Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    vendor due diligence assessment

    1

    Assess IT vendor risk and compliance using SOC reports, questionnaires, and evidence to produce audit-ready reports.

    $15

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    vendor due diligence assessment

    vendor due diligence assessment

    Example session with this skill installed

    Assess CloudSecure Inc. They provide managed hosting for our PII. I have their SOC 2 Type II, ISO 27001 cert, and a completed questionnaire. Map the gaps and give a risk score.

    • Read your context and instructions
    • Compiled the vendor due diligence
    • Generated the document

    I have analyzed the provided documentation for CloudSecure Inc. (Managed Hosting). The assessment focused on the protection of PII and operational resilience.

    Vendor Due Diligence Assessment: CloudSecure Inc.

    Risk DomainEvidence ReviewedFinding / GapResidual Risk
    Information SecuritySOC 2 Type II (2023), ISO 27001No material exceptions in Trust Services Criteria. Encryption at rest/transit verified.Low
    Data PrivacyQuestionnaire, Data Processing AddendumGAP: Sub-processor list for fourth-party CDN providers is 14 months out of date.Medium
    AvailabilitySOC 2 (Section 4), SLA Policy99.99% uptime commitment backed by financial credits. Redundancy verified across 3 zones.Low
    ComplianceISO 27001 CertificateCertificate is valid until Dec 2025. Scope includes all relevant data centers.Low
    Fourth-Party RiskQuestionnaireReliance on "GlobalCDN" for edge delivery; no recent audit report provided for this entity.Medium

    Risk Scoring Summary

    Overall Score: 72/100 (Medium Risk)

    • Security: 90/100 (Strong evidence)
    • Privacy: 65/100 (Stale fourth-party documentation)
    • Resilience: 88/100 (Strong infrastructure redundancy)

    Recommendation: Approve with conditions.

    Next steps

    1. Request an updated Sub-processor/Fourth-party list from CloudSecure.
    2. Obtain the latest SOC 2 report for "GlobalCDN" to close the fourth-party gap.
    3. Schedule the next evidence refresh for November 2024.

    vendor-due-diligence-assessment.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Generate risk-based vendor assessments for procurement teams.Identify gaps between vendor assertions and provided audit evidence.Create comparison matrices for selecting between multiple technology providers.Build ongoing monitoring plans for high-criticality third parties.Assess a SaaS payroll vendor using a supplied questionnaire, SOC 2 summary and privacy policy, producing a due diligence report with evidence gaps and approval conditions.Compare three cloud storage vendors using a consistent risk scoring model and produce a comparison matrix with a supported recommendation.Generate a risk-based document request list for a high-criticality vendor that stores and processes personal and payment data.Review an existing vendor monitoring programme and identify gaps in review cadence, early warning indicators and off-cycle trigger criteria.

    About this skill

    The problem

    Third-party risk management is stalled by manual evidence review. Analysts waste hours parsing SOC 2 reports, ISO certificates, and vendor questionnaires to find material gaps.

    What it does

    • Performs risk-based assessments of IT service providers and SaaS vendors using supplied evidence.
    • Extracts findings from SOC 2 reports, audit logs, and compliance certificates into structured registers.
    • Generates vendor comparison matrices to support procurement selection based on risk scores.
    • Produces remediation plans and ongoing monitoring schedules for existing partners.
    • Identifies fourth-party dependencies and supply chain risks hidden in vendor disclosures.

    Why this beats prompting it yourself

    General-purpose prompts often miss the nuance of evidence validation, treating vendor self-assertions as verified facts. This skill enforces a rigorous review process that distinguishes between assertions and independent evidence, ensuring risk scores are based on documented proof rather than marketing claims.

    Use cases

    • Pre-contract due diligence for a new SaaS platform handling sensitive customer data.
    • Annual renewal reviews for critical infrastructure partners to refresh evidence.
    • Comparing three different cloud storage providers across security and privacy domains.
    • Drafting targeted document request lists for vendors based on their service criticality.

    Known limitations

    Does not provide legal advice or draft contract language. Cannot perform live external monitoring of vendor environments or verify data not provided in the input.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 29 days ago

    • Passed all security checks, Safe to install

    Listed29 days ago

    What's inside

    Frequently Asked Questions