Loading

Vendor risk review

Go/no-go on the vendor with required mitigations.

10 minOperationsClaude Cowork
Loading

Set up

Try a plugin

The Operations plugin ships with /risk-assessment and other vendor-management skills as a starting point, already structured to read security documentation and score against a framework. If your admin manages plugins and it's not available yet, skip this; nothing below requires it.

OperationsOptimize business operations — vendor management, process documentation, change management, capacity planning, and compliance tracking. Keep your organization running efficiently.
Add
/risk-assessmentIdentify, assess, and mitigate operational risks.
Run
/vendor-reviewEvaluate a vendor — cost analysis, risk assessment, and recommendation.
Run

Connect your tools

Claude Cowork is more powerful when it works directly with your systems. You control permissions and access. Learn about tool access.

Navigate to Customize → Connectors in Cowork to set up.

Google Drive
Connect
Microsoft 365
Connect
IroncladOptional
If your executed contracts live in Ironclad, connect it so Claude can match the vendor's MSA and DPA to the signed record.
Connect
Browse all connectorsOpen in Cowork

Set your working folder

Drag the files you'll use (the vendor's SOC 2, their questionnaire responses, the DPA and MSA, your risk framework) into one folder on your machine, then point Cowork at it. Cowork reads from it and writes the scored memo and mitigation list back to it. If you run vendor reviews regularly, create a Cowork project from that folder so your framework, instructions, and memory stay attached.

Vendors / Northwind / risk-review
northwind-soc2-type2.pdfApr 20, 20262.4 MB
security-questionnaire-responses.xlsxApr 18, 202696 KB
northwind-dpa-and-msa.docxApr 18, 2026312 KB
vendor-risk-framework.pdfJan 9, 2026184 KB
In Cowork’s chat bar:Vendors / Northwind / risk-review

The prompt

Copy this into Claude Cowork

Score this vendor's SOC 2, security questionnaire, DPA, and MSA against our risk framework. Write the review memo with a clear go or no-go and the required mitigations with owners. Cite the source document and section for every finding.

Vendors / Northwind / risk-review

Why this works

Source

List the sources to read together. "SOC 2, questionnaire, DPA, and MSA" tells Cowork to cross-read security evidence and contract terms together, so a control gap and a missing contract clause show up as one finding, not two reviews.

Source

Use your own risk criteria. "Against our risk framework" points the scoring at the document in the folder, so the tier and the go/no-go reflect your thresholds for data sensitivity and access.

Prompt

Ask for a go or no-go recommendation. "Clear go or no-go" plus "required mitigations with owners" makes the memo something procurement can act on, not a list of observations someone still has to interpret.

Prompt

Citations make it auditable. "Cite the source document and section" means every finding traces back to a page in the SOC 2 or a clause in the DPA, so security and legal can verify without re-reading the packet.

Get a better draft

Practice

Add an example to match. Drop an example you like into the folder and Cowork matches your structure and voice.

Practice

Ask it to flag uncertainty. Add "flag anything you're not confident about" so you know where to look first when you review the draft.

Make Cowork work for you

A plugin skill is a starting point — customize it with your own practices and expertise. A few minutes of conversation and it runs with your standards from then on.

Make what we've done in this task so far into a skill, or edit the /risk-assessment skill with my feedback.

Vendors

Make it repeatable

Run it on every new vendor

When a vendor packet arrives, the scored memo should already be drafting. Type /schedule in the prompt, or open Scheduled in the Cowork sidebar, and the customized skill runs whenever a new risk-review folder appears under Vendors.

/schedule Weekdays at 9am, check Vendors for any new risk-review folder and run /risk-assessment against the docs inside and write the scored memo and mitigation list to that folder.

Vendors
Scheduled taskActive
Vendor risk first pass

Runs /risk-assessment on every new risk-review folder under Vendors and writes the scored memo and mitigation list back to it.

Every weekday at 9amOpen in Cowork

Share with your teammates

Your customized /risk-assessment now carries your risk tiers, your deal-breaker controls, and your memo format. Share it so procurement, security, and legal score every vendor the same way and the approval chain reads a consistent memo no matter who ran the review.

Going forward