Understanding the full scope of vendor risks is crucial to supply chain-related decision-making—but it may not be the easiest of tasks. According to Optiv’s research, 74% of companies do not have a list of all the vendors that have access to their data and personally identifiable information (PII), while 23% don’t evaluate third parties at all.

This is a major oversight as it can leave an organization vulnerable to numerous unidentified risks. To prevent this issue and understand vendor risks more deeply, you need to implement a comprehensive vendor due diligence (VDD) process.

Our guide will teach you everything you should know about VDD, including:

  • Common VDD use cases and benefits
  • The three approaches to VDD
  • Steps to conducting VDD (with a documentation checklist)

What is vendor due diligence?

Vendor due diligence is the process of gathering and assessing data from a vendor, supplier, or a similar third party to determine whether their business and security practices are acceptable for you to proceed with a partnership. It’s a crucial aspect of vendor risk management (VRM) because it lets you proactively address threats and vulnerabilities that can be exploited during the vendor lifecycle.

Specifically, VDD lets you address various types of vendor risks, such as:

{{cta_withimage20="/cta-blocks"}}

Vendor due diligence use cases

Organizations typically conduct due diligence before onboarding a new vendor—but this isn’t the only scenario where it can be useful. It’s also worth performing vendor due diligence in the following situations:

  • Contract renewals
  • Major regulatory changes
  • Service additions, changes, or updates
  • Service issues

There are two main categories of vendor due diligence:

  1. Initial: A traditional type of procurement-related due diligence performed after a vendor responds to a request for proposal (RFP).
  2. Ongoing: Conducted periodically to remediate specific issues, uncover new risk points, and shape future vendor relationships.

Risk managers should combine both types of due diligence to fine-tune their VRM program and prioritize relevant risks as they emerge.

Benefits of vendor due diligence

Thorough due diligence might seem like a considerable endeavor—but it’s well worth the effort and resources you invest in it. In today’s complex supply chain environment with multiple interrelated parties, VDD offers the following concrete benefits:

Increased confidence in vendor decisions

Vendor due diligence gives you critical security and performance information before you commit to a partnership. Instead of relying on a sales pitch or a gut feeling, you make the call based on evidence. That confidence matters most for the vendors you'll depend on heavily, where a wrong choice is expensive to unwind.

Risk identification and mitigation

VDD gives you a clear understanding of the vendor's risk profile, which you can then compare to your organization's risk appetite. From there you can decide whether the detected risk level is acceptable, or whether the vendor needs to close gaps first. The same process helps you develop proactive response plans for high-tier risk events, so you're not improvising when something goes wrong.

Better visibility of vendor risks

If each vendor goes through a thorough VDD process, there's a much lower chance of a risk slipping past you undetected. You build a consistent picture of where your exposure actually sits across your whole vendor base. That visibility turns a pile of one-off assessments into something you can manage as a program.

Regulatory compliance

Some regulations make vendor due diligence a legal obligation, not just good practice. Under GDPR, you can only hand personal data to a processor that gives sufficient guarantees they'll protect it, which means you have to vet them first. HIPAA places similar duties on healthcare organizations and the vendors handling protected health information. Running documented diligence is how you satisfy these requirements and how you prove you did when a regulator asks.

Negotiation leverage with vetted vendors

A VDD report paints a risk-aware vendor profile, which can prevent overpriced bids and help you negotiate on favorable terms. Knowing a vendor's weak spots gives you something to push on during contracting. You can tie pricing or specific protections to the gaps you found, rather than accepting the terms as offered.

Three approaches to vendor due diligence

Depending on the size and complexity of your vendor network, as well as your available resources and staff, you can choose between the following three approaches to VDD:

1. In-house VDD

In-house VDD suggests you take care of the entire process internally, which enables complete control over every activity. For some organizations, this can mean they save a sizable amount of money they’d otherwise spend on outsourced procedures.

The downside of in-house VDD is that it can be time-consuming and potentially burden your team with additional work, especially if you rely on disparate systems and manual processes. The best way around this is to use a capable vendor risk management platform that can automate and streamline VDD and other activities to simplify your team's workflows.

{{cta_webinar4="/cta-blocks"}} | Webinar: Vendor risk management

2. Shared VDD

Shared VDD refers to networks and data pools where you can find completed risk assessments and other relevant content maintained by vendors. The idea is for vendors to share resources like audit reports and compliance certificates on an accessible platform. This provides prospective organizations with up-to-date information during their diligence process.

While this approach takes most of the data-gathering work off your hands, it may not be as comprehensive as internal VDD. Every vendor has a unique risk profile, so you may still want to conduct a more tailored due diligence internally.

3. Outsourced VDD

The third option is to outsource VDD entirely to a provider offering managed services. This might be a good idea if your organization is severely understaffed and doesn’t have the necessary know-how or software resources.

Still, outsourced VDD can be quite costly, so it might not be the best solution for organizations on a limited risk management budget.

How to perform vendor due diligence

The VDD process involves the following four steps:

Step 1: Planning a baseline

The first step is preparation. Start by setting the objective of the process, since that informs everything after it. If the goal is to look into a specific compliance concern with an existing vendor, for example, you'll request a focused set of documentation, like evidence of recurring activities, policies, procedures, or a third-party attestation.

This is also where you assess your organization's risk appetite, the level of risk you're willing to accept across different vulnerabilities a vendor might bring, whether financial, operational, or otherwise. Once you set that baseline, you have a clear reference point to compare findings against when it's time to decide.

Part of planning is deciding how much diligence a given vendor warrants. Not every vendor needs the same scrutiny, and treating them as if they do is how programs drown. Score each vendor on how sensitive the data they'll access is, how deep their system access goes, and how much your operations would suffer if they failed. Most vendors sort cleanly into three tiers.

Tier What lands here Diligence depth Review frequency
Critical Deep system access or large volumes of sensitive data; a failure would halt your business. Full assessment with security reports, financial review, and expert sign-off. Continuous monitoring plus an annual deep review.
High Some sensitive data or moderate access; a failure would cause real disruption. Security questionnaire, attestation review, and targeted follow-up. Annual review with monitoring on key controls.
Low No access to sensitive data or systems; a failure is an inconvenience. A light check of the basics and reputation. Reassess only when something changes.

Finally, check any regulations and standards, whether industry- or location-specific, that affect your vendor relationships. The goal is to know whether you need to report specific information to regulatory bodies, which matters most if you're in a heavily regulated industry.

Step 2: Gathering documents and analyzing various risks

The scope of VDD paperwork may typically cover the following six types of analyses:

  1. Financial analysis
  2. Cybersecurity assessment
  3. Market assessment
  4. Legal and compliance assessment
  5. Operational review
  6. HR evaluation

Each of these analyses requires you to collect specific documents and data. The following table provides a condensed checklist of some of the key items you should gather:

Analysis Documents and data points
Financial analysis
  • Annual report
  • Tax documents
  • Loans and liabilities
Cybersecurity assessment
  • Internal or third-party cybersecurity audit reports
  • Data breach history
  • Incident response plan
  • Penetration testing report
  • Disaster recovery plan
Market assessment
  • Business plans
  • Main competitors
  • Industry trends
Legal and compliance assessment
  • Relevant regulatory and compliance attestations
  • Litigation history reports
  • Ongoing legal liabilities
Operational review
  • Business licenses
  • Corporate structure reports
  • List of subcontractors
HR evaluation
  • Hiring policies
  • Biographical data of key executives
  • Corporate culture statements

How deep you go in each area depends on the tier you assigned in the first step. A critical vendor warrants the full set, while a low-risk one needs only the basics. Wherever a vendor already holds an attestation like a SOC 2 report, ask for that first, because it answers more questions, more credibly, than any form you write. Organizations using a vendor management platform usually gather and store these documents in one place, which gives risk teams shared visibility instead of scattered email threads.

{{cta_withimage5="/cta-blocks"}}

Step 3: Report and decide

Once you've gathered and assessed the data, turn it into actionable insight through a VDD report. There's no fixed structure it has to follow, but it should cover the scope of the diligence, the key findings and risks, and your suggestions for the path forward.

The report is what drives the decision, and for any given gap you have four honest responses. You can accept it if it's minor and within tolerance, mitigate it on your side with compensating controls, require the vendor to remediate before you proceed, or walk away. Share the report with the relevant stakeholders, including your legal and financial teams, to gather the input you'll use to make the final call. Whatever you decide, record the reasoning, because that rationale is what protects you if a vendor incident ever lands on your desk.

The findings should also shape the contract. What you learned in diligence tells you which protections to negotiate, like a right to audit, defined breach notification windows, specific data handling requirements, service-level commitments, and disclosure of any subcontractors who'll touch your data. A strong assessment that leads to a weak contract leaves the risk exactly where you found it. The contract is where your diligence becomes enforceable.

Step 4: Establishing continuous monitoring procedures

VDD isn’t only done pre-emptively or on a one-time basis. Risks don’t disappear after you’ve onboarded a vendor—if anything, many risks surface later (e.g., data privacy risks). That’s why you need to have a continuous monitoring process and system in place to track interconnected vendors and perform periodic assessments throughout your partnerships with them.

For such a continuous system to work, set clear monitoring parameters and controls against which you’ll compare a vendor’s performance and risk profile. Another great practice is to configure a unified overview of your relevant vendor risk data on a dashboard so that potential threats aren’t overlooked.

Develop in-depth VDD processes with Vanta

Vanta is an end-to-end trust management platform that helps organizations of all sizes automate compliance, manage risk, and prove trust. With Vanta's Vendor Risk Management Platform, you can automate VDD and other VRM processes. The platform comes with built-in content—like risk scenarios and checklists— to help you design a tailored VDD workflow. Here are some features loved by VRM teams:

  • Automated vendor discovery (which also helps you uncover shadow IT)
  • Centralized vendor inventory with risk-tier categorizations
  • Customizable vendor risk auto-scoring and visualizations for easy comparison
  • Continuous monitoring of vendor status and risk profile
  • Over 400 integrations with various platforms, including procurement solutions
  • Vanta AI for fast review of vendor documents

Vanta also lets you (and any vendor using the platform) showcase your security and compliance posture through a dedicated Trust Center.

If you want to see the above features live, schedule a custom demo or or watch our free webinar to get started.

{{cta_simple5="/cta-blocks"}}

Vendor lifecycle management

Vendor due diligence (VDD): A step-by-step guide

Written by
Vanta
Written by
Vanta
Reviewed by

Understanding the full scope of vendor risks is crucial to supply chain-related decision-making—but it may not be the easiest of tasks. According to Optiv’s research, 74% of companies do not have a list of all the vendors that have access to their data and personally identifiable information (PII), while 23% don’t evaluate third parties at all.

This is a major oversight as it can leave an organization vulnerable to numerous unidentified risks. To prevent this issue and understand vendor risks more deeply, you need to implement a comprehensive vendor due diligence (VDD) process.

Our guide will teach you everything you should know about VDD, including:

  • Common VDD use cases and benefits
  • The three approaches to VDD
  • Steps to conducting VDD (with a documentation checklist)

What is vendor due diligence?

Vendor due diligence is the process of gathering and assessing data from a vendor, supplier, or a similar third party to determine whether their business and security practices are acceptable for you to proceed with a partnership. It’s a crucial aspect of vendor risk management (VRM) because it lets you proactively address threats and vulnerabilities that can be exploited during the vendor lifecycle.

Specifically, VDD lets you address various types of vendor risks, such as:

{{cta_withimage20="/cta-blocks"}}

Vendor due diligence use cases

Organizations typically conduct due diligence before onboarding a new vendor—but this isn’t the only scenario where it can be useful. It’s also worth performing vendor due diligence in the following situations:

  • Contract renewals
  • Major regulatory changes
  • Service additions, changes, or updates
  • Service issues

There are two main categories of vendor due diligence:

  1. Initial: A traditional type of procurement-related due diligence performed after a vendor responds to a request for proposal (RFP).
  2. Ongoing: Conducted periodically to remediate specific issues, uncover new risk points, and shape future vendor relationships.

Risk managers should combine both types of due diligence to fine-tune their VRM program and prioritize relevant risks as they emerge.

Benefits of vendor due diligence

Thorough due diligence might seem like a considerable endeavor—but it’s well worth the effort and resources you invest in it. In today’s complex supply chain environment with multiple interrelated parties, VDD offers the following concrete benefits:

Increased confidence in vendor decisions

Vendor due diligence gives you critical security and performance information before you commit to a partnership. Instead of relying on a sales pitch or a gut feeling, you make the call based on evidence. That confidence matters most for the vendors you'll depend on heavily, where a wrong choice is expensive to unwind.

Risk identification and mitigation

VDD gives you a clear understanding of the vendor's risk profile, which you can then compare to your organization's risk appetite. From there you can decide whether the detected risk level is acceptable, or whether the vendor needs to close gaps first. The same process helps you develop proactive response plans for high-tier risk events, so you're not improvising when something goes wrong.

Better visibility of vendor risks

If each vendor goes through a thorough VDD process, there's a much lower chance of a risk slipping past you undetected. You build a consistent picture of where your exposure actually sits across your whole vendor base. That visibility turns a pile of one-off assessments into something you can manage as a program.

Regulatory compliance

Some regulations make vendor due diligence a legal obligation, not just good practice. Under GDPR, you can only hand personal data to a processor that gives sufficient guarantees they'll protect it, which means you have to vet them first. HIPAA places similar duties on healthcare organizations and the vendors handling protected health information. Running documented diligence is how you satisfy these requirements and how you prove you did when a regulator asks.

Negotiation leverage with vetted vendors

A VDD report paints a risk-aware vendor profile, which can prevent overpriced bids and help you negotiate on favorable terms. Knowing a vendor's weak spots gives you something to push on during contracting. You can tie pricing or specific protections to the gaps you found, rather than accepting the terms as offered.

Three approaches to vendor due diligence

Depending on the size and complexity of your vendor network, as well as your available resources and staff, you can choose between the following three approaches to VDD:

1. In-house VDD

In-house VDD suggests you take care of the entire process internally, which enables complete control over every activity. For some organizations, this can mean they save a sizable amount of money they’d otherwise spend on outsourced procedures.

The downside of in-house VDD is that it can be time-consuming and potentially burden your team with additional work, especially if you rely on disparate systems and manual processes. The best way around this is to use a capable vendor risk management platform that can automate and streamline VDD and other activities to simplify your team's workflows.

{{cta_webinar4="/cta-blocks"}} | Webinar: Vendor risk management

2. Shared VDD

Shared VDD refers to networks and data pools where you can find completed risk assessments and other relevant content maintained by vendors. The idea is for vendors to share resources like audit reports and compliance certificates on an accessible platform. This provides prospective organizations with up-to-date information during their diligence process.

While this approach takes most of the data-gathering work off your hands, it may not be as comprehensive as internal VDD. Every vendor has a unique risk profile, so you may still want to conduct a more tailored due diligence internally.

3. Outsourced VDD

The third option is to outsource VDD entirely to a provider offering managed services. This might be a good idea if your organization is severely understaffed and doesn’t have the necessary know-how or software resources.

Still, outsourced VDD can be quite costly, so it might not be the best solution for organizations on a limited risk management budget.

How to perform vendor due diligence

The VDD process involves the following four steps:

Step 1: Planning a baseline

The first step is preparation. Start by setting the objective of the process, since that informs everything after it. If the goal is to look into a specific compliance concern with an existing vendor, for example, you'll request a focused set of documentation, like evidence of recurring activities, policies, procedures, or a third-party attestation.

This is also where you assess your organization's risk appetite, the level of risk you're willing to accept across different vulnerabilities a vendor might bring, whether financial, operational, or otherwise. Once you set that baseline, you have a clear reference point to compare findings against when it's time to decide.

Part of planning is deciding how much diligence a given vendor warrants. Not every vendor needs the same scrutiny, and treating them as if they do is how programs drown. Score each vendor on how sensitive the data they'll access is, how deep their system access goes, and how much your operations would suffer if they failed. Most vendors sort cleanly into three tiers.

Tier What lands here Diligence depth Review frequency
Critical Deep system access or large volumes of sensitive data; a failure would halt your business. Full assessment with security reports, financial review, and expert sign-off. Continuous monitoring plus an annual deep review.
High Some sensitive data or moderate access; a failure would cause real disruption. Security questionnaire, attestation review, and targeted follow-up. Annual review with monitoring on key controls.
Low No access to sensitive data or systems; a failure is an inconvenience. A light check of the basics and reputation. Reassess only when something changes.

Finally, check any regulations and standards, whether industry- or location-specific, that affect your vendor relationships. The goal is to know whether you need to report specific information to regulatory bodies, which matters most if you're in a heavily regulated industry.

Step 2: Gathering documents and analyzing various risks

The scope of VDD paperwork may typically cover the following six types of analyses:

  1. Financial analysis
  2. Cybersecurity assessment
  3. Market assessment
  4. Legal and compliance assessment
  5. Operational review
  6. HR evaluation

Each of these analyses requires you to collect specific documents and data. The following table provides a condensed checklist of some of the key items you should gather:

Analysis Documents and data points
Financial analysis
  • Annual report
  • Tax documents
  • Loans and liabilities
Cybersecurity assessment
  • Internal or third-party cybersecurity audit reports
  • Data breach history
  • Incident response plan
  • Penetration testing report
  • Disaster recovery plan
Market assessment
  • Business plans
  • Main competitors
  • Industry trends
Legal and compliance assessment
  • Relevant regulatory and compliance attestations
  • Litigation history reports
  • Ongoing legal liabilities
Operational review
  • Business licenses
  • Corporate structure reports
  • List of subcontractors
HR evaluation
  • Hiring policies
  • Biographical data of key executives
  • Corporate culture statements

How deep you go in each area depends on the tier you assigned in the first step. A critical vendor warrants the full set, while a low-risk one needs only the basics. Wherever a vendor already holds an attestation like a SOC 2 report, ask for that first, because it answers more questions, more credibly, than any form you write. Organizations using a vendor management platform usually gather and store these documents in one place, which gives risk teams shared visibility instead of scattered email threads.

{{cta_withimage5="/cta-blocks"}}

Step 3: Report and decide

Once you've gathered and assessed the data, turn it into actionable insight through a VDD report. There's no fixed structure it has to follow, but it should cover the scope of the diligence, the key findings and risks, and your suggestions for the path forward.

The report is what drives the decision, and for any given gap you have four honest responses. You can accept it if it's minor and within tolerance, mitigate it on your side with compensating controls, require the vendor to remediate before you proceed, or walk away. Share the report with the relevant stakeholders, including your legal and financial teams, to gather the input you'll use to make the final call. Whatever you decide, record the reasoning, because that rationale is what protects you if a vendor incident ever lands on your desk.

The findings should also shape the contract. What you learned in diligence tells you which protections to negotiate, like a right to audit, defined breach notification windows, specific data handling requirements, service-level commitments, and disclosure of any subcontractors who'll touch your data. A strong assessment that leads to a weak contract leaves the risk exactly where you found it. The contract is where your diligence becomes enforceable.

Step 4: Establishing continuous monitoring procedures

VDD isn’t only done pre-emptively or on a one-time basis. Risks don’t disappear after you’ve onboarded a vendor—if anything, many risks surface later (e.g., data privacy risks). That’s why you need to have a continuous monitoring process and system in place to track interconnected vendors and perform periodic assessments throughout your partnerships with them.

For such a continuous system to work, set clear monitoring parameters and controls against which you’ll compare a vendor’s performance and risk profile. Another great practice is to configure a unified overview of your relevant vendor risk data on a dashboard so that potential threats aren’t overlooked.

Develop in-depth VDD processes with Vanta

Vanta is an end-to-end trust management platform that helps organizations of all sizes automate compliance, manage risk, and prove trust. With Vanta's Vendor Risk Management Platform, you can automate VDD and other VRM processes. The platform comes with built-in content—like risk scenarios and checklists— to help you design a tailored VDD workflow. Here are some features loved by VRM teams:

  • Automated vendor discovery (which also helps you uncover shadow IT)
  • Centralized vendor inventory with risk-tier categorizations
  • Customizable vendor risk auto-scoring and visualizations for easy comparison
  • Continuous monitoring of vendor status and risk profile
  • Over 400 integrations with various platforms, including procurement solutions
  • Vanta AI for fast review of vendor documents

Vanta also lets you (and any vendor using the platform) showcase your security and compliance posture through a dedicated Trust Center.

If you want to see the above features live, schedule a custom demo or or watch our free webinar to get started.

{{cta_simple5="/cta-blocks"}}

See how VRM automation works

Let's walk through an interactive tour of Vanta's Vendor Risk Management solution.

Explore more TPRM articles

Get started with TPRM

Start your TPRM journey with these related resources.

How to minimize third party risk with strong vendor management.

How to minimize third-party risk with vendor management

Get insights and best practices from security & compliance experts on how to manage third-party vendor risk in this free guide.

How to minimize third-party risk with vendor management
How to minimize third-party risk with vendor management
Vanta in Action: Vendor Risk Management

Vanta in Action: Vendor Risk Management

Vendor security reviews can be manual and time-consuming, draining security teams of precious hours. Vanta’s Vendor Risk Management solution changes that, automating and streamlining security reviews so that you can spend less time on repetitive work and more time strengthening your security posture. Curious to see what it looks like?

Vanta in Action: Vendor Risk Management
Vanta in Action: Vendor Risk Management

10 important questions to add to your security questionnaire [with examples]

Use these 10 vendor security questionnaire questions to assess compliance, uncover risks, and evaluate third-party vendors before onboarding.

10 important questions to add to your security questionnaire [with examples]
10 important questions to add to your security questionnaire [with examples]