Automate Vendor Due Diligence Research with Gemini & Jina AI

This workflow contains community nodes that are only compatible with the self-hosted version of n8n.

Screenshot 20250706 at 3.09.17 PM.png

πŸ‘₯ Who is this for?

This workflow is designed for a variety of professionals who manage vendor relationships and data security. It is especially beneficial for:

  • πŸ›‘οΈ GRC (Governance, Risk, and Compliance) Professionals: Streamline your risk assessment processes
  • πŸ”’ Information Security Teams: Quickly evaluate the security posture of third-party vendors
  • πŸ“‹ Procurement Departments: Enhance due diligence when onboarding new service providers
  • πŸš€ Startup Founders: Efficiently assess vendors without a dedicated security team

This tool is perfect for anyone looking to automate the manual review of vendor websites, policies, and company data. ✨

🎯 What problem is this workflow solving?

Manual vendor due diligence is a time-consuming process that can take hours for a single vendor. This workflow automates over 80% of these manual tasks, which typically include:

  • πŸ” Finding and organizing basic vendor information
  • 🏒 Researching the company's background
  • πŸ“„ Collecting links to key documents like Privacy Policies, Terms of Service, and Trust Pages
  • πŸ“– Manually reviewing each document to extract risk-relevant information
  • πŸ“Š Compiling all findings into a formatted report or spreadsheet for record-keeping

By leveraging Gemini for structured parsing and web scraping with live internet data, this workflow frees you up to focus on critical analysis and final review. ⚑

βš™οΈ What this workflow does

This end-to-end automated n8n workflow performs the following steps:

  1. πŸ“ Intake: Begins with a simple form to capture the vendor's name, the business use case, and the type of data they will handle
  2. πŸ”Ž Background Research: Gathers essential background information on the company
  3. ⚠️ Risk Analysis: Conducts comprehensive research on various risk-related topics
  4. πŸ”— URL Extraction: Finds and validates public URLs for privacy policies, security pages, and trust centers
  5. πŸ“ˆ Risk Assessment: Generates a structured risk score and a detailed assessment based on the collected content and context
  6. πŸ“€ Export: Exports the final results to a Google Sheet for easy access and record-keeping

πŸš€ Setup

To get started with this workflow, follow these steps:

  1. πŸ”‘ Configure Credentials: Set up your API credentials for Gemini and Jina AI
  2. πŸ“Š Connect Google Sheets: Authenticate your Google Sheets account and configure the the Sheet where you want to store the results
  3. πŸ”— Download the Google Sheet template for your assessment ouput from here
  4. βš™οΈ (Optional) Customize Prompts: Adjust the prompts within the workflow to better suit your specific needs
  5. 🎯 (Optional) Align Risk Framework: Modify the risk questions to align with your organization's internal vendor risk framework