Process & executionsupplier due diligencevendor due diligence process

Vendor Due Diligence

The step-by-step process, from pre-screening to sign-off, and how to tell a real due-diligence engagement from a document-collection exercise.

Quick answer

Vendor due diligence is the step-by-step process of investigating a prospective vendor before a contract is signed: pre-screening for obvious disqualifiers, gathering evidence on financial stability and security posture, verifying that evidence against real documentation, and formally signing off against a documented threshold. It runs once per vendor at onboarding, distinct from ongoing TPRM monitoring that continues afterward.

Real US search demand (Ahrefs): ~700 searches/mo for "vendor due diligence" · ~$6.00 CPC.

The buyer problem

"We do vendor due diligence" covers a huge range of actual rigor, from a five-minute web search to a structured, evidenced process with a documented sign-off. Buyers bringing in an advisor or standing up an internal process need a clear picture of what the individual process steps actually are, so they can evaluate whether a proposed engagement is a real due-diligence process or a lighter-weight activity being marketed with due-diligence language.

What a vendor due diligence engagement covers

A vendor due-diligence engagement moves through a defined sequence: pre-screening to rule out obvious disqualifiers (sanctions-list hits, active litigation, no verifiable business registration) before deeper work begins; risk-scoped evidence gathering matched to what the vendor relationship actually involves (financial statements for a vendor handling material spend, security documentation for one touching sensitive data, business-continuity plans for one supporting a critical process); verification of that evidence against source documents rather than vendor self-reporting; and a final sign-off step where findings are weighed against the organization's documented risk thresholds and a decision - approve, approve with conditions, or reject - is formally recorded.

Methods and techniques

  • Pre-screening: sanctions/watchlist checks, business-registration verification, litigation and adverse-media screening
  • Financial due diligence: financial statement review, credit and payment-history checks, insurance-coverage verification
  • Security and operational due diligence: SOC 2/ISO 27001 evidence review, data-handling practices, subcontractor disclosure
  • Business-continuity due diligence: disaster-recovery and continuity plans, historical uptime/incident record where available
  • Reference and track-record checks where the relationship criticality warrants them
  • Formal sign-off against documented thresholds, with the decision and supporting evidence retained on record

What to verify before you retain

  • A defined process, not an activity list. Ask for the actual sequence of steps and what triggers moving from one step to the next. A due-diligence process should have a defined start and a defined sign-off point, not an open-ended list of things that might get checked.
  • Evidence review, not document collection. Confirm whether gathered documents (financial statements, insurance certificates) are actually reviewed for red flags, or simply filed as proof that a document was requested.
  • Pre-screening happens before deep work. A vendor with a sanctions-list hit or no verifiable business registration should be disqualified early, not discovered after a full financial and security review has already been billed.
  • Sign-off is documented and attributable. Ask what the final deliverable looks like. A due-diligence process should end in a specific, retained decision record, not a verbal go-ahead.
  • Depth matches relationship criticality. A vendor supplying office snacks doesn't need the same due-diligence depth as one hosting your production database. Confirm the proposed process actually scales to the relationship.

Questions to put in your RFP

  1. Walk us through your due-diligence process step by step, from initial screening to final sign-off.
  2. What pre-screening checks happen before deeper financial or security work begins?
  3. How do you verify financial statements, insurance certificates, and security evidence rather than just collecting them?
  4. What does the final due-diligence deliverable look like, and how is the sign-off decision documented?
  5. How does the depth of your process scale between a low-risk and a high-risk vendor relationship?
  6. What is your typical turnaround time for a standard vendor due-diligence engagement?

Skip the cold search. Send this scope to us and we route it toward qualified vendor due diligence advisors.

Request advisors

Red flags

  • The process is described only as a document checklist with no verification step.
  • No pre-screening step - deep financial/security work happens before basic disqualifiers are checked.
  • No clearly defined final deliverable or sign-off record.
  • The same process and timeline apply regardless of vendor risk or relationship size.
  • Vague or evasive answers about typical turnaround time or what a completed engagement looks like.

Standards & frameworks referenced

Real, named standards bodies and frameworks relevant to this category. Listed for context; they do not endorse this index or any vendor. Verify any framework-alignment claim directly against the issuing body.

SIG
Shared Assessments Program. The SIG questionnaire is commonly used as the evidence-gathering instrument within a vendor due-diligence process.
FATF
Financial Action Task Force. FATF sanctions and anti-money-laundering guidance informs the pre-screening/watchlist-check step common to rigorous due-diligence processes.

Notable vendor due diligence vendors

Real, publicly-documented vendors active in this category. Sourced and verified; not a ranking or endorsement.

Sourcing intake

Request a vendor due diligence advisor

Tell us the service category and a procurement-safe scope. We route it toward qualified third-party risk management advisory firms and procurement due-diligence consultancies. Keep confidential vendor risk reports or internal system details out of this form. Procurement support, not a compliance guarantee and not legal advice.

No fee. No obligation. We reply by email, usually within one business day.

Vendor Due Diligence: buyer FAQ

Is vendor due diligence a one-time process or ongoing?

Due diligence, strictly defined, is the pre-onboarding investigation and sign-off. Once a vendor is approved, ongoing risk oversight becomes third-party risk management (TPRM) - ongoing monitoring, reassessment, and rescoring over the life of the relationship. Both matter; they're different phases of the same lifecycle.

How long does vendor due diligence usually take?

It depends heavily on relationship criticality and vendor responsiveness. A low-risk vendor with readily available documentation might clear in days; a high-risk vendor requiring financial-statement review, security-evidence verification, and legal review can take several weeks, particularly if evidence has to be requested and chased.

Who should be involved in vendor due diligence?

Procurement typically owns the process, but a genuine due-diligence process usually needs input from security (for data-handling and technical evidence), finance (for financial-stability review), and legal (for contract and liability terms), especially above a defined risk threshold.

Related guides