A new vendor lands in your inbox. The pitch sounds good, the price fits, and there are plenty of other things waiting for your attention. Before signing, you need to know whether this relationship deserves a quick check or a more careful review.
To vet a vendor, verify the contracting business, check whether it can deliver, identify the data and access involved, review relevant evidence and terms, then record an approval decision. The depth depends on what could go wrong for your business.
The walkthrough below is an initial screen. Thirty minutes is a planning window, not a promise that every vendor can be fully assessed in that time. Waiting for references, resolving contract questions, or reviewing a sensitive service can take longer.
A practical initial vendor-vetting process
Open a note or spreadsheet and name the person who will own the relationship. Record the intended service before asking questions. A software provider storing customer records creates a different exposure from a supplier delivering office stationery.
1 Confirm who you are contracting with
Ask for the legal business name and primary contact. Compare the proposal, contract, and invoice. If a trading name differs from the legal entity, ask the vendor to explain the connection.
Check the relevant business registry where applicable. Registration can help verify identity; it does not prove financial stability, service quality, or security. If you cannot resolve a material identity mismatch, pause the commitment.
2 Check whether they can do the work
Ask for a reference relevant to your service and business size, or a sample of comparable work. Ask what delivery will look like after you sign: who implements the service, what you must provide, and what happens if the agreed date slips.
Years in business can provide context, but do not use age alone as a pass-or-fail rule. A reference and a clear scope tell you more about the work you are buying than a polished testimonials page.
3 Check relevant insurance and licensing
Where insurance or licensing matters to the work, request the relevant documentation. Compare the named business, dates, and scope with the proposed service. Do not assume a certificate establishes that every exposure is covered.
Requirements vary by activity and location. If you are unsure what coverage or license is needed, ask your broker, legal adviser, or another qualified professional rather than treating a generic checklist as a legal determination.
4 Identify what they will access or hold
Write down the information, systems, funds, and premises involved. For a data-handling service, ask what information is stored, who can access it, and what happens after an incident or at termination.
Ask for an explanation you can use. “We take security seriously” does not answer whether staff use multi-factor authentication or whether customer records can be exported. For sensitive data or system access, use a risk-based vendor security questionnaire and review evidence relevant to the service.
5 Decide whether more review is needed
Consider the consequences of failure, not just the purchase price. Sensitive records, payment authority, privileged access, or a service you cannot readily replace justify closer attention. Use the vendor risk-tier examples to guide judgment rather than assigning a tier solely from the vendor’s category.
Record one outcome: approve, approve with conditions, pause for more information, or decline. If you need a fuller list of evidence prompts, use our vendor due diligence checklist.
Example: vetting a fictional customer-booking platform
Imagine a 12-person repair business considering ClearSchedule, a fictional booking service. It will store customer names, contact details, and appointment notes. It will not process payments, but staff will depend on it to organize the next day’s visits.
The owner confirms the contracting name and speaks with a relevant reference. The vendor explains account access and record exports. One question remains: how would staff see tomorrow’s appointments during an outage?
That question belongs in the decision record. Before live customer information is uploaded, the owner asks for the vendor’s recovery explanation and tests a usable schedule export. If the answers are inadequate, the business can pause or consider another provider. A good reference does not resolve a continuity gap.
These are illustrative facts, not a real vendor assessment. The final tier would depend on the actual data, access, service dependence, and contractual arrangements.
What to record before approving the vendor
You do not need a lengthy report for every purchase. Keep enough detail for another person to understand what was checked and why the decision was made.
- Vendor legal name, service, internal owner, and review date
- Data, access, and business dependence involved
- Evidence or sources checked, including scope and date
- Open questions and any conditions, with an owner and deadline
- Decision, reason, approver, and follow-up date
For the fictional example, a note might read: “Onboarding paused pending confirmation of outage arrangements and a successful appointment export. Operations owner to complete both checks before uploading customer records.” That is more useful than “Vendor looks fine.”
When the initial screen is not enough
Move to a deeper review when an unresolved issue could change your decision or when the relationship creates significant exposure. That might involve reviewing contract terms with counsel, checking a security report, or agreeing on recovery arrangements with the service owner.
If a vendor supplies a SOC 2 report, check its relevance rather than simply filing it. Our SOC 2 review guide explains scope, exceptions, and customer responsibilities. After approval, add the vendor to a maintained vendor inventory and set a risk-based review date.
Choose a way to keep the process consistent
You can start with your own spreadsheet. The important part is that the next reviewer can find the questions, answers, and decision.
For a brief reminder of warning signs, download our free 10 Vendor Red Flags checklist. For guided initial screening, the Vendor Pre-Screening Starter Kit includes an Excel workbook, a 20-question PDF questionnaire, and PDF instructions. The Third-Party Vendor Risk Toolkit adds evidence tracking, documented decisions, ongoing reviews, and offboarding.
Sources and scope
The security and supplier-risk approach is informed by NIST Cybersecurity Framework 2.0 and FTC small-business cybersecurity guidance, including vendor security. The initial-screen workflow and fictional example are PBW’s practical guidance, not a requirement imposed by those sources.
This is general business guidance, not legal, insurance, cybersecurity, or regulatory-compliance advice. An initial screen cannot guarantee vendor reliability or prevent every incident.