# Vendor Onboarding Due Diligence Workflow

Design a risk-based vendor onboarding automation covering intake, due diligence, approvals, remediation, setup, and ongoing ownership.

## Prompt

You are a third-party risk automation architect who specializes in vendor onboarding, due diligence, and controlled activation.

Inputs:
1. Vendor types, services, and business intake process: {{vendor_context}}
2. Data access, system access, spend, geography, and operational criticality: {{risk_profile}}
3. Security, privacy, legal, finance, procurement, and compliance checks: {{review_requirements}}
4. Systems, reviewers, approval authority, and setup actions: {{workflow_environment}}
5. Evidence validity, exceptions, service levels, and audit constraints: {{constraints}}

Do the following:
1. Create an intake and inherent-risk classification using observable factors, then map each risk tier to required evidence and reviewers.
2. Design evidence requests, secure collection, validity checks, expiration rules, duplicate reuse, reviewer decisions, clarifications, and remediation tracking.
3. Define conditional approvals, segregation of duties, exception authority, expiry, compensating controls, and conditions that block purchase order, account, payment, or integration activation.
4. Sequence vendor-master creation, contract completion, tax and bank verification, least-privilege access, owner assignment, and monitoring enrollment only after prerequisites are met.
5. Produce the risk questionnaire, routing matrix, workflow states, evidence register, exception log, vendor-facing messages, service targets, and test scenarios. Do not treat a completed questionnaire as proof that a control exists.

## Best for

Procurement and risk teams automating vendor setup without applying identical reviews to every supplier or activating high-risk vendors prematurely.

## Compatible tools

- Claude
- ChatGPT

## How to use

- Define risk factors with measurable values.
- List systems that must remain blocked until approval.
- Set evidence validity and exception expiry.
- Assign one accountable business owner per vendor.

## Customization tips

- Reuse valid evidence without bypassing applicability checks.
- Verify bank changes outside email.
- Separate inherent risk from residual risk.
- Enroll approved vendors into ongoing review automatically.

## Example input

Context: European SaaS company onboarding software, contractors, consultants, and facilities suppliers. Risk factors: personal data, production access, annual spend, critical operations, subprocessors, and non-EU transfers. Reviews: procurement, finance, privacy, security, legal, and business owner. Systems: intake form, GRC platform, contract repository, ERP, and identity provider. Constraints: bank changes require out-of-band verification; evidence expires after 12 months; emergency exceptions last at most 30 days.

## Example output

The workflow gives low-risk facilities suppliers a light review while production-access and personal-data vendors receive security, privacy, and legal paths. Evidence is checked for issuer, scope, date, and applicability rather than presence alone. ERP activation waits for approved contract and verified banking, and identity access waits for named ownership and least-privilege scope. Temporary exceptions include owner, control, expiry, and automatic re-escalation.
