All prompts
Draft
Draft a vendor risk memo with a real decision at the end
Turns a pile of diligence artifacts into a tiered vendor-risk memo the deal team can act on this week, with contract conditions written as language procurement can paste.
Your prompt
2
Pressure-test it
3
Go deeper
Before you run it
What to gather first
Watch for
What comes back
See an example of what you’ll get
MEMORANDUM - ATTORNEY-CLIENT PRIVILEGED
To: J. Reyes, GC; M. Patel, Medical Affairs · From: Counsel · Re: Vendor Risk - BlueRiver Analytics · April 27, 2026
Tier 2 (Significant). Pseudonymized clinical data plus a write-back API into the CTMS and a three-year commitment. Not Tier 1 because the data is pseudonymized at source; not Tier 3 because the integration creates an operational dependency we cannot unwind in a week.
Executive summary. Conditional approval. The security posture is genuinely strong and the regulatory exposure is manageable; the problems are a $5M cyber limit against a 190,000-record footprint, sub-processor terms that give us 14 days and no right to object, and a vendor with 14 months of runway that declined to show us its cash position. Four conditions, 30 days to negotiate.
Security: STRONG. SOC 2 Type II for the period March 2024 to February 2025, unqualified opinion on Security, one change-management exception remediated before report date. ISO 27001 current. Encryption and MFA confirmed by questionnaire. *Missing:* the pen-test summary was promised and never delivered: condition, not a blank.
Data: MODERATE. Processor role. EU-stored data moves from Helix's German entity to us-east-1; transfer mechanism not yet papered. Sub-processor list names six, two in the EEA. Current DPA gives 14 days' notice with no objection right. Deletion at 30 days post-termination with backup retention undocumented.
Financial: MODERATE. FY24 revenue $14M against a $2.1M net loss. Cash position withheld on request. Runway is an estimate, not a fact.
Regulatory: MODERATE. Data is pseudonymized at source, so HIPAA does not attach at the vendor. Whether the CTMS write-back makes these Part 11 records is open and needs a 20-minute call with regulatory affairs.
Insurance arithmetic. ~190,000 records at the $165 per-record incident benchmark our broker used for the 2025 renewal is roughly $31M of gross exposure; even at a 50% realization assumption the $5M limit is short. Ask: cyber $15M, E&O $10M, Helix named additional insured on the cyber tower.
Required conditions (paste-ready).
1. *Sub-processors.* "Vendor shall give Customer thirty (30) days' prior written notice of any new sub-processor. Customer may object on reasonable data-protection grounds, and if the parties cannot resolve the objection within fifteen (15) days, Customer may terminate the affected services without penalty and receive a pro-rata refund."
2. *Insurance.* Cyber $15M, E&O $10M, Helix as additional insured on cyber; certificates annually at renewal.
3. *Financial notice.* "Vendor shall notify Customer within five (5) business days of any event that materially impairs its ability to perform, including a going-concern qualification, a missed payroll, or a change of control."
4. *Exit.* Transition assistance for twelve months at then-current rates and full data export in a documented format on demand.
Recommendation. Conditional approval, all four conditions in the executed agreement. Monitoring: Tier 2 cadence: annual SOC 2 review each March, quarterly sub-processor list check, insurance certificate at renewal, financial notice on trigger, full revalidation in year two.
---
Assumptions I made. The 190,000-record figure came from the medical affairs scoping deck, not the vendor [verify]. The SOC 2 scope covered the production environment serving this product [verify - the report names three systems and I cannot tell which one we sit on]. Pseudonymization happens at Helix before transmission [safe - per the integration spec].
Where this is weakest. The financial score. I graded MODERATE on one year of audited financials and a refusal, which is a judgment call rather than a finding. If the cash position is worse than estimated, the exit condition matters more than everything else in this memo.
What only you can decide. Conditional approval with a 30-day negotiation window keeps M. Patel's Q3 launch, but risks signing before the insurance increase lands and the vendor knows it. Holding until the pen test and cash position arrive is the cleaner record and costs the launch about a quarter. Separately: whether the financial risk is priced by the exit condition or by moving to RidgePine, which is more expensive and slower to integrate but not two years from a raise.
What would make this materially better. (1) The pen-test summary and the SOC 2 system description page. (2) The actual record count from medical affairs. (3) The vendor's current sub-processor list with hosting regions. (4) Whether M. Patel has already told BlueRiver a start date.
Why this prompt is built the way it is
## Framework
1. **Tier before you score.** Data sensitivity plus operational criticality sets Tier 1 through 4, and the tier sets how much diligence is proportionate.
2. **Artifacts, not assertions.** A SOC 2 has a report period, a scope, an opinion, and exceptions. Cite them. Existence is not a finding.
3. **Missing is a finding.** A declined cash-position disclosure or a pen-test summary that never arrived belongs in the memo, not in a blank cell.
4. **Follow the data across borders.** Every flow needs a named transfer mechanism, or a line saying the flow is domestic.
5. **Insurance is arithmetic.** Record count times a per-record cost you name and source. Round numbers with no math are guesses.
6. **Conditions are contract language.** Clause name, obligation, number, remedy, owner. "Tighten sub-processor controls" is not a condition.
7. **One decision, one cadence.** Approve, conditional, or decline, and a monitoring rhythm tied to the tier you assigned.