PromptBase
Upgrade
Close icon
General
Home
Marketplace
Create
Hire
Login
Chat
Sell
Explore

Skill Details

Runtime
(gpt-5.6)
Example user message
[userMessage]: Create a supplier due diligence pack for a new IT support provider. They will have remote access to internal systems and may see employee data. Include questionnaire, evidence list, approval summary, onboarding notes, and review schedule.
Example agent response
# Supplier Due Diligence Pack: IT Support Provider ## Supplier Context Summary Supplier type: IT support provider. Service: remote IT support for internal systems. Data/system access: remote access to internal systems and possible employee data exposure. Risk level: likely high, subject to procurement, data protection, and information security review. Key review areas: information security, data protection, confidentiality, access control, incident reporting, business continuity, insurance, financial viability, subcontractors, and contract terms. Missing details to confirm: supplier name, contract value, service scope, countries of operation, access method, data categories, contract term, and approval route. ## Supplier Risk Profile Operational criticality: High to confirm. IT support may affect service continuity. Data protection risk: High to confirm. Supplier may access employee data. Information security risk: High. Remote access to internal systems requires security review. Financial exposure: To confirm based on contract value and dependency. Business continuity risk: Medium/High to confirm depending on support criticality. Legal and contractual risk: High to confirm due to data, access, confidentiality, and service obligations. Overall proposed risk rating: High for review, not final approval. ## Due Diligence Questionnaire Company information: - What is your registered legal name and company registration number? - Where are your main operating locations? - Who will be the account manager and service contact? Service scope: - What services will you provide? - What systems will you need to access? - Will support be remote, onsite, or both? - What support hours and escalation routes are proposed? Information security: - What access controls do you use for remote support? - Do you support MFA for all remote access? - How do you manage privileged access? - How do you log and monitor support activity? - How are support sessions approved and recorded? - What security certifications or independent assurance can you provide? Data protection and confidentiality: - What personal data may your staff access? - Where will data be accessed from or processed? - Do you use sub-processors or subcontractors? - What is your incident notification process? - How do you train staff on confidentiality and data handling? - How do you delete or return data at contract end? Business continuity: - Do you have a business continuity plan? - How do you maintain service if key staff are unavailable? - What recovery arrangements support your service? Insurance: - What professional indemnity, cyber, and public liability insurance do you hold? - Can you provide current certificates? Compliance and ethics: - Do you have anti-bribery and corruption controls? - Do you screen staff or subcontractors where appropriate? - Do you have a modern slavery or responsible sourcing statement, if applicable? Declarations: - Are there any conflicts of interest? - Can you confirm that all responses are accurate and supported by evidence? ## Evidence Request List - Company registration details. - Insurance certificates, including cyber insurance if applicable. - Information security policy summary. - Access control policy summary. - Remote support procedure. - Incident response procedure. - Security certification or assurance evidence, if available. - Data protection addendum or privacy documentation. - Sub-processor or subcontractor list, if applicable. - Business continuity plan summary. - Disaster recovery summary, where relevant. - Anti-bribery policy or supplier declaration. - Staff confidentiality training summary. - Reference or case study, where appropriate. Do not request passwords, API keys, MFA codes, private keys, or sensitive security secrets. ## Risk Check Summary Risk area: information security. Check planned: security questionnaire and information security review. Evidence requested: access control policy, remote support procedure, incident response process, assurance evidence. Preliminary rating: High. Gap: security controls not yet evidenced. Owner: information security lead to confirm. Next action: complete security review before onboarding. Risk area: data protection. Check planned: data processing and privacy review. Evidence requested: data protection addendum, data handling process, incident notification process, sub-processor list. Preliminary rating: High. Gap: data categories and processing location to confirm. Owner: data protection/privacy lead to confirm. Next action: complete privacy review before contract finalization. Risk area: operational continuity. Check planned: service resilience review. Evidence requested: business continuity summary and support escalation process. Preliminary rating: Medium/High. Gap: continuity arrangements not yet confirmed. Owner: service owner to confirm. Next action: review business continuity evidence. ## Financial and Operational Review Notes - Contract value to confirm. - Finance/procurement should consider supplier financial viability if the supplier is critical or high spend. - Service owner should confirm support hours, escalation route, SLAs, reporting cadence, and exit requirements. - Operational dependency should be assessed before onboarding. ## Legal, Compliance, and Procurement Review Notes - Contract review required before onboarding. - Procurement route to confirm. - Conflict of interest declaration required. - Insurance requirements to confirm. - Subcontractor approval process to confirm. - Supplier code of conduct acknowledgement to confirm. - Anti-bribery and sanctions screening route to verify through official process. ## Data Protection, Confidentiality, and Information Security Review Notes - Supplier may access employee data, so data protection review is required. - Remote access to internal systems requires information security review. - Confirm least-privilege access, MFA, access logging, session approval, and offboarding process. - Confirm incident notification process and contract wording. - Confirm data retention, deletion, and return arrangements. - Confirm sub-processors and data locations. ## Health, Safety, Ethics, and Responsible Sourcing Review Notes - Health and safety review may be low unless onsite work occurs. - Responsible sourcing and modern slavery checks may be required depending on policy and jurisdiction. - Ethics and anti-bribery declaration should be completed. - Safeguarding review is only relevant if the supplier has access to children, vulnerable people, or regulated environments. ## Supplier Approval Summary Supplier: IT support provider, name to confirm. Service: remote support for internal systems. Proposed risk rating: High for review. Evidence received: to confirm. Evidence outstanding: - security questionnaire - data protection review evidence - insurance certificates - remote access procedure - incident response process - business continuity summary - subcontractor list - contract review Proposed recommendation for review: Defer final approval until information security, data protection, procurement, legal, and service-owner reviews are completed. Conditional approval may be considered only through the organization’s approved process if critical gaps are resolved or formally accepted by authorized owners. ## Onboarding Notes - Complete procurement approval route. - Complete contract review. - Complete information security review. - Complete data protection review. - Confirm insurance evidence. - Verify payment setup through approved finance route. - Assign service owner. - Define support escalation route. - Define reporting cadence. - Provision access using least privilege. - Log access approvals. - Confirm offboarding process before access is granted. - Store evidence in approved supplier file. ## Monitoring and Review Schedule Pre-onboarding: complete all high-risk evidence checks. First 30–60 days: confirm service setup, access controls, reporting, and escalation process are working. Quarterly: review support performance, incidents, access, and open issues, if supplier remains high risk. Annually: refresh insurance, security, data protection, business continuity, and supplier risk assessment. Contract renewal point: review supplier performance, risk rating, incidents, and alternatives before renewal decision. Risk reassessment triggers: - security incident - service failure - major contract change - new system access - new data processing - subcontractor change - ownership change ## Escalation and Open Issues Log Issue: data processing details not confirmed. Risk area: data protection. Owner: privacy lead to confirm. Due date: before contract finalization. Status: Open. Escalation required: yes if unresolved before onboarding. Issue: remote access control evidence not provided. Risk area: information security. Owner: information security lead to confirm. Due date: before access provisioning. Status: Open. Escalation required: yes if access is needed before review completion. Issue: insurance evidence outstanding. Risk area: legal/procurement. Owner: procurement to confirm. Due date: before onboarding. Status: Open. Escalation required: if not provided before approval deadline. ## Final Supplier Due Diligence QA Checklist - Supplier service scope is clear. - Data and system access are identified. - Risk rating is proposed with rationale. - Questionnaire is tailored to supplier risk. - Evidence request list is complete. - Security review needs are flagged. - Data protection review needs are flagged. - Financial and operational review notes are included. - Legal/procurement review notes are included. - Approval summary distinguishes proposed recommendation from final approval. - Onboarding actions are listed. - Monitoring schedule is defined. - Open issues are visible. - No supplier approval is claimed without authority. ## Disclaimer This supplier due diligence pack is procurement, third-par
💬 ChatGPT Skill

Supplier Due Diligence Pack

Add to Cart
PromptBase Select
Or get it with Select10 Select prompts/mo — under $2 each
Learn more
Instant accessInstant access
Usage rightsCommercial use
Money-back guaranteeMoney‑back
By purchasing this skill, you agree to our terms of service
GPT-5.6
Tested icon
Guide icon
Free credits icon
Creates supplier due diligence questionnaires, third-party risk checks, onboarding summaries, approval notes, evidence requests, review schedules, risk ratings, monitoring actions, and supplier governance packs for procurement, compliance, finance, operations, legal, IT, information security, and vendor management teams.
...more
Added 2 days ago
Report
Browse Marketplace