Prompt Library / Operational & Third-party Risk

Vendor Contract Summariser

Summarises a vendor contract against outsourcing requirements.

ConfidentialThird-partyGenAIThird-party risk review · by Priya Ramasamy · v1.6
★ 4.5 410 runsUpdated 2026-06-22

Prompt template

3 variables
Summarise the vendor contract below for a third-party risk reviewer at the Bank. Focus on what matters under the BNM Policy Document on Outsourcing and BNM RMiT.

Vendor: {vendor_name}
Service: {service_description}
Contract text:
{contract_text}

Return:
1. Scope of service in two sentences
2. Whether the arrangement looks like material outsourcing, and why
3. Data location and data access terms (flag any customer data leaving Malaysia)
4. Audit and access rights for the Bank, Internal Audit and BNM
5. Termination, exit and business continuity terms
6. Gaps the reviewer should raise with Procurement, as a numbered list
{vendor_name}{service_description}{contract_text}

Playground

Simulated sandbox

Ownership and sensitivity

Owned by

Group Risk ManagementOperational & Third-party Risk

Accountable owner: Aminah Yusof

Who approves access

  1. Owner, Operational & Third-party Risk, Aminah Yusof
  2. Operational & Third-party Risk, Aminah Yusof
Confidential

Business-sensitive. Models and data products scoped to named business units.

Entitlement per business unit, approved by the owner; conditions attach.

Third-party
Supplied by an approved vendor; outsourcing and third-party risk controls apply.
GenAI
Generates text; prompt screening for customer data and output review apply.

Example input & output

Example input

{vendor_name}
Contoh Cloud Services Sdn Bhd (synthetic)
{service_description}
Managed document scanning and indexing for branch loan files
{contract_text}
Clause 4.2: Vendor may use sub-processors located in Malaysia or Singapore. Clause 9.1: Client may audit Vendor on 30 days' notice, once per year. Clause 12: Either party may terminate on 90 days' notice. Clause 14: Vendor will return or destroy client data within 60 days of termination.

Example output

1. Scope: Contoh Cloud Services scans and indexes branch loan files and hosts the images for retrieval by credit operations. The service handles customer documents end to end. 2. Material outsourcing: likely yes. The service touches customer information under banking secrecy and a failure would disrupt loan operations. 3. Data location: Clause 4.2 allows sub-processors in Singapore. Customer data leaving Malaysia needs explicit approval and a documented risk assessment. 4. Audit rights: Clause 9.1 gives the Bank one audit per year on 30 days' notice. There is no express right of access for BNM or Internal Audit. 5. Exit: 90 days' notice, data returned or destroyed within 60 days. No exit plan or transition support is described. 6. Gaps to raise: (1) add BNM and Internal Audit access rights; (2) restrict sub-processors to Malaysia or require prior written consent; (3) require a tested exit plan; (4) add incident notification within the timeline RMiT expects.

Details

Author
Priya Ramasamy
Version
v1.6
Rating
★ 4.5
Runs
410
Licence
BU Restricted
Updated
2026-06-22

Powered by

credit-memo-summariser →

This template is tuned for the target model above. Forked copies keep the same target model binding until republished.

Community · 0 threads

Questions, findings and requests from the business units that use this asset. Owners reply here; threads with upvotes surface to the owning team's inbox.

No threads yet. Be the first to ask, or to share what you found.