Skip to main content
Category: Third-Party & Supply Chain Risk

Onboarding Due Diligence

Also known as: Onboarding Due Diligence Process, Pre-Relationship Due Diligence
Simply put

Onboarding due diligence is the process of investigating and evaluating a customer, vendor, or business partner before formally entering into a relationship with them. The goal is to verify who the party is, understand the risks of doing business with them, and confirm they meet the organization's requirements before access, contracts, or transactions proceed. It is a checkpoint performed at the start of a relationship, and in many programs it also feeds into ongoing monitoring afterward.

Formal definition

Onboarding due diligence is the structured investigation and risk evaluation of a prospective party (customer, vendor, or counterparty) conducted before a business relationship or agreement is established. Depending on the sector and the type of party, it may include identity verification, risk assessment, and screening as part of the onboarding workflow. In regulated financial services, this often takes the form of Customer Due Diligence (CDD), a narrower AML/KYC-driven discipline that verifies a customer's identity, assesses the risk of the relationship, and typically involves sanctions and PEP screening and beneficial-ownership collection; outside that context, CDD and onboarding due diligence are not strictly synonymous, and onboarding due diligence more broadly may cover vendor risk review, contract-risk evaluation, and financial or operational assessment. Note that in complex cases, such as corporate customer onboarding, this process can be time- and resource-intensive. Onboarding due diligence is typically a gating control at relationship inception; where the assessed party must meet specific security or compliance regimes (for example because they are being evaluated against a standard), the relevant obligations should be scoped explicitly rather than assumed. This should not be confused with the internal onboarding of a security leader or advisor into an organization, which is a distinct activity.

Why it matters

Onboarding due diligence is the point at which an organization decides whether to trust a customer, vendor, or partner before granting access, signing contracts, or transacting. Skipping or rushing this checkpoint means an organization may enter a relationship without knowing who the counterparty actually is, what risk they carry, or whether they meet the requirements the business depends on. Because it is a gating control at relationship inception, weaknesses here propagate downstream: a poorly vetted vendor can become a supply-chain exposure, and an inadequately verified customer can create legal, financial, or reputational liability that is far harder to unwind once the relationship is live.

The stakes vary by sector. In regulated financial services, onboarding due diligence often takes the form of Customer Due Diligence (CDD), an AML/KYC-driven discipline that typically includes identity verification, sanctions and PEP screening, and beneficial-ownership collection. Failure to perform this adequately can expose an institution to regulatory consequences. Outside that context, onboarding due diligence more broadly may cover vendor risk review, contract-risk evaluation, and financial or operational assessment, where the failure mode is less about regulatory penalty and more about accepting unmanaged operational or supply-chain risk.

Due diligence is also frequently where onboarding programs succeed or fail as disciplines rather than as one-off tasks. It is the stage that tends to become complex, inconsistent, and resource-intensive, particularly for corporate customers where the process can be time- and resource-intensive. Programs that treat due diligence as a repeatable, scoped control tend to mature; those that treat it as a rubber stamp accumulate hidden risk. A virtual CISO or security leader may advise on how these controls are structured and scoped, but accountability for accepting or rejecting a given relationship generally remains with the client organization and its officers.

Who it's relevant to

Financial services and regulated institutions
Organizations subject to AML/KYC obligations rely on onboarding due diligence in its narrower CDD form, which typically involves identity verification, relationship risk assessment, sanctions and PEP screening, and beneficial-ownership collection. For these institutions, the distinction matters: CDD carries specific regulatory expectations that broader vendor or partner due diligence does not.
Procurement and vendor risk teams
Teams onboarding suppliers and partners use due diligence to evaluate vendor risk, review contract terms, and assess financial or operational stability before access or agreements proceed. This is often where onboarding becomes complex and inconsistent, so a repeatable, well-scoped process is where these programs either mature or accumulate risk.
Security leaders and virtual CISOs
A vCISO or fractional security leader may advise on how onboarding due diligence controls are designed, scoped, and integrated with ongoing monitoring, particularly for third-party and supply-chain risk. Their role is typically strategic and governance-oriented, directing and advising, while accountability for accepting or rejecting a given relationship generally remains with the client organization and its officers. Any specific security or compliance regime a party must meet should be scoped explicitly rather than assumed.
Legal, compliance, and risk officers
These stakeholders own the requirements a prospective party must meet and the risk-acceptance decisions at the gate. They are also the parties for whom the CDD-versus-broader-due-diligence distinction is most consequential, since obligations differ substantially between regulated financial contexts and general vendor or partner onboarding.

Inside Onboarding Due Diligence

Third-Party Identity Verification
Confirmation of the legal identity, registration, and legitimacy of a prospective vendor, supplier, or partner before formalizing a relationship. This typically includes collecting business registration details, verifying corporate existence, and confirming the entity is who it claims to be. In many engagements a virtual CISO advises on the process and criteria but does not personally execute verification, which often falls to procurement, legal, or compliance functions.
Beneficial-Ownership Collection
The gathering of information identifying the individuals who ultimately own or control a counterparty. In regulated financial services this is often driven by requirements such as the FinCEN Customer Due Diligence (CDD) Rule. Outside that context, ownership information may still be collected to understand concentration risk or hidden affiliations, though the obligation is generally narrower and varies by sector and jurisdiction.
Sanctions and PEP Screening
Screening a counterparty and its principals against sanctions lists and politically exposed person (PEP) designations to identify legal or reputational exposure. This is a core element of due diligence in regulated environments. A virtual CISO may recommend that such screening occur and help integrate its results into a risk decision, but the screening itself is typically performed by compliance or specialized tooling rather than by the security leader.
Security and Control Assessment of the Counterparty
Evaluation of the prospective third party's security posture, often through questionnaires, evidence requests, or review of attestations such as SOC 2 reports or ISO 27001 certificates. It is important to distinguish supporting a readiness or risk assessment from asserting a counterparty's certification: reviewing an attestation confirms what the third party claims, not a guarantee of ongoing compliance. Where a counterparty is being assessed against regimes such as HIPAA, PCI DSS, or CMMC, those frameworks become relevant only because the counterparty handles data or performs functions in scope for them.
Financial Health and Viability Review
Assessment of a counterparty's financial stability to gauge the risk of service disruption, insolvency, or inability to meet contractual obligations. This is generally led by finance or procurement, with security leadership contributing input on the operational impact of a counterparty failure rather than performing the financial analysis.
Contract and Legal Risk Review
Review of proposed contractual terms including data protection clauses, liability allocation, subprocessor and flow-down obligations, audit rights, and termination provisions. A virtual CISO commonly advises on security-relevant clauses, but legal and organizational accountability for the terms agreed remains with the client's officers and counsel, not with the advisory security leader.
Risk Tiering and Decision Record
Classification of a counterparty by inherent and residual risk, feeding a documented approve, reject, or conditional-approval decision. Tiering typically calibrates the depth of due diligence to the risk the relationship presents, so that low-risk vendors receive lighter review than those handling sensitive data or critical operations.
Ongoing Monitoring Provisions
Establishment of how the counterparty will be monitored after onboarding, since due diligence is not a one-time event. This may include periodic reassessment, renewed attestations, continuous sanctions rescreening, or event-driven review. The intensity of ongoing monitoring often varies by risk tier and by provider practice.

Common questions

Answers to the questions practitioners most commonly ask about Onboarding Due Diligence.

Is onboarding due diligence the same thing as the onboarding activities a virtual CISO performs when starting a new client engagement?
No, and this is a frequent point of confusion. Onboarding due diligence in the third-party and supply-chain context refers to the assessment a purchasing or contracting organization performs on a prospective vendor, supplier, partner, or customer before formally establishing the relationship. It typically covers areas such as identity and legitimacy verification, financial stability, security posture, regulatory and sanctions screening, and contractual risk. This is distinct from the internal ramp-up activities a virtual CISO carries out when beginning to advise a client, such as current-state assessment and stakeholder mapping. A vCISO may help design or oversee a third-party onboarding due-diligence program as part of governance and risk management, but the two concepts should not be conflated.
Is onboarding due diligence just another name for Customer Due Diligence (CDD)?
Not universally. Customer Due Diligence has a specific, narrower meaning within regulated financial services, where it forms part of anti-money-laundering (AML) and know-your-customer (KYC) obligations and often includes beneficial-ownership collection consistent with requirements such as the FinCEN CDD Rule. Onboarding due diligence is a broader operational concept used across many sectors to describe vetting a counterparty before a relationship begins, and it may or may not include formal AML/KYC steps depending on the industry and the nature of the party being onboarded. Treating the two as interchangeable can lead organizations outside regulated finance to either overlook applicable AML obligations or apply financial-sector procedures where they are not required. The applicable scope typically varies by sector and regulatory exposure.
What elements are typically included in an onboarding due-diligence process for a new vendor or counterparty?
The specific elements vary by organization, sector, and risk appetite, but many programs include verification of legal identity and legitimacy, collection of beneficial-ownership information where required, screening against sanctions and politically-exposed-person (PEP) lists, financial-health or solvency review, assessment of the counterparty's security posture and controls, and review of contractual terms and liability allocation. Where the counterparty is being assessed against a particular regime, that assessment is scoped to the regime relevant to the relationship. The depth of each element often scales with the risk the relationship presents.
How should the depth of onboarding due diligence be determined for a given counterparty?
Due diligence is commonly applied on a risk-tiered basis rather than uniformly. Factors that often influence depth include the sensitivity of data or systems the counterparty would access, the financial value and duration of the relationship, the counterparty's jurisdiction, and applicable regulatory exposure. Lower-risk relationships may warrant a streamlined review, while higher-risk ones may require enhanced measures such as deeper ownership tracing, expanded screening, or independent verification of security controls. Defining these tiers in advance, typically as part of a documented policy, helps ensure consistency and defensibility.
Does completing onboarding due diligence mean the counterparty relationship no longer requires monitoring?
No. Onboarding due diligence establishes a baseline at the point of entry, but risk profiles can change over time as ownership, financial condition, sanctions status, or security posture evolve. Many programs pair initial onboarding with ongoing or periodic monitoring, with reassessment triggered by defined events or at set intervals. Relying solely on point-in-time onboarding checks is a common gap that can leave an organization exposed to risks that emerge after the relationship begins.
Who is accountable for decisions made based on onboarding due diligence, and what role might a virtual CISO play?
Accountability for accepting or rejecting a counterparty, and for the resulting risk, generally remains with the contracting organization and its officers, not with any advisor. A virtual CISO may support this process by helping design the due-diligence framework, defining risk tiers and screening criteria, advising on security-posture evaluation, and integrating third-party risk into broader governance. However, the vCISO typically advises and directs rather than assuming legal or regulatory accountability for onboarding decisions unless a contract specifies otherwise. The effectiveness of any such program also depends heavily on organizational cooperation, access to information, and the maturity of existing risk processes.

Common misconceptions

Onboarding due diligence is the same as Customer Due Diligence (CDD) in every sector.
Customer Due Diligence has a specific, narrower meaning in regulated financial services, where it is tied to anti-money-laundering (AML) and know-your-customer (KYC) obligations and rules such as the FinCEN CDD Rule. Outside that context, onboarding due diligence is a broader concept covering security, financial, and contractual risk of a counterparty, and it should not be treated as interchangeable with AML/KYC CDD.
Collecting a counterparty's SOC 2, ISO 27001, or similar attestation confirms they are compliant and secure.
An attestation or certificate reflects a point-in-time assessment against a defined scope and confirms what the third party claims, not a guarantee of ongoing compliance or of security in areas outside the assessment's scope. Reviewing evidence supports a risk judgment; it does not assert certification or eliminate the need for ongoing monitoring.
A virtual CISO who advises on onboarding due diligence assumes accountability for the counterparty's risk.
A virtual CISO typically advises on criteria, evaluates security evidence, and directs process, but legal and organizational accountability for accepting a counterparty and its associated risk generally remains with the client organization and its officers unless a contract explicitly states otherwise.

Best practices

Calibrate the depth of due diligence to a risk tier, reserving intensive review such as ownership collection and sanctions screening for higher-risk counterparties and applying lighter review to low-risk vendors.
Clarify at the outset whether the engagement involves regulated Customer Due Diligence (AML/KYC) or a broader security and business-risk review, since the required elements and obligations differ significantly by sector.
Treat SOC 2, ISO 27001, and similar attestations as evidence to be reviewed within their stated scope, and document what they do and do not cover rather than accepting them as blanket assurance.
Define scope and responsibility boundaries clearly, distinguishing what the virtual CISO advises on from what compliance, legal, procurement, and finance execute, and record who holds accountability for the onboarding decision.
Establish ongoing monitoring at onboarding, including reassessment frequency, renewed attestations, and event-driven review, so due diligence is not treated as a one-time gate.
Ensure access to internal stakeholders and to counterparty-supplied evidence early, since the value and reliability of due diligence depend heavily on cooperation, complete information, and defined scope.