- Home
- Skills
- Business & Operations
- vendor due diligence assessment
Works with the AI tools you already use
vendor due diligence assessment
Assess IT vendor risk and compliance using SOC reports, questionnaires, and evidence to produce audit-ready reports.
$15
vendor due diligence assessment
Example session with this skill installed
Assess CloudSecure Inc. They provide managed hosting for our PII. I have their SOC 2 Type II, ISO 27001 cert, and a completed questionnaire. Map the gaps and give a risk score.
- Read your context and instructions
- Compiled the vendor due diligence
- Generated the document
I have analyzed the provided documentation for CloudSecure Inc. (Managed Hosting). The assessment focused on the protection of PII and operational resilience.
Vendor Due Diligence Assessment: CloudSecure Inc.
| Risk Domain | Evidence Reviewed | Finding / Gap | Residual Risk |
|---|---|---|---|
| Information Security | SOC 2 Type II (2023), ISO 27001 | No material exceptions in Trust Services Criteria. Encryption at rest/transit verified. | Low |
| Data Privacy | Questionnaire, Data Processing Addendum | GAP: Sub-processor list for fourth-party CDN providers is 14 months out of date. | Medium |
| Availability | SOC 2 (Section 4), SLA Policy | 99.99% uptime commitment backed by financial credits. Redundancy verified across 3 zones. | Low |
| Compliance | ISO 27001 Certificate | Certificate is valid until Dec 2025. Scope includes all relevant data centers. | Low |
| Fourth-Party Risk | Questionnaire | Reliance on "GlobalCDN" for edge delivery; no recent audit report provided for this entity. | Medium |
Risk Scoring Summary
Overall Score: 72/100 (Medium Risk)
- Security: 90/100 (Strong evidence)
- Privacy: 65/100 (Stale fourth-party documentation)
- Resilience: 88/100 (Strong infrastructure redundancy)
Recommendation: Approve with conditions.
Next steps
- Request an updated Sub-processor/Fourth-party list from CloudSecure.
- Obtain the latest SOC 2 report for "GlobalCDN" to close the fourth-party gap.
- Schedule the next evidence refresh for November 2024.
vendor-due-diligence-assessment.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Third-party risk management is stalled by manual evidence review. Analysts waste hours parsing SOC 2 reports, ISO certificates, and vendor questionnaires to find material gaps.
What it does
- Performs risk-based assessments of IT service providers and SaaS vendors using supplied evidence.
- Extracts findings from SOC 2 reports, audit logs, and compliance certificates into structured registers.
- Generates vendor comparison matrices to support procurement selection based on risk scores.
- Produces remediation plans and ongoing monitoring schedules for existing partners.
- Identifies fourth-party dependencies and supply chain risks hidden in vendor disclosures.
Why this beats prompting it yourself
General-purpose prompts often miss the nuance of evidence validation, treating vendor self-assertions as verified facts. This skill enforces a rigorous review process that distinguishes between assertions and independent evidence, ensuring risk scores are based on documented proof rather than marketing claims.
Use cases
- Pre-contract due diligence for a new SaaS platform handling sensitive customer data.
- Annual renewal reviews for critical infrastructure partners to refresh evidence.
- Comparing three different cloud storage providers across security and privacy domains.
- Drafting targeted document request lists for vendors based on their service criticality.
Known limitations
Does not provide legal advice or draft contract language. Cannot perform live external monitoring of vendor environments or verify data not provided in the input.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 29 days ago
- Passed all security checks, Safe to install