Vendor due diligence

Vendor due diligence, before you sign.

Vendor due diligence is the investigation you run on a supplier before you commit — what it would hold, what happens if it fails, whether it is financially and legally sound, and whether its security holds up. It decides whether the relationship should exist and on what terms. This page covers what to ask, how deep to go, and where most programs waste the effort.

Last reviewed by Darren Craig

What is vendor due diligence?

A pre-contract decision, not a recurring one.

Vendor due diligence is the work you do before a contract exists: establishing who the supplier is, what the arrangement would expose you to, and whether the answers are good enough to proceed. It covers more than security. Financial stability and ownership, sanctions and adverse media, insurance, data protection and international transfers, resilience, sub-contracting, and — in UK and EU procurement — modern slavery and anti-bribery positions all sit inside it.

The distinction from a vendor risk assessment is timing and purpose rather than method. Due diligence answers "should we do this at all, and on what terms". The assessment answers "is this relationship still acceptable", repeatedly, for as long as it lasts. Due diligence has leverage the assessment never will: before signature you can still walk away, and the supplier knows it.

Third-party due diligence is the same exercise with a wider population. A vendor is someone you buy from; a third party is anyone outside your organization whose failure lands on you, which includes partners, agents, franchisees and the parties you share data with without a purchase order. If your diligence is scoped from the supplier list finance exports, the parties it omits are by definition the ones nobody has looked at.

The vendor due diligence checklist checklist

Seven areas. Scale the depth to the tier — a supplier with no data access and no operational dependency does not need all of this, and asking anyway is how response rates collapse.

  • Corporate and financial standing
    Registered entity, beneficial ownership, filed accounts, and whether the company is solvent enough to still be here in three years. Cheap to check and the failure mode nobody models: suppliers that go under take your service with them.
  • Sanctions, adverse media and integrity
    Sanctions and PEP screening on the entity and its owners, court records, regulatory enforcement, and negative news. In regulated sectors this is not optional, and it is the check most often skipped for a supplier someone already wants to use.
  • Security posture and controls
    Independent assurance first — SOC 2 Type II, ISO 27001 with its statement of applicability, recent penetration test summaries — then a security questionnaire for what the documents did not answer. Not the other way round.
  • Data protection
    What personal data is involved, the lawful basis, where it will be processed, and whether a data processing agreement and a transfer mechanism are in place. Ask for the sub-processor list at this stage: it is the cheapest fourth-party visibility you will ever get.
  • Resilience and continuity
    Recovery objectives, when continuity was last tested and what the test found, and — for anything critical — whether you could exit and where you would go. An exit plan written after signature is a document; one written before it is leverage.
  • Sub-contracting and concentration
    Who the supplier depends on to deliver, whether those parties change without notice, and whether they are the same providers half your other suppliers use. Concentration is invisible per supplier and obvious across the portfolio.
  • Contract terms the diligence feeds
    Diligence findings are worth nothing unless they change the contract: audit rights, breach notification windows, sub-contractor approval, data location and return, remediation obligations, and the exit terms. This is where the leverage gets spent.

The vendor due diligence process process

Five stages. The order matters more than the content: nearly every wasted week in diligence comes from doing stage three before stage one.

  1. 1. Scope it on inherent risk
    Before anything is sent, establish what the supplier would hold, reach and support. That is inherent risk, it is knowable from the business owner in minutes, and it sets how deep the rest goes. Skipping it is how a stationery supplier receives a 300-question security review.
  2. 2. Collect what already exists
    Certifications, audit reports, test summaries, filed accounts, trust centre content, published sub-processor lists. A current SOC 2 Type II and an ISO 27001 certificate answer a large share of a standard questionnaire between them, and the supplier does not have to lift a finger for you to read them.
  3. 3. Question only the gaps
    Then issue a questionnaire scoped to what the documents left open. A short, specific question set returns faster and produces better evidence than a long generic one, and it is the difference between a supplier that engages and a supplier that stalls.
  4. 4. Validate rather than file
    Check the answers against the documents and against what the supplier’s external estate actually shows. Contradictions between a questionnaire and a document the same supplier provided are the highest-value finding in the whole exercise — and the one a human reading their nineteenth review of the month will miss.
  5. 5. Decide, and write the decision down
    Proceed, proceed with conditions in the contract, proceed with remediation by a date, or decline. Record who accepted any residual risk, against what appetite, and until when. A diligence file with no recorded decision is an audit finding waiting to be written.

How deep to go

Depth proportional to exposure. The two ends of the range, with everything in between scaled between them.

Low inherent risk
A screen, not an investigation
  • Entity and solvency check, sanctions screen
  • Evidence of a current certification, if one exists
  • Standard contract terms, no negotiation
  • Reassess on change, not on a calendar
  • Hours, not weeks
Critical vendor
The full exercise
  • Ownership, financials, sanctions, adverse media
  • Independent assurance read in full, not filed
  • Scoped questionnaire, answers validated against evidence
  • Sub-processor list and fourth-party mapping
  • Negotiated audit, notification and exit terms
  • Tested exit plan before signature

Vendor due diligence software

What tooling changes, and what it does not.

Due diligence software earns its place on the logistics: maintaining the register, scoping question sets by tier, chasing suppliers who have not replied, storing evidence against controls so it can be found again, and producing the audit trail that shows what was asked, what came back and who decided. That is most of the elapsed time in a diligence cycle and almost none of the judgement.

What it does not change: who decides the relationship is acceptable, what your risk appetite is, and who signs when a supplier falls short of it. A platform that automates the chasing and keeps the decisions is the one that scales. RiskXchange runs the collection and validation side — documents parsed against a 157-control framework, questionnaire answers cross-checked against external evidence, outreach and chasing handled per vendor — and leaves the decision with the person accountable for it.

Where diligence goes wrong

Four failures, in the order they cost the most.

Diligence after selection. The business has chosen, the start date is set, and the review becomes a formality nobody is empowered to fail. If the only acceptable outcome is "proceed", the exercise is theatre — and expensive theatre, because it consumes the one moment when you had leverage.

The same depth for everyone. Uniform diligence spreads a fixed amount of effort evenly across suppliers whose risk is not evenly distributed, producing thin assurance everywhere and real assurance nowhere.

Findings that never reach the contract. A weakness identified before signature and not written into terms is a weakness you have documented and accepted. The file proves you knew.

Nothing after day one. Diligence describes a supplier on the day it was done. Everything after that is a claim about the past being used as a statement about the present, which is what continuous monitoring exists to fix.

Vendor due diligence, answered.

What is vendor due diligence?
The investigation run on a supplier before contracting: what it would hold and reach, whether it is financially and legally sound, whether its security holds up, and what happens if it fails. It decides whether the relationship should exist and what the contract has to contain.
What should a vendor due diligence checklist contain?
Seven areas: corporate and financial standing; sanctions, adverse media and integrity; security posture and independent assurance; data protection and sub-processors; resilience and exit; sub-contracting and concentration; and the contract terms the findings feed. Scale the depth to inherent risk rather than sending all of it to every supplier.
What is the difference between vendor due diligence and a vendor risk assessment?
Timing and purpose. Due diligence happens before contract and decides whether the relationship should exist, while you still have the leverage to walk away. A vendor risk assessment is the recurring examination of a relationship that already exists. The methods overlap heavily; what they decide does not.
What is third-party due diligence?
The same exercise across a wider population. A vendor is someone you buy from; a third party is anyone outside your organization whose failure reaches you, including partners, agents, franchisees and data-sharing counterparties you do not pay. The method is identical — the scoping is not.
How long should vendor due diligence take?
For a low-risk supplier, hours: an entity and sanctions check and evidence of a current certification. For a critical vendor, weeks — most of it waiting on the supplier rather than working. Collecting existing documents before issuing a questionnaire is the single biggest lever on that elapsed time.
Do you need a questionnaire if the vendor has a SOC 2?
Usually a much shorter one. A current SOC 2 Type II covering the relevant criteria has already tested access management, change control and monitoring, so the questionnaire should cover what the report’s scope excludes — carve-outs, sub-service organizations, and anything specific to how you will use the service.

Diligence is mostly waiting. It does not have to be.

See a supplier scored from the outside before they have answered a single question.