← All postsHow-to

Vendor due diligence checklist: proving a supplier is safe before you sign

A vendor due diligence checklist that procurement can actually run — the evidence to demand, proportionate tiers, and how to keep the answers current after onboarding.

How-toV

A vendor due diligence checklist is the evidence you require from a supplier before signing, and the reason you can defend the decision afterwards. It is not the same document as a deal checklist: you are not buying the company, you are letting it near your customers, your data or your production line. What matters is whether the supplier can do the work, survive the contract term, and not create a liability that lands on you.

Tier the vendor due diligence checklist before you use it

Running the full vendor due diligence checklist on every supplier is how procurement earns a reputation for obstruction. Decide the tier from exposure, not from spend alone.

  • Tier 1 — touches personal data, production systems, or your customers directly. Full checklist, annual refresh.
  • Tier 2 — material spend or an operational dependency with a workaround. Core checks, refresh on renewal.
  • Tier 3 — commodity purchase, easily replaced. Identity, bank details and insurance only.

The core evidence

  1. Legal identity: registration number, registered address, and confirmation that the trading name matches the entity signing the contract.
  2. Ownership and control, far enough to name a beneficial owner, plus a sanctions and adverse media check.
  3. Financial standing — filed accounts, and for a critical supplier a view of liquidity rather than just profit.
  4. Insurance certificates with cover levels and expiry dates, checked against what the contract requires.
  5. Capability evidence: two references for work of comparable size, not a logo wall.
  6. Information security posture, proportionate to the data involved — certification where it exists, a completed questionnaire where it does not.
  7. Data protection: what personal data they process, where, on what lawful basis, and which sub-processors they use.
  8. Subcontracting: who actually performs the work, because your controls follow the work and not the invoice.
  9. Business continuity: recovery objectives they will commit to in writing, and when they last tested them.

Ask for bank details through a separate verified channel and confirm them by telephone against a number you looked up yourself. Supplier payment fraud almost always arrives inside an otherwise legitimate onboarding thread.

Collect it once, in a structured form

Email threads are where vendor due diligence goes to die: attachments land in three inboxes, nobody can say which version is current, and the expiry dates live in people’s memories. Send the checklist as a form instead. Ettex Forms turns each line into a field with a required attachment, so a partial response is visibly partial and the answers arrive in one place, timestamped. The completed responses then belong on the supplier record with their review dates, next to the contract — which is where supplier onboarding and the wider procurement process pick the work up.

Due diligence does not end at signature

Certificates expire, owners change, and a supplier that was solvent at tender can be in difficulty by the second renewal. Give every Tier 1 and Tier 2 answer a review date and let the register surface what has gone stale. This ongoing half of the job is what third party risk management describes, and it is the half that most organisations skip; a supplier audit then becomes the only mechanism for finding out, long after the exposure started.

What to do with a failed check

  • Missing evidence is not the same as bad evidence. Ask again, with a deadline, before escalating.
  • Record the gap and the decision to proceed anyway, with who accepted the risk and until when.
  • Where a control is absent, write the compensating control into the contract rather than into a hope.
  • Where ownership or sanctions screening raises a hit, stop and escalate; that one is not a procurement judgement call.

A vendor due diligence checklist that produces a written decision — approved, approved with conditions, or declined, with the evidence attached — is worth more than a longer list that produces a feeling. The decision is what you will be asked to justify.

Frequently asked

How is vendor due diligence different from client due diligence?

Direction and purpose. Client due diligence is an anti-money-laundering obligation about who you take money from; vendor due diligence is a risk and capability assessment of who you pay. The evidence overlaps on identity and ownership, nothing else.

Can we accept a supplier’s own security questionnaire?

Yes for lower tiers. For Tier 1, ask for the certification scope or an independent report; a self-assessment tells you what a supplier believes about itself.

How often should the checklist be refreshed?

Annually for Tier 1, at renewal for Tier 2, and immediately on a trigger — a change of ownership, a breach notification, a missed delivery that revealed a subcontractor you did not know about.

EP
Written by Elena P.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.