Consulting-informed guidance

Our approach draws on the consulting background described on our expertise page. See our editorial and quality standards for how we prepare these resources.

Vendor due diligence should answer a simple question: do we know enough about this company and this relationship to make a reasonable decision?

The depth should match the risk. A low-cost office supplier and a payroll platform should not receive the same review.

Working checklist

  • Confirm legal name, address, registration, and primary contact
  • Understand the exact service and internal business owner
  • Check references, experience, and ability to deliver
  • Confirm relevant licensing and insurance
  • Identify data collected, stored, transmitted, or accessed
  • Identify system, administrative, payment, or facility access
  • Review security and privacy practices when relevant
  • Understand subcontractors and hosting locations
  • Review incident, termination, data-return, and deletion terms
  • Record red flags, missing evidence, approval, and follow-up

A practical way to approach it

1Define the relationship

Write down what the vendor will do and what it will touch.

2Verify basic facts

Resolve mismatched names, unclear ownership, unverifiable references, or missing documentation.

3Focus on the real exposure

Ask deeper questions where the vendor can affect customers, employees, finances, systems, or continuity.

4Review the contract

Make sure important operational promises are reflected in written terms.

5Choose and record the outcome

Approve, approve with conditions, pause, or decline—and state why.

What to request, and what to do with the answer

A checklist is easier to use when each item ends with an action. Keep a note of the source you checked, the date, and any unanswered question. Use “not applicable” only when you can explain why the check does not apply.

Evidence prompts for a new-vendor review
CheckUseful evidenceYour next action
Business identityContracting name, invoice details, registration record where applicableResolve different names before signing. Registration alone does not establish reliability.
Delivery capabilityA relevant reference, sample work, service scope, implementation planCheck whether the vendor can support your actual size, deadline, and use case.
Insurance or licensingRelevant certificate, license record, or explanation of applicabilityCheck names, dates, and relevance to the work. Ask a qualified adviser about required coverage.
Data and accessData description, access requirements, questionnaire responses, relevant security evidenceIdentify sensitive information and privileged access. Route unresolved concerns for a deeper review.
Contract and exitWritten terms covering service, renewal, cancellation, incident notification, and data handling where relevantClarify operational gaps before commitment; seek legal review when needed.

Worked example: a fictional payroll provider

ABC Payroll Services would receive employee details and help process payroll for a 24-person business. These are fictional facts used to show the workflow, not an assessment of a real provider.

The reviewer records the contracting entity and names the finance manager as the relationship owner. Because the service handles sensitive employee information and supports a time-critical payment process, the review needs more than a reference check.

The vendor explains its access controls, but its proposed terms do not clearly explain how the business can retrieve payroll records at termination. The reviewer records that gap, asks for written clarification, and keeps onboarding on hold until the responsible approver has enough information to decide.

A useful entry would read: “Pending approval. Finance manager to confirm record export and termination arrangements before onboarding. Security reviewer to resolve outstanding access-control questions. No live employee data to be uploaded before approval.” The tier and final decision still depend on the complete relationship assessment.

A decision record you can copy

Vendor and service
Legal entity, service description, internal owner
Exposure
Data involved, access required, operational dependence
Evidence reviewed
Document or source, scope, date, and reviewer
Open questions
Missing answer, responsible person, and follow-up date
Outcome
Approve, approve with conditions, pause, or decline; explain the reason
Approval and follow-up
Approver, decision date, conditions, and next review date

When should you pause onboarding?

Pause when an unanswered question could materially affect the decision. Examples include an unresolved contracting identity, unexplained administrative access, or missing evidence needed for a sensitive service. A condition should have an owner and deadline. Do not record a vendor as approved merely because the questionnaire came back.

For lower-exposure purchases, a short documented review may be enough. For higher-risk relationships, use risk-based security questions and review evidence appropriate to the service. Our vendor risk-tier examples explain why vendor category alone is not enough to choose a tier.

Keep the checklist, or use a prepared workbook

You can use this page without buying anything. For a quick prompt, download the free 10 Vendor Red Flags checklist. The Vendor Pre-Screening Starter Kit provides an Excel workbook and PDF questionnaire and instructions for initial screening. If you also need evidence tracking, ongoing reviews, and offboarding, compare the complete Third-Party Vendor Risk Toolkit.

Common mistakes to avoid

  • Accepting a polished sales presentation as evidence
  • Failing to verify the contracting legal entity
  • Asking questions that nobody reviews
  • Ignoring contract renewal and termination provisions
  • Leaving conditions without an owner or deadline
The practical takeaway

A good checklist creates a defensible pause before commitment while keeping routine purchases moving.

Sources and further reading

These sources inform the methodology. Inclusion does not imply endorsement, certification, or applicability to every organization. The worked examples and decision prompts are PBW’s practical guidance.

This guidance is a general business resource, not legal, insurance, cybersecurity, or regulatory-compliance advice. Adapt it to your circumstances and obtain qualified advice when appropriate.