Safety, Privacy & Compliance

Vendor & Third-Party Risk Assessor

Reviews a described vendor or third-party tool for data, security, and dependency risk before you sign, returning a rated checklist with the real blockers.

Last updated Jul 11, 2026
FreeClaudeChatGPTCursor
TL;DR

Vendor & Third-Party Risk Assessor is a free AI skill for safety, privacy & compliance. Reviews a described vendor or third-party tool for data, security, and dependency risk before you sign, returning a rated checklist with the real blockers. It works with Claude, ChatGPT, Cursor and is ready to use out of the box.

Download Skill.md Package

About this skill

Vendor & Third-Party Risk Assessor takes a description of a vendor, tool, or third-party service being considered and runs it through a practical due-diligence pass: what data it would touch, how critical it would become to operations, what happens if it fails or shuts down, and what contractual protections are missing. It's built for teams without a dedicated procurement or security function who still need a real risk read before signing.

What it does

Given a description of a vendor or tool under consideration and what it would be used for, the skill assesses risk across five areas — data exposure, security posture (as far as it can be inferred or is known), operational dependency, exit/portability risk, and contractual gaps — rates each, and returns the specific questions to ask the vendor before signing, prioritized by what actually matters most for this use case.

What is included

  • Five-area vendor risk framework (data exposure, security posture, dependency, exit risk, contract gaps)
  • Severity-rated risk summary
  • Prioritized vendor questions to ask before signing
  • Exit/portability risk checklist
  • Lightweight vendor comparison template for evaluating alternatives

How to use it

1. Download the SKILL.md file
2. Upload it to Claude, ChatGPT, or Cursor as a project skill or custom instructions
3. Describe the vendor/tool and what it would be used for
4. Receive a rated risk summary and the specific questions to ask before signing

Examples

Example input
We're considering a third-party tool that would store and process our customer support tickets, including some customer PII, to auto-generate response suggestions.
Example output
Risk assessment:
- Data exposure: HIGH — customer PII flowing to a third party for processing is a meaningful exposure; confirm what data is retained, for how long, and whether it's used to train the vendor's models
- Operational dependency: MEDIUM — if this becomes core to support workflow, an outage or price change later has real leverage over you
- Exit/portability: VERIFY — ask whether ticket data and any custom configuration can be exported if you switch vendors later
- Contract gaps: VERIFY — confirm data processing terms, breach notification obligations, and subprocessor disclosure are in the contract, not just marketing claims
- Security posture: VERIFY — ask for their most recent SOC 2 or equivalent certification rather than taking security claims at face value

Top questions to ask before signing: 1) Is customer data used for model training? 2) What's the data export process if we leave? 3) Can we see a current SOC 2 report or equivalent?

FAQ

What is this skill for?
It reviews a vendor or third-party tool for data, security, and dependency risk, and returns rated findings plus questions to ask before signing.
How do I install it?
Upload the SKILL.md as a custom skill or instructions file in Claude, ChatGPT, or Cursor, then describe the vendor and its intended use.
Can it review the vendor's actual security certifications?
Not directly — it works from what you describe and flags what to ask the vendor to confirm (like a SOC 2 report), since it can't verify unstated facts about the vendor.
Is this a substitute for a legal review of the contract?
No — it flags likely contractual gaps to raise with the vendor or legal counsel, but doesn't replace a lawyer reviewing the actual contract language.
How is this different from a generic vendor evaluation checklist?
It's tailored to the specific data and dependency risk of the use case described, and prioritizes the questions that matter most for that scenario rather than a one-size-fits-all list.
Can it help me compare multiple vendor options?
Yes — describe each option and it will apply the same framework to each for a side-by-side comparison.

Related Skills

Safety, Privacy & ComplianceFree

AI Governance & Compliance Checklist

Reviews an AI-related workflow, tool, or output against a practical governance checklist covering data privacy, bias, accountability, and transparency.

ClaudeChatGPTCursor
#AI governance#compliance#responsible AI
Safety, Privacy & ComplianceFree

MCP Server Security Reviewer

Static, read-only security review for MCP servers and tool handlers — checks for prompt injection surfaces, secrets leakage, and unsafe tool permissions before deployment.

ClaudeClaude CodeCursor
#mcp#security review#prompt injection
Safety, Privacy & ComplianceFree

Consent Notice and User Disclosure Reviewer

Review consent notices and user disclosures for clarity, specificity, choice, timing, data use, withdrawal, accessibility, and dark-pattern risk.

ClaudeChatGPT
#consent notice#privacy disclosure#user transparency

Related Prompts

Free

Vendor Security & Compliance Risk Review

Systematically evaluate a third-party vendor or tool for security, data privacy, and compliance risk before integrating it into your business.

ClaudeChatGPT
#vendor risk#security review#compliance
Free

Purchase Order Request Builder

Turn a purchase need, quote, budget details, and approval rules into a complete purchase-order request and procurement review checklist.

ClaudeChatGPT
#purchase order#procurement#approval request
Free

Vendor Onboarding Due Diligence Workflow

Design a risk-based vendor onboarding automation covering intake, due diligence, approvals, remediation, setup, and ongoing ownership.

ClaudeChatGPT
#vendor-onboarding#third-party-risk#due-diligence

Related Articles

Article · Safety & Review

AI Privacy Checklist Before Launching an AI App

A practical, non-legal checklist covering data collection, uploads, logging, admin access, and disclosure before launching an AI app.

Jul 6, 20268 min read
Read AI Privacy Checklist Before Launching an AI App
Article · Safety Privacy and Compliance AI Skills

How to Use an AI Security Review Skill Before Launching a Vibe-Coded App

Use an AI security review skill to prepare a vibe-coded app for safer launch without sharing secrets or claiming compliance.

Jul 8, 20268 min read
Read How to Use an AI Security Review Skill Before Launching a Vibe-Coded App