Vendor due diligence has a reputation problem inside organisations, and it has earned it. In most programs it means a questionnaire of two hundred questions sent to every supplier regardless of what they do, answered by a salesperson, scored by a tool, and filed. Low-risk suppliers are tortured with it, high-risk suppliers sail through it, and nobody reads the SOC report past the opinion page. This guide is the alternative: a due-diligence workbench organised by what the organisation actually needs to know before it signs, calibrated by risk tier so that effort goes where failure would hurt, and specific about which evidence counts and which is theatre. It covers the fourteen due-diligence factors the US banking agencies named in 2023, financial viability checks that work for private companies, security assurance and its limits, the compliance screenings, operational capability and resilience, a checklist skeleton by tier, and a worked example from a distributor’s first third-party audit.
This is the third stage of the lifecycle set out in the third-party risk management program guide, and it assumes the tiering decision from that guide has been made before any supplier is approached. It is also the stage the IIA’s Third-Party Topical Requirement, effective 15 September 2026, names first among its control processes: due diligence and a business case before a relationship is entered, at a depth proportionate to risk. Internal auditors testing conformance will find the evidence standard here and the applicability mapping in the requirement mapped for 15 September.
In this guide
- What due diligence is for, and why questionnaires are not it
- The fourteen factors, and the evidence that counts for each
- Depth by tier: what to check for whom
- Financial viability: reading a private supplier’s numbers
- Security posture: SOC reports, certifications, testing, and their limits
- Compliance screening: sanctions, adverse media, privacy and insurance
- Operational capability and resilience: the evidence beyond the certificate
- Refreshing due diligence: the calendar and the triggers that reset it
- The due-diligence checklist skeleton
- Worked example: a distributor’s six critical relationships, diligenced properly
- Related guides
What due diligence is for, and why questionnaires are not it
Due diligence answers three questions about a specific supplier for a specific activity. Can it do the work: does it have the capability, capacity, people, locations and track record the activity needs? Will it survive the term: is it financially sound, stably owned, and not dependent on a customer or funder whose exit would take it down? And will it protect what we give it: the data, the access, the process, the customers, the reputation? Everything in a due-diligence file should trace to one of the three, and an item that traces to none of them, which describes a surprising share of most questionnaires, is cost without control.
The questionnaire fails those questions for a structural reason: it is the supplier’s evidence about itself. The interagency guidance’s due-diligence section is built around the organisation’s own verification, and the phrase that recurs in every regime is “independent” or “verify”. A questionnaire is where diligence starts, because it tells you what the supplier claims; the file is made of what you then confirmed. For a Tier 1 supplier that means documents you can read for yourself (audited financials, assurance reports, test results, insurance certificates, subcontractor lists, contracts with key subcontractors), conversations with people who are not selling (references, the supplier’s own security and operations leads, your peers who use them), and where the risk justifies it, a site visit or a control assessment of your own. The tiering model exists so that this depth is spent on the forty relationships that matter, not the four hundred that do not.
The fourteen factors, and the evidence that counts for each
The 2023 interagency guidance lists fourteen due-diligence factors. They were written for banks, but they are the most complete public checklist of what a buyer should know, and non-bank organisations use them as a reference without apology. The table gives each factor, what to check in practice, and the difference between evidence that establishes the fact and evidence that only asserts it.
| Factor | What to check | Evidence that counts | Evidence that only asserts |
|---|---|---|---|
| Strategies and goals | Whether the supplier’s business direction fits the organisation’s need over the term; planned exits from the product line; concentration of the supplier’s revenue | Investor or owner communications; product roadmap commitments in the contract; customer references on continuity | A sales deck |
| Legal and regulatory compliance | Licences and registrations the service needs; regulatory actions and litigation; ability to comply with the laws that apply to the organisation’s use of the service | Regulator registers; litigation and enforcement searches; the supplier’s compliance attestations with named regimes | A statement that the supplier “complies with all applicable laws” |
| Financial condition | Solvency, liquidity, profitability, funding runway, customer concentration, parent support | Audited or reviewed financial statements; for private firms, management accounts plus bank or funding confirmations; credit reports | A Dun and Bradstreet rating alone; the supplier’s assurance that it is “well funded” |
| Business experience | Track record in the specific service, at the organisation’s scale, in its sector | Reference calls with comparable customers; case studies with verifiable outcomes; years in service | Logos on a website |
| Qualifications and backgrounds of key personnel | Who will actually deliver; background screening of staff with access; turnover; key-person dependence | Named delivery team with CVs; the supplier’s screening policy and evidence it is applied; turnover figures | “Our team of experts” |
| Risk management | Whether the supplier manages its own risks in a way the organisation can rely on | Risk framework documents; internal audit or independent review reports; issue logs | An org chart with a risk function on it |
| Information security | Controls over the organisation’s data and the service’s infrastructure | SOC 2 Type 2 report read in full; ISO/IEC 27001 certificate with scope statement; penetration test summary with remediation status; the method in the SOC 2 review guide | A SOC 2 cover page; an ISO certificate for a different legal entity or scope; a questionnaire |
| Management of information systems | Change management, development practices, capacity, monitoring for the systems that deliver the service | SOC report control descriptions and test results for change and operations; architecture documentation; incident history | Marketing descriptions of the platform |
| Operational resilience | Business continuity and disaster recovery for the service; recovery objectives against the organisation’s tolerance | Test results from the last twelve months with recovery times achieved; recovery objectives in the contract | A continuity policy; a statement that plans exist |
| Incident reporting and management | How incidents are detected, classified, escalated and notified to customers | The incident process with notification periods; history of notifications to customers; the incident response coverage in the incident response audit guide | “We take security seriously” |
| Physical security | Controls over facilities that hold data or deliver the service, including data centres the supplier does not own | Data-centre assurance reports (the supplier’s own suppliers); site visit notes for supplier-operated facilities | A photograph of a badge reader |
| Reliance on subcontractors | Which parts of the service are delivered by others, where, and under what controls | A subcontractor list with services and locations; flow-down clauses in the subcontracts; the subcontractors’ own assurance where critical | “We use industry-leading partners” |
| Insurance coverage | Cover types and limits proportionate to the exposure: cyber, professional liability, general liability, crime | Current certificates naming the cover and limits; renewal dates in the inventory | A line in the proposal |
| Contractual arrangements with other parties | Obligations to others that could affect the service: exclusivities, licensing, data-sharing agreements | Disclosure schedule; licence terms for embedded components | Silence |
The pattern in the right-hand columns is deliberate. Evidence that counts is either produced by someone independent of the supplier, or is a result rather than a policy, or is specific enough to be checked. Evidence that only asserts is the supplier describing itself. A due-diligence file for a Tier 1 relationship should be mostly the first kind; a file that is mostly the second kind is a questionnaire with attachments, however thick it is.
Depth by tier: what to check for whom
Depth by tier is where the program stops being a questionnaire factory. The table sets a default: which of the domains above are examined, and how, for each tier in the model from the program guide. The principle is that a Tier 3 supplier is screened, a Tier 2 supplier is assessed on documents, and a Tier 1 supplier is verified, including by the organisation’s own people looking at the supplier’s controls where the exposure justifies it. Organisations in regulated sectors will add regime-specific items (the DORA register fields, the EBA’s pre-outsourcing analysis, the PRA’s materiality assessment), but the shape is the same.
| Domain | Tier 1: critical | Tier 2: significant | Tier 3: managed | Tier 4: transactional |
|---|---|---|---|---|
| Financial condition | Three years of audited or reviewed statements analysed; funding and ownership confirmed; customer concentration asked; annual refresh | Latest statements or credit report reviewed; refresh on renewal | Credit report or registry check at onboarding | None |
| Information security | SOC 2 Type 2 or equivalent read in full with complementary controls mapped; penetration test summary; certificate scope verified; own assessment for the highest exposures | Assurance report or certificate reviewed for scope and exceptions; questionnaire for gaps | Attestation only if the supplier touches data | None |
| Compliance screening | Sanctions, adverse media, litigation and enforcement, beneficial ownership, anti-bribery representations; privacy terms and subprocessor list; re-screened continuously or annually | Sanctions and adverse media at onboarding and annually; privacy terms if data is processed | Sanctions and adverse media at onboarding | Sanctions at onboarding |
| Operational capability | References with comparable customers; named delivery team; capacity and key-person review; site or virtual walkthrough | References; delivery approach reviewed | Business owner’s judgment | None |
| Resilience | Recovery objectives matched to the organisation’s tolerance; last twelve months’ test results obtained; exit plan drafted before signature | Continuity plan existence and last test date confirmed | Not assessed | None |
| Subcontractors | Full list with locations and services; critical subcontractors’ own assurance obtained; consent rights in contract | List obtained; flow-down confirmed | Disclosure question only | None |
| Legal and insurance | Licences verified; insurance certificates against required limits; contractual arrangements with others disclosed | Insurance certificate; licences where relevant | Insurance certificate where relevant | None |
| Approval | Risk function and business owner sign the file; findings resolved or accepted by an executive before signature | Business owner signs; risk function reviews exceptions | Procurement confirms screening | Automatic |
Two calibration notes. A supplier’s own tier can be raised by what diligence finds: a Tier 2 supplier that turns out to subcontract the whole service offshore, or to be funded for nine months, moves up before signature, not after the first incident. And diligence findings need a decision, not a filing; every program has files in which the penetration test was two years old and the SOC report carried a qualified opinion, both noted, neither acted on. The Topical Requirement’s Control Processes A asks whether due diligence informed the decision, which is a different question from whether it was performed.
Financial viability: reading a private supplier’s numbers
Financial diligence on a listed supplier is easy and rarely the problem; the risk is in the private supplier that will not share statements and the venture-funded supplier whose statements show a runway rather than a business. For the first, the position is simple: a Tier 1 supplier that will not share financial information under a confidentiality agreement is telling you something, and the organisation should decide whether to accept that risk explicitly, in writing, at executive level, or walk away. Most will share once the request comes from the buyer’s finance function rather than procurement and is framed as a standing annual requirement. For the second, read what is there for what matters: months of runway at the current burn rate, the date and terms of the last funding round, customer concentration, and whether the organisation would be one of the top customers. A supplier for which you would be a top-three customer is a supplier whose survival you are partly funding, and the contract should reflect that with escrow, step-in or data-portability terms.
The analysis itself is the one an auditor already knows how to do. Liquidity: current ratio and cash against monthly costs. Leverage: debt service against operating cash flow, covenant headroom if disclosed. Profitability and trend: three years, with the reason for any deterioration. Going concern: the auditor’s opinion and any emphasis paragraph, which is the single most under-read line in supplier diligence. Ownership and parent support: who owns the supplier, whether a parent guarantee is available, and whether an acquisition is likely, since a change of control clause is only useful if you know one is coming. For public-sector buyers and for financial firms under the EBA and PRA regimes, this analysis is expected to be documented and refreshed, and for everyone else it is simply the difference between a supplier that fails on a Tuesday and one whose failure you saw coming in the spring.
Security posture: SOC reports, certifications, testing, and their limits
Security diligence is where most organisations have the most documents and the least knowledge, because each document has a limit that the file rarely records. A SOC 2 Type 2 report is the best evidence available for a service provider’s controls, and it has five limits: the scope (which system, which locations, which trust services criteria), the period (a report ending nine months ago says nothing about today, which is what bridge letters are for), the carve-outs (subservice organisations excluded from the opinion, which is where the data centre and the cloud usually are), the complementary user entity controls (the controls the supplier assumes you operate, which the file must map to your own controls), and the exceptions (test deviations in the body of the report, which a cover-page reader never sees). The reading method in how to review a SOC 2 report and, for financially relevant services, how to review a SOC 1 report turns the document into knowledge; the file should hold the completed review, not the PDF.
An ISO/IEC 27001 certificate proves that a management system exists and was audited against the standard for the scope stated on the certificate; it does not prove any particular control operated, and a certificate issued to a parent entity for a head-office scope proves nothing about the subsidiary delivering your service. Read the scope statement, the certificate’s validity dates and the issuing body’s accreditation. A penetration test summary is valuable only with the date, the scope, the tester’s independence, the findings by severity and the remediation status; a summary that says “no critical findings” without those five items is marketing. Questionnaires such as the Shared Assessments SIG have a role for Tier 2, where they establish a baseline cheaply, and a role for Tier 1 in finding the gaps between the assurance documents; they are not a substitute for reading the documents. And for the highest exposures, the organisation’s own assessment, a walkthrough of the supplier’s controls by someone who can test a configuration, is the only evidence that does not depend on the supplier’s choice of what to show you.
Compliance screening: sanctions, adverse media, privacy and insurance
Screening is the cheapest part of diligence and the part with the least excuse for gaps, because the tools are commodity and the consequences of missing a hit are disproportionate. Sanctions screening against the lists that apply to the organisation (OFAC in the United States, the UN, EU and UK lists, and others by jurisdiction) is a minimum for every tier, including transactional, and it has to cover beneficial owners for Tier 1 and 2, not only the legal entity, because the entity is the easy thing to keep clean. Adverse media and litigation searches find the regulatory action, the data breach, the labour dispute or the fraud that the questionnaire did not mention; they are run at onboarding and refreshed annually for Tier 2 and continuously, through a monitoring service, for Tier 1. Anti-bribery and corruption representations matter where the supplier acts for the organisation in front of officials or customers, agents and distributors above all, and the file should hold the representation, the screening of the supplier’s principals and, for higher-risk jurisdictions, the supplier’s own anti-corruption policy and training evidence.
Privacy diligence is its own discipline where personal data is processed: a data processing agreement with the required terms, the list of subprocessors and the mechanism for objecting to changes, the international transfer mechanism where data leaves the jurisdiction, the supplier’s breach notification period against the organisation’s own regulatory clock, and evidence of the technical measures the agreement promises; the coverage in the data privacy audit guide sets out what a reviewer checks. Insurance is the last screening item and the most often expired: the certificate must name the cover types the exposure requires, cyber and professional liability for any supplier with data or advice, with limits proportionate to the loss the organisation could suffer, and the renewal date belongs in the inventory next to the contract date, because a certificate that lapsed in March is discovered in the claim in October.
Operational capability and resilience: the evidence beyond the certificate
Operational diligence answers the first of the three questions, whether the supplier can do the work, and it is the domain most often skipped because it requires conversations rather than documents. Reference calls with two or three customers of comparable size and sector, made by the business owner and the risk function together, with a fixed set of questions (what went wrong in implementation, what the supplier does when a service level is missed, who they escalate to, whether they would renew) produce more decision-relevant information per hour than anything else in the file. Named delivery staff, their tenure and the supplier’s turnover give the key-person picture; a supplier whose service depends on two engineers is a Tier 1 risk however large its parent. Locations matter for data, for regulation and for resilience: where the service is delivered from, where data rests, and where the people who can access it sit.
Resilience diligence is where the certificate problem is worst. Every supplier has a business continuity policy; what the organisation needs is the result of the supplier’s last recovery test for the specific service, with the recovery time and point achieved, measured against the organisation’s own tolerance for that service, and the supplier’s own dependency on its subcontractors and cloud regions. For a Tier 1 supplier the exit plan is drafted at diligence, not at termination, because diligence is when the organisation still knows what the alternatives are; the approach, including how to test the plan and what to demand in the contract, is set out in third-party resilience, and the concentration questions that go with it in fourth parties and vendor concentration. A resilience file that holds the supplier’s policy, its test results, its subcontractor dependencies and the organisation’s own exit sketch is complete; one that holds a certificate and a paragraph is not.
Refreshing due diligence: the calendar and the triggers that reset it
Due diligence is a snapshot, and a Tier 1 file that was excellent at signature is a historical document three years later. Every program needs two refresh mechanisms: a calendar, annual for Tier 1, at renewal for Tier 2, which re-performs the parts of the file that decay (financial condition, assurance reports, screenings, insurance, subcontractor lists), and a set of triggers that force an out-of-cycle refresh when the relationship changes in a way the calendar cannot see. The table gives the triggers that matter, what they should reopen, and who decides whether the relationship continues while the refresh is done. Trigger-based refresh is the part most programs lack, and it is the part that distinguishes monitoring from filing.
| Trigger | What it reopens | Who decides, and by when |
|---|---|---|
| Change of ownership or control at the supplier | Identity, beneficial ownership and sanctions; financial condition of the new owner; strategy and goals; key personnel; the change-of-control clause | Risk function with the business owner, within thirty days of notice; termination right assessed |
| Material scope change (new data, new process, new volume) | Tier assignment first; then whatever the new tier requires that the file lacks; contract addendum | Business owner proposes, risk function confirms the tier, before the change goes live |
| Security incident or breach at the supplier or a subcontractor | Incident handling against the contract; security assurance; subcontractor list; the organisation’s own exposure and regulatory notifications | Security and risk within the notification period; executive decision on continuation if data was affected |
| Qualified or adverse assurance opinion; new exceptions in the SOC report | The affected controls mapped to the organisation’s reliance; compensating controls; complementary control mapping | Risk function within the review cycle; findings tracked as issues |
| Adverse financial signal (losses, covenant breach, failed funding, late payments to its own suppliers) | Financial condition in full; exit plan readiness; data portability | Finance and risk within thirty days; executive acceptance or exit decision |
| Regulatory action, litigation or adverse media hit | Legal and regulatory compliance; reputational exposure; the representations in the contract | Legal and risk within the screening cycle; decision recorded |
| Subcontractor change for a critical part of the service | Subcontractor list, the new subcontractor’s assurance, location and data implications, consent rights | Risk function; consent or objection under the contract before the change |
| Missed service levels for two consecutive periods | Operational capability; key personnel; capacity; remedies | Business owner with the supplier; escalation under the program’s threshold |
Auditors testing refresh look for two things: that the calendar was met for Tier 1 and 2 (the overdue share is a standing indicator in the program guide), and that each trigger event in the period can be traced to a reopened file and a decision. A program that refreshed every file on schedule but did not reopen the file when its largest supplier was acquired has a calendar, not a control.
The due-diligence checklist skeleton
The skeleton below is written to be adopted as the organisation’s standard and completed once per relationship, with the tier deciding which sections apply (T1, T2, T3 marks the lowest tier for which the item is required). Every item is phrased as a fact to establish, and the file entry for each is the evidence reference and the reviewer’s conclusion, never a yes or no. It is deliberately shorter than a questionnaire, because it is the organisation’s list, not the supplier’s.
Section 1. Identity and legal (T4). Legal entity and registration verified; beneficial owners identified (T2); sanctions screening of entity and owners with date and lists used (T4); adverse media and litigation search with date (T3); licences and registrations the service requires, verified against the register (T2).
Section 2. Financial condition (T3). Credit report or registry check (T3); latest financial statements reviewed with liquidity, leverage, profitability and going-concern notes (T2); three years analysed, funding and ownership confirmed, customer concentration and the organisation’s share of revenue recorded (T1); refresh date set.
Section 3. Capability and experience (T2). Comparable customer references completed with the standard questions (T2); named delivery team with tenure and key-person assessment (T1); capacity to deliver at the organisation’s volume confirmed (T1); delivery locations and data locations recorded (T2).
Section 4. Information security (T3 where data is touched). Assurance report obtained and reviewed in full with scope, period, carve-outs, complementary user entity controls mapped and exceptions assessed (T1); certificate scope and validity verified (T2); penetration test summary with date, scope, severity findings and remediation status (T1); questionnaire completed for gaps (T2); own control assessment where exposure justifies it (T1, judgment); security attestation (T3).
Section 5. Privacy and data (T3 where personal data is processed). Data processing agreement terms confirmed; subprocessor list obtained; transfer mechanism recorded; breach notification period shorter than the organisation’s regulatory clock; deletion and return terms.
Section 6. Resilience (T2). Continuity plan existence and last test date (T2); recovery objectives for the service against the organisation’s tolerance, with last test results (T1); subcontractor and cloud dependencies recorded (T1); exit plan drafted (T1).
Section 7. Subcontractors (T2). Disclosure obtained (T2); full list with services and locations, critical subcontractors’ assurance, flow-down and consent terms (T1).
Section 8. Insurance and contractual arrangements (T2). Certificates for required cover types and limits with renewal dates (T2); disclosure of arrangements with others that could affect the service (T1).
Section 9. Conclusion and approval. Findings listed with severity; each resolved, mitigated in the contract or accepted by a named executive; tier confirmed or raised; file signed by the business owner and the risk function (T2) before contract signature; refresh calendar entered in the inventory.
Worked example: a distributor’s six critical relationships, diligenced properly
MidState Beverage, the three-state drinks distributor used across this site, ran its first third-party management audit in FY28 under the Topical Requirement, a 400-hour engagement that grew to 460 once the inventory reconciliation found 186 paid service providers against 118 on the procurement list. The tiering produced six Tier 1 relationships: the cloud payroll provider, the ERP vendor, the ERP hosting provider, the managed security service adopted after the FY27 cyber audit, the fleet maintenance contractor, and the vendor of the 380 route handhelds the drivers use for cash and delivery. Due diligence was tested for all six against the skeleton above, and the results are the kind a first audit finds everywhere.
Three of the six had no due-diligence file at all, because they had been engaged before the company had a policy and nobody had gone back. The ERP hosting provider’s SOC 2 report was on file and had been read only to the opinion page; read in full, it carved out the data-centre operator, whose own report nobody had ever requested, and listed nine complementary user entity controls of which the company operated four. The payroll provider’s SOC 1 review, done by internal audit two years earlier, had already found two of four complementary controls unoperated, and the finding was still open. The managed security service had been onboarded in FY27 with a thorough security assessment and no financial check; it was a sixty-person firm for which MidState was the second-largest customer, and its most recent statements, obtained during the audit, showed nine months of runway at the current burn. The fleet maintenance contractor’s insurance certificate had lapsed in the spring. The handheld vendor had a current SOC 2 and a subcontractor list; it was the only file that passed the skeleton as written.
The remediation applied the tiering rather than the questionnaire. For the six Tier 1 relationships, full files were built to the skeleton over one quarter by the business owners with the risk function’s help, roughly twelve hours per relationship, and each file ended with a decision: the data-centre report was obtained through the hosting provider and reviewed, the five unoperated complementary controls were assigned to owners with dates, the managed security service’s financial position was accepted in writing by the chief financial officer with a data-portability clause added at renewal and a six-month exit sketch, and the maintenance contractor’s insurance was reinstated before the next invoice was paid. For the fifteen Tier 2 relationships sampled, the documents-only assessment was completed in an average of three hours each. For everyone else, screening and an insurance certificate where relevant, in minutes. The company had spent more hours in the previous year sending questionnaires to stationery suppliers than it spent building the six files that mattered, which is the point of the whole method.
Related guides
Related guides
- Third-Party Risk Management End-to-End: The Full Lifecycle Program
- Third-Party Topical Requirement: The 17 Requirements, Mapped for 15 September 2026
- Fourth Parties and Vendor Concentration
- Third-Party Resilience: Continuity When the Failure Is Not Yours
- How to Review a SOC 2 Report
- How to Review a SOC 1 Report
- How to Audit Data Privacy Compliance
- How to Audit the Vendor Master File
- How to Audit Procurement
- How to Audit Incident Response
- How to Audit Business Continuity and Resilience
- Operational Risk (category)
Leave a Reply