Vendor due diligence is the process of checking a supplier before you enter or expand a business relationship with them. You gather evidence about the vendor and the work they’ll perform, identify risks or unanswered questions, and use that information to decide how you want to proceed.
The level of review should reflect the relationship. A vendor storing sensitive customer data will usually need more scrutiny than a supplier providing office plants. You need enough relevant information to understand the risks, address gaps, and support the decision you make.
This guide covers a practical vendor due diligence process, including what to assess and how to respond when a vendor can’t provide everything you request.
If your process includes recurring non-disclosure agreements (NDAs), attestations, or agreements, Dropbox Sign can help you prepare, send, sign, and track those documents as the review process moves forward.
Disclaimer: This information is for general purposes only. It isn’t legal advice and shouldn’t replace advice from a licensed attorney.
What is vendor due diligence?
In procurement, vendor due diligence means gathering and reviewing information about a supplier before doing business with them or expanding the work they already perform.
Your review might cover the vendor’s financial condition, regulatory history, information security, operational resilience, key personnel, subcontractors, and internal controls. Which areas need attention depends on what you’re asking the vendor to do and the risks involved.
You may also come across terms such as supplier due diligence, third-party due diligence, and vendor assessment. Their exact meanings vary between organizations and frameworks.
Third-party vendor due diligence can extend beyond paid suppliers. A referral partner, affiliate, consultant, or other organization may warrant review if it can access your data, interact with customers, or support an important operation.
In Mergers and Acquisitions (M&A), vendor due diligence usually refers to a review commissioned by the seller and shared with prospective buyers. If that’s the process you’re looking for, see our M&A due diligence checklist.
How is vendor due diligence different from a vendor risk assessment?
In this guide, vendor due diligence means gathering and checking information about a proposed relationship. A vendor risk assessment uses that information to evaluate any potential issues the relationship creates.
Organizations don’t always use these terms in the same way, so follow the terminology in your own policies and applicable requirements.
A completed questionnaire, financial statement, or SOC report gives you evidence to review. Check whether that evidence is current, whether it covers the service you’re buying, and whether unanswered questions need further investigation.
A practical vendor due diligence process
Your vendor due diligence process should reflect the work the supplier will actually perform rather than putting every vendor through an identical review.
You can structure the process around six steps:
- Tier the relationship by risk
- Assess the work the vendor will perform
- Review evidence relevant to that work
- Record and address missing information
- Make and document your decision
- Complete required agreements and set reassessment triggers
The assessment areas in this guide draw on the June 2023 Interagency Guidance on Third-Party Relationships: Risk Management.
The Federal Reserve Board, FDIC, and Office of the Comptroller of the Currency issued guidance for the banking organizations they supervise. It’s supervisory guidance, not a regulation, and it doesn’t have the force and effect of law or itself impose requirements on software companies, manufacturers, retailers, or other nonbanks.
1. Consider the relationship before you start collecting documents
Start with the work the vendor will actually perform.
Think about which systems it can access, whether it will handle confidential information, which customers or operations depend on the service, and what would happen if it can’t complete the work.
A low-risk, easily replaced supplier may only need a basic review. A vendor storing customer data or supporting an important operation may require detailed evidence about security, finances, resilience, subcontractors, or other areas relevant to the work.
Sending the same questionnaire to both vendors can potentially overburden one while overlooking the risks that matter for the other.
If an answer shows a new dependency or concern, expand the review accordingly.
2. Assess the activity, not just the vendor’s reputation
Previous experience with a supplier can tell you how reliably it delivered its earlier work. It doesn’t necessarily show that the vendor can safely or reliably perform a different service.
For example, you might already use a company for a low-risk administrative task and later consider using its software to store customer information. Its history with you is useful, but you’ll also need evidence relevant to the new system, such as the vendor’s security controls, subcontractors, and recovery arrangements.
You can reuse information you already have after confirming that it remains current and relevant.
Recheck existing evidence when a familiar vendor launches a product, changes its operating model, takes on a new function, or introduces new subcontractors.
3. Review the evidence that matters for the relationship
There’s no universal vendor due diligence checklist that fits every supplier. These areas can help you decide what to request.
- Company, ownership, and compliance: Confirm the vendor’s legal identity and ownership structure. Where relevant, check required licenses or registrations, regulatory history, and legal issues that could affect the planned work.
- Financial condition: Review enough information to judge whether the vendor is likely to have the resources and stability to perform throughout the relationship. Evidence could include audited financial statements, annual reports, public filings, credit information, access to funding, debt, or pending litigation.
- Experience and people: Look at the expertise, staffing, and resources behind the service you plan to use. Where appropriate and lawful, review how the vendor screens and trains people with access to sensitive systems or information. You may also need to understand how access is removed and how the service continues if key personnel leave.
- Risk management and controls: Review relevant policies and internal controls, along with evidence of regular testing. Independent certifications and SOC reports can provide useful information, but check their scope and reporting period. A report covering another product or service may have limited value for your assessment.
- Information security: Focus on the systems, content, and data the vendor can access. For higher-risk technology services, relevant evidence might cover access controls, multifactor authentication (MFA), encryption, vulnerability management, penetration testing, and how identified problems get addressed.
- Systems and subcontractors: Identify the technology and outside providers involved in delivering the service. Where data or important operations are involved, find out which subcontractors can access information or perform important parts of the work.
- Operational resilience: Review how the vendor plans to continue or recover after a disruption. For higher-risk relationships, look at recovery objectives, continuity testing, backup arrangements, and your own contingency plans if the vendor can’t perform.
The evidence needs to relate to the service and risks you’re assessing whether you manage this work internally, use vendor due diligence software, or engage outside services.
4. Record and address missing information
A vendor may have a short financial history, decline an on-site review, provide a security report that excludes the product you plan to use, or be unable to disclose information because of another agreement.
For banking organizations, the federal guidance describes how to handle limitations in available information. A practical approach is to:
- Record the limitation: Note what you requested, what the vendor provided, what remains missing, and any explanation the vendor gave.
- Assess the resulting risk: Identify what you can’t verify and how that uncertainty could affect the proposed relationship.
- Choose a response: You may be able to use alternative evidence, add controls or monitoring, narrow the initial scope, or choose another vendor.
If a supplier can’t provide several years of audited financial statements, other financial evidence or a smaller initial engagement may help you address some of the uncertainty.
If the vendor can’t provide a complete subcontractor list, you may be unable to establish who can access your data or support the service. Record what’s still unknown and account for it in your decision.
Documenting an information gap doesn’t remove the risk or prove that the decision meets every applicable requirement. It provides a record of what was unavailable, what your team couldn’t verify, and why you chose to proceed or stop.
5. Document your decision
Bring the findings together once you have reviewed the available evidence and investigated significant gaps.
Depending on your vendor due diligence policy and approval process, the outcome might be approval, rejection, approval subject to conditions, or an exception that requires additional review.
Record the reasoning behind the outcome, including any unresolved information gaps and how they affected the decision. If approval depends on a smaller initial scope, additional monitoring, a contractual control, or another condition, include that in the record too.
Build the diligence file as the review progresses so the evidence stays connected to the decision it supports. Depending on the relationship, your file might include:
- Vendor questionnaires or new vendor forms
- NDAs
- Tax and insurance documents
- Financial information
- Relevant SOC reports or certifications
- Approval records and exceptions
- Records of information gaps and how they were addressed
- Attestations
- Final agreements
If you rely on a shared assessment, vendor due diligence consultant, or outside vendor due diligence services, keep the relevant findings with your own assessment. Record how the outside work related to how you planned to use the vendor rather than treating it as an automatic approval.
The 2023 banking guidance discusses shared assessments and cites federal collaboration guidelines from 2000. The FTC and DOJ withdrew those guidelines in December 2024.
Organizations considering shared assessments with competitors should get current antitrust guidance instead of relying on the withdrawn document.
6. Complete the required agreements and plan for reassessment
Once the review reaches a decision, identify which documents need to be completed before the relationship can move forward. These might include the final contract, attestations, approvals, or other agreements relevant to the work.
Some agreements need attention much earlier. A vendor may require an NDA before it can share security reports, technical documentation, subcontractor information, or other confidential material. Getting the NDA signed near the beginning of diligence can keep paperwork from delaying the review later.
Not every document in your diligence file needs a signature. For the ones that do, using a consistent process can make recurring vendor requests easier to manage.
If you regularly use an NDA, attestation, or other documents that need signatures, Dropbox Sign templates let you prepare a reusable version and update only the information that changes for each vendor. You can add required signer fields and pre-fill any details you already know.
Automated reminders can help with outstanding signatures, while status visibility lets you see which requests are complete and which still need attention. That can be useful when the review is ready to move forward but an NDA, approval, attestation, or final agreement is still waiting for signature.
Dropbox Sign helps you prepare and send these documents for signature and track request status. It doesn’t assess vendors, assign risk scores, decide how to handle missing information, or monitor vendor performance. Your team is still responsible for the diligence review and its supporting record.
Vendor relationships can also change after approval. You may need to reassess if:
- The service or scope changes significantly
- Audit findings recur or control issues remain unresolved
- The vendor experiences a security incident or data loss
- Its financial condition deteriorates materially
- Important systems, subcontractors, or key personnel change
- Serious compliance problems or service interruptions occur
For banking organizations, the federal guidance calls for monitoring throughout the relationship, with the frequency and depth matched to its risk and complexity. Organizations outside banking should set their approach based on applicable laws, contracts, internal policies, and the risks of the relationship.
A reassessment may result in a new attestation, amended agreement, or revised terms. Documents requiring signature can follow the same established process rather than being prepared and tracked differently each time.
Keep recurring vendor documents moving with Dropbox Sign
Vendor due diligence can generate the same types of documents across multiple relationships: NDAs before confidential information is shared, attestations during review, approvals before work begins, and agreements once a vendor is accepted.
With Dropbox Sign, you can turn frequently used documents into reusable templates, send them for signature, automate reminders, and track request status.
You can spend less time preparing the same documents and checking whether they’ve been completed, while your team stays responsible for assessing the vendor and making the final decision.
If you’d like to discuss how Dropbox Sign could support your procurement or vendor agreement workflows, talk to a specialist.
Vanliga frågor
What’s the difference between vendor due diligence and a vendor risk assessment?
Vendor due diligence means collecting and checking relevant information about a proposed supplier relationship. A vendor risk assessment uses that information to evaluate potential issues the relationship creates.
Organizations and frameworks may define these terms differently, so follow the terminology used in your policies and applicable requirements.
What’s a vendor due diligence report?
In M&A, a vendor due diligence report is generally commissioned by the seller and made available to prospective buyers. It may cover the target company’s finances, commercial position, operations, tax affairs, or legal issues.
In procurement, vendor due diligence refers to assessing a supplier before entering or expanding a business relationship.
What are red flags in vendor due diligence?
Possible red flags include unclear ownership, missing required licenses, financial instability, audit reports that don’t cover the relevant service, weak recovery planning, incomplete subcontractor information, and unexplained gaps in requested evidence.
A red flag calls for follow-up rather than automatically determining the outcome. Assess what the issue means for the specific relationship and document your response.
What should be included in a vendor due diligence checklist?
A vendor due diligence checklist should reflect the work the vendor will perform and the risks involved.
Relevant areas can include company and ownership information, legal and regulatory compliance, financial condition, experience and personnel, risk management, information security, systems and subcontractors, and operational resilience.
A low-risk supplier may only need a relatively light review. A vendor with access to sensitive information or an important operation may require much more evidence.
Ready to experience the difference?
Håll er uppdaterade
Thank you!
Thank you for subscribing!



