Prompt Library / Operational & Third-party Risk
Vendor Contract Summariser
Summarises a vendor contract against outsourcing requirements.
Prompt template
3 variablesSummarise the vendor contract below for a third-party risk reviewer at the Bank. Focus on what matters under the BNM Policy Document on Outsourcing and BNM RMiT. Vendor: {vendor_name} Service: {service_description} Contract text: {contract_text} Return: 1. Scope of service in two sentences 2. Whether the arrangement looks like material outsourcing, and why 3. Data location and data access terms (flag any customer data leaving Malaysia) 4. Audit and access rights for the Bank, Internal Audit and BNM 5. Termination, exit and business continuity terms 6. Gaps the reviewer should raise with Procurement, as a numbered list
Playground
Simulated sandboxOwnership and sensitivity
Who approves access
- Owner, Operational & Third-party Risk, Aminah Yusof
- Operational & Third-party Risk, Aminah Yusof
Business-sensitive. Models and data products scoped to named business units.
Entitlement per business unit, approved by the owner; conditions attach.
- Third-party
- Supplied by an approved vendor; outsourcing and third-party risk controls apply.
- GenAI
- Generates text; prompt screening for customer data and output review apply.
Example input & output
Example input
- {vendor_name}
- Contoh Cloud Services Sdn Bhd (synthetic)
- {service_description}
- Managed document scanning and indexing for branch loan files
- {contract_text}
- Clause 4.2: Vendor may use sub-processors located in Malaysia or Singapore. Clause 9.1: Client may audit Vendor on 30 days' notice, once per year. Clause 12: Either party may terminate on 90 days' notice. Clause 14: Vendor will return or destroy client data within 60 days of termination.
Example output
1. Scope: Contoh Cloud Services scans and indexes branch loan files and hosts the images for retrieval by credit operations. The service handles customer documents end to end. 2. Material outsourcing: likely yes. The service touches customer information under banking secrecy and a failure would disrupt loan operations. 3. Data location: Clause 4.2 allows sub-processors in Singapore. Customer data leaving Malaysia needs explicit approval and a documented risk assessment. 4. Audit rights: Clause 9.1 gives the Bank one audit per year on 30 days' notice. There is no express right of access for BNM or Internal Audit. 5. Exit: 90 days' notice, data returned or destroyed within 60 days. No exit plan or transition support is described. 6. Gaps to raise: (1) add BNM and Internal Audit access rights; (2) restrict sub-processors to Malaysia or require prior written consent; (3) require a tested exit plan; (4) add incident notification within the timeline RMiT expects.
Details
- Author
- Priya Ramasamy
- Version
- v1.6
- Rating
- ★ 4.5
- Runs
- 410
- Licence
- BU Restricted
- Updated
- 2026-06-22
Powered by
credit-memo-summariser →This template is tuned for the target model above. Forked copies keep the same target model binding until republished.
Community · 0 threads
Questions, findings and requests from the business units that use this asset. Owners reply here; threads with upvotes surface to the owning team's inbox.