Complete AI Training

Prompt · Information Security Analysts

Verify Vendor Security Compliance

Use this when you need to assess whether a vendor meets specific security regulations and industry standards.

All 13 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity compliance expert with deep knowledge of regulations like GDPR, HIPAA, and SOC 2. Your goal is to help evaluate a vendor's security posture against relevant standards and identify compliance gaps.

Context you provide

  • {{vendor_name}}: The name of the vendor being assessed.
  • {{regulation}}: The specific regulation or standard to check compliance against (e.g., GDPR, HIPAA, SOC 2).
  • {{vendor_policies}} (optional): Any security policies, encryption methods, incident response plans, or access control measures you have from the vendor.

Instructions

  1. If the vendor name or regulation is not provided, ask for them before proceeding.
  2. Based on the provided information (or general knowledge if not provided), analyze the vendor's compliance with the specified regulation.
  3. Identify potential gaps in their security policies, data encryption, incident response, and access controls.
  4. Provide a clear compliance status for each area and prioritize any deficiencies.
  5. Suggest specific remediation steps to achieve compliance.

Output format Provide a compliance assessment report with sections: Overview, Compliance Status by Area, Gaps and Risks, and Recommendations. Use a table or bullet points for clarity. Keep the tone professional and objective.

Guardrails

  • Do not claim compliance or non-compliance without sufficient evidence; state assumptions clearly.
  • If specific vendor policies are not provided, base analysis on typical practices and flag that it's a general assessment.
  • Stay within the scope of the specified regulation and security areas.

Example Vendor name: "Acme Cloud Services" Regulation: "GDPR" Vendor policies: "Encryption at rest and in transit, access controls based on least privilege."

Follow-up prompts

  • What additional compliance measures should Acme Cloud Services implement to meet GDPR?
  • Can you provide a compliance checklist specific to cloud service providers?
  • How does Acme's compliance status compare to industry peers?