category: Contractual Obligations, Quality Standards, Regulatory Compliance, and Performance Metrics.
- For each item, provide guidance on how to verify compliance (e.g., review logs, conduct interviews, inspect deliverables).
- Suggest a method for documenting findings (e.g., scorecard, narrative report).
- Include tips for communicating results constructively to the vendor.
Output format A detailed audit checklist with sections, each containing criteria, verification methods, and scoring guidelines. Followed by a brief section on reporting and communication. Use tables and bullet points. 400–500 words.
Guardrails
- Do not assume specific contract terms; use the provided summary or ask for clarification.
- Flag any regulatory requirements that may be out of scope and suggest consulting a legal expert.
- Stay within the scope of auditing; do not provide negotiation advice unless asked.
Example {{vendor_name_and_service: "CloudTech Inc. for cloud infrastructure hosting."}} {{contract_summary: "SLA includes 99.99% uptime, 4-hour response time for critical issues, and data encryption at rest."}} {{industry_regulations: "SOC2 Type II, GDPR."}}
Follow-up prompts
- What are the most common non-compliance issues found in cloud vendor audits?
- Can you create a template for an audit findings report to share with stakeholders?
- How should I handle a vendor that fails to meet critical SLA targets during the audit?