Vendor Due Diligence
Vendor due diligence is how you assess a third-party vendor's risk. See the process, a full checklist, risk tiers, and red flags
What is vendor due diligence?
Vendor due diligence is the process an organization uses to assess the financial, legal, security, compliance, operational, and reputational risks of working with a third-party vendor before signing, and to keep monitoring those risks throughout the relationship. It replaces trust with evidence, so the buyer knows a vendor can deliver and will not introduce unacceptable risk.
Unlike the one-time due diligence in a merger, vendor due diligence is ongoing. A vendor is reassessed on a schedule set by its risk level, because a supplier that was safe last year may not be today. It usually runs through a questionnaire the vendor completes, backed by independent verification.
Why vendor due diligence matters
A vendor's failure becomes your failure. A supplier that suffers a breach, misses its service levels, or falls out of compliance can disrupt your operations, expose your customers' data, and damage your reputation. Third-party incidents are among the most common and most costly sources of enterprise risk, which is why regulated industries mandate a formal vendor risk program. Due diligence is how you catch the risk before you sign, not after.
The risks vendor due diligence assesses
The vendor due diligence process
- Set policy and ownership. Define who runs the program and what standards vendors must meet.
- Categorize the vendor by risk. A vendor handling customer data carries more risk than a stationery supplier.
- Collect information. Send a due diligence questionnaire covering the risk areas above.
- Verify independently. Confirm certifications, financials, and references rather than taking claims at face value.
- Score the risk. Rate the vendor and decide whether to proceed, proceed with conditions, or decline.
- Document and contract. Record the findings and reflect them in the contract, then monitor on a schedule.
Vendor due diligence checklist
Work through each category before onboarding a vendor.
Company and financial
- Legal structure, ownership, and locations.
- Multi-year financial statements and stability.
- Insurance coverage and funding dependencies.
Legal and compliance
- Required licenses and registrations.
- Litigation history and sanctions screening.
- Data privacy practices and applicable regulations.
Security and technology
- SOC 2 Type II, ISO 27001, or equivalent certifications.
- Access controls, encryption, and incident response.
- Disaster recovery and business continuity plans.
Operational and reputational
- Service-level agreements and past performance.
- Customer references and support model.
- Ethics, ESG policy, and any adverse media.
For a ready-made version, see our vendor risk assessment template.
Risk tiers and review cadence
Not every vendor needs the same scrutiny. Tier vendors by risk and review them on a matching schedule.
Red flags to watch for
- Incomplete or evasive answers to the questionnaire.
- Missing or expired security certifications.
- Frequent service-level breaches or thin recovery plans.
- Negative regulatory attention or unresolved litigation.
- Heavy dependence on a single customer or supplier.
Vendor due diligence vs the DDQ vs a security questionnaire
These terms overlap. Vendor due diligence is the overall process. The due diligence questionnaire (DDQ) is the document that collects the information. A security questionnaire is the security-focused part of that document. In practice, the buyer runs due diligence by sending a questionnaire, and the vendor's job is to answer it accurately and fast.
For the vendor being assessed, diligence is a speed test
Buyers run due diligence. If you are the vendor on the receiving end, the questionnaires arrive constantly, repeat the same questions, and every slow or inconsistent answer stalls your deal.
Inventive AI drafts each answer from your connected knowledge with a source citation and a confidence score, flags anything outdated, and keeps every response consistent, so you clear diligence in hours instead of weeks. It is SOC 2 Type II compliant and does not train public models on your data.
Frequently Asked Questions
Everything you need to know about Inventive AI. Can’t find the answer you’re looking for? Please chat to our friendly team.
What is vendor due diligence?
Vendor due diligence is the process of assessing a third-party vendor's financial, legal, security, compliance, operational, and reputational risk before signing, and monitoring it throughout the relationship.
What does a vendor due diligence checklist include?
Company and financial information, legal and compliance status, security and technology controls, and operational and reputational factors such as service levels, references, and ethics.
What are the steps in the vendor due diligence process?
Set policy and ownership, categorize the vendor by risk, collect information via a questionnaire, verify it independently, score the risk, and document the findings in the contract, then monitor on a schedule.
How often should you review vendors?
By risk tier: high-risk vendors quarterly, medium-risk semiannually, and low-risk annually.
What is the difference between vendor due diligence and a DDQ?
Vendor due diligence is the overall process of assessing a vendor. A due diligence questionnaire is the document used to collect the information the process needs.
What are red flags in vendor due diligence?
Incomplete answers, missing or expired certifications, frequent service-level breaches, negative regulatory attention, and heavy dependence on a single customer or supplier.