Vendor Due Diligence
Vendor due diligence is the process of investigating and evaluating a third-party vendor, supplier, or partner before entering into or continuing a business relationship with them. It involves gathering and assessing information about the vendor's business to understand the risks they may introduce. Organizations use it to decide whether a vendor is trustworthy and suitable to work with.
Vendor due diligence (VDD) is a structured process for gathering and assessing data about a third party to evaluate financial, legal, operational, and regulatory risks before establishing or maintaining a business relationship. It typically forms a component of broader third-party risk management, informing vendor selection, onboarding, and ongoing monitoring decisions. In a security leadership context, a virtual CISO often advises on VDD program design, risk criteria, and evaluation of a vendor's security posture, while the client organization generally retains accountability for the final vendor risk-acceptance and contracting decisions. The depth and rigor of VDD typically vary by provider, vendor criticality, data sensitivity, and applicable regulatory obligations; it should be understood as a risk-informing exercise rather than a guarantee against vendor-related incidents.
Why it matters
Every third party an organization engages introduces risk that extends beyond the vendor's own walls. A supplier with weak security controls, unstable finances, or unresolved regulatory issues can become a channel for data exposure, service disruption, or compliance failures that ultimately land on the organization that hired them. Vendor due diligence exists to surface these risks before a relationship is formalized, and to reinforce them through ongoing monitoring, so that vendor selection and contracting decisions are informed rather than assumed.
Because a virtual CISO frequently advises on the design of a VDD program, its risk criteria, and the evaluation of a vendor's security posture, it is important to be clear about where the value lies and where it does not. VDD is a risk-informing exercise, not a guarantee. Investigating a vendor thoroughly reduces the likelihood of unpleasant surprises, but it does not eliminate the possibility of a vendor-related incident, and it should never be presented to executives as if it did. The final decision to accept a vendor's risk and enter into a contract generally remains with the client organization and its officers.
The practical worth of VDD also depends heavily on organizational maturity and follow-through. Diligence performed once at onboarding and never revisited provides limited protection as a vendor's circumstances, controls, and criticality change over time. Programs that scale the depth of review to vendor criticality, data sensitivity, and applicable regulatory obligations tend to produce more useful risk signals than uniform checklists applied to every supplier regardless of exposure.
Who it's relevant to
Inside VDD
Common questions
Answers to the questions practitioners most commonly ask about VDD.