Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

vendor due diligence checklist — Vendor Due Diligence Checklist: 14 Factors, Three Depths, One Evidence Rule (2026)

Vendor Due Diligence Checklist: 14 Factors, Three Depths, One Evidence Rule (2026)

A vendor due diligence checklist is the list of what gets checked, by whom and against what evidence before a provider is allowed to hold your data, touch your systems or run a function you depend on. The good ones are not long; they are tiered, so that a low-risk supplier takes minutes and a critical provider takes the full review, and they distinguish evidence from assertion at every line. This guide builds a vendor due diligence checklist on the fourteen factors the 2023 Interagency Guidance names, shows how depth changes by tier, and sets the evidence rule that makes the checklist worth signing.

What this guide covers

vendor due diligence checklist explained
A vendor due diligence checklist tiered by risk

The fourteen factors behind every vendor due diligence checklist

The Interagency Guidance lists the factors a banking organisation typically considers in due diligence, lettered (a) to (n): strategies and goals; legal and regulatory compliance; financial condition; business experience; qualifications and backgrounds of principals; risk management; information security; management of information systems; operational resilience; incident reporting and management; physical security; reliance on subcontractors; insurance coverage; and contractual arrangements with other parties. Nothing in the other regimes contradicts that list, and DORA Article 28(4)(d), GDPR Article 28(1), PCI DSS 12.8.3 and 23 NYCRR 500.11(a)(3) all require the review it describes.

That makes the fourteen factors the right rows for a vendor due diligence checklist whatever sector you are in. What changes by sector is the depth and the evidence, and what changes by provider is the tier.

The vendor due diligence checklist by tier

Factor Lite (low tier) Standard Enhanced (high and critical)
Strategies, goals, business experience Company profile References from comparable customers References plus the provider’s stated strategy and planned changes
Legal and regulatory compliance Registration check Licences, regulatory actions, litigation search As standard, plus regulator correspondence where the provider is regulated
Principals Sanctions screening Screening plus ownership structure Screening, ownership, background of key executives
Financial condition Not required below a spend threshold Viability checklist Audited accounts, credit assessment, going-concern read
Risk management Questionnaire answers Policy set reviewed Policies, risk register extract, internal audit summary
Information security Lite questionnaire Standard questionnaire scored; assurance report reviewed Enhanced questionnaire, penetration test summary, on-site or remote assessment at critical
Information systems management Questionnaire Change, patch and configuration practice evidenced As standard, plus architecture review
Operational resilience; incident management Not required Questionnaire sections Continuity and resilience checklist; recovery objectives compared
Physical security Not required Questionnaire Assessed on site where the provider holds your data or equipment
Subcontractors Declared Declared with locations; material ones registered As standard, plus the provider’s own oversight evidenced
Insurance Not required Certificates for the cover the contract requires Limits tested against exposure
Other contractual arrangements Not required Conflicts and exclusivities disclosed Dependence on other customers assessed

The tier comes from the inherent-risk assessment run before the checklist starts; our guide to the third-party risk assessment covers the twelve questions that set it. A vendor due diligence checklist applied at one depth to every provider is a sure way for a programme to exhaust itself on the wrong suppliers.

The evidence rule

Every line of the checklist records what supports the answer, and the rule is simple: a provider’s statement is an answer, not evidence. Accepted evidence is an independent assurance report covering the control and the period; a certificate with its scope statement and number; a dated, approved policy or procedure extract; a configuration export or screenshot; a penetration test executive summary with date and scope; or the reviewer’s own observation. Marketing material, a summary of a policy, a description of a configuration, or a statement that testing is performed are answers awaiting evidence.

The rule has a consequence for scoring. A control that is in place, evidenced and meets the requirement scores full marks; asserted but not evidenced scores one; absent scores zero. Ten questions in the security section are mandatory, so that a zero on multi-factor authentication, encryption, backups, incident notification, subcontractors, data location, data return, assurance or patching is a finding whatever the total.

Reading assurance reports on a vendor due diligence checklist

A SOC 2 report, an ISO/IEC 27001 certificate or a PCI DSS attestation is strong evidence for the controls and period it covers, and no evidence at all for anything outside them. The checklist therefore asks five questions of every report: are the services you use inside the scope; are the locations and subservice providers that deliver them inside it; what is the period end and is it still within twelve months or covered by a bridge letter; what does the opinion say and what were the exceptions; and which complementary user entity controls does the report assume you operate.

Carved-out subservice organisations are fourth parties and go on the subcontractor register. Our guide to the SOC 2 bridge letter covers the currency gap in detail.

Financial condition, screening and data protection

Three checks sit outside the questionnaire. Financial viability, proportionate to spend and criticality: accounts, audit opinion, going-concern statement, liquidity, ownership and funding, with a going-concern doubt, a qualified opinion or a venture-backed provider whose runway is shorter than the contract term treated as adverse indicators. Integrity screening of the entity and its principals: sanctions, politically exposed persons, adverse media, regulatory registers, litigation, anti-bribery and beneficial ownership, with a confirmed sanctions match a bar. And data protection where personal or health data is involved: the processor’s guarantees, the sub-processor list and objection rights, transfers, breach notification timing and deletion, before any processor agreement or business associate agreement is signed.

Resilience on the vendor due diligence checklist

For any provider supporting a function with a recovery objective, the vendor due diligence checklist compares the provider’s recovery time and recovery point objectives with the organisation’s own for the function. A gap is a finding, closed by a contractual commitment, by an organisation-side measure such as a backup provider or independently held data, or by an accepted risk signed by the business line head. It is not closed by assuming the provider’s plan is conservative. The same section asks when the plans were last tested, what the provider’s own critical dependencies are, whether backups are isolated and restore-tested, and how fast the organisation is told when the service fails.

What a vendor due diligence checklist is not for

It is not a substitute for tiering, which decides the depth before the checklist opens. It is not a questionnaire the provider fills in unsupervised; the reviewer scores every answer against evidence. It is not a one-time event; the same vendor due diligence checklist is re-run at the tier’s cadence and on any material change. And it is not the contract: the findings it produces become conditions of approval and contract requirements, but the checklist itself binds nobody. A programme that treats a completed checklist as the end of the process has confused the review with the relationship.

Closing the vendor due diligence checklist: the report and the decision

The vendor due diligence checklist ends in two records. The due diligence report states, area by area, who reviewed, what was found and which findings are conditions of approval, plus what evidence from others was relied on and its limits. The selection decision record then names the alternatives considered, the conflicts of interest declared, the suitability determination and the authority that approved, which for a critical arrangement is the committee.

Every finding enters the findings register on the day the report is signed. A provider that refuses to provide evidence has generated a finding; the options are to require the evidence as a condition of contract, to accept the gap with compensating controls under an approved exception, or to walk away.

Where the checklist and its instruments come from

The TPRM Toolkit ships the vendor due diligence checklist as an operating set rather than a list: the tiered due diligence procedure, three questionnaires at 21, 84 and 136 questions with the evidence expected against every question, the scoring guide, the financial viability, screening, data protection and resilience checklists, the assurance report review procedure and template, the on-site assessment checklist, the due diligence report and the selection decision record, each mapped to the regime that requires it.

For the questions from the provider’s side, read the vendor security questionnaire playbook; for where due diligence sits in the programme, the TPRM lifecycle. The subcontractor rows lead into fourth-party risk, and the TPRM policy guide covers the commitment that nothing is signed without this review.

Frequently asked questions about a vendor due diligence checklist

How long should a vendor due diligence checklist be?

As long as the tier requires. A low-tier provider answers around twenty questions and provides a handful of documents; a critical provider answers 136 across twenty domains and supplies accounts, assurance reports, test results and a subcontractor list. Fourteen factors, three depths.

Can the checklist be completed from a SOC 2 report alone?

No. A report covers information security and some resilience for a defined scope and period. Financial condition, principals, subcontractors, insurance, other contractual arrangements and data protection are not in it, and the questions the report does answer still need their scope and exceptions read.

Who completes a vendor due diligence checklist?

The relationship owner owns it and signs the report; information security scores the security sections; finance, compliance, data protection and business continuity complete their checks; the TPRM function confirms the depth matched the tier and accepts the report.

How often is it repeated?

At the tier’s reassessment cadence, annually for critical and high tiers, and on any material change at the provider, any incident, or any change in how the organisation uses the service.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.