PromptBase
Upgrade
Close icon
General
Home
Marketplace
Create
Hire
Login
Chat
Sell
Explore

Prompt Details

Model
(claude-5-sonnet)
Token size
5,085
Example input
[VENDOR_DOCS]: - SOC 2 Type II report, period Jan 1 2026 – Jun 30 2026, covers Security, Availability, Confidentiality trust criteria. Issued by an independent CPA firm. No exceptions noted. - ISO 27001 certificate, issued 2025-09-10, valid until 2028-09-10, scope: "Cloud HR SaaS platform, primary data center operations." - Penetration test executive summary, dated 2026-05-15, performed by a third-party firm, scope: external web app + API. 2 medium findings, both marked remediated with retest confirmation dated 2026-06-01. - Cyber liability insurance certificate, $5M coverage, effective through 2026-12-31. - Security questionnaire: states data encrypted at rest (AES-256) and in transit (TLS 1.2+), MFA enforced for all admin access, employee background checks performed pre-hire, incident response plan exists with a stated 24-hour notification SLA for confirmed breaches. - Data Processing Agreement (DPA) draft provided, includes standard contractual clauses for EU data transfer. - References: 2 existing customers listed, not yet contacted. [VENDOR_SCOPE]: Vendor will host our employee HR data (names, salaries, bank details for payroll, national ID numbers) on their cloud platform. Full read/write API integration with our internal payroll system. Data includes EU national employees. [REGULATORY_CONTEXT]: GDPR (EU employee personal data). Local labor law data retention rules (not yet specified by legal team). [EXISTING_RELATIONSHIP]: New vendor.
Example output
═══════════════════════════════════════════════════════════ THIRD-PARTY RISK ONBOARDING ASSESSMENT — Cloud HR Platform (Vendor) Relationship Scope: Hosts employee HR data (names, salaries, bank details, national ID numbers) on vendor's cloud platform; full R/W API integration with internal payroll system; includes EU nationals' data. Regulatory Context: GDPR (confirmed applicable — EU employee personal data). Local labor law retention rules — named but not yet specified. ═══════════════════════════════════════════════════════════ 1. EXECUTIVE RISK SUMMARY Domains assessed: Data Security & Access Controls · Incident Response & Breach Notification · Business Continuity & Disaster Recovery · Subcontractor/Fourth-Party Risk · Contractual & SLA Terms · Financial Stability · Data Residency & Cross-Border Transfer · Regulatory- Specific Controls (GDPR) · Encryption Standards · Employee Background Screening & Insider Risk · API/Integration Security Domains not applicable: - Physical Security — VENDOR_SCOPE describes no physical facility or hardware access; relationship is entirely cloud/API-based. - Change Management on Vendor's Side — no evidence this vendor's internal change process has a continuity dependency for us beyond what's already captured under Business Continuity; not treated as a distinct domain here. Finding counts by Current Operating Status: CONFIRMED-CURRENT: 6 LIKELY-CURRENT: 3 STALE: 0 UNKNOWN: 3 CONTRADICTED: 0 Onboarding Blockers: 0 Most significant exposures: - Full R/W payroll API integration + national ID + bank detail access is a high blast-radius combination; no finding here is a blocker, but severity floor on this domain is HIGH by default given data sensitivity, not the vendor's documentation quality. - Local labor law retention rules are unconfirmed on both sides (REGULATORY_CONTEXT admits this) — this is a REQUIRES VALIDATION item, not a gap attributable to the vendor. - References exist but are unconfirmed (not yet contacted) — Attestation Type NOT PROVIDED for the reference-check domain until contact is made. Major evidence limitations: - Subcontractor disclosure is entirely absent despite this being a cloud SaaS platform, where infrastructure subcontracting (e.g. a hosting provider) is structurally likely. This is the single most consequential gap in this evidence set — see Section 5. - Incident response plan is described (24-hour SLA claim) but only via questionnaire — Attestation Type SELF-REPORTED, not independently verified anywhere in VENDOR_DOCS. RECOMMENDED ONBOARDING POSITION: ONBOARD WITH CONDITIONS Rationale: No ONBOARDING BLOCKER identified in any applicable domain. SOC 2 Type II (OPERATING-PERIOD, CONFIRMED-CURRENT) and ISO 27001 (POINT-IN-TIME but within currency window) cover the core security domains credibly. Condition is driven by the undisclosed subcontractor gap (Section 5) and the self-reported-only incident response claim — both are HIGH severity given data sensitivity, not blockers, but should be closed before full-scope go-live. 2. EVIDENCE & ATTESTATION MAP | Source Tag | Document | Attestation Type | Coverage Period | Currency Check | Domain(s) Covered | |---|---|---|---|---|---| | {SOC2-TYPE2} | SOC 2 Type II Report | OPERATING-PERIOD | 2026-01-01 to 2026-06-30 | Current (period ends ~6 weeks ago) | Data Security, Access Controls, Availability, Confidentiality | | {ISO-CERT} | ISO 27001 Certificate | POINT-IN-TIME | Issued 2025-09-10, valid to 2028-09-10 | Within validity window, ~11 months old | Data Security (ISMS scope) | | {PENTEST} | Pentest Executive Summary | POINT-IN-TIME | Test 2026-05-15, retest 2026-06-01 | Current (~2 months old) | API/Integration Security, Data Security | | {INSURANCE} | Cyber Liability Certificate | POINT-IN-TIME | Effective through 2026-12-31 | Current | Financial Stability (risk transfer) | | {QUESTIONNAIRE} | Security Questionnaire | SELF-REPORTED | Not dated in input | UNKNOWN — no date supplied | Encryption, Access Controls (MFA), Background Screening, Incident Response | | {DPA} | DPA Draft (SCCs) | SELF-REPORTED (draft, unsigned) | N/A — draft | N/A | Data Residency & Cross-Border Transfer, GDPR | | {REFERENCE} | 2 customer references | NOT PROVIDED (listed, not contacted) | N/A | N/A | General reliability — unconfirmed | 3. RISK DOMAIN FINDINGS | ID | Domain | Claim | Source | Attestation Type | Current Operating Status | Severity | Gap/Exposure | Remediation | Target Timing | |---|---|---|---|---|---|---|---|---|---| | F1 | Data Security & Access Controls | AES-256 at rest, TLS 1.2+ in transit, MFA enforced | {QUESTIONNAIRE}, corroborated by {SOC2-TYPE2} scope | SELF-REPORTED (encryption specifics) / OPERATING-PERIOD (general security criteria via SOC 2) | CONFIRMED-CURRENT (SOC 2 scope) / UNKNOWN (specific encryption claim not independently itemized in SOC 2 excerpt provided) | MEDIUM | SOC 2 report as summarized doesn't itemize the specific encryption algorithm claims — those remain vendor-stated | Request the encryption-control detail section of the SOC 2 report itself, not just the questionnaire restatement | Before full-scope access | | F2 | Incident Response & Breach Notification | 24-hour notification SLA, IR plan exists | {QUESTIONNAIRE} | SELF-REPORTED | UNKNOWN | HIGH | No IR plan document, runbook, or third-party attestation provided — only a questionnaire claim | Request the actual IR plan/runbook document and, if available, evidence of a past tabletop exercise or real incident response | Before onboarding | | F3 | Business Continuity & Disaster Recovery | Not addressed in VENDOR_DOCS | — | NOT PROVIDED | UNKNOWN | HIGH | No BCDR plan, RTO/RPO commitments, or backup architecture disclosed at all | Request BCDR plan with stated RTO/RPO; structurally required given payroll-system dependency | Before onboarding | | F4 | Subcontractor / Fourth-Party Risk | No subcontractor disclosed | — | NOT PROVIDED | UNKNOWN | HIGH | See Section 5 — undisclosed subcontractor risk on a cloud SaaS platform | Request explicit subcontractor list + confirmation of whether SOC 2 scope includes them | Before onboarding | | F5 | Contractual & SLA Terms | DPA draft with SCCs provided | {DPA} | SELF-REPORTED (draft, unsigned) | UNKNOWN | MEDIUM | DPA is a draft, not executed; SCCs present but unsigned | Execute final DPA before data transfer begins | Before onboarding | | F6 | Financial Stability | $5M cyber liability coverage | {INSURANCE} | POINT-IN-TIME | CONFIRMED-CURRENT | LOW | Coverage confirms risk transfer capacity; no broader financial health data (revenue, solvency) provided | Request basic financial stability indicator if relationship value is high | Next reassessment cycle | | F7 | Data Residency & Cross-Border Transfer | SCCs included in DPA draft for EU transfer | {DPA} | SELF-REPORTED (draft) | UNKNOWN | HIGH | Applies because VENDOR_SCOPE explicitly includes EU national employee data; SCCs draft-only, not executed; no stated data center region | Confirm data center region(s) and execute DPA with SCCs before EU data flows | Before onboarding | | F8 | Regulatory-Specific Controls (GDPR) | Implied coverage via SOC 2 Confidentiality criteria + DPA | {SOC2-TYPE2}, {DPA} | OPERATING-PERIOD (SOC2) / SELF-REPORTED (DPA) | LIKELY-CURRENT | HIGH | SOC 2 Confidentiality criteria is not the same as a GDPR Article 28 processor assessment; gap between "security control" and "GDPR compliance" evidence | Request confirmation of GDPR Article 28 sub-processor obligations, DPIA if applicable | Before onboarding | | F9 | Encryption Standards | AES-256 at rest, TLS 1.2+ in transit | {QUESTIONNAIRE} | SELF-REPORTED | UNKNOWN | MEDIUM | Same gap as F1 — no independent corroboration of the specific algorithm/version claims | Request technical architecture doc or SOC 2 control detail confirming encryption specifics | Within 90 days | | F10 | Employee Background Screening & Insider Risk | Pre-hire background checks performed | {QUESTIONNAIRE} | SELF-REPORTED | LIKELY-CURRENT | LOW | Self-reported only; SOC 2 Type II may cover this under access-control testing but not confirmed in the excerpt given | Confirm whether SOC 2 testing scope included personnel screening controls | Next reassessment cycle | | F11 | API/Integration Security | Pentest covered external web app + API, 2 medium findings remediated + retested | {PENTEST} | POINT-IN-TIME | CONFIRMED-CURRENT | LOW | Findings were remediated and retested within the same evidence set — no open exposure identified | None required; re-test at next annual pentest cycle | Next reassessment cycle | 4. ONBOARDING BLOCKER REGISTER None. No finding in this assessment meets ONBOARDING BLOCKER severity. The BCDR and IR plan gaps (F2, F3) and the subcontractor gap (F4) are HIGH, not blockers, because the underlying control category (SOC 2 Type II, ISO 27001) provides a credible general security baseline — but they should be tracked as conditions, not silently accepted. 5. FOURTH-PARTY / SUBCONTRACTOR EXPOSURE REGISTER | Subcontractor (disclosed or inferred) | Function | Attestation Coverage | Gap | Recommendation | |---|---|---|---|---| | Unnamed cloud infrastructure provider (inferred) | Underlying hosting for the "cloud HR SaaS platform" | None — not disclosed anywhere in VENDOR_DOCS | OWNERSHIP GAP — REQUIRES VALIDATION. A SaaS platform of this type almost always runs on a hyperscaler (AWS/Azure/GCP) or similar; VENDOR_DOCS is silent, and it is not stated whether the vendor's own SOC 2 Type II scope extends to cover this infrastructure layer or excludes it (common exclusion pattern: "complementary user entity controls") | RECOMMENDATION (not a finding of fact): request explicit disclosure of infrastructure subcontractors and written confirmation of whether SOC 2 Type II scope includes or excludes them | 6. CONDITIONAL ACCEPTANCE & RISK ACCEPTANCE REGISTER | Item | Residual Risk | Impact | Temporary Control | Risk Owner | Formal Approval Required? | Review/Expiry Point | |---|---|---|---|---|---|---| | Subcontractor disclosure gap (F4) | Data could pass through an unvetted infrastructure layer | HIGH (payroll + national ID data) | Limit initial go-live to non-production/test data only until disclosure received | Named risk owner not specified in input — REQUIRES VALIDATION | Yes | Before full-scope production access | | IR plan self-reported only (F2) | No verified breach response capability | HIGH | Contractual breach-notification clause with penalty terms in final DPA as interim control | Named risk owner not specified in input — REQUIRES VALIDATION | Yes | Within 90 days of onboarding | | DPA still in draft (F5, F7) | No enforceable data protection terms yet | HIGH (GDPR exposure) | No data transfer of live employee records until DPA executed | Named risk owner not specified in input — REQUIRES VALIDATION | Yes | Before onboarding | 7. VALIDATION REQUEST PLAN | Priority | Evidence Needed | Reason | Requested From | Acceptance Criteria | |---|---|---|---|---| | 1 | Subcontractor/infrastructure disclosure + SOC 2 scope confirmation | Could change onboarding position from CONDITIONS to BLOCKER if a subcontractor is uncontrolled | Vendor | Named subcontractor(s), written statement on SOC 2 scope inclusion | | 2 | BCDR plan with RTO/RPO | Payroll dependency makes continuity failure a direct business impact | Vendor | Documented plan with stated recovery targets | | 3 | IR plan/runbook document | Currently self-reported only on a HIGH-severity domain | Vendor | Actual plan document, ideally with evidence of a test/exercise | | 4 | Executed DPA (not draft) | Required before any live EU personal data transfer under GDPR | Vendor + internal legal | Signed DPA with SCCs in force | | 5 | Local labor law retention requirement | REGULATORY_CONTEXT admits this is unspecified | Internal legal team | Documented retention period to build into contract terms | | 6 | Reference contact | Currently listed but unconfirmed | Internal (initiate contact) | At least 1 reference call completed and documented | NOT INFERRED — deliberately excluded, no supporting evidence in any input: - Whether the vendor has ever had a prior security incident or breach (no incident history disclosure was provided). - The vendor's specific cloud hosting region(s) or data center locations. - Any financial statement, revenue figure, or solvency indicator beyond the existence of cyber liability insurance. - Whether SOC 2 Type II testing scope included personnel background screening controls specifically. - Named accountable risk owner on our side for any conditional acceptance item (input did not supply one). ═══════════════════════════════════════════════════════════
🌀 Claude

Vendor Trust Gate

Add to Cart
Instant accessInstant access
Usage rightsCommercial use
Money-back guaranteeMoney‑back
By purchasing this prompt, you agree to our terms of service
CLAUDE-5-SONNET
Tested icon
Guide icon
4 examples icon
Free credits icon
ssess new or renewing vendors before they receive system access, sensitive data, or contractual approval. This prompt converts questionnaires, SOC 2 reports, ISO certificates, penetration tests, DPAs, incident disclosures, and scope details into a structured onboarding decision with evidence gaps, risk severity, blockers, fourth-party exposure, remediation requirements, and validation requests.
...more
Added 4 days ago
Report
Browse Marketplace