Vendor Risk Assessment
Assess third-party vendor risk for AI and SaaS products. Evaluates security posture, data handling, compliance, financial stability, and operational resilience. Use when onboarding new vendors, conducting annual reviews, or building a vendor management program. Generates a scored risk report with mitigation recommendations. Built by AfrexAI.
Best use case
Vendor Risk Assessment is best used when you need a repeatable AI agent workflow instead of a one-off prompt. It is especially useful for teams working in multi. Assess third-party vendor risk for AI and SaaS products. Evaluates security posture, data handling, compliance, financial stability, and operational resilience. Use when onboarding new vendors, conducting annual reviews, or building a vendor management program. Generates a scored risk report with mitigation recommendations. Built by AfrexAI.
Assess third-party vendor risk for AI and SaaS products. Evaluates security posture, data handling, compliance, financial stability, and operational resilience. Use when onboarding new vendors, conducting annual reviews, or building a vendor management program. Generates a scored risk report with mitigation recommendations. Built by AfrexAI.
Users should expect a more consistent workflow output, faster repeated execution, and less time spent rewriting prompts from scratch.
Practical example
Example input
Use the "Vendor Risk Assessment" skill to help with this workflow task. Context: Assess third-party vendor risk for AI and SaaS products. Evaluates security posture, data handling, compliance, financial stability, and operational resilience. Use when onboarding new vendors, conducting annual reviews, or building a vendor management program. Generates a scored risk report with mitigation recommendations. Built by AfrexAI.
Example output
A structured workflow result with clearer steps, more consistent formatting, and an output that is easier to reuse in the next run.
When to use this skill
- Use this skill when you want a reusable workflow rather than writing the same prompt again and again.
When not to use this skill
- Do not use this when you only need a one-off answer and do not need a reusable workflow.
- Do not use it if you cannot install or maintain the related files, repository context, or supporting tools.
Installation
Claude Code / Cursor / Codex
Manual Installation
- Download SKILL.md from GitHub
- Place it in
.claude/skills/afrexai-vendor-risk-assessment/SKILL.mdinside your project - Restart your AI agent — it will auto-discover the skill
How Vendor Risk Assessment Compares
| Feature / Agent | Vendor Risk Assessment | Standard Approach |
|---|---|---|
| Platform Support | Not specified | Limited / Varies |
| Context Awareness | High | Baseline |
| Installation Complexity | Unknown | N/A |
Frequently Asked Questions
What does this skill do?
Assess third-party vendor risk for AI and SaaS products. Evaluates security posture, data handling, compliance, financial stability, and operational resilience. Use when onboarding new vendors, conducting annual reviews, or building a vendor management program. Generates a scored risk report with mitigation recommendations. Built by AfrexAI.
Where can I find the source code?
You can find the source code on GitHub using the link provided at the top of the page.
Related Guides
AI Agents for Startups
Explore AI agent skills for startup validation, product research, growth experiments, documentation, and fast execution with small teams.
AI Agents for Coding
Browse AI agent skills for coding, debugging, testing, refactoring, code review, and developer workflows across Claude, Cursor, and Codex.
AI Agent for SaaS Idea Validation
Use AI agent skills for SaaS idea validation, market research, customer discovery, competitor analysis, and documenting startup hypotheses.
SKILL.md Source
# Vendor Risk Assessment Evaluate any AI/SaaS vendor across 6 risk dimensions. Outputs a scored report with go/no-go recommendation. ## When to Use - Onboarding a new SaaS or AI vendor - Annual vendor review cycle - Evaluating build-vs-buy decisions - Due diligence for partnerships or acquisitions - Compliance requirements (SOC2, ISO 27001, GDPR) ## How to Use The user provides vendor details (name, product, website, any available documentation). The agent researches and scores the vendor across 6 dimensions. ### Input Format ``` Vendor: [Company Name] Product: [Product/Service Name] Website: [URL] Use Case: [What you'd use it for] Data Sensitivity: [low/medium/high/critical] Additional Context: [Any docs, certifications, or concerns] ``` ## Assessment Framework ### 6 Risk Dimensions (each scored 1-10) #### 1. Security Posture - SOC2 Type II certification? - Penetration testing cadence - Encryption (at rest + in transit) - Access controls and authentication - Incident response plan - Bug bounty program #### 2. Data Handling & Privacy - Data residency and sovereignty - Data retention and deletion policies - Sub-processor transparency - GDPR/CCPA compliance - Data portability (can you get your data out?) - AI training opt-out policies #### 3. Compliance & Certifications - SOC2, ISO 27001, HIPAA, FedRAMP - Industry-specific (PCI-DSS, HITRUST, etc.) - AI-specific (EU AI Act readiness, NIST AI RMF) - Audit frequency and transparency - Regulatory track record #### 4. Financial Stability - Funding stage and runway - Revenue indicators (public or estimated) - Customer concentration risk - Acquisition risk - Pricing stability history #### 5. Operational Resilience - Uptime SLA and historical performance - Disaster recovery plan - Multi-region availability - Dependency on single cloud provider - Support responsiveness and escalation paths - Change management process #### 6. Contractual Terms - Termination and exit clauses - Liability caps and indemnification - IP ownership clarity - Auto-renewal traps - Price increase limitations - SLA breach remedies ## Output Format ```markdown # Vendor Risk Assessment: [Vendor Name] **Date:** YYYY-MM-DD **Assessor:** AI Agent (AfrexAI) **Data Sensitivity Level:** [low/medium/high/critical] ## Overall Risk Score: [X/10] — [LOW/MEDIUM/HIGH/CRITICAL] ## Dimension Scores | Dimension | Score | Risk Level | Key Finding | |-----------|-------|------------|-------------| | Security Posture | X/10 | LOW/MED/HIGH | ... | | Data Handling | X/10 | LOW/MED/HIGH | ... | | Compliance | X/10 | LOW/MED/HIGH | ... | | Financial Stability | X/10 | LOW/MED/HIGH | ... | | Operational Resilience | X/10 | LOW/MED/HIGH | ... | | Contractual Terms | X/10 | LOW/MED/HIGH | ... | ## Recommendation: [APPROVE / APPROVE WITH CONDITIONS / REJECT] ## Critical Findings - [Finding 1] - [Finding 2] ## Mitigation Requirements (if Approve with Conditions) 1. [Requirement 1 — deadline] 2. [Requirement 2 — deadline] ## Research Sources - [Source 1] - [Source 2] ``` ## Scoring Guide - **9-10:** Excellent — minimal risk, enterprise-grade - **7-8:** Good — acceptable for most use cases - **5-6:** Moderate — proceed with caution, mitigations needed - **3-4:** Poor — significant concerns, conditional approval only - **1-2:** Critical — recommend rejection or major remediation ## Overall Risk Calculation - Average of 6 dimensions, weighted by data sensitivity: - Low sensitivity: equal weights - Medium: Security 2x, Data 2x - High: Security 3x, Data 3x, Compliance 2x - Critical: Security 4x, Data 4x, Compliance 3x, Financial 2x ## Research Process 1. Check vendor website for security/compliance pages 2. Search for SOC2/ISO certifications and trust pages 3. Check status pages for uptime history 4. Search for breach history or security incidents 5. Review pricing page for contract terms indicators 6. Check Crunchbase/LinkedIn for financial stability signals 7. Search for customer reviews mentioning reliability/support ## Pro Tips - Request the vendor's SOC2 Type II report directly — if they hesitate, that's a signal - Check their status page history (statuspage.io, etc.) for real uptime data - For AI vendors specifically: ask about model training on your data, output ownership, and hallucination liability - Compare their security page to competitors — vague = red flag --- *Need help managing vendor risk across your entire stack? AfrexAI builds autonomous AI agents that monitor vendors continuously — not just at onboarding. Visit [afrexai.com](https://afrexai.com) or book a call: [calendly.com/cbeckford-afrexai/30min](https://calendly.com/cbeckford-afrexai/discovery-call)*
Related Skills
Portfolio Risk Analyzer
Complete investment portfolio risk management system. Analyze positions, calculate risk metrics, stress test scenarios, optimize allocations, and generate institutional-grade risk reports — all without external APIs.
Energy Audit — Commercial Building Assessment
Run a full energy audit for commercial or industrial facilities. Identifies waste, models savings, and generates a prioritized retrofit roadmap with ROI timelines.
Employee Retention & Turnover Risk Analyzer
Diagnose why people leave. Fix it before they do.
Cybersecurity Risk Assessment
You are a cybersecurity risk assessment specialist. When the user needs a security audit, threat assessment, or compliance review, follow this framework.
Churn Risk Analyzer
Identify customers most likely to churn before they leave. Uses behavioral signals, usage patterns, and engagement data to score accounts and recommend retention actions.
AI Readiness Assessment
Run a structured AI readiness audit for any organization. Scores 8 dimensions, identifies gaps, produces a prioritized 90-day action plan with budget ranges.
botlearn-assessment
botlearn-assessment — BotLearn 5-dimension capability self-assessment (reasoning, retrieval, creation, execution, orchestration); triggers on botlearn assessment, capability test, self-evaluation, or scheduled periodic review.
risk-management-specialist
Medical device risk management specialist implementing ISO 14971 throughout product lifecycle. Provides risk analysis, risk evaluation, risk control, and post-production information analysis. Use when user mentions risk management, ISO 14971, risk analysis, FMEA, fault tree analysis, hazard identification, risk control, risk matrix, benefit-risk analysis, residual risk, risk acceptability, or post-market risk.
cold-chain-risk-calculator
Calculate cold chain transport risks
Binance Event Contract Risk Manager
## 1. Scenario Definition
vendor-risk-brief
对外部 SaaS/API 形成风险摘要,聚焦集成影响、权限、数据流向和替代方案。;use for vendor-risk, saas, security workflows;do not use for 冒充安全认证结论, 替代正式法务/安全审批.
skill-risk-splitter
把职责过杂的 Skill 拆成安全版、增强版或多子 Skill,降低扫描和维护风险。;use for skills, refactor, risk workflows;do not use for 为了拆分而失去清晰定位, 隐藏高风险行为.