Vendor due diligence checklist
In short. Due diligence is checking, before you sign, that a vendor can do the work, will still be there, will protect your data and will let you leave cleanly. Use every section for a critical tier 1 vendor, the core sections for tier 2 and only the basics for tier 3.
Written for Leaders, finance and operations, administrators.
Before you sign, confirm that a vendor can do the work, will still be in business, will protect your data, will support you and will let you leave with your data. This checklist follows the due diligence factors in the 2023 interagency guidance on third-party relationships (Federal Register, June 9, 2023, retrieved 2026-09-28), rewritten for a distributor instead of a bank.
Do not run every item on every vendor. Use the tier table to decide which sections apply, and when you strike an item, do it on purpose.
Which sections apply to which tier
Section titled: Which sections apply to which tierTiers come from third-party risk management. Tier 1 vendors could stop you shipping, invoicing or collecting, or hold sensitive data. Tier 3 vendors could not. The table shows how deep to go in each section by tier.
| Section | Tier 1, critical | Tier 2, important | Tier 3, low |
|---|---|---|---|
| Company and financial health | Full | Core items | Basic identity only |
| Ownership and change of control | Full | Full | Skip |
| References | Three or more, including one that left | Two | Skip |
| Product fit | Full, with scripted demo or pilot | Full | Quick check |
| Security | Full, independent evidence required | Full, questionnaire accepted | Only if it touches data or systems |
| Privacy | Full | If personal data is shared | Skip unless personal data |
| Compliance | Full | Core items | Skip |
| Insurance | Full, certificates on file | Certificates on file | General liability if on site |
| Business continuity and disaster recovery | Full, with tested evidence | Stated RTO and RPO | Skip |
| Support model | Full | Full | Skip |
| Subcontractors | Full | Core items | Skip |
| Data ownership and exit | Full, exit plan written | Full | Skip unless it holds your data |
| Contract terms | Full, negotiated | Checklist review | Standard terms reviewed |
| Pricing | Full, multi-year cost | Full | Quote only |
Company and financial health
Section titled: Company and financial health- Legal entity confirmed. The contracting entity, its registration and its address match the proposal, so you know who to enforce the contract against.
- Years in business and size. Enough staff support your product that one resignation does not stop support.
- Financial statements or equivalent. Audited statements, or a bank or accountant letter for small private vendors, show it can operate through your term.
- Customer concentration. No one or two customers make up most of its revenue.
- Revenue trend and profitability. Growing or stable, since heavy investor-funded losses mean pricing and direction can change quickly.
- Litigation and regulatory actions. Any material lawsuits, judgments or regulator actions in the last five years, and how they were resolved.
- Credit report or public filings. No late payments, liens or going-concern warnings in a credit report or annual reports.
- Sanctions and restricted party screening. Neither the vendor nor its owners appear on sanctions or restricted party lists, which matters for payment and export compliance.
Ownership and change of control
Section titled: Ownership and change of control- Current owners named. Founders, private equity, a strategic parent or public shareholders, since each behaves differently on price and product investment.
- Recent or pending transactions. Any acquisition, merger or sale in the last three years or under way, since products are often consolidated or retired after a sale.
- Change of control clause. You can terminate or renegotiate if the vendor is acquired, especially by one of your competitors.
- Product roadmap commitment. A written support horizon that covers your contract term.
- Key person dependency. If the product depends on one founder or developer, ask about succession and documentation.
References
Section titled: References- References like you. Customers of similar size, industry and ERP, since one 10 times your size has different leverage and problems.
- A reference live for over a year. Newer customers cannot tell you about renewals or support decline.
- A former customer. Why they left and how the exit went tells you more than any happy customer.
- Specific questions asked. Support response, surprise costs, upgrade pain, escalations and whether they would buy again.
- Independent checks. User groups, public reviews and your own network, weighed with care since praise and complaints both skew loud.
Product fit
Section titled: Product fit- Requirements written first. Must-haves and nice-to-haves agreed before demos, so demos are judged against your needs.
- Scripted demo with your data. The vendor runs your scenarios on a sample of your items, customers and orders instead of its demo company.
- Integration with your ERP confirmed. ERP version, integration method (API, file, database) and who maintains and fixes it after an upgrade.
- Pilot or proof of concept for tier 1. A time-boxed trial with success criteria written down in advance.
- Scale and performance. Customers running your transaction volumes, with their numbers in round terms.
- Configuration versus customization. What settings can change and what needs paid custom work, which often breaks at upgrade.
- Roadmap items not counted as features. A promised future feature counts as absent unless it is in the contract.
Security
Section titled: SecuritySee security and data sharing with vendors for how to read the evidence.
- Independent evidence. A SOC 2 Type 2 report or ISO/IEC 27001 certificate from the last 12 months, with a clean opinion and few exceptions.
- Scope covers your service. The report or certificate names the product and locations you will use.
- Complementary user entity controls listed. You know which controls the vendor expects you to run, and someone owns each one.
- Questionnaire where evidence is thin. The vendor's SIG or CAIQ, or your own short questionnaire, answered and read.
- MFA and access control. Multi-factor authentication for vendor staff and your users, and role-based access in the product.
- Encryption. Data encrypted in transit and at rest, with a clear answer on who manages the keys.
- Vulnerability management. Regular patching and an independent penetration test in the last 12 months, with a summary shared.
- How the vendor reaches your systems. Named accounts and on-demand remote access, with no shared logins or permanent unattended connections.
- Incident history and notification. Reportable incidents in the last three years, what changed and a committed notification timeframe.
- Secure development. For software vendors, how code is reviewed and tested and how third-party components are tracked.
Privacy
Section titled: Privacy- Data inventory. Which personal data the vendor will hold: customer contacts, employees, consumers, payment details.
- Purpose limitation. The vendor uses your data only to provide the service, not to train products or sell, unless you explicitly agree.
- Data location. Countries where data is stored and accessed, including support staff locations.
- Subprocessors disclosed. A subprocessor list and a commitment to notify you before changes.
- Applicable law terms. A data processing agreement or service provider terms where GDPR, state laws such as the CCPA or HIPAA apply, as counsel confirms.
- Retention and deletion. How long data is kept and how deletion is confirmed at contract end.
Compliance
Section titled: Compliance- Industry obligations you pass down. Customer terms, government contract clauses or export controls your vendors must meet.
- Payment card handling. If the vendor touches card data, evidence of PCI DSS compliance appropriate to its role.
- Tax and invoicing accuracy. For tax, billing or payment services, how rate changes are tracked and who pays for the vendor's errors.
- Safeguards Rule oversight, if you are in scope. If counsel says the FTC Safeguards Rule applies, the vendor is selected, contracted and assessed as 16 CFR 314.4(f) expects.
- Accessibility and records. Where relevant, accessible customer-facing tools and retention of records you must keep.
- Code of conduct. Anti-bribery, labor and ethical sourcing commitments, especially for suppliers and offshore providers.
Insurance
Section titled: Insurance- Cyber liability. Breach and network security coverage with limits your broker considers proportionate to the data held.
- Technology errors and omissions (E&O). Coverage for losses from the service failing or the vendor's professional mistakes.
- General liability. Required for any vendor that sends people to your sites.
- Workers' compensation and auto. For on-site service providers and carriers, as your broker advises.
- Certificates of insurance on file. Current certificates showing carrier, limits and expiry dates, with renewal tracked.
- Additional insured status where appropriate. Your company named as additional insured on general liability for on-site work, if your broker recommends it.
- Limits of liability read against coverage. The liability cap fits the risk, unlike a one-month-of-fees cap on a service holding all your customer data.
Business continuity and disaster recovery
Section titled: Business continuity and disaster recovery- Written continuity and recovery plan. A shared summary, with NIST SP 800-34 as a good public reference for what it should cover.
- RTO stated. A recovery time objective that fits how long your own dependency mapping says you can cope.
- RPO stated. A recovery point objective in hours for some services, and minutes for order entry.
- Tested, with date. A recovery test in the last 12 months, with a summary of results.
- Backups. Frequency, separate location, ransomware protection and whether you can get a copy.
- Hosting and region. The cloud platform and regions, and whether failover exists (see fourth parties and concentration risk).
- Status page and outage history. A public status page and a record of major outages in the last two years.
Support model
Section titled: Support model- Hours and channels. Support hours in your time zone, the channels offered and after-hours coverage for tier 1 services.
- Severity levels and response times. Written severity definitions with target response and resolution times for each.
- Escalation path. Named contacts beyond the front line, up to an executive for critical issues.
- Who actually supports you. In-house staff, a partner or an offshore team, and whether they know your ERP.
- Account management. A named account manager and a regular review cadence for tier 1.
- Upgrade and release process. Release frequency, whether you can delay and notice of breaking changes.
- Training and documentation. Included training, current documentation and a knowledge base your staff can use.
Subcontractors
Section titled: Subcontractors- Subcontractors disclosed. Which parts of the service other companies deliver: hosting, support, development, logistics.
- Flow-down of obligations. Security, confidentiality and privacy obligations passed to subcontractors in writing.
- Notice of changes. You are told before a critical subcontractor changes.
- Vendor oversight of its own vendors. The vendor reviews its subcontractors, for example by collecting their SOC reports.
- Offshore work disclosed. Any work done outside your country, especially work with access to your data.
Data ownership and exit
Section titled: Data ownership and exitSee leaving a vendor for the exit itself.
- You own your data. The contract says your data, and data derived from it, belongs to you.
- Export on demand. All of your data, any time, in a documented usable format, free or at a stated fee.
- Exit assistance. Transition help for a defined period and rate after termination.
- Retention after termination. A retrieval window (for example 30 to 90 days) followed by deletion.
- Deletion certificate. Written confirmation of deletion from production and, on schedule, from backups.
- Custom work ownership. Who owns reports, integrations, configurations and custom code built for you.
- Exit plan written at signing for tier 1. Where the data is, how to get it out and what you would move to.
Contract terms
Section titled: Contract termsSee contracts, SLAs and data rights for detail on each.
- Service levels with remedies. Uptime or performance targets with credits or termination rights when missed.
- Term and renewal. Initial term, renewal notice period and auto-renewal, with the notice date in your diary.
- Price increase caps. A limit on annual increases at renewal.
- Termination for convenience and for cause. Your rights to leave, with notice periods and any fees stated.
- Liability caps and exclusions. Caps proportionate to risk, with carve-outs for data breach and confidentiality where negotiable.
- Indemnities. Vendor indemnity for intellectual property infringement and, where negotiable, its data breaches.
- Security and breach notice terms. Security duties, a breach notification timeframe and your right to evidence or audit.
- Confidentiality. Mutual confidentiality covering your business data, pricing and customer lists.
- Assignment. No assignment to another company without notice and, for tier 1, your consent.
- Governing law and disputes. Where disputes are heard and under which law, reviewed by counsel.
Pricing
Section titled: Pricing- All cost components listed. Licenses or subscriptions, implementation, integration, training, support, hosting, storage and transaction fees.
- Pricing unit understood. Per user, site, transaction, order line or revenue band, and what happens when you grow.
- Multi-year total. Total cost over at least three years, including expected increases and your internal time.
- Overage and minimums. Charges for exceeding volume tiers and any minimum commitments.
- Services rate card. Rates for extra work and how change requests are estimated and approved.
- Payment terms. Invoicing frequency, payment terms and whether multi-year terms are paid in advance.
- Exit costs. Fees for data export, transition help or early termination.
With invented round numbers, a subscription of $24,000 a year rising 5% a year totals $75,660 over three years, before internal time.
Questions to ask before you sign
Section titled: Questions to ask before you sign- If this vendor disappeared tomorrow, what would stop, and how would we get our data?
- Which items on this checklist did we skip, and did we skip them on purpose?
- Has anyone outside the buying team (IT, finance, operations) reviewed the parts that affect them?
- Does the contract say what the salesperson told us?
- Who owns this vendor relationship after signing?
Red flags
Section titled: Red flagsAny of these in a tier 1 evaluation deserves a direct conversation before you sign.
| Red flag | Why it matters |
|---|---|
| Will not share financials, references or security evidence for a tier 1 service | You are asked to trust without any basis |
| No former-customer reference available | Exits may be hard or unhappy |
| Key capability exists only on the roadmap | You may pay for something that never ships |
| Data export only through paid professional services | Leaving becomes expensive and slow |
| Automatic renewal with a long notice period and uncapped increases | Bargaining power shifts to the vendor every year |
| Liability capped at a small fraction of fees for a service holding sensitive data | You carry the loss if something goes wrong |
| Recent change of ownership and vague answers about the product future | Support and pricing may change soon after you sign |
Next steps
Section titled: Next stepsCopy the sections that apply to the vendor's tier into your evaluation file, tick items as evidence arrives and store the evidence with the contract. Record any item you strike and why.
At renewal, reopen the same checklist and refresh the security, insurance, financial and continuity sections, since those change most. Pair it with the scoring approach in choosing a vendor so diligence findings feed the decision before it is made.
Sources
- Interagency Guidance on Third-Party Relationships: Risk Management (Federal Register, June 9, 2023)
- The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 (February 26, 2024)
- System and Organization Controls: SOC Suite of Services (AICPA & CIMA)
- 16 CFR Part 314, Standards for Safeguarding Customer Information (eCFR)
- SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems (NIST)