Skip to main content
Category: Third-Party & Supply Chain Risk

Vendor Due Diligence

Also known as: VDD, supplier due diligence, third-party due diligence
Simply put

Vendor due diligence is the process of investigating and evaluating a third-party vendor, supplier, or partner before entering into or continuing a business relationship with them. It involves gathering and assessing information about the vendor's business to understand the risks they may introduce. Organizations use it to decide whether a vendor is trustworthy and suitable to work with.

Formal definition

Vendor due diligence (VDD) is a structured process for gathering and assessing data about a third party to evaluate financial, legal, operational, and regulatory risks before establishing or maintaining a business relationship. It typically forms a component of broader third-party risk management, informing vendor selection, onboarding, and ongoing monitoring decisions. In a security leadership context, a virtual CISO often advises on VDD program design, risk criteria, and evaluation of a vendor's security posture, while the client organization generally retains accountability for the final vendor risk-acceptance and contracting decisions. The depth and rigor of VDD typically vary by provider, vendor criticality, data sensitivity, and applicable regulatory obligations; it should be understood as a risk-informing exercise rather than a guarantee against vendor-related incidents.

Why it matters

Every third party an organization engages introduces risk that extends beyond the vendor's own walls. A supplier with weak security controls, unstable finances, or unresolved regulatory issues can become a channel for data exposure, service disruption, or compliance failures that ultimately land on the organization that hired them. Vendor due diligence exists to surface these risks before a relationship is formalized, and to reinforce them through ongoing monitoring, so that vendor selection and contracting decisions are informed rather than assumed.

Because a virtual CISO frequently advises on the design of a VDD program, its risk criteria, and the evaluation of a vendor's security posture, it is important to be clear about where the value lies and where it does not. VDD is a risk-informing exercise, not a guarantee. Investigating a vendor thoroughly reduces the likelihood of unpleasant surprises, but it does not eliminate the possibility of a vendor-related incident, and it should never be presented to executives as if it did. The final decision to accept a vendor's risk and enter into a contract generally remains with the client organization and its officers.

The practical worth of VDD also depends heavily on organizational maturity and follow-through. Diligence performed once at onboarding and never revisited provides limited protection as a vendor's circumstances, controls, and criticality change over time. Programs that scale the depth of review to vendor criticality, data sensitivity, and applicable regulatory obligations tend to produce more useful risk signals than uniform checklists applied to every supplier regardless of exposure.

Who it's relevant to

Security and risk leaders
CISOs, virtual CISOs, and risk managers use VDD to understand and document the risks a third party may introduce before it gains access to systems, data, or business processes. For a vCISO, the typical role is advising on program design, risk criteria, and posture evaluation rather than making the final risk-acceptance decision, which usually stays with the client's officers.
Procurement and vendor management teams
Teams responsible for sourcing and onboarding suppliers rely on VDD to inform selection and contracting. Scaling the depth of review to vendor criticality and data sensitivity helps focus limited diligence effort where the potential exposure is greatest, rather than applying the same review to every supplier.
Compliance and legal functions
Because VDD evaluates legal and regulatory risks alongside financial and operational ones, compliance and legal stakeholders use it to identify obligations and exposures tied to a third party. The rigor applied often varies with applicable regulatory requirements, and diligence supports informed decisions without guaranteeing regulatory outcomes.
Executives and business owners
Leaders accountable for the organization's risk posture depend on VDD to make informed decisions about which vendors to trust. It is important for executives to understand that diligence reduces uncertainty but does not prevent vendor-related incidents, and that accountability for accepting vendor risk remains with the organization.

Inside VDD

Security Questionnaires
Structured requests sent to a prospective or existing vendor asking about their security controls, policies, and practices. Common formats include standardized questionnaires such as those aligned to widely used control catalogs. Responses are typically self-attested by the vendor, which is a limitation buyers should account for by seeking corroborating evidence.
Evidence and Attestation Review
Examination of supporting documentation such as SOC 2 reports, ISO 27001 certificates, penetration test summaries, or policy excerpts. It is important to distinguish between a certificate or attestation existing and the scope it actually covers; a SOC 2 report, for example, applies only to defined systems and a specified period, and does not by itself guarantee the vendor's security posture across all services.
Risk Tiering and Classification
The practice of categorizing vendors by the level of risk they introduce, often based on the sensitivity of data accessed, criticality of the service, and depth of system integration. Higher-tier vendors typically warrant deeper scrutiny, while lower-tier vendors may undergo a lighter review. Tiering criteria vary by organization.
Contractual and Legal Safeguards
Review of security-relevant contract terms such as data protection clauses, breach notification obligations, right-to-audit provisions, and, where applicable, data processing agreements tied to regulations such as GDPR or HIPAA business associate requirements. Contracts define where accountability and obligations sit between the parties.
Ongoing Monitoring and Reassessment
Due diligence is not solely a one-time, pre-onboarding activity. Many programs include periodic reassessment and continuous monitoring, since a vendor's risk profile can change over time. The cadence and depth of reassessment often depend on the vendor's risk tier.
Fourth-Party and Subprocessor Consideration
Assessment of the vendor's own supply chain, including subprocessors and downstream providers a vendor relies upon. Risk can be inherited through these relationships, so understanding a vendor's dependencies is often part of a thorough review.

Common questions

Answers to the questions practitioners most commonly ask about VDD.

Does a virtual CISO perform the actual vendor security assessments and hands-on testing during due diligence?
Typically not. A virtual CISO generally defines the due diligence process, sets risk criteria, reviews findings, and advises on whether a vendor's risk posture is acceptable. Hands-on tasks such as scanning vendor environments, administering assessment tooling, or executing technical validation usually fall outside the standard scope unless explicitly contracted. In many engagements, the client's internal team or a specialized third party performs the actual assessment work, while the vCISO provides governance and executive-level judgment on the results.
If a virtual CISO approves a vendor, does that mean the vCISO is accountable for any breach originating from that vendor?
Not usually. A virtual CISO advises on and directs vendor risk decisions, but legal and organizational accountability for accepting a vendor relationship typically remains with the client organization and its officers. The vCISO helps inform the decision and document the rationale, yet the client generally retains ownership of the residual risk. Any transfer of liability would need to be specified in a contract, and even then it may vary by provider and jurisdiction.
How does a virtual CISO structure a vendor due diligence process for an organization that has none in place?
In many engagements, a vCISO begins by establishing a vendor inventory and a tiering approach that classifies vendors by the sensitivity of data they access and their criticality to operations. They then define assessment requirements proportionate to each tier, often drawing on questionnaires, evidence requests such as SOC 2 reports or ISO 27001 certificates, and contractual security clauses. The depth and pace of rollout typically depend on organizational maturity, stakeholder cooperation, and available resources.
What frameworks or evidence does a virtual CISO commonly rely on to evaluate a vendor?
A vCISO often references independent attestations and certifications such as SOC 2 reports, ISO 27001 certificates, and, where relevant to the data involved, evidence of alignment with regulations like HIPAA, PCI DSS, or GDPR. It is important to note that possessing such reports supports an assessment but does not guarantee a vendor is secure or that the client will be compliant; the vCISO typically interprets scope, exceptions, and applicability rather than treating any document as a pass or fail stamp.
How often should vendor due diligence be repeated once a vendor is onboarded?
Practices vary by provider and organization, but a virtual CISO often recommends periodic reassessment tied to a vendor's risk tier, with higher-risk vendors reviewed more frequently. Reassessment may also be triggered by events such as contract renewal, a change in the services provided, a reported incident, or the vendor accessing new categories of sensitive data. The cadence ultimately depends on defined scope, risk appetite, and the resources available to sustain ongoing monitoring.
What determines whether vendor due diligence delivers real value in a vCISO engagement?
Value generally depends on clearly defined scope, access to the stakeholders who own vendor relationships, and cooperation from procurement, legal, and business units. Without a maintained vendor inventory and support for enforcing assessment requirements before contracts are signed, a due diligence process may become a formality rather than a control. A common mistake is treating vendor due diligence as a purely technical checklist rather than a governance and business risk function that requires organizational buy-in.

Common misconceptions

A vendor holding a SOC 2 or ISO 27001 certification means they are secure and no further diligence is needed.
A certification or attestation confirms that certain controls were assessed within a defined scope and time period; it does not guarantee the vendor is secure across all services or that the scope covers the specific data or integration relevant to your organization. Practitioners should review the actual scope, exceptions, and applicability rather than treating the certificate as a pass.
Vendor due diligence transfers accountability for security risk to the vendor.
Contracts can allocate certain obligations and responsibilities, but organizational and, in many cases, regulatory accountability for protecting data typically remains with the client organization and its officers. Due diligence informs risk decisions; it does not offload the underlying accountability unless specific terms establish that.
A virtual or fractional CISO performs vendor due diligence as a hands-on operational task end to end.
A vCISO or fractional CISO typically provides governance, risk framing, program design, and executive-level oversight for the due diligence process. Detailed operational execution such as running assessments, collecting evidence, or tool administration is often out of scope unless explicitly contracted, and the value of their involvement depends on client cooperation and access to stakeholders.

Best practices

Apply risk-based tiering so that scrutiny is proportional to the data sensitivity, service criticality, and integration depth of each vendor rather than treating all vendors identically.
Corroborate self-attested questionnaire responses with independent evidence such as SOC 2 reports, certificates, or test summaries, and always review the actual scope and exceptions of that evidence rather than the existence of the document alone.
Embed security requirements into contracts, including data protection, breach notification, and right-to-audit provisions, and align them with applicable regulatory obligations where relevant.
Treat due diligence as an ongoing lifecycle activity by defining reassessment cadence and monitoring appropriate to each vendor's risk tier, since vendor risk profiles change over time.
Extend review to fourth parties and subprocessors so that inherited supply-chain risk is understood and factored into decisions.
Clarify roles and accountability up front, documenting that the client organization retains decision accountability while a vCISO or fractional CISO advises and directs the process, and confirm stakeholder access needed for the review to be effective.