Vendor Due Diligence Checklist | Certifyi
Compliance checklist

Vendor Due Diligence Checklist

Your vendors' risk becomes your risk. Here's how to assess third parties before and during the relationship.

Book a 20-min deal readiness call
  1. Build a vendor inventory

    List every third party and exactly what data or systems they can access.

  2. Tier vendors by risk

    A payroll processor is not the same risk as a design tool. Prioritize accordingly.

  3. Collect security documentation

    Request SOC 2 reports, ISO 27001 certificates, pen test summaries, and questionnaires.

  4. Review data handling

    Understand what data they access, where it's stored, and how it's protected.

  5. Check compliance posture

    Confirm they meet the frameworks your own customers require of you.

  6. Sign the right agreements

    DPA, BAA, and security addenda as applicable to the data involved.

  7. Assess subprocessors

    Know who your vendors rely on downstream, since their risk flows to you.

  8. Set a review cadence

    Re-assess high-risk vendors at least annually, not just at onboarding.

  9. Monitor for changes

    Watch for breaches, ownership changes, and posture drift over time.

  10. Document everything

    Keep an auditable trail of your due diligence for every vendor.

← Back to all checklists

What auditors actually ask for

  • Do you have a complete vendor inventory with data-access mapping?
  • Are vendors risk-tiered, with deeper diligence on the critical ones?
  • Have you collected and reviewed current SOC 2 or ISO certificates?
  • Are DPAs and BAAs signed where applicable?
  • When did you last reassess your high-risk vendors?

Where teams most often trip up

  • Collecting a SOC 2 report but never actually reading the exceptions
  • One-time onboarding checks with no reassessment cadence
  • No visibility into fourth parties, your vendors' vendors
  • Treating every vendor with equal scrutiny, which exhausts the team
  • Certificates expiring unnoticed

Realistic timeline

Standing up a tiered programme takes 3-6 weeks; reassessment is annual for high-risk vendors.

Scroll to Top