メイン コンテンツにスキップする
Dropbox Sign のロゴ
Dropbox Sign が選ばれる理由
アコーディオンの展開と折りたたみ

機能

ドキュメントへのオンライン署名
電子署名の作成
テンプレートを選択または作成する
PDF への入力と署名
契約書へのオンライン署名
ドキュメント管理
機能を見る
右矢印のアイコン

ユースケース

セールス/ビジネス開発
人事
スタートアップ
金融テクノロジー
不動産
オンデマンド サービス
製品
アコーディオンの展開と折りたたみ
Dropbox のアイコン
Sign
手軽に送信、手軽に署名
Dropbox のアイコン
Sign API
電子署名をワークフローに統合
Dropbox Fax のアイコン
Fax
ファクス機なしでファクスを送信
Dropbox インテグレーションのアイコン
インテグレーション
さまざまなツールと連携
リソース
アコーディオンの展開と折りたたみ
公式ブログ
ワークフローの専門知識と製品ニュース
お客様の体験談
実際の導入事例とその成果
ヘルプセンター
当社製品の詳細ガイド
リソース ライブラリ
レポート、動画、情報シート
開発者向け情報
価格
アコーディオンの展開と折りたたみ
Dropbox Sign の価格
ニーズに合わせてお選びください
Dropbox Sign API の価格
実際の導入事例とその成果
セールス担当に連絡
登録
セールス担当へ連絡する
ログイン
アコーディオンの展開と折りたたみ
Dropbox Sign
Dropbox Fax
無料トライアル
公式ブログ
/
ワークフロー管理

Vendor due diligence: What to assess and what to do when information is missing

by 
Dropbox Sign team
September 30, 2026
11
分(記事閲覧時間)
A woman standing at a conference table gestures while three colleagues listen, with charts and a laptop on the table.
ツールチップのアイコン

新しい名前でも変わらぬ高品質!HelloSign の名称が Dropbox Sign になりました。

閉じるアイコン

Vendor due diligence is the process of checking a supplier before you enter or expand a business relationship with them. You gather evidence about the vendor and the work they’ll perform, identify risks or unanswered questions, and use that information to decide how you want to proceed.

The level of review should reflect the relationship. A vendor storing sensitive customer data will usually need more scrutiny than a supplier providing office plants. You need enough relevant information to understand the risks, address gaps, and support the decision you make.

This guide covers a practical vendor due diligence process, including what to assess and how to respond when a vendor can’t provide everything you request.

If your process includes recurring non-disclosure agreements (NDAs), attestations, or agreements, ⁠Dropbox Sign can help you prepare, send, sign, and track those documents as the review process moves forward.

Disclaimer: This information is for general purposes only. It isn’t legal advice and shouldn’t replace advice from a licensed attorney.

What is vendor due diligence?

In procurement, vendor due diligence means gathering and reviewing information about a supplier before doing business with them or expanding the work they already perform.

Your review might cover the vendor’s financial condition, regulatory history, information security, operational resilience, key personnel, subcontractors, and internal controls. Which areas need attention depends on what you’re asking the vendor to do and the risks involved.

You may also come across terms such as supplier due diligence, third-party due diligence, and vendor assessment. Their exact meanings vary between organizations and frameworks.

Third-party vendor due diligence can extend beyond paid suppliers. A referral partner, affiliate, consultant, or other organization may warrant review if it can access your data, interact with customers, or support an important operation.

In Mergers and Acquisitions (M&A), vendor due diligence usually refers to a review commissioned by the seller and shared with prospective buyers. If that’s the process you’re looking for, see our M&A due diligence checklist⁠.

How is vendor due diligence different from a vendor risk assessment?

In this guide, vendor due diligence means gathering and checking information about a proposed relationship. A vendor risk assessment uses that information to evaluate any potential issues the relationship creates.

Organizations don’t always use these terms in the same way, so follow the terminology in your own policies and applicable requirements.

A completed questionnaire, financial statement, or SOC report gives you evidence to review. Check whether that evidence is current, whether it covers the service you’re buying, and whether unanswered questions need further investigation.

A practical vendor due diligence process

Your vendor due diligence process should reflect the work the supplier will actually perform rather than putting every vendor through an identical review.

You can structure the process around six steps:

  1. Tier the relationship by risk
  2. Assess the work the vendor will perform
  3. Review evidence relevant to that work
  4. Record and address missing information
  5. Make and document your decision
  6. Complete required agreements and set reassessment triggers

The assessment areas in this guide draw on the June 2023 ⁠Interagency Guidance on Third-Party Relationships: Risk Management.

The Federal Reserve Board, FDIC, and Office of the Comptroller of the Currency issued guidance for the banking organizations they supervise. It’s supervisory guidance, not a regulation, and it doesn’t have the force and effect of law or itself impose requirements on software companies, manufacturers, retailers, or other nonbanks.

1. Consider the relationship before you start collecting documents

Start with the work the vendor will actually perform.

Think about which systems it can access, whether it will handle confidential information, which customers or operations depend on the service, and what would happen if it can’t complete the work.

A low-risk, easily replaced supplier may only need a basic review. A vendor storing customer data or supporting an important operation may require detailed evidence about security, finances, resilience, subcontractors, or other areas relevant to the work.

Sending the same questionnaire to both vendors can potentially overburden one while overlooking the risks that matter for the other.

If an answer shows a new dependency or concern, expand the review accordingly.

2. Assess the activity, not just the vendor’s reputation

Previous experience with a supplier can tell you how reliably it delivered its earlier work. It doesn’t necessarily show that the vendor can safely or reliably perform a different service.

For example, you might already use a company for a low-risk administrative task and later consider using its software to store customer information. Its history with you is useful, but you’ll also need evidence relevant to the new system, such as the vendor’s security controls, subcontractors, and recovery arrangements.

You can reuse information you already have after confirming that it remains current and relevant.

Recheck existing evidence when a familiar vendor launches a product, changes its operating model, takes on a new function, or introduces new subcontractors.

Collect vendor documents
Send questionnaires, security exhibits, and authorization forms for signature, then see which vendors have completed the request and which haven’t.
Create a vendor request template
矢印のアイコン

3. Review the evidence that matters for the relationship

There’s no universal vendor due diligence checklist that fits every supplier. These areas can help you decide what to request.

  • Company, ownership, and compliance: Confirm the vendor’s legal identity and ownership structure. Where relevant, check required licenses or registrations, regulatory history, and legal issues that could affect the planned work.‍
  • Financial condition: Review enough information to judge whether the vendor is likely to have the resources and stability to perform throughout the relationship. Evidence could include audited financial statements, annual reports, public filings, credit information, access to funding, debt, or pending litigation.‍
  • Experience and people: Look at the expertise, staffing, and resources behind the service you plan to use. Where appropriate and lawful, review how the vendor screens and trains people with access to sensitive systems or information. You may also need to understand how access is removed and how the service continues if key personnel leave.‍
  • Risk management and controls: Review relevant policies and internal controls, along with evidence of regular testing. Independent certifications and SOC reports can provide useful information, but check their scope and reporting period. A report covering another product or service may have limited value for your assessment.‍
  • Information security: Focus on the systems, content, and data the vendor can access. For higher-risk technology services, relevant evidence might cover access controls, multifactor authentication (MFA), encryption, vulnerability management, penetration testing, and how identified problems get addressed.‍
  • Systems and subcontractors: Identify the technology and outside providers involved in delivering the service. Where data or important operations are involved, find out which subcontractors can access information or perform important parts of the work.‍
  • Operational resilience: Review how the vendor plans to continue or recover after a disruption. For higher-risk relationships, look at recovery objectives, continuity testing, backup arrangements, and your own contingency plans if the vendor can’t perform.

The evidence needs to relate to the service and risks you’re assessing whether you manage this work internally, use vendor due diligence software, or engage outside services.

4. Record and address missing information

A vendor may have a short financial history, decline an on-site review, provide a security report that excludes the product you plan to use, or be unable to disclose information because of another agreement.

For banking organizations, the federal guidance describes how to handle limitations in available information. A practical approach is to:

  1. Record the limitation: Note what you requested, what the vendor provided, what remains missing, and any explanation the vendor gave.‍
  2. Assess the resulting risk: Identify what you can’t verify and how that uncertainty could affect the proposed relationship.‍
  3. Choose a response: You may be able to use alternative evidence, add controls or monitoring, narrow the initial scope, or choose another vendor.

If a supplier can’t provide several years of audited financial statements, other financial evidence or a smaller initial engagement may help you address some of the uncertainty.

If the vendor can’t provide a complete subcontractor list, you may be unable to establish who can access your data or support the service. Record what’s still unknown and account for it in your decision.

Documenting an information gap doesn’t remove the risk or prove that the decision meets every applicable requirement. It provides a record of what was unavailable, what your team couldn’t verify, and why you chose to proceed or stop.

5. Document your decision

Bring the findings together once you have reviewed the available evidence and investigated significant gaps.

Depending on your vendor due diligence policy and approval process, the outcome might be approval, rejection, approval subject to conditions, or an exception that requires additional review.

Record the reasoning behind the outcome, including any unresolved information gaps and how they affected the decision. If approval depends on a smaller initial scope, additional monitoring, a contractual control, or another condition, include that in the record too.

Build the diligence file as the review progresses so the evidence stays connected to the decision it supports. Depending on the relationship, your file might include:

  • Vendor questionnaires or new vendor forms
  • NDAs
  • Tax and insurance documents
  • Financial information
  • Relevant SOC reports or certifications
  • Approval records and exceptions
  • Records of information gaps and how they were addressed
  • Attestations
  • Final agreements

If you rely on a shared assessment, vendor due diligence consultant, or outside vendor due diligence services, keep the relevant findings with your own assessment. Record how the outside work related to how you planned to use the vendor rather than treating it as an automatic approval.

The 2023 banking guidance discusses shared assessments and cites federal collaboration guidelines from 2000. The FTC and DOJ withdrew those guidelines in December 2024.

Organizations considering shared assessments with competitors should get current antitrust guidance instead of relying on the withdrawn document.

6. Complete the required agreements and plan for reassessment

Once the review reaches a decision, identify which documents need to be completed before the relationship can move forward. These might include the final contract, attestations, approvals, or other agreements relevant to the work.

Some agreements need attention much earlier. A vendor may require an NDA before it can share security reports, technical documentation, subcontractor information, or other confidential material. Getting the NDA signed near the beginning of diligence can keep paperwork from delaying the review later.

Not every document in your diligence file needs a signature. For the ones that do, using a consistent process can make recurring vendor requests easier to manage.

If you regularly use an NDA, attestation, or other documents that need signatures, ⁠Dropbox Sign templates let you prepare a reusable version and update only the information that changes for each vendor. You can add required signer fields and pre-fill any details you already know.

Automated reminders can help with outstanding signatures, while status visibility lets you see which requests are complete and which still need attention. That can be useful when the review is ready to move forward but an NDA, approval, attestation, or final agreement is still waiting for signature.

Dropbox Sign helps you prepare and send these documents for signature and track request status. It doesn’t assess vendors, assign risk scores, decide how to handle missing information, or monitor vendor performance. Your team is still responsible for the diligence review and its supporting record.

Vendor relationships can also change after approval. You may need to reassess if:

  • The service or scope changes significantly
  • Audit findings recur or control issues remain unresolved
  • The vendor experiences a security incident or data loss
  • Its financial condition deteriorates materially
  • Important systems, subcontractors, or key personnel change
  • Serious compliance problems or service interruptions occur

For banking organizations, the federal guidance calls for monitoring throughout the relationship, with the frequency and depth matched to its risk and complexity. Organizations outside banking should set their approach based on applicable laws, contracts, internal policies, and the risks of the relationship.

A reassessment may result in a new attestation, amended agreement, or revised terms. Documents requiring signature can follow the same established process rather than being prepared and tracked differently each time.

Keep recurring vendor documents moving with Dropbox Sign

Vendor due diligence can generate the same types of documents across multiple relationships: NDAs before confidential information is shared, attestations during review, approvals before work begins, and agreements once a vendor is accepted.

With Dropbox Sign, you can turn frequently used documents into reusable templates, send them for signature, automate reminders, and track request status.

You can spend less time preparing the same documents and checking whether they’ve been completed, while your team stays responsible for assessing the vendor and making the final decision.

If you’d like to discuss how Dropbox Sign could support your procurement or vendor agreement workflows, ⁠talk to a specialist.

よくある質問

What’s the difference between vendor due diligence and a vendor risk assessment?

Vendor due diligence means collecting and checking relevant information about a proposed supplier relationship. A vendor risk assessment uses that information to evaluate potential issues the relationship creates.

Organizations and frameworks may define these terms differently, so follow the terminology used in your policies and applicable requirements.

What’s a vendor due diligence report?

In M&A, a vendor due diligence report is generally commissioned by the seller and made available to prospective buyers. It may cover the target company’s finances, commercial position, operations, tax affairs, or legal issues.

In procurement, vendor due diligence refers to assessing a supplier before entering or expanding a business relationship.

What are red flags in vendor due diligence?

Possible red flags include unclear ownership, missing required licenses, financial instability, audit reports that don’t cover the relevant service, weak recovery planning, incomplete subcontractor information, and unexplained gaps in requested evidence.

A red flag calls for follow-up rather than automatically determining the outcome. Assess what the issue means for the specific relationship and document your response.

What should be included in a vendor due diligence checklist?

A vendor due diligence checklist should reflect the work the vendor will perform and the risks involved.

Relevant areas can include company and ownership information, legal and regulatory compliance, financial condition, experience and personnel, risk management, information security, systems and subcontractors, and operational resilience.

A low-risk supplier may only need a relatively light review. A vendor with access to sensitive information or an important operation may require much more evidence.

‍

Ready to experience the difference?

Try Dropbox Sign for free →

Explore our API capabilities →

Talk to our team about your needs →

効率を維持

完了しました。受信トレイをご確認ください。

Thank you!
Thank you for subscribing!

Lorem ipsum

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Lorem ipsum
右矢印のアイコン
閉じるアイコン

次の予定

Four people sit around a long table in a bright office, with laptops and papers spread out in front of them.
ワークフロー管理
10
分(記事閲覧時間)

M&A due diligence checklist: What to review before a deal

背景に別の人物がいる机の上でタブレットを使用している手。
ワークフロー管理
8
分(記事閲覧時間)

効率性を引き出す:書類のデジタル化の見落とされているメリット

e ブック

人事業務の自動化ツールキット:円滑な人事業務のための必須ツール

製品
Dropbox SignDropbox Sign APIDropbox Faxインテグレーション
Dropbox Sign が選ばれる理由
電子署名ドキュメントへの署名PDF への入力と署名オンライン契約書電子署名の作成署名エディタWord ドキュメントへの署名
サポート
ヘルプセンターセールス担当に連絡サポートへのお問い合わせCookie の管理スタート ガイド:Dropbox Signスタート ガイド:Dropbox Sign API
リソース
公式ブログお客様の体験談リソース センター適法性ガイドトラスト センター
パートナー
戦略的パートナーパートナー ロケーター
会社
採用情報利用規約プライバシー
Facebook のアイコンYouTube のアイコン

利用可能なお支払い方法

Mastercard のロゴVISA のロゴAmerican Express のロゴDiscover のロゴ
CPA 準拠のバッジHIPAA 準拠のバッジSky High Enterprise Ready のバッジISO 9001 認証のバッジ

Dropbox Sign の電子署名は、米国、欧州連合、英国などを含め、世界中の多くの国で法的に有効です。
詳細については、利用規約およびプライバシー ポリシーをご覧ください。