Vendor due diligence, before you sign.
Vendor due diligence is the investigation you run on a supplier before you commit — what it would hold, what happens if it fails, whether it is financially and legally sound, and whether its security holds up. It decides whether the relationship should exist and on what terms. This page covers what to ask, how deep to go, and where most programs waste the effort.
Last reviewed by Darren Craig
What is vendor due diligence?
A pre-contract decision, not a recurring one.
Vendor due diligence is the work you do before a contract exists: establishing who the supplier is, what the arrangement would expose you to, and whether the answers are good enough to proceed. It covers more than security. Financial stability and ownership, sanctions and adverse media, insurance, data protection and international transfers, resilience, sub-contracting, and — in UK and EU procurement — modern slavery and anti-bribery positions all sit inside it.
The distinction from a vendor risk assessment is timing and purpose rather than method. Due diligence answers "should we do this at all, and on what terms". The assessment answers "is this relationship still acceptable", repeatedly, for as long as it lasts. Due diligence has leverage the assessment never will: before signature you can still walk away, and the supplier knows it.
Third-party due diligence is the same exercise with a wider population. A vendor is someone you buy from; a third party is anyone outside your organization whose failure lands on you, which includes partners, agents, franchisees and the parties you share data with without a purchase order. If your diligence is scoped from the supplier list finance exports, the parties it omits are by definition the ones nobody has looked at.
The vendor due diligence checklist checklist
Seven areas. Scale the depth to the tier — a supplier with no data access and no operational dependency does not need all of this, and asking anyway is how response rates collapse.
- Corporate and financial standingRegistered entity, beneficial ownership, filed accounts, and whether the company is solvent enough to still be here in three years. Cheap to check and the failure mode nobody models: suppliers that go under take your service with them.
- Sanctions, adverse media and integritySanctions and PEP screening on the entity and its owners, court records, regulatory enforcement, and negative news. In regulated sectors this is not optional, and it is the check most often skipped for a supplier someone already wants to use.
- Security posture and controlsIndependent assurance first — SOC 2 Type II, ISO 27001 with its statement of applicability, recent penetration test summaries — then a security questionnaire for what the documents did not answer. Not the other way round.
- Data protectionWhat personal data is involved, the lawful basis, where it will be processed, and whether a data processing agreement and a transfer mechanism are in place. Ask for the sub-processor list at this stage: it is the cheapest fourth-party visibility you will ever get.
- Resilience and continuityRecovery objectives, when continuity was last tested and what the test found, and — for anything critical — whether you could exit and where you would go. An exit plan written after signature is a document; one written before it is leverage.
- Sub-contracting and concentrationWho the supplier depends on to deliver, whether those parties change without notice, and whether they are the same providers half your other suppliers use. Concentration is invisible per supplier and obvious across the portfolio.
- Contract terms the diligence feedsDiligence findings are worth nothing unless they change the contract: audit rights, breach notification windows, sub-contractor approval, data location and return, remediation obligations, and the exit terms. This is where the leverage gets spent.
The vendor due diligence process process
Five stages. The order matters more than the content: nearly every wasted week in diligence comes from doing stage three before stage one.
- 1. Scope it on inherent riskBefore anything is sent, establish what the supplier would hold, reach and support. That is inherent risk, it is knowable from the business owner in minutes, and it sets how deep the rest goes. Skipping it is how a stationery supplier receives a 300-question security review.
- 2. Collect what already existsCertifications, audit reports, test summaries, filed accounts, trust centre content, published sub-processor lists. A current SOC 2 Type II and an ISO 27001 certificate answer a large share of a standard questionnaire between them, and the supplier does not have to lift a finger for you to read them.
- 3. Question only the gapsThen issue a questionnaire scoped to what the documents left open. A short, specific question set returns faster and produces better evidence than a long generic one, and it is the difference between a supplier that engages and a supplier that stalls.
- 4. Validate rather than fileCheck the answers against the documents and against what the supplier’s external estate actually shows. Contradictions between a questionnaire and a document the same supplier provided are the highest-value finding in the whole exercise — and the one a human reading their nineteenth review of the month will miss.
- 5. Decide, and write the decision downProceed, proceed with conditions in the contract, proceed with remediation by a date, or decline. Record who accepted any residual risk, against what appetite, and until when. A diligence file with no recorded decision is an audit finding waiting to be written.
How deep to go
Depth proportional to exposure. The two ends of the range, with everything in between scaled between them.
- Entity and solvency check, sanctions screen
- Evidence of a current certification, if one exists
- Standard contract terms, no negotiation
- Reassess on change, not on a calendar
- Hours, not weeks
- Ownership, financials, sanctions, adverse media
- Independent assurance read in full, not filed
- Scoped questionnaire, answers validated against evidence
- Sub-processor list and fourth-party mapping
- Negotiated audit, notification and exit terms
- Tested exit plan before signature
Vendor due diligence software
What tooling changes, and what it does not.
Due diligence software earns its place on the logistics: maintaining the register, scoping question sets by tier, chasing suppliers who have not replied, storing evidence against controls so it can be found again, and producing the audit trail that shows what was asked, what came back and who decided. That is most of the elapsed time in a diligence cycle and almost none of the judgement.
What it does not change: who decides the relationship is acceptable, what your risk appetite is, and who signs when a supplier falls short of it. A platform that automates the chasing and keeps the decisions is the one that scales. RiskXchange runs the collection and validation side — documents parsed against a 157-control framework, questionnaire answers cross-checked against external evidence, outreach and chasing handled per vendor — and leaves the decision with the person accountable for it.
Where diligence goes wrong
Four failures, in the order they cost the most.
Diligence after selection. The business has chosen, the start date is set, and the review becomes a formality nobody is empowered to fail. If the only acceptable outcome is "proceed", the exercise is theatre — and expensive theatre, because it consumes the one moment when you had leverage.
The same depth for everyone. Uniform diligence spreads a fixed amount of effort evenly across suppliers whose risk is not evenly distributed, producing thin assurance everywhere and real assurance nowhere.
Findings that never reach the contract. A weakness identified before signature and not written into terms is a weakness you have documented and accepted. The file proves you knew.
Nothing after day one. Diligence describes a supplier on the day it was done. Everything after that is a claim about the past being used as a statement about the present, which is what continuous monitoring exists to fix.
Vendor due diligence, answered.
What is vendor due diligence?
What should a vendor due diligence checklist contain?
What is the difference between vendor due diligence and a vendor risk assessment?
What is third-party due diligence?
How long should vendor due diligence take?
Do you need a questionnaire if the vendor has a SOC 2?
Related reading.
Diligence is mostly waiting. It does not have to be.
See a supplier scored from the outside before they have answered a single question.