Vendor Due Diligence Checklist
Your vendors' risk becomes your risk. Here's how to assess third parties before and during the relationship.
Book a 20-min deal readiness callBuild a vendor inventory
List every third party and exactly what data or systems they can access.
Tier vendors by risk
A payroll processor is not the same risk as a design tool. Prioritize accordingly.
Collect security documentation
Request SOC 2 reports, ISO 27001 certificates, pen test summaries, and questionnaires.
Review data handling
Understand what data they access, where it's stored, and how it's protected.
Check compliance posture
Confirm they meet the frameworks your own customers require of you.
Sign the right agreements
DPA, BAA, and security addenda as applicable to the data involved.
Assess subprocessors
Know who your vendors rely on downstream, since their risk flows to you.
Set a review cadence
Re-assess high-risk vendors at least annually, not just at onboarding.
Monitor for changes
Watch for breaches, ownership changes, and posture drift over time.
Document everything
Keep an auditable trail of your due diligence for every vendor.
What auditors actually ask for
- Do you have a complete vendor inventory with data-access mapping?
- Are vendors risk-tiered, with deeper diligence on the critical ones?
- Have you collected and reviewed current SOC 2 or ISO certificates?
- Are DPAs and BAAs signed where applicable?
- When did you last reassess your high-risk vendors?
Where teams most often trip up
- Collecting a SOC 2 report but never actually reading the exceptions
- One-time onboarding checks with no reassessment cadence
- No visibility into fourth parties, your vendors' vendors
- Treating every vendor with equal scrutiny, which exhausts the team
- Certificates expiring unnoticed
Realistic timeline
Standing up a tiered programme takes 3-6 weeks; reassessment is annual for high-risk vendors.