Vendor Onboarding Due Diligence Workflow
Design a risk-based vendor onboarding automation covering intake, due diligence, approvals, remediation, setup, and ongoing ownership.
Procurement and risk teams automating vendor setup without applying identical reviews to every supplier or activating high-risk vendors prematurely.
You are a third-party risk automation architect who specializes in vendor onboarding, due diligence, and controlled activation.
Inputs:
1. Vendor types, services, and business intake process: {{vendor_context}}
2. Data access, system access, spend, geography, and operational criticality: {{risk_profile}}
3. Security, privacy, legal, finance, procurement, and compliance checks: {{review_requirements}}
4. Systems, reviewers, approval authority, and setup actions: {{workflow_environment}}
5. Evidence validity, exceptions, service levels, and audit constraints: {{constraints}}
Do the following:
1. Create an intake and inherent-risk classification using observable factors, then map each risk tier to required evidence and reviewers.
2. Design evidence requests, secure collection, validity checks, expiration rules, duplicate reuse, reviewer decisions, clarifications, and remediation tracking.
3. Define conditional approvals, segregation of duties, exception authority, expiry, compensating controls, and conditions that block purchase order, account, payment, or integration activation.
4. Sequence vendor-master creation, contract completion, tax and bank verification, least-privilege access, owner assignment, and monitoring enrollment only after prerequisites are met.
5. Produce the risk questionnaire, routing matrix, workflow states, evidence register, exception log, vendor-facing messages, service targets, and test scenarios. Do not treat a completed questionnaire as proof that a control exists.How to use
- Define risk factors with measurable values.
- List systems that must remain blocked until approval.
- Set evidence validity and exception expiry.
- Assign one accountable business owner per vendor.
Example input
Context: European SaaS company onboarding software, contractors, consultants, and facilities suppliers. Risk factors: personal data, production access, annual spend, critical operations, subprocessors, and non-EU transfers. Reviews: procurement, finance, privacy, security, legal, and business owner. Systems: intake form, GRC platform, contract repository, ERP, and identity provider. Constraints: bank changes require out-of-band verification; evidence expires after 12 months; emergency exceptions last at most 30 days.
Example output
The workflow gives low-risk facilities suppliers a light review while production-access and personal-data vendors receive security, privacy, and legal paths. Evidence is checked for issuer, scope, date, and applicability rather than presence alone. ERP activation waits for approved contract and verified banking, and identity access waits for named ownership and least-privilege scope. Temporary exceptions include owner, control, expiry, and automatic re-escalation.
Customization tips
- — Reuse valid evidence without bypassing applicability checks.
- — Verify bank changes outside email.
- — Separate inherent risk from residual risk.
- — Enroll approved vendors into ongoing review automatically.
Tags
FAQ
What is this prompt for?
How should I customize it?
Are there any limitations?
How is it different from a basic prompt?
Related Prompts
All Automation Workflows prompts →Inventory Reorder Automation Designer
Design a stock-replenishment workflow using demand, lead time, safety stock, supplier constraints, approvals, and exception handling.
Employee Onboarding Access Workflow
Design employee onboarding across HR, identity, equipment, accounts, training, approvals, and evidence without granting unsafe automatic access.
Automation Failure Monitoring & Recovery
Create an observability and incident-recovery design for business automations, including logs, alerts, retry policy, ownership, replay, and post-incident review.
Related Skills
Vendor Due Diligence Process Designer
Design vendor due-diligence workflows covering business fit, security, privacy, finance, contracts, risk, approval, and ongoing review.
Vendor & Third-Party Risk Assessor
Reviews a described vendor or third-party tool for data, security, and dependency risk before you sign, returning a rated checklist with the real blockers.
Content Review and Publication Automation Designer
Design content-review automations with intake, ownership, editorial checks, approvals, scheduling, versioning, publishing, and rollback.