What is vendor due diligence?

Vendor due diligence is the assessment a customer makes of a supplier before signing and periodically thereafter. For a bid team, it takes the form of a due diligence questionnaire and evidence requests, answered by subject matter experts and signed off by the bid manager.

The customer first rates the risk your service carries: the data it touches, the access it needs, and how much the customer’s business would rely on it. The customer then gathers information from your organisation, decides whether to proceed and under what conditions, and continues monitoring you once the contract is in place. In third-party risk management, banks and insurers call any supplier a third party. Customers therefore also call the assessment third-party due diligence.

The term covers the customer’s assessment of your organisation as a whole. The DDQs and security questionnaires your team answers feed into that assessment, and the customer’s decision and later monitoring belong to it.

In mergers and acquisitions, the same words refer to a report a seller commissions on its own business for prospective buyers.

What does a customer assess?

The areas it covers

A customer’s assessment commonly covers your financial standing, information security and data protection, legal and regulatory compliance, and operational capability, including business continuity.

Under the Basel Committee’s principles, a bank’s due diligence should consider how you manage your supply chain and key subcontractors, as well as your business continuity and disaster recovery plans. A bank’s questions can therefore extend beyond your organisation to the providers your service depends on.

Why one customer asks more than another

Before assessing anything, the customer ranks its suppliers by risk. The ranking weighs a supplier’s access needs, the sensitivity of the data it handles, and how far the customer’s business depends on it. The riskiest suppliers get the most effort.

The same work can therefore require different levels of effort for two customers, as the rank depends on how much each relies on the service.

Take your bid team’s response to a bank’s RFP for a hosted service that supports one of the bank’s critical functions. Because the bank’s business depends on that service, it ranks you as a top risk and assesses your organisation in depth.

How does vendor due diligence run?

The vendor due diligence questionnaire

The customer collects its information through a vendor due diligence questionnaire, or supplier due diligence questionnaire, that you complete about your organisation. The customer also asks for documents, such as certifications and audit reports.

Suppliers often send minimum assurance evidence while the RFP is still open, such as a SOC 2 Type II report or an ISO 27001 certification.

The bank’s RFP pack for the hosted service includes its questionnaire and a request for your SOC 2 report and business continuity plan. That evidence should therefore go with your bid.

Who takes part on each side

Several customer teams take part, among them risk management, information security, legal or compliance, and procurement or the business unit that needs the service.

On your side, the work runs as on any response: subject matter experts answer their areas, reviewers check, and the bid manager signs off. In the bank’s questionnaire, your information security lead is the subject matter expert for the security questions.

The customer’s decision

The customer has critical control gaps closed before the service goes live. Where your organisation cannot close a risk, the customer writes remediation actions and payment-tied conditions into the contract, so an answer your information security lead gives in the bank’s questionnaire can come back as a condition in the bank’s contract.

The evidence, owners, and answers to gather before a customer asks are set out in how to prepare for a due diligence check.

When does vendor due diligence happen?

Before the contract is signed

The customer runs its due diligence while it selects a supplier, before its stakeholders, legal and compliance among them, review and approve the contract. A DDQ your team answers with the bid belongs to that first round.

In the third-party life cycle that the Institute of Internal Auditors sets out, selection comes first, followed by contracting, onboarding, monitoring, and offboarding.

While the contract runs

Once the contract is signed, the customer continues to monitor your organisation for the contract’s duration. The customer also re-evaluates your performance periodically and whenever the agreement changes, and tracks the contract’s expiry and renewal dates.

Under the Basel Committee’s principles, a bank renewing the contract is expected to repeat its due diligence first, using what onboarding and monitoring showed. Hence, a DDQ answer from before signature that no longer matches how your organisation works comes up at renewal.

Which rules require vendor due diligence?

No single law governs vendor due diligence everywhere. Banks assess suppliers because the frameworks their supervisors apply require it, and those duties flow to you through the contract.

The Basel Committee’s principles are meant to be applied proportionately and are directed at large banks that operate internationally and at their supervisors. Many jurisdictions also have their own third-party risk frameworks. Third-party risk management scales to each bank and to the risk and criticality of each arrangement under those principles.

In the EU, for example, the Digital Operational Resilience Act (DORA) keeps a financial entity that uses ICT providers fully responsible for meeting its own obligations.

Audit and information rights

Under the Basel Committee’s principles, bank contracts are expected to give the bank timely information, including incidents, and rights of access and audit. In the bank’s draft contract for the hosted service, the audit clause your legal reviewer reads extends those rights to the bank’s supervisor.

In the EU, for example, a contract for an ICT service supporting a critical function must grant unrestricted access, inspection, and audit rights under DORA. Those rights extend to the financial entity, an auditor it appoints, and the supervisor, and you owe each full cooperation. The contract sets the scope, procedures, and frequency of audits. Where an audit would affect your other clients’ rights, the parties may agree alternative levels of assurance, which you can propose.

Your own subcontractors

For critical arrangements, a bank’s contract is expected to carry further conditions on your key subcontractors under the Basel Committee’s principles: notice before you use or change one, incident reporting, access and audit rights over them, and your obligations passed down to them.

In the bank’s draft contract for the hosted service, your legal reviewer finds the notice condition as a clause on changing a subcontractor.

In the EU, for example, the contract keeps you responsible for your subcontractors’ services under the technical standard on subcontracting that supplements DORA. You must also monitor those subcontractors and report on them. A material change to your subcontracting is announced in time for the financial entity to assess the change, and the entity approves or objects within a reasonable notice period. You make the change only once the entity approves or raises no objection, and you can rely on that notice period.

Exit from the contract

Bank contracts are also expected to cover termination and your support for the bank’s exit, under the Basel Committee’s principles. Plans for what happens once a supplier agreement ends are also listed as a cybersecurity outcome.

In the EU, for example, DORA requires an exit strategy for a critical function, with a mandatory transition period. During that period, you keep delivering while the financial entity moves to another provider or brings the service in-house.

Vendor due diligence and a DDQ

A DDQ is a document you complete when a bank, insurer, or corporate buyer assesses you as a third party. Vendor due diligence is the assessment the DDQ feeds.

The assessment goes past your answers to the evidence behind them, any audit, the customer’s decision, and its later reassessment of you.

Vendor due diligence and a security questionnaire

A security questionnaire covers one area of the assessment: information security. It is often a standard set such as the SIG or the CAIQ, or the customer’s own control-focused set built to compare suppliers.

Where you have no assurance report to offer, the customer relies on the security questionnaire and tests samples of your control evidence.

Vendor due diligence and pre-qualification

A PQQ decides whether you stay in the competition, before your capability is assessed. Vendor due diligence decides whether the customer takes on the risk your organisation brings, and the assessment carries on after signature.

In EU public procurement, for example, Directive 2014/24/EU limits selection criteria to suitability to pursue the professional activity, economic and financial standing, and technical and professional ability, in proportion to the contract.

Vendor due diligence in SEQUESTO

Vendor due diligence leaves your team to answer every round with answers it can trace to a source, and SEQUESTO brings auditability to that work. James orchestrates the response, and Agent Force’s specialist agents draft each answer from approved content, showing the reasoning behind each draft. Subject matter experts and reviewers work in the same workflow, where each question can have its own reviewer and approver. The bid manager owns the final word and signs off.

Each answer names the policy and clause it rests on. You can attach evidence, such as your SOC 2 report, to the answers it supports. When a policy changes, SEQUESTO flags every answer drawn from that policy for review. Each answer’s record also notes the policy version behind the answer, so your team can show what it approved at each round.

SEQUESTO logs every action with the item it concerns, the person who took it, and the time. The log can be searched and exported for the customer’s due diligence questionnaire.

Frequently Asked Questions

Put the terminology to work

Now you know the language, see how SEQUESTO automates the process. Book a demo and experience AI-powered bid management first-hand.