Set up
Try a plugin
The Operations plugin ships with /risk-assessment and other vendor-management skills as a starting point, already structured to read security documentation and score against a framework. If your admin manages plugins and it's not available yet, skip this; nothing below requires it.
Connect your tools
Claude Cowork is more powerful when it works directly with your systems. You control permissions and access. Learn about tool access(opens in new tab).
Navigate to Customize → Connectors in Cowork to set up.
Set your working folder
Drag the files you'll use (the vendor's SOC 2, their questionnaire responses, the DPA and MSA, your risk framework) into one folder on your machine, then point Cowork at it. Cowork reads from it and writes the scored memo and mitigation list back to it. If you run vendor reviews regularly, create a Cowork project(opens in new tab) from that folder so your framework, instructions, and memory stay attached.
The prompt
Copy this into Claude Cowork
Score this vendor's SOC 2, security questionnaire, DPA, and MSA against our risk framework. Write the review memo with a clear go or no-go and the required mitigations with owners. Cite the source document and section for every finding.
Why this works
List the sources to read together. "SOC 2, questionnaire, DPA, and MSA" tells Cowork to cross-read security evidence and contract terms together, so a control gap and a missing contract clause show up as one finding, not two reviews.
Use your own risk criteria. "Against our risk framework" points the scoring at the document in the folder, so the tier and the go/no-go reflect your thresholds for data sensitivity and access.
Ask for a go or no-go recommendation. "Clear go or no-go" plus "required mitigations with owners" makes the memo something procurement can act on, not a list of observations someone still has to interpret.
Citations make it auditable. "Cite the source document and section" means every finding traces back to a page in the SOC 2 or a clause in the DPA, so security and legal can verify without re-reading the packet.
Get a better draft
Add an example to match. Drop an example you like into the folder and Cowork matches your structure and voice.
Ask it to flag uncertainty. Add "flag anything you're not confident about" so you know where to look first when you review the draft.
Make Cowork work for you
A plugin skill is a starting point — customize it with your own practices and expertise. A few minutes of conversation and it runs with your standards from then on.
Make what we've done in this task so far into a skill, or edit the /risk-assessment skill with my feedback.
Make it repeatable
Run it on every new vendor
When a vendor packet arrives, the scored memo should already be drafting. Type /schedule in the prompt, or open Scheduled in the Cowork sidebar, and the customized skill runs whenever a new risk-review folder appears under Vendors.
/schedule Weekdays at 9am, check Vendors for any new risk-review folder and run /risk-assessment against the docs inside and write the scored memo and mitigation list to that folder.
Runs /risk-assessment on every new risk-review folder under Vendors and writes the scored memo and mitigation list back to it.
Share with your teammates
Your customized /risk-assessment now carries your risk tiers, your deal-breaker controls, and your memo format. Share it so procurement, security, and legal score every vendor the same way and the approval chain reads a consistent memo no matter who ran the review.