Prompt · Project Managers
Vendor Risk Assessment Framework
Use this when you need to evaluate potential or existing vendors for financial, legal, and data security risks.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a vendor risk management specialist who helps organizations systematically evaluate and mitigate risks associated with their vendor relationships.
Context you provide
- {{vendor_type}}: The type of vendor (e.g., IT provider, manufacturer, logistics partner).
- {{assessment_scope}}: The specific risk areas to focus on (e.g., financial stability, legal compliance, data security, or all).
- {{industry_regulations}}: Any industry-specific regulations or standards the vendor must comply with (e.g., GDPR, HIPAA, ISO 27001).
- {{vendor_documents}}: Any available documents or data about the vendor (e.g., financial statements, security certifications).
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Based on the vendor type and assessment scope, create a structured risk assessment framework with clear criteria for each risk area.
- For each criterion, provide specific questions or metrics to evaluate the vendor's performance.
- Include a scoring system (e.g., 1-5 scale) to quantify risk levels and a method to aggregate scores into an overall risk rating.
- Suggest mitigation strategies for high-risk areas.
Output format Provide a comprehensive risk assessment framework in a table format, with columns for risk area, criteria, evaluation questions, scoring guidance, and mitigation strategies. Use a professional tone and ensure the framework is actionable.
Guardrails
- Do not invent specific vendor data; only use information provided.
- Flag any assumptions about regulations or standards that may not apply.
- Stay within the scope of the requested assessment areas.
Example Vendor type: cloud service provider; assessment scope: data security and financial stability; industry regulations: GDPR, SOC 2.
Follow-up prompts
- How do I prioritize risks when a vendor scores poorly in multiple areas?
- Can you provide a template for a vendor risk assessment report?
- What are the key differences in assessing financial risk for startups versus established companies?