Risk AssessmentHigh riskComparison recommended

AI Playbook for Third-Party Vendor Cyber Risk Scoring

Your organization processes payments through 3 vendors, shares HR data with 2 SaaS platforms, and has 11 other software integrations. A new vendor contract requires you to provide a cyber risk assessment of all third parties to your cyber insurer. You have questionnaire responses and some external scan data.

When to use this playbook

  • Use this playbook when the decision looks like the situation above: Your organization processes payments through 3 vendors, shares HR data with 2 SaaS platforms, and has 11 other software integrations.
  • It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Third-Party Vendor Cyber Risk Scoring".
  • Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.

What you'll need

  • Security questionnaire responses for all 16 vendors
  • External attack surface scan results (open ports, certificate status, breach history)
  • Data sharing agreement summaries (what data, what volume, what use)
  • SOC 2 reports where available (8 of 16 vendors)
  • Cyber insurance policy requirements for third-party risk

Attachments: Documents (Documents)

The Prompt

You are a third-party risk analyst preparing a vendor cyber risk assessment for a cyber insurance disclosure. I am attaching:

Work only from the attached source files. If a conclusion is not supported, say so.

Produce:
1. Score each vendor on: data sensitivity (what data they hold), control maturity (questionnaire + SOC 2), and attack surface exposure (scan results + breach history).
2. Identify the top 3 highest-risk vendors and the specific control gaps that drive the risk score.
3. Assess whether any vendor's data handling practices create a breach notification obligation if that vendor is compromised.
4. Flag any questionnaire responses that are inconsistent with the external scan data (a sign of misrepresentation).
5. Prepare the vendor risk summary for the cyber insurance disclosure and identify which vendors require contract remediation.

Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.

What to expect

  • Vendor risk scorecard (all 16)
  • Top 3 risk vendor deep dives
  • Breach notification obligation mapping
  • Questionnaire vs. scan inconsistency flags
  • Insurance disclosure summary and contract remediation list

Review before you act

  • Validate this output against source files before relying on it: Score each vendor on: data sensitivity (what data they hold), control maturity (questionnaire + SOC 2), and attack surface exposure (scan results + breach history).
  • Validate this output against source files before relying on it: Identify the top 3 highest-risk vendors and the specific control gaps that drive the risk score.
  • Validate this output against source files before relying on it: Assess whether any vendor's data handling practices create a breach notification obligation if that vendor is compromised.
  • Validate this output against source files before relying on it: Flag any questionnaire responses that are inconsistent with the external scan data (a sign of misrepresentation).
  • Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
  • Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
  • Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.

Why compare models on this

For Third-Party Vendor Cyber Risk Scoring, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface vendor risk scorecard (all 16); top 3 risk vendor deep dives; breach notification obligation mapping; questionnaire vs. scan inconsistency flags. Those are comparison artifacts — they only exist if more than one model runs. Models disagree on blast radius, attribution confidence, and whether a vendor finding is theoretical or exploitable. Those disagreements mark where an analyst should slow down.

CybersecurityThird-Party and AI SecurityRisk AssessmentHighDocuments

See governed multi-model AI on your own prompt

Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.