Our approach draws on the consulting background described on our expertise page. See our editorial and quality standards for how we prepare these resources.
Vendor due diligence should answer a simple question: do we know enough about this company and this relationship to make a reasonable decision?
The depth should match the risk. A low-cost office supplier and a payroll platform should not receive the same review.
Working checklist
- Confirm legal name, address, registration, and primary contact
- Understand the exact service and internal business owner
- Check references, experience, and ability to deliver
- Confirm relevant licensing and insurance
- Identify data collected, stored, transmitted, or accessed
- Identify system, administrative, payment, or facility access
- Review security and privacy practices when relevant
- Understand subcontractors and hosting locations
- Review incident, termination, data-return, and deletion terms
- Record red flags, missing evidence, approval, and follow-up
A practical way to approach it
1Define the relationship
Write down what the vendor will do and what it will touch.
2Verify basic facts
Resolve mismatched names, unclear ownership, unverifiable references, or missing documentation.
3Focus on the real exposure
Ask deeper questions where the vendor can affect customers, employees, finances, systems, or continuity.
4Review the contract
Make sure important operational promises are reflected in written terms.
5Choose and record the outcome
Approve, approve with conditions, pause, or decline—and state why.
What to request, and what to do with the answer
A checklist is easier to use when each item ends with an action. Keep a note of the source you checked, the date, and any unanswered question. Use “not applicable” only when you can explain why the check does not apply.
| Check | Useful evidence | Your next action |
|---|---|---|
| Business identity | Contracting name, invoice details, registration record where applicable | Resolve different names before signing. Registration alone does not establish reliability. |
| Delivery capability | A relevant reference, sample work, service scope, implementation plan | Check whether the vendor can support your actual size, deadline, and use case. |
| Insurance or licensing | Relevant certificate, license record, or explanation of applicability | Check names, dates, and relevance to the work. Ask a qualified adviser about required coverage. |
| Data and access | Data description, access requirements, questionnaire responses, relevant security evidence | Identify sensitive information and privileged access. Route unresolved concerns for a deeper review. |
| Contract and exit | Written terms covering service, renewal, cancellation, incident notification, and data handling where relevant | Clarify operational gaps before commitment; seek legal review when needed. |
Worked example: a fictional payroll provider
ABC Payroll Services would receive employee details and help process payroll for a 24-person business. These are fictional facts used to show the workflow, not an assessment of a real provider.
The reviewer records the contracting entity and names the finance manager as the relationship owner. Because the service handles sensitive employee information and supports a time-critical payment process, the review needs more than a reference check.
The vendor explains its access controls, but its proposed terms do not clearly explain how the business can retrieve payroll records at termination. The reviewer records that gap, asks for written clarification, and keeps onboarding on hold until the responsible approver has enough information to decide.
A useful entry would read: “Pending approval. Finance manager to confirm record export and termination arrangements before onboarding. Security reviewer to resolve outstanding access-control questions. No live employee data to be uploaded before approval.” The tier and final decision still depend on the complete relationship assessment.
A decision record you can copy
- Vendor and service
- Legal entity, service description, internal owner
- Exposure
- Data involved, access required, operational dependence
- Evidence reviewed
- Document or source, scope, date, and reviewer
- Open questions
- Missing answer, responsible person, and follow-up date
- Outcome
- Approve, approve with conditions, pause, or decline; explain the reason
- Approval and follow-up
- Approver, decision date, conditions, and next review date
When should you pause onboarding?
Pause when an unanswered question could materially affect the decision. Examples include an unresolved contracting identity, unexplained administrative access, or missing evidence needed for a sensitive service. A condition should have an owner and deadline. Do not record a vendor as approved merely because the questionnaire came back.
For lower-exposure purchases, a short documented review may be enough. For higher-risk relationships, use risk-based security questions and review evidence appropriate to the service. Our vendor risk-tier examples explain why vendor category alone is not enough to choose a tier.
Keep the checklist, or use a prepared workbook
You can use this page without buying anything. For a quick prompt, download the free 10 Vendor Red Flags checklist. The Vendor Pre-Screening Starter Kit provides an Excel workbook and PDF questionnaire and instructions for initial screening. If you also need evidence tracking, ongoing reviews, and offboarding, compare the complete Third-Party Vendor Risk Toolkit.
Common mistakes to avoid
- Accepting a polished sales presentation as evidence
- Failing to verify the contracting legal entity
- Asking questions that nobody reviews
- Ignoring contract renewal and termination provisions
- Leaving conditions without an owner or deadline
A good checklist creates a defensible pause before commitment while keeping routine purchases moving.
Sources and further reading
- NIST Cybersecurity Framework 2.0
- NIST SP 800-161 Rev. 1: Supply Chain Risk Management
- CISA Cyber Guidance for Small Businesses
- FTC Cybersecurity for Small Business
These sources inform the methodology. Inclusion does not imply endorsement, certification, or applicability to every organization. The worked examples and decision prompts are PBW’s practical guidance.
This guidance is a general business resource, not legal, insurance, cybersecurity, or regulatory-compliance advice. Adapt it to your circumstances and obtain qualified advice when appropriate.