vendor-due-diligence-patrick-munro

Frame vendor due-diligence assessments across financial, operational, compliance, security, and reputational dimensions.

630|79|Updated Dec 18, 2025
One-click install
npx skills add https://github.com/lawvable/awesome-legal-skills --skill vendor-due-diligence-patrick-munro
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vendor-due-diligence-patrick-munro
Source: https://github.com/lawvable/awesome-legal-skills/tree/main/%F0%9F%8C%90/vendor-due-diligence-patrick-munro
Command: npx skills add https://github.com/lawvable/awesome-legal-skills --skill vendor-due-diligence-patrick-munro

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill frames and guides comprehensive vendor due-diligence assessments for IT service providers and technology vendors, enabling consistent risk judgments across multiple dimensions.

Core Features & Use Cases

  • Three-Phase risk assessment framework (Initial Screening, Detailed Assessment, Final Evaluation) to structure vendor reviews.
  • Regulatory checklists (GDPR, DORA, NIS2, SOX) with gap analysis and evidence-based findings.
  • Documentation templates and onboarding artifacts (DPA lists, insurance, SLAs, termination rights) to accelerate procurement and governance.
  • Executive risk reporting and ongoing monitoring roadmap to support continuous oversight.

Quick Start

Apply the vendor-due-diligence-patrick-munro framework to evaluate an IT vendor and generate an executive risk report.

Frequently Asked Questions about vendor-due-diligence-patrick-munro

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct vendor due diligence for IT service providers?

Vendor due diligence for IT providers requires a structured assessment across financial, operational, compliance, security, and reputational dimensions. This framework guides you through initial screening, detailed assessment, and final evaluation to generate consistent risk judgments.

What regulatory checklists are needed for vendor risk assessment?

Vendor risk assessment requires regulatory checklists for GDPR, DORA, NIS2, and SOX to ensure compliance. This framework provides structured checklists with gap analysis capabilities to identify and document vendor compliance gaps.

How do I structure a third-party risk assessment framework?

A third-party risk assessment framework should follow a three-phase structure: initial screening, detailed assessment, and final evaluation. This approach ensures comprehensive coverage of financial, operational, compliance, security, and reputational risk dimensions.

What documentation is required for IT vendor onboarding?

IT vendor onboarding requires documentation templates including Data Processing Agreements (DPAs), insurance certificates, Service Level Agreements (SLAs), and termination rights. This framework provides these artifacts to accelerate procurement and governance processes.

How do I create an ongoing monitoring roadmap for vendor compliance?

An ongoing monitoring roadmap for vendor compliance is created after final evaluation by establishing continuous oversight procedures. This framework generates the roadmap alongside executive risk reporting to support long-term vendor governance.