Agent skill · Security

vendor-due-diligence-patrick-munro

Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR. Provides three-phase process (Initial Screening / Detailed Assessment / Final Evaluation), six-dimension risk scoring (Financial/Operational/Compliance/Security/Reputational/Strategic) with weighted matrices, full DORA Art. 28-30 contractual checklist, NIS2 Art. 21(2) security measures enumeration, GDPR Art. 28 documentation checks, red flags per dimension, trigger-based review criteria, and document templates. Use when: (1) Evaluating new vendors or technology

lawve-aigithub.com/lawve-aiGitHub ↗
claude-codeNOASSERTION
Install
npx skills add lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 3
SKILL.md size: 16 KB
Bundled scripts: none
Version: 2026-04-25
Declared author: Patrick Munro
Path: skills/vendor-due-diligence-patrick-munro/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 618
Language: Python

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

From the SKILL.md

# Vendor Due Diligence Framework ## Overview Risk-based vendor assessment framework that identifies material risks early, ensures DORA/NIS2/GDPR compliance, and provides clear recommendations for selection, contract calibration, and ongoing management. Built for regulated sectors (financial services under DORA, KRITIS sectors under NIS2) and for any organisation with meaningful ICT third-party exposure. ## LEGAL DISCLAIMER This skill provides frameworks for vendor assessment purposes only. It does not constitute legal, financial, or professional advice. Users should: - Consult qualified legal counsel for specific requirements in their jurisdiction; - Engage financial and security professionals for detailed assessments; - Verify all regulatory requirements independently; - Adapt frameworks to specific organisational needs and risk tolerance; - Not rely on this skill as a substitute for professional due diligence services. The frameworks are templates. Actual assessments require expertise in law, finance, cybersecurity, and risk management. Neither the skill creator nor Claude/Anthropic assumes liability for decisions made based on this skill's output. **Regulatory references current

What's inside
Steps it walks through
  1. Overview
  2. LEGAL DISCLAIMER
  3. When to Use This Skill
  4. Core Capabilities
  5. 1. Three-Phase Assessment Process
  6. 2. Detailed Assessment Dimensions
  7. 3. Six-Dimension Risk Scoring
  8. 4. DORA Critical Vendor Assessment
  9. 5. NIS2 Vendor Assessment
  10. 6. Risk Mitigation Strategies
  11. 7. Ongoing Vendor Management
  12. 8. Output Formats
  13. Best Practices
  14. Common Mistakes
Ships with 2 files
  • LICENSE.txt
  • README.md
More from awesome-legal-skills
All skills →
About this skill
What does the vendor-due-diligence-patrick-munro skill do?

Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR. Provides three-phase process (Initial Screening / Detailed Assessment / Final Evaluation), six-dimension risk scoring (Financial/Operational/Compliance/Security/Reputational/Strategic) with weighted matrices, full DORA Art. 28-30 contractual checklist, NIS2 Art. 21(2) security measures enumeration, GDPR Art. 28 documentation checks, red flags per dimension, trigger-based review criteria, and document templates. Use when: (1) Evaluating new vendors or technology

How do I install it?

Run `npx skills add lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From lawve-ai/awesome-legal-skills, a repository with 618 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going