Vendor & Third-Party Risk Assessor
Reviews a described vendor or third-party tool for data, security, and dependency risk before you sign, returning a rated checklist with the real blockers.
Vendor & Third-Party Risk Assessor is a free AI skill for safety, privacy & compliance. Reviews a described vendor or third-party tool for data, security, and dependency risk before you sign, returning a rated checklist with the real blockers. It works with Claude, ChatGPT, Cursor and is ready to use out of the box.
About this skill
Vendor & Third-Party Risk Assessor takes a description of a vendor, tool, or third-party service being considered and runs it through a practical due-diligence pass: what data it would touch, how critical it would become to operations, what happens if it fails or shuts down, and what contractual protections are missing. It's built for teams without a dedicated procurement or security function who still need a real risk read before signing.
What it does
Given a description of a vendor or tool under consideration and what it would be used for, the skill assesses risk across five areas — data exposure, security posture (as far as it can be inferred or is known), operational dependency, exit/portability risk, and contractual gaps — rates each, and returns the specific questions to ask the vendor before signing, prioritized by what actually matters most for this use case.
What is included
- Five-area vendor risk framework (data exposure, security posture, dependency, exit risk, contract gaps)
- Severity-rated risk summary
- Prioritized vendor questions to ask before signing
- Exit/portability risk checklist
- Lightweight vendor comparison template for evaluating alternatives
How to use it
1. Download the SKILL.md file 2. Upload it to Claude, ChatGPT, or Cursor as a project skill or custom instructions 3. Describe the vendor/tool and what it would be used for 4. Receive a rated risk summary and the specific questions to ask before signing
Examples
We're considering a third-party tool that would store and process our customer support tickets, including some customer PII, to auto-generate response suggestions.
Risk assessment: - Data exposure: HIGH — customer PII flowing to a third party for processing is a meaningful exposure; confirm what data is retained, for how long, and whether it's used to train the vendor's models - Operational dependency: MEDIUM — if this becomes core to support workflow, an outage or price change later has real leverage over you - Exit/portability: VERIFY — ask whether ticket data and any custom configuration can be exported if you switch vendors later - Contract gaps: VERIFY — confirm data processing terms, breach notification obligations, and subprocessor disclosure are in the contract, not just marketing claims - Security posture: VERIFY — ask for their most recent SOC 2 or equivalent certification rather than taking security claims at face value Top questions to ask before signing: 1) Is customer data used for model training? 2) What's the data export process if we leave? 3) Can we see a current SOC 2 report or equivalent?
FAQ
What is this skill for?
How do I install it?
Can it review the vendor's actual security certifications?
Is this a substitute for a legal review of the contract?
How is this different from a generic vendor evaluation checklist?
Can it help me compare multiple vendor options?
Related Skills
AI Governance & Compliance Checklist
Reviews an AI-related workflow, tool, or output against a practical governance checklist covering data privacy, bias, accountability, and transparency.
MCP Server Security Reviewer
Static, read-only security review for MCP servers and tool handlers — checks for prompt injection surfaces, secrets leakage, and unsafe tool permissions before deployment.
Consent Notice and User Disclosure Reviewer
Review consent notices and user disclosures for clarity, specificity, choice, timing, data use, withdrawal, accessibility, and dark-pattern risk.
Related Prompts
Vendor Security & Compliance Risk Review
Systematically evaluate a third-party vendor or tool for security, data privacy, and compliance risk before integrating it into your business.
Purchase Order Request Builder
Turn a purchase need, quote, budget details, and approval rules into a complete purchase-order request and procurement review checklist.
Vendor Onboarding Due Diligence Workflow
Design a risk-based vendor onboarding automation covering intake, due diligence, approvals, remediation, setup, and ongoing ownership.
Related Articles
AI Privacy Checklist Before Launching an AI App
A practical, non-legal checklist covering data collection, uploads, logging, admin access, and disclosure before launching an AI app.
How to Use an AI Security Review Skill Before Launching a Vibe-Coded App
Use an AI security review skill to prepare a vibe-coded app for safer launch without sharing secrets or claiming compliance.