The Vendor Due Diligence Checklist

Introduction

A proposal looks polished. A reference call sounds reassuring. Neither tells you whether a vendor's insurance has lapsed, whether its license covers the work you're hiring it for, or whether it shares an address with three entities you've never heard of.

That gap matters more than ever. Third parties were involved in 48% of confirmed breaches analyzed in Verizon's 2026 Data Breach Investigations Report, up from 30% in the prior dataset. When a vendor touches your property, systems, customer data, or money, self-reported claims aren't enough.

A vendor due diligence checklist gives your team a repeatable way to collect comparable evidence, spot red flags before you sign, and document a decision you can defend later. This article walks through defining vendor risk, reviewing the right categories, verifying claims independently, documenting your decision, and monitoring vendors after onboarding.

Key Takeaways

  • Tier vendors by risk: those with data access, operational importance, or subcontractor dependencies need deeper review.
  • Treat questionnaires as claims to verify, not proof — record the source, capture date, and any gaps.
  • Cover legitimacy, finances, insurance, reputation, compliance, security, resilience, and fourth-party exposure.
  • Make decisions explicit: approve, approve with conditions, defer, or reject, with a named owner.
  • Reassess vendors after incidents, ownership changes, expanded access, or contract renewals.

What Is Vendor Due Diligence?

Vendor due diligence is the structured investigation of a third party before — and during — a business relationship. It examines whether a vendor is legitimate, capable, financially stable, secure, compliant, and suited to your organization's risk tolerance.

This isn't the same as comparing three quotes or filing a completed questionnaire. Real due diligence combines vendor-provided documentation, internal review, independent research, and a documented decision. Questionnaires capture what a vendor claims; independent checks—public records, filings, and live systems—show what you can verify.

The process applies well beyond software providers, including:

  • Contractors and subcontractors
  • Property-service vendors (landscaping, HVAC, cleaning)
  • Consultants and professional-service firms
  • Payment providers and financial intermediaries
  • Logistics and freight partners

Risk Tiering: Not Every Vendor Needs the Same Scrutiny

A landscaping crew and a payment processor don't warrant the same review. NIST's supply-chain due diligence guidance recommends prioritizing the amount of research by supplier criticality rather than applying one standard checklist to every relationship.

Tier vendors based on:

  • Data or system access granted
  • Operational criticality to your business
  • Dollar value of the contract
  • Regulatory exposure created by the relationship
  • Geographic or service dependencies
  • Reliance on their own subcontractors

A vendor handling customer payment data or running a critical facility deserves a far deeper file than a one-time supplier delivering office furniture.

The Vendor Due Diligence Checklist

Start With a Vendor Record

Before diving into verification, build a baseline record: legal name, trade names, entity type, registration details, business address, ownership, key contacts, services provided, locations served, and intended contract scope. This becomes your reference point for spotting inconsistencies later.

Confirm Legal Standing and Licensing

Verify business registration, required licenses or permits, professional credentials, and the vendor's authority to operate in the relevant jurisdiction. Watch for mismatches between what the vendor claims and what official records show.

California's Contractors State License Board, for example, instructs filers to match the exact contractor business name and license number across insurance certificates — a small detail that catches a surprising number of discrepancies.

Check Financial Health and Insurance

Request financial evidence, tax documentation, and insurance certificates. Then check coverage limits, policy dates, exclusions, and named-insured information. A single document isn't proof of overall solvency. Federal interagency guidance on third-party risk management recommends assessing financial condition through multiple types of evidence, not one submitted statement.

A fictional specimen built by Salvara illustrates why this matters: "Cascade Comfort Mechanical LLC" showed a current $20,000 bond, but only after a 26-day coverage gap, with general-liability insurance set to expire in 41 days. An active license at the moment of signing doesn't guarantee coverage through project completion.

Vendor insurance and licensing coverage gap timeline with key risk dates

Investigate Reputation and Conduct

Pull litigation records, regulatory actions, sanctions screening where relevant, adverse media, and customer complaints. Separate verified findings from unsubstantiated online claims. A one-star review proves frustration, not misconduct.

Evaluate Operational Resilience and Cybersecurity

For vendors supporting critical operations, review:

  • Staffing qualifications and response times
  • Service-level commitments and continuity plans
  • Backup arrangements and incident-notification procedures
  • Capacity to scale and dependence on critical subcontractors
  • Access controls, encryption practices, and breach history
  • Relevant certifications, such as SOC 2 reports or ISO/IEC 27001

Real-World Scenarios

These checks look different depending on who you're hiring:

  • A property owner verifies a contractor's license and insurance before work starts.
  • A general contractor reviews a subcontractor's bonding and shared business addresses.
  • A multi-site operator evaluates a facilities provider's capacity across locations.
  • An SMB assesses a software partner's security documentation and uptime history.

In another fictional illustration, a freight-broker specimen combined a federal $75,000 bond record with a state registry showing a shared address across four logistics entities, one of which had its operating authority revoked. Neither fact alone would raise concern, but combined they're reason enough to ask more questions before signing.

How to Verify Vendor Information and Evidence

A checklist item isn't complete until the claim is checked against something the vendor doesn't control.

Build an Evidence Standard

For each checklist item, run the same four steps:

  1. Identify the claim the vendor is making
  2. Request supporting documentation
  3. Verify it through an independent source when the stakes are high
  4. Record the source, capture date, and any unresolved limitation That file becomes an audit trail you can reopen months later.

Cross-Check Against Authoritative Sources

Claim Where to verify
Contractor license State licensing board lookup (for example, CSLB's license search)
Business registration Secretary of State business-entity search
Insurer standing State insurance department company search
Security certification IAF CertSearch or the certifying body's directory
Federal litigation PACER (federal courts only; not state courts)
Sanctions exposure OFAC's Specially Designated Nationals search
Match each claim to the right primary source. One database is rarely enough.

Watch for Red Flags

Inconsistencies worth flagging include:

  • Different legal names across documents
  • Expired licenses presented as active
  • Conflicting business addresses
  • Unexplained ownership changes
  • Missing or vague insurance details
  • Unverifiable certifications
  • Reviews that contradict the vendor's own service claims Single mismatches are noisy. Patterns are signal. A fictional five-month-old entity, "Larkspur Express Inc.," shows why. Six dated events (shared address, terminal, officer, insurance chain, and financed equipment) tied it to a revoked predecessor through five independent continuity indicators. No single data point proved the link. Together, they told a clear story. That is the kind of work Salvara is built for: source-verified public records, live registry data, and open-web findings in one file, with every claim dated and sourced so a stakeholder or counsel can re-check it. The output supports decisions. It does not replace legal, insurance, or regulatory review. Evidence-register fields to track:
  • Checklist item and vendor response
  • Source and capture date
  • Finding and risk implication
  • Owner and follow-up deadline

How to Make and Document the Decision

Set Thresholds Before You Review

Decide in advance what's non-negotiable, what exceptions are acceptable, and who's authorized to accept residual risk. Reviewing a vendor without pre-set thresholds invites inconsistent decisions.

Four Practical Outcomes

  1. Approve: findings meet the risk tier's requirements with no material gaps.
  2. Approve with conditions: minor gaps exist, with deadlines and named owners for remediation.
  3. Pause: pending additional evidence or remediation before any work begins.
  4. Reject: unresolved findings exceed the organization's risk appetite.

A minor documentation gap might be fine for a low-risk supplier. The same gap is unacceptable for a vendor handling sensitive data or critical operations. Compare findings against the vendor's tier, not a single universal bar.

Put Findings Into the Contract

Once you choose an outcome, translate material risks into contract terms:

  • Insurance requirements and notice of coverage changes
  • Security obligations and audit or evidence rights
  • Incident-notification timelines
  • Data-return and deletion duties
  • Subcontractor oversight and exit provisions

Require Cross-Functional Sign-Off

Involve the teams affected by the risk (procurement, operations, finance, legal, security, facilities), scaled to the vendor's tier. A low-risk supplier needs a quick sign-off. A vendor with system access needs several names on the record.

Document the unresolved issues, compensating controls, and named approver so the organization can later explain exactly how and why it accepted the relationship.

Vendor risk decision and approval workflow from thresholds to documentation

After Approval: Monitor and Reassess the Vendor

Approval isn't the finish line. Public records, insurance policies, and ownership structures change constantly. A vendor approved in January can look different by June.

Monitoring Triggers

Watch for:

  • Expired licenses or insurance
  • Ownership, leadership, or financial distress changes
  • Lawsuits, regulatory actions, or adverse media
  • Security incidents or service failures
  • Major subcontractor changes
  • Expanded access to systems or data

Reassessment Timing

Set frequency by risk tier, not a single calendar rule. High-impact vendors warrant more frequent checks; low-impact suppliers need less. Add event-driven reviews for material changes and contract renewals regardless of schedule.

A monthly check catches a lapse while it's happening. A one-time annual check only sees whichever side of the lapse it happens to land on. That gap is exactly where problems hide.

Offboarding Controls

When a relationship ends:

  • Revoke system and facility access
  • Recover or delete data and assets
  • Settle open obligations
  • Confirm subcontractor termination where relevant
  • Preserve the final vendor file

Recurring, source-verified monitoring can close manual gaps between reviews, but a human should always confirm a finding before it changes a vendor's status.

Vendor lifecycle monitoring reassessment and offboarding control cycle

Frequently Asked Questions

What is vendor due diligence?

Vendor due diligence is the documented review of a third party's legal, financial, operational, reputational, cybersecurity, compliance, and resilience risks before and during a business relationship, combining vendor documentation with independent verification.

What should be included in a vendor due diligence checklist?

Business legitimacy, ownership, finances, insurance, reputation, compliance, security, continuity planning, subcontractor exposure, references, evidence verification, and a documented approval decision.

When should vendor due diligence be performed?

Begin before contract signature, refresh it at onboarding and renewal, and repeat it after material changes, incidents, or expanded access to systems or data.

How do you verify information provided by a vendor?

Compare vendor claims against independent sources such as government registries, regulator databases, insurance evidence, certification directories, and references, then record the source, capture date, and any limitations.

How should vendors be prioritized for due diligence?

Tier vendors by data or system access, operational criticality, financial impact, regulatory exposure, geographic dependencies, and reliance on their own subcontractors.

What's the difference between vendor due diligence and ongoing vendor risk management?

Due diligence is the pre-contract investigation that informs the initial decision. Ongoing risk management is the broader lifecycle process: monitoring, remediating, reassessing, and eventually offboarding the vendor.