vendor-due-diligence-patrick-munro

Assess vendor regulatory and operational risk across DORA, NIS2, and GDPR contexts.

630|79|Updated Dec 18, 2025
One-click install
npx skills add https://github.com/lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro-lawve-ai
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vendor-due-diligence-patrick-munro
Source: https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/vendor-due-diligence-patrick-munro
Command: npx skills add https://github.com/lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro-lawve-ai

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps regulated organizations identify and manage vendor-related regulatory and operational risk across ICT third parties, reducing compliance gaps and contract exposure.

Core Features & Use Cases

  • Three-Phase Assessment Process, including Initial Screening, Detailed Assessment, and Final Evaluation, to streamline onboarding and monitoring.
  • Six-Dimension Risk Scoring (Financial, Operational, Compliance, Security, Reputational, Strategic) with clear mitigation guidance and governance output.
  • DORA, NIS2, and GDPR compliance coverage, contractual obligation templates, and robust exit strategies for regulated vendors.

Quick Start

Begin with Phase 1 screening to quickly identify vendors warranting detailed assessment and then execute the three-phase evaluation.

Frequently Asked Questions about vendor-due-diligence-patrick-munro

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is vendor due diligence for DORA, NIS2, and GDPR compliance?

Vendor due diligence is a structured assessment of third-party regulatory and operational risk. This process evaluates ICT vendors across six risk dimensions to ensure compliance with DORA, NIS2, and GDPR requirements before onboarding and during ongoing monitoring.

How do I assess ICT third-party risk for regulated firms?

Assess ICT third-party risk by executing a three-phase evaluation: Initial Screening, Detailed Assessment, and Final Evaluation. This framework scores vendors across financial, operational, compliance, security, reputational, and strategic dimensions to produce governance output and mitigation guidance.

What should be included in DORA and NIS2 vendor contracts?

DORA and NIS2 vendor contracts must include mandatory regulatory obligations, robust exit strategies, and specific risk management clauses. The framework provides contractual obligation templates to ensure third-party agreements meet strict regulatory compliance standards.

Does vendor due diligence work for ongoing monitoring or only new vendor onboarding?

Vendor due diligence applies to both new vendor onboarding and ongoing monitoring. The three-phase assessment framework continuously evaluates contract risk management and vendor compliance across DORA, NIS2, and GDPR contexts throughout the vendor lifecycle.

What is the best way to score vendor risk in regulated sectors?

The best way to score vendor risk is using a six-dimension framework covering financial, operational, compliance, security, reputational, and strategic factors. This structured approach generates clear mitigation guidance and formal risk reporting for regulated firms.

When do I need a structured vendor risk assessment framework?

You need a structured vendor risk assessment framework when onboarding new ICT third parties, managing existing vendor contracts, or ensuring DORA, NIS2, and GDPR compliance. It reduces compliance gaps and operational exposure for regulated organizations.