vendor-diligence

Automate creation and analysis of second-line vendor diligence packs.

Updated May 9, 2026
One-click install
npx skills add https://github.com/anotb/second-line-financial-services --skill vendor-diligence
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vendor-diligence
Source: https://github.com/anotb/second-line-financial-services/tree/main/plugins/capability-plugins/third-party-operational-resilience/skills/vendor-diligence
Command: npx skills add https://github.com/anotb/second-line-financial-services --skill vendor-diligence

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires criticality-assessment, source-anchors.md, sector-overlays, and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill streamlines the process of performing second-line vendor diligence, helping you identify risks and mitigate them efficiently.

Core Features & Use Cases

  • Risk Assessment: Automates the assessment of inherent risk and residual risk.
  • Diligence Execution: Captures due-diligence evidence and reviews against regulatory criteria.
  • Exit Strategy Planning: Generates an exit posture and identifies gaps to be closed.
  • Use Case: Use this Skill to evaluate a vendor for potential risks, including operational resilience, cybersecurity, privacy, and financial conditions.

Quick Start

Use the vendor-diligence skill to review the vendor diligence for "Vendor A", considering their operational resilience, cyber and information security, and privacy posture.

Frequently Asked Questions about vendor-diligence

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate second-line vendor diligence and risk assessment?

Automate second-line vendor diligence by using this Skill to generate diligence packs, assess inherent and residual risks, and collect evidence against regulatory criteria. It evaluates operational resilience, cybersecurity, privacy, and financial conditions for both AI and non-AI vendors.

What is included in a vendor diligence pack for operational resilience and privacy?

A vendor diligence pack includes inherent and residual risk assessments, regulatory and operational frame evaluations, risk-based evidence collection, and exit strategy planning. It specifically reviews operational resilience, cybersecurity, privacy posture, and financial conditions.

Can I evaluate AI vendors differently from non-AI vendors during risk assessment?

Yes, vendor diligence supports assessing both AI vendors and non-AI vendors. The process handles regulatory and operational frame assessments, risk-based evidence collection, and residual risk analysis tailored to the specific type of vendor being evaluated.

Do I need a criticality-assessment to perform residual risk analysis on a vendor?

Yes, a criticality-assessment is required as input data before performing residual risk analysis. You also need reference data from source-anchors and sector-specific overlays to accurately evaluate operational and regulatory risks.

How do I generate an exit strategy plan during the vendor review process?

Generate an exit strategy plan by analyzing the collected due-diligence evidence and regulatory criteria. The Skill identifies your exit posture and highlights specific gaps that need to be closed to ensure operational resilience.

Does vendor diligence work with sector-specific regulatory overlays?

Yes, vendor diligence requires sector-specific overlays to function correctly. These overlays, combined with source-anchors and criticality-assessment data, ensure the regulatory and operational frame assessment matches your industry requirements.