All prompts

Draft

Draft a vendor risk memo with a real decision at the end

Turns a pile of diligence artifacts into a tiered vendor-risk memo the deal team can act on this week, with contract conditions written as language procurement can paste.

About 20 minintermediateIn-house, Regulatory, Privacy

Your prompt4,894 characters

Still to fill in: Vendor and engagement, Diligence artifacts received, Governing law and where the data lands

RoleYou are an in-house lawyer who runs third-party risk for a regulated business. You read the exceptions section of a SOC 2 before the cover letter, you size insurance against the actual record count rather than a round number, and you refuse to write a condition procurement cannot put into a contract.What I needAssess the vendor below and write the memo to the GC and the business owner. Regulatory regime: Healthcare: HIPAA and state health-data law. Highest data sensitivity in play: No personal data.InputsVendor and engagement: Vendor and engagement Diligence artifacts received: Diligence artifacts received Governing law and data locations: Governing law and where the data landsHow to work this1. Tier the engagement before scoring anything. Tier 1 through 4, one sentence, from No personal data and operational criticality. Calibrate everything after to that tier. 2. Score four domains (security, data, financial, regulatory) STRONG, MODERATE, or WEAK, each tied to a named artifact. Report period, scope, opinion, and exceptions, not "they have a SOC 2." 3. List what you did not receive and what is stale. A refused cash-position disclosure or a missing pen-test summary is a finding with a mitigation, not a blank row. 4. Trace every data flow implied by Governing law and where the data lands and name the transfer mechanism for each. Domestic flows get four words. 5. Size the insurance ask with the arithmetic visible: record count times a per-record cost you name and source, then the limit you want. 6. Write every condition as language procurement can paste: clause name, obligation, number, remedy, owner. "Tighten sub-processor controls" is not a condition; "30 days' notice of any new sub-processor, with a right to object and terminate without penalty" is. 7. Close with one decision (Approve, Conditional, or Decline) and a monitoring cadence tied to the tier from step 1.Close with these four sections, every time, without being askedAssumptions I made. Every factual and legal assumption behind the assessment: what the SOC 2 scope covered, whether the vendor's stated sub-processor list is complete, what the record count is, and which regime governs. Mark each [verify] or [safe]. Where this is weakest. The two or three conclusions most likely to be wrong: the domain score resting on the thinnest artifact, the risk I sized without data. Name the domain, not "the assessment generally." What only you can decide. Present each as options with tradeoffs. At minimum: conditional approval now with contract conditions and a 30-day negotiation window, which keeps the business timeline but risks signing before conditions land, versus holding until the missing artifacts arrive, which is cleaner but pushes the project a quarter. Also yours: whether the financial-distress risk is priced by conditions or by choosing a different vendor, and how much of the security ask to spend on a vendor this size. What would make this materially better. Rank by impact: the missing artifacts, the record count, the vendor's current sub-processor list with locations, and whether the business owner has already committed to a start date.Output formatA privileged memo: recipients and privilege legend, tier classification, a three-sentence executive summary carrying the decision, four scored domain sections, a risk table of Risk | Likelihood | Impact | Mitigation, the required contract terms as paste-ready language, the recommendation, the monitoring cadence, then the four closing sections.Never do this- If the memo would read the same for any vendor selling any service, it is too generic. Anchor every finding to this vendor's artifacts, this data, this deal size. - No hedging filler. Cut "arguably," "it should be noted," and "best practice suggests" used in place of a position. Do not tell me to consult counsel. I am the counsel signing this memo. - Never invent a SOC 2 finding, a certification, a policy number, an insurance limit, or a regulatory citation. Anything not in my inputs gets [UNVERIFIED - confirm with the vendor before signature]. - Where you do not know whether a control exists or a regime applies, say you do not know and put it on the missing-artifact list rather than scoring through it. - Do not pad with domains that are clean. If financial and regulatory are fine, give each a line and spend the memo on the two that are not. Length is not value.Before you answer- Did I tier the engagement before scoring, and is the depth proportionate to that tier? - Is every domain score tied to a named artifact with a date? - Did I show the arithmetic behind the insurance ask? - Can procurement paste each condition into a contract without rewriting it? - Would this memo be useless for a different vendor? It should be.

Adds driver's-seat tunes: options instead of answers, questions before work, every citation flagged. Your values come with it.

2

Pressure-test it

Makes the AI switch hats and attack its own answer.

The vendor's CISO has a quarter to close and a legal team of one, and he is on the redline call with your conditions in front of him. Read your own required-conditions list as the CISO. Name the two conditions you sign without argument, the two you push back on and the business reason you give, and the one that makes you tell your CEO this deal is not worth it. Then rewrite those two pushback conditions as fallback language that still achieves the security objective (narrower scope, longer runway, or a different remedy) and say what protection you gave up.
3

Go deeper

Pushes the work further once the basics are right.

The business owner who has to live with this decision will not read a risk memo. Write the one-page briefing for that person: what the vendor does, the recommendation in one sentence, the two conditions likely to slow the negotiation and by how long, what the conditions do to the deal economics, and the realistic onboarding date. No security or privacy jargon; this reads like a business memo.

Before you run it

What to gather first

  • What the vendor does, deal value, term, and whether it touches production systems
  • Every diligence artifact received, with dates: SOC 2, pen test, insurance certificates, financials
  • The data the vendor will hold: type, sensitivity, volume, and where it lands
  • Which regulatory regime the business operates under
  • What the business owner has already promised the vendor about timing

Watch for

  • SOC 2 Type II reports are point-in-time and scope-limited. Confirm the report period, which trust services criteria were in scope, and whether the exceptions were remediated. A clean cover letter can sit on top of a narrow scope.
  • The model will happily accept the vendor's own questionnaire answers as evidence. Self-attestation is not an artifact; treat unanswered controls as gaps.
  • Do not paste vendor confidential material (SOC 2 reports and financial statements are usually under NDA) unless your AI policy and that NDA permit it.
  • Cross-border transfer mechanisms and the assessments behind them change with case law and regulator guidance. Verify the current requirement before relying on any transfer conclusion here.
  • Insurance limits sized to a generic benchmark rather than your record count will look inadequate the day you need them. Confirm the per-record figure with your broker.

What comes back

A privileged memo: recipients and privilege legend, tier classification with a one-sentence rationale, a three-sentence executive summary containing the decision, four domain sections scored STRONG / MODERATE / WEAK against named artifacts, a risk table with likelihood, impact, and mitigation, required contract terms written as paste-ready clause language, the approve / conditional / decline recommendation, a tier-matched monitoring cadence, and the four collaboration sections.

See an example of what you’ll get
MEMORANDUM - ATTORNEY-CLIENT PRIVILEGED To: J. Reyes, GC; M. Patel, Medical Affairs · From: Counsel · Re: Vendor Risk - BlueRiver Analytics · April 27, 2026 Tier 2 (Significant). Pseudonymized clinical data plus a write-back API into the CTMS and a three-year commitment. Not Tier 1 because the data is pseudonymized at source; not Tier 3 because the integration creates an operational dependency we cannot unwind in a week. Executive summary. Conditional approval. The security posture is genuinely strong and the regulatory exposure is manageable; the problems are a $5M cyber limit against a 190,000-record footprint, sub-processor terms that give us 14 days and no right to object, and a vendor with 14 months of runway that declined to show us its cash position. Four conditions, 30 days to negotiate. Security: STRONG. SOC 2 Type II for the period March 2024 to February 2025, unqualified opinion on Security, one change-management exception remediated before report date. ISO 27001 current. Encryption and MFA confirmed by questionnaire. *Missing:* the pen-test summary was promised and never delivered: condition, not a blank. Data: MODERATE. Processor role. EU-stored data moves from Helix's German entity to us-east-1; transfer mechanism not yet papered. Sub-processor list names six, two in the EEA. Current DPA gives 14 days' notice with no objection right. Deletion at 30 days post-termination with backup retention undocumented. Financial: MODERATE. FY24 revenue $14M against a $2.1M net loss. Cash position withheld on request. Runway is an estimate, not a fact. Regulatory: MODERATE. Data is pseudonymized at source, so HIPAA does not attach at the vendor. Whether the CTMS write-back makes these Part 11 records is open and needs a 20-minute call with regulatory affairs. Insurance arithmetic. ~190,000 records at the $165 per-record incident benchmark our broker used for the 2025 renewal is roughly $31M of gross exposure; even at a 50% realization assumption the $5M limit is short. Ask: cyber $15M, E&O $10M, Helix named additional insured on the cyber tower. Required conditions (paste-ready). 1. *Sub-processors.* "Vendor shall give Customer thirty (30) days' prior written notice of any new sub-processor. Customer may object on reasonable data-protection grounds, and if the parties cannot resolve the objection within fifteen (15) days, Customer may terminate the affected services without penalty and receive a pro-rata refund." 2. *Insurance.* Cyber $15M, E&O $10M, Helix as additional insured on cyber; certificates annually at renewal. 3. *Financial notice.* "Vendor shall notify Customer within five (5) business days of any event that materially impairs its ability to perform, including a going-concern qualification, a missed payroll, or a change of control." 4. *Exit.* Transition assistance for twelve months at then-current rates and full data export in a documented format on demand. Recommendation. Conditional approval, all four conditions in the executed agreement. Monitoring: Tier 2 cadence: annual SOC 2 review each March, quarterly sub-processor list check, insurance certificate at renewal, financial notice on trigger, full revalidation in year two. --- Assumptions I made. The 190,000-record figure came from the medical affairs scoping deck, not the vendor [verify]. The SOC 2 scope covered the production environment serving this product [verify - the report names three systems and I cannot tell which one we sit on]. Pseudonymization happens at Helix before transmission [safe - per the integration spec]. Where this is weakest. The financial score. I graded MODERATE on one year of audited financials and a refusal, which is a judgment call rather than a finding. If the cash position is worse than estimated, the exit condition matters more than everything else in this memo. What only you can decide. Conditional approval with a 30-day negotiation window keeps M. Patel's Q3 launch, but risks signing before the insurance increase lands and the vendor knows it. Holding until the pen test and cash position arrive is the cleaner record and costs the launch about a quarter. Separately: whether the financial risk is priced by the exit condition or by moving to RidgePine, which is more expensive and slower to integrate but not two years from a raise. What would make this materially better. (1) The pen-test summary and the SOC 2 system description page. (2) The actual record count from medical affairs. (3) The vendor's current sub-processor list with hosting regions. (4) Whether M. Patel has already told BlueRiver a start date.
Why this prompt is built the way it is
## Framework 1. **Tier before you score.** Data sensitivity plus operational criticality sets Tier 1 through 4, and the tier sets how much diligence is proportionate. 2. **Artifacts, not assertions.** A SOC 2 has a report period, a scope, an opinion, and exceptions. Cite them. Existence is not a finding. 3. **Missing is a finding.** A declined cash-position disclosure or a pen-test summary that never arrived belongs in the memo, not in a blank cell. 4. **Follow the data across borders.** Every flow needs a named transfer mechanism, or a line saying the flow is domestic. 5. **Insurance is arithmetic.** Record count times a per-record cost you name and source. Round numbers with no math are guesses. 6. **Conditions are contract language.** Clause name, obligation, number, remedy, owner. "Tighten sub-processor controls" is not a condition. 7. **One decision, one cadence.** Approve, conditional, or decline, and a monitoring rhythm tied to the tier you assigned.