Vendor due diligence is the process of verifying that a vendor is who they say they are, can deliver what they promise, and does not represent unacceptable risk before you sign a contract and begin work.
The depth of due diligence should be proportional to the risk the vendor represents. A one-time $500 purchase from a known vendor does not need the same process as a $500,000 annual technology contract with a company that handles your customer data.
This checklist covers the full range of due diligence. Apply the sections that are appropriate to the vendor relationship.
Legal and Identity Verification
- Entity verification. Confirm the vendor's legal entity name, business registration, and jurisdiction. Look them up in the state business registry to confirm they are an active, registered entity.
- Business license check. Verify they hold the required business licenses for the work they will be performing in your jurisdiction.
- Professional license verification. If their work requires professional licensure, verify the license is active, in the correct state, and covers the specific work.
- Sanctions screening. If your risk and legal analysis calls for it, screen against current OFAC and other applicable government lists using a documented matching and escalation process.
- Litigation check. A search of public court records for significant pending litigation or judgments can surface risk that is otherwise invisible.
Financial Stability
- Years in business. A vendor with two years of operating history is higher risk than one with ten. This is not disqualifying, but it is relevant.
- Financial references. For high-value relationships, request references from other customers who can speak to the vendor's financial reliability.
- Credit check. For vendors you will be paying in arrears or giving significant advance payments, a business credit report provides useful financial health indicators.
- Insurance adequacy. Verify that coverage meets your requirements. Confirming that a policy exists is not enough.
Compliance Documents
- W-9 on file. Collect before the first payment.
- Certificate of Insurance reviewed. Coverage types, limits, effective dates, and certificate holder verified against your requirements.
- Professional licenses verified. Active, in-jurisdiction, appropriate scope.
- Contract executed. Signed by authorized representatives of both parties before work begins.
- ACH authorization (if paying by direct deposit). Proper authorization form with signature and banking details.
- Tax exemption certificate (if applicable). Valid for your jurisdiction if the vendor claims exemption.
Data Security (For Vendors with System or Data Access)
- Security questionnaire completed. A standard vendor security questionnaire assessing their security controls.
- Independent assurance reviewed. If a vendor provides a SOC 2 report or other independent assurance, review the current report, scope, period, exceptions, and complementary controls relevant to your reliance.
- Data-processing terms evaluated. Determine whether applicable privacy law and the parties' roles require a data-processing agreement or specific contract clauses.
- Technical assurance selected. For higher-risk technology suppliers, choose evidence appropriate to the risk, which may include independent reports, testing summaries, questionnaires, or technical validation.
- Data-protection controls confirmed. Verify the technical and organizational safeguards your risk assessment and contract require.
- Incident response process reviewed. Understand how they will notify you in the event of a breach.
Operational Capability
- Reference checks. Where useful, speak with current or recent customers about delivery, communication, and problem-solving.
- Subcontractor review. If the vendor uses subcontractors for your work, understand who they are and what their compliance looks like.
- Business continuity plan. For critical vendors, verify they have a documented plan for maintaining operations through disruptions.
- Key person dependency. If the relationship depends on one or two specific individuals, understand the vendor's succession plan.
Contract Review
- Scope of work is specific and measurable. Vague scopes create disputes. Verify the contract describes deliverables in terms both parties can objectively evaluate.
- Indemnification is mutual and appropriate. Understand what you are indemnifying the vendor for and what they are indemnifying you for.
- Insurance requirements are specified. The contract should include the insurance requirements and require the vendor to maintain them for the duration of the relationship.
- Data handling terms are present. If the vendor will have access to any customer, employee, or sensitive business data, the contract must address ownership, handling, breach notification, and deletion.
- Termination rights are clear. Know what triggers your right to terminate, how much notice is required, and what your obligations are post-termination.
- Governing law and dispute resolution. Where would a dispute be adjudicated? Is it your jurisdiction or theirs?
Post-Onboarding Considerations
- Expiration tracking established. All time-sensitive documents (COI, licenses, contract term) entered in your tracking system with alerts, and a defined expiration process for when they lapse.
- Vendor contact information recorded. Primary contact, billing contact, and escalation contact on file.
- Review schedule set. Base reassessment frequency and event-driven review on risk, contract, law, incidents, control dependencies, and material changes.
The goal of due diligence is to support an informed decision and surface risks before they become problems. Preserve the assessment and revisit it at the risk-based interval or when material changes, incidents, sanctions updates, ownership changes, or new services warrant review.