Resource - Checklist
Vendor Due Diligence Checklist
Why due diligence decides the whole relationship
Due diligence is the only point in a vendor relationship where you can set conditions instead of requesting favours. Done uniformly it becomes an administrative tax. Done against a dependency map it becomes the mechanism that keeps critical services defensible.
Diligence is your last cheap moment
Before signature you have leverage: you can require evidence, audit rights, subcontractor disclosure and exit terms. After signature every one of those becomes a negotiation. A checklist makes sure nothing that matters is left off the table while it is still free to ask.
Uniform checklists waste the effort
Sending every vendor the same 200-question pack produces volume, not insight. Teams burn weeks reviewing evidence for tools nobody depends on while a genuinely critical dependency gets the same superficial pass. Depth has to follow criticality.
Fourth parties hide in the gaps
Most vendors sit on shared infrastructure and subcontract parts of their delivery. If your checklist does not require that disclosure, you inherit those dependencies unmapped and find out about them during an outage.
The checklist
Eight stages of vendor due diligence
Work through the stages in order. The first stage sets the tier; the remaining seven scale to it. For a low-criticality vendor several stages collapse into a short attestation, and that is the intended outcome.
1. Map the dependency first
Before requesting a single document, record which business services, processes and data this vendor will support, and what happens to those services if the vendor is unavailable for a day, a week, a month. That answer sets the tier and therefore the depth of everything that follows. This is the Where. step.
2. Corporate, legal and regulatory standing
Verify legal entity and registration, beneficial ownership, jurisdictions of operation, sanctions and adverse-media screening, litigation history, and any licences or regulatory authorisations the service requires. Confirm the contracting entity is the one that actually delivers the service.
3. Financial viability
Review audited financials or credit reporting, revenue concentration, funding runway for earlier-stage providers, and insurance cover including cyber and professional indemnity. A vendor whose finances fail is an availability risk regardless of how strong its controls are.
4. Information security controls
Request current certifications and reports rather than self-assertions: ISO 27001 certificate with scope statement, SOC 2 Type II with the auditor's exceptions, recent penetration-test summary, vulnerability-management and patching cadence, access control and MFA posture, encryption in transit and at rest, and logging and monitoring arrangements.
5. Data protection and privacy
Establish what personal or regulated data the vendor will process, on what lawful basis, where it is stored and replicated, which cross-border transfer mechanism applies, retention and deletion commitments, breach-notification timelines, and whether a data processing agreement and, where relevant, an impact assessment are in place.
6. Subcontractors and fourth parties
Require a written list of material subcontractors, the hosting provider and regions, and any onward processors. Ask for notification rights before a subcontractor changes. Check whether their critical dependencies overlap with those of your other vendors, because that overlap is concentration risk you would otherwise never see.
7. Resilience and continuity
Collect the business continuity and disaster recovery plans, stated RTO and RPO against your own service requirements, evidence of the last test and its results, incident-notification commitments and contact paths, and historical uptime or incident disclosure. For critical vendors, confirm what your own contingency is if their plan fails.
8. Contract, monitoring and exit
Close with the terms that keep diligence alive: service levels and remedies, audit and information rights, right to require remediation, security and privacy schedules, and a documented exit plan covering data return and deletion, transition assistance, and the trigger conditions for termination.
Put the checklist to work
Adapt the stages to your regulatory environment and tier definitions, then attach the evidence to the dependency it protects rather than to a vendor folder. Our assessment tools benchmark how well your current onboarding process holds up against this structure.
The foundational principle
Start with Where.
A checklist applied evenly to every vendor tells you a great deal about vendors and almost nothing about your exposure. The difference is knowing which business service sits behind each relationship.
Start with where. Map the dependency, set the tier, then run diligence proportionate to what would actually break.
What good due diligence achieves
The output is not a folder of documents. It is a defensible, proportionate record of what each critical dependency requires and who is accountable for it.
Frequently asked
What is a vendor due diligence checklist?
A vendor due diligence checklist is the structured set of evidence and questions an organisation works through before onboarding a third party. It typically covers legal standing, financial health, information security, data protection, subcontractor disclosure, business continuity and exit terms. VenDefend adds a first step most checklists miss: mapping which business services will depend on the vendor, so the depth of diligence matches the exposure.
What should be included in vendor due diligence?
At minimum: corporate and legal verification, financial viability, security certifications or audit reports, data-protection and cross-border transfer arrangements, subcontractor and fourth-party disclosure, business continuity and disaster recovery evidence, contractual service levels, and documented exit and transition provisions.
How deep should due diligence go for each vendor?
Scale it to criticality, not to spend. A vendor that keeps a revenue-generating service running warrants site or audit-level evidence and named contingency arrangements. A low-criticality tool warrants a short attestation. Mapping dependencies first is what lets you make that call defensibly rather than sending every vendor the same questionnaire.
How often should due diligence be refreshed?
Refresh critical vendors annually and on trigger events: change of ownership, a material incident, a new subcontractor, a shift in hosting or jurisdiction, or a downgrade in financial standing. Lower tiers can run on a two to three year cycle with continuous monitoring in between.
Is due diligence the same as a risk assessment?
No. Due diligence is the evidence-gathering that happens before and at onboarding. A risk assessment interprets that evidence against your risk appetite and the criticality of the service the vendor supports. Due diligence tells you what is true; the assessment tells you whether it is acceptable.
Start with Where.
A 45-minute executive review. We map one critical service with you and show you what your current programme is missing.
