BEFORE YOU RUN
Know the job and the reviewer.
This playbook is for security, IT, and operations teams doing an initial vendor review.
TARGET OUTCOME
A structured review packet that makes evidence gaps visible without pretending to make the approval decision.
Bring these inputs
Better source material makes the result easier to review and safer to reuse.
- Your review checklist
- Vendor questionnaire and supplied documents
- Risk tier and intended use
- Policy for required evidence
COPYABLE STARTER
Start with this prompt.
Replace bracketed details, attach the source material, and keep the limits until your team has reviewed a few runs.
Prepare an initial vendor security review from supplied documents and our checklist. For each control, mark answered, partially answered, unanswered, or conflicting. Link the exact supporting evidence. List follow-up questions, data-handling concerns, and claims needing independent verification. Do not approve or reject the vendor.
THE PLAYBOOK
Move from context to a reviewed result.
- 01
Define the review frame
Provide intended use, data classification, and risk tier so the packet focuses on relevant controls.
- 02
Map evidence to controls
Require exact document references. Marketing language should not count as technical evidence.
- 03
Expose gaps and conflicts
Separate missing answers from contradictory statements and expired or scope-limited evidence.
- 04
Route to the owner
A qualified security owner validates evidence, requests follow-up, and makes the risk decision.
DELIVERABLES
What the run should produce
- Control matrix
- Evidence index
- Gap and conflict list
- Vendor follow-up questions
HUMAN REVIEW
Check this before it leaves the team
- Evidence applies to the reviewed product
- Document dates and scope are visible
- Open gaps are not treated as passes
- A security owner makes the decision
Keep exploring this workflow