跳到主要内容
dropboxsign 徽标
为什么选择 Dropbox Sign?
展开或折叠手风琴

您可以做什么

在线签署文档
创建电子签名
选择或创建模板
填写和签署 PDF
完成线上合同
文档管理
探索功能
向右箭头图标

用例

销售与业务拓展
人力资源
初创公司
金融科技
房地产
按需服务
产品
展开或折叠手风琴
Dropbox 图标
Sign
实现轻松发送和签字
Dropbox 图标
Sign API
将电子签名集成到您的工作流程中
dropbox fax 图标
Fax
无需传真机便能发送传真
dropbox 集成图标
集成
无缝集成助力您轻松工作
资源
展开或折叠手风琴
博客
工作流程专业知识和产品新闻
客户案例
讲述取得实际成果的真实故事
帮助中心
关于我们产品的深入指南
资源库
报告、视频和信息表
开发人员
定价
展开或折叠手风琴
Dropbox Sign 定价
找到适合您的套餐
Dropbox Sign API 定价
讲述取得实际成果的真实故事
与销售人员联系
注册
联系销售人员
登录
展开或折叠手风琴
Dropbox Sign
Dropbox Fax
免费试用版
博客
/
工作流程管理

Vendor due diligence: What to assess and what to do when information is missing

by 
Dropbox Sign team
September 30, 2026
11
分钟阅读时间
A woman standing at a conference table gestures while three colleagues listen, with charts and a laptop on the table.
工具提示图标

外观全新但功能同样出色的产品!HelloSign 现为 Dropbox Sign。

关闭图标

Vendor due diligence is the process of checking a supplier before you enter or expand a business relationship with them. You gather evidence about the vendor and the work they’ll perform, identify risks or unanswered questions, and use that information to decide how you want to proceed.

The level of review should reflect the relationship. A vendor storing sensitive customer data will usually need more scrutiny than a supplier providing office plants. You need enough relevant information to understand the risks, address gaps, and support the decision you make.

This guide covers a practical vendor due diligence process, including what to assess and how to respond when a vendor can’t provide everything you request.

If your process includes recurring non-disclosure agreements (NDAs), attestations, or agreements, ⁠Dropbox Sign can help you prepare, send, sign, and track those documents as the review process moves forward.

Disclaimer: This information is for general purposes only. It isn’t legal advice and shouldn’t replace advice from a licensed attorney.

What is vendor due diligence?

In procurement, vendor due diligence means gathering and reviewing information about a supplier before doing business with them or expanding the work they already perform.

Your review might cover the vendor’s financial condition, regulatory history, information security, operational resilience, key personnel, subcontractors, and internal controls. Which areas need attention depends on what you’re asking the vendor to do and the risks involved.

You may also come across terms such as supplier due diligence, third-party due diligence, and vendor assessment. Their exact meanings vary between organizations and frameworks.

Third-party vendor due diligence can extend beyond paid suppliers. A referral partner, affiliate, consultant, or other organization may warrant review if it can access your data, interact with customers, or support an important operation.

In Mergers and Acquisitions (M&A), vendor due diligence usually refers to a review commissioned by the seller and shared with prospective buyers. If that’s the process you’re looking for, see our M&A due diligence checklist⁠.

How is vendor due diligence different from a vendor risk assessment?

In this guide, vendor due diligence means gathering and checking information about a proposed relationship. A vendor risk assessment uses that information to evaluate any potential issues the relationship creates.

Organizations don’t always use these terms in the same way, so follow the terminology in your own policies and applicable requirements.

A completed questionnaire, financial statement, or SOC report gives you evidence to review. Check whether that evidence is current, whether it covers the service you’re buying, and whether unanswered questions need further investigation.

A practical vendor due diligence process

Your vendor due diligence process should reflect the work the supplier will actually perform rather than putting every vendor through an identical review.

You can structure the process around six steps:

  1. Tier the relationship by risk
  2. Assess the work the vendor will perform
  3. Review evidence relevant to that work
  4. Record and address missing information
  5. Make and document your decision
  6. Complete required agreements and set reassessment triggers

The assessment areas in this guide draw on the June 2023 ⁠Interagency Guidance on Third-Party Relationships: Risk Management.

The Federal Reserve Board, FDIC, and Office of the Comptroller of the Currency issued guidance for the banking organizations they supervise. It’s supervisory guidance, not a regulation, and it doesn’t have the force and effect of law or itself impose requirements on software companies, manufacturers, retailers, or other nonbanks.

1. Consider the relationship before you start collecting documents

Start with the work the vendor will actually perform.

Think about which systems it can access, whether it will handle confidential information, which customers or operations depend on the service, and what would happen if it can’t complete the work.

A low-risk, easily replaced supplier may only need a basic review. A vendor storing customer data or supporting an important operation may require detailed evidence about security, finances, resilience, subcontractors, or other areas relevant to the work.

Sending the same questionnaire to both vendors can potentially overburden one while overlooking the risks that matter for the other.

If an answer shows a new dependency or concern, expand the review accordingly.

2. Assess the activity, not just the vendor’s reputation

Previous experience with a supplier can tell you how reliably it delivered its earlier work. It doesn’t necessarily show that the vendor can safely or reliably perform a different service.

For example, you might already use a company for a low-risk administrative task and later consider using its software to store customer information. Its history with you is useful, but you’ll also need evidence relevant to the new system, such as the vendor’s security controls, subcontractors, and recovery arrangements.

You can reuse information you already have after confirming that it remains current and relevant.

Recheck existing evidence when a familiar vendor launches a product, changes its operating model, takes on a new function, or introduces new subcontractors.

Collect vendor documents
Send questionnaires, security exhibits, and authorization forms for signature, then see which vendors have completed the request and which haven’t.
Create a vendor request template
箭头图标

3. Review the evidence that matters for the relationship

There’s no universal vendor due diligence checklist that fits every supplier. These areas can help you decide what to request.

  • Company, ownership, and compliance: Confirm the vendor’s legal identity and ownership structure. Where relevant, check required licenses or registrations, regulatory history, and legal issues that could affect the planned work.‍
  • Financial condition: Review enough information to judge whether the vendor is likely to have the resources and stability to perform throughout the relationship. Evidence could include audited financial statements, annual reports, public filings, credit information, access to funding, debt, or pending litigation.‍
  • Experience and people: Look at the expertise, staffing, and resources behind the service you plan to use. Where appropriate and lawful, review how the vendor screens and trains people with access to sensitive systems or information. You may also need to understand how access is removed and how the service continues if key personnel leave.‍
  • Risk management and controls: Review relevant policies and internal controls, along with evidence of regular testing. Independent certifications and SOC reports can provide useful information, but check their scope and reporting period. A report covering another product or service may have limited value for your assessment.‍
  • Information security: Focus on the systems, content, and data the vendor can access. For higher-risk technology services, relevant evidence might cover access controls, multifactor authentication (MFA), encryption, vulnerability management, penetration testing, and how identified problems get addressed.‍
  • Systems and subcontractors: Identify the technology and outside providers involved in delivering the service. Where data or important operations are involved, find out which subcontractors can access information or perform important parts of the work.‍
  • Operational resilience: Review how the vendor plans to continue or recover after a disruption. For higher-risk relationships, look at recovery objectives, continuity testing, backup arrangements, and your own contingency plans if the vendor can’t perform.

The evidence needs to relate to the service and risks you’re assessing whether you manage this work internally, use vendor due diligence software, or engage outside services.

4. Record and address missing information

A vendor may have a short financial history, decline an on-site review, provide a security report that excludes the product you plan to use, or be unable to disclose information because of another agreement.

For banking organizations, the federal guidance describes how to handle limitations in available information. A practical approach is to:

  1. Record the limitation: Note what you requested, what the vendor provided, what remains missing, and any explanation the vendor gave.‍
  2. Assess the resulting risk: Identify what you can’t verify and how that uncertainty could affect the proposed relationship.‍
  3. Choose a response: You may be able to use alternative evidence, add controls or monitoring, narrow the initial scope, or choose another vendor.

If a supplier can’t provide several years of audited financial statements, other financial evidence or a smaller initial engagement may help you address some of the uncertainty.

If the vendor can’t provide a complete subcontractor list, you may be unable to establish who can access your data or support the service. Record what’s still unknown and account for it in your decision.

Documenting an information gap doesn’t remove the risk or prove that the decision meets every applicable requirement. It provides a record of what was unavailable, what your team couldn’t verify, and why you chose to proceed or stop.

5. Document your decision

Bring the findings together once you have reviewed the available evidence and investigated significant gaps.

Depending on your vendor due diligence policy and approval process, the outcome might be approval, rejection, approval subject to conditions, or an exception that requires additional review.

Record the reasoning behind the outcome, including any unresolved information gaps and how they affected the decision. If approval depends on a smaller initial scope, additional monitoring, a contractual control, or another condition, include that in the record too.

Build the diligence file as the review progresses so the evidence stays connected to the decision it supports. Depending on the relationship, your file might include:

  • Vendor questionnaires or new vendor forms
  • NDAs
  • Tax and insurance documents
  • Financial information
  • Relevant SOC reports or certifications
  • Approval records and exceptions
  • Records of information gaps and how they were addressed
  • Attestations
  • Final agreements

If you rely on a shared assessment, vendor due diligence consultant, or outside vendor due diligence services, keep the relevant findings with your own assessment. Record how the outside work related to how you planned to use the vendor rather than treating it as an automatic approval.

The 2023 banking guidance discusses shared assessments and cites federal collaboration guidelines from 2000. The FTC and DOJ withdrew those guidelines in December 2024.

Organizations considering shared assessments with competitors should get current antitrust guidance instead of relying on the withdrawn document.

6. Complete the required agreements and plan for reassessment

Once the review reaches a decision, identify which documents need to be completed before the relationship can move forward. These might include the final contract, attestations, approvals, or other agreements relevant to the work.

Some agreements need attention much earlier. A vendor may require an NDA before it can share security reports, technical documentation, subcontractor information, or other confidential material. Getting the NDA signed near the beginning of diligence can keep paperwork from delaying the review later.

Not every document in your diligence file needs a signature. For the ones that do, using a consistent process can make recurring vendor requests easier to manage.

If you regularly use an NDA, attestation, or other documents that need signatures, ⁠Dropbox Sign templates let you prepare a reusable version and update only the information that changes for each vendor. You can add required signer fields and pre-fill any details you already know.

Automated reminders can help with outstanding signatures, while status visibility lets you see which requests are complete and which still need attention. That can be useful when the review is ready to move forward but an NDA, approval, attestation, or final agreement is still waiting for signature.

Dropbox Sign helps you prepare and send these documents for signature and track request status. It doesn’t assess vendors, assign risk scores, decide how to handle missing information, or monitor vendor performance. Your team is still responsible for the diligence review and its supporting record.

Vendor relationships can also change after approval. You may need to reassess if:

  • The service or scope changes significantly
  • Audit findings recur or control issues remain unresolved
  • The vendor experiences a security incident or data loss
  • Its financial condition deteriorates materially
  • Important systems, subcontractors, or key personnel change
  • Serious compliance problems or service interruptions occur

For banking organizations, the federal guidance calls for monitoring throughout the relationship, with the frequency and depth matched to its risk and complexity. Organizations outside banking should set their approach based on applicable laws, contracts, internal policies, and the risks of the relationship.

A reassessment may result in a new attestation, amended agreement, or revised terms. Documents requiring signature can follow the same established process rather than being prepared and tracked differently each time.

Keep recurring vendor documents moving with Dropbox Sign

Vendor due diligence can generate the same types of documents across multiple relationships: NDAs before confidential information is shared, attestations during review, approvals before work begins, and agreements once a vendor is accepted.

With Dropbox Sign, you can turn frequently used documents into reusable templates, send them for signature, automate reminders, and track request status.

You can spend less time preparing the same documents and checking whether they’ve been completed, while your team stays responsible for assessing the vendor and making the final decision.

If you’d like to discuss how Dropbox Sign could support your procurement or vendor agreement workflows, ⁠talk to a specialist.

常见问题解答

What’s the difference between vendor due diligence and a vendor risk assessment?

Vendor due diligence means collecting and checking relevant information about a proposed supplier relationship. A vendor risk assessment uses that information to evaluate potential issues the relationship creates.

Organizations and frameworks may define these terms differently, so follow the terminology used in your policies and applicable requirements.

What’s a vendor due diligence report?

In M&A, a vendor due diligence report is generally commissioned by the seller and made available to prospective buyers. It may cover the target company’s finances, commercial position, operations, tax affairs, or legal issues.

In procurement, vendor due diligence refers to assessing a supplier before entering or expanding a business relationship.

What are red flags in vendor due diligence?

Possible red flags include unclear ownership, missing required licenses, financial instability, audit reports that don’t cover the relevant service, weak recovery planning, incomplete subcontractor information, and unexplained gaps in requested evidence.

A red flag calls for follow-up rather than automatically determining the outcome. Assess what the issue means for the specific relationship and document your response.

What should be included in a vendor due diligence checklist?

A vendor due diligence checklist should reflect the work the vendor will perform and the risks involved.

Relevant areas can include company and ownership information, legal and regulatory compliance, financial condition, experience and personnel, risk management, information security, systems and subcontractors, and operational resilience.

A low-risk supplier may only need a relatively light review. A vendor with access to sensitive information or an important operation may require much more evidence.

‍

Ready to experience the difference?

Try Dropbox Sign for free →

Explore our API capabilities →

Talk to our team about your needs →

保持更新

完成!请检查您的收件箱。

Thank you!
Thank you for subscribing!

Lorem ipsum

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Lorem ipsum
向右箭头图标
关闭图标

下一项:

Four people sit around a long table in a bright office, with laptops and papers spread out in front of them.
工作流程管理
10
分钟阅读时间

M&A due diligence checklist: What to review before a deal

一双手在办公桌上使用平板电脑,背景中还有另一个人。
工作流程管理
8
分钟阅读时间

提升效率:文档数字化被忽视的优势

电子书

人力资源自动化工具包:实现高效人力资源管理的基本工具

产品
Dropbox SignDropbox Sign APIDropbox Fax集成
为什么选择 Dropbox Sign
电子签名签署文档签署和填写 PDF在线合同创建电子签名签名编辑器签署 Word 文档
支持
帮助中心与销售人员联系联系支持人员管理 Cookie开始使用:Dropbox Sign开始使用:Dropbox Sign API
资源
博客客户案例资源中心合法性指南信任中心
合作伙伴
战略合作伙伴合作伙伴查找工具
公司
招贤纳士条款隐私
Facebook 图标YouTube 图标

接受的付款方式

Mastercard 徽标Visa 徽标American Express 徽标Discover 徽标
CPA 合规标记HIPAA 合规标记Sky High Enterprise Ready 标记ISO 9001 认证标志

在美国、欧盟、英国和世界许多其他地区,Dropbox Sign 电子签名均具有法律约束力。
如需了解更多信息,请查看我们的条款和条件以及隐私政策