Skip to main content
Category: Third-Party & Supply Chain Risk

Vendor Onboarding Due Diligence

Also known as: VDD, Vendor Due Diligence, Supplier Due Diligence, Third-Party Due Diligence
Simply put

Vendor onboarding due diligence is the process of gathering and reviewing information about a third-party vendor or supplier before you start, or continue, doing business with them. It is used to understand whether the vendor poses financial, security, operational, compliance, or reputational risks. Although it is often carried out as a checkpoint when first bringing a vendor on, it is intended to function as an ongoing risk control rather than a one-time task.

Formal definition

Vendor onboarding due diligence (VDD) is a structured process for gathering and assessing data about a third party to evaluate whether their business, operations, and risk posture meet the acquiring organization's requirements before establishing or maintaining a relationship. Practitioners typically assess dimensions including financial stability, information security, operational capability, compliance, and reputational risk. While commonly treated as an onboarding checkpoint, it is more accurately understood as a risk control mechanism embedded within a broader third-party risk management (TPRM) program, applied at initial engagement and, in many programs, revisited periodically throughout the vendor lifecycle. This is a risk-mitigation and governance practice; it is distinct from risk transfer through insurance and does not by itself constitute a coverage term. The specific scope, evidence collected, and risk thresholds vary by organization, sector, and applicable regulatory regime.

Why it matters

Modern organizations depend on extensive networks of third-party vendors and suppliers, and each of those relationships can introduce financial, security, operational, compliance, or reputational risk into the acquiring organization. Vendor onboarding due diligence matters because it is one of the primary points at which an organization can identify and act on those risks before they become embedded in a live business relationship. Once a vendor is integrated into critical workflows or granted access to systems and data, unwinding the relationship or remediating a problem is typically far more costly and disruptive than screening for it at the outset.

Because due diligence is a risk-mitigation and governance practice, it is important to be clear about what it does and does not accomplish. It can reduce the likelihood and severity of vendor-related incidents by informing whether and how an organization engages a third party, but it does not transfer risk the way an insurance policy does, and it does not by itself guarantee that a vendor will perform as expected. Conversely, purchasing cyber or other insurance does not substitute for due diligence; the two are complementary rather than interchangeable. Treating diligence as a one-time onboarding formality is a common weakness, since a vendor's financial stability, security posture, and compliance status can all deteriorate after the relationship begins.

For this reason, due diligence is more accurately understood as an ongoing control embedded within a broader third-party risk management program, applied at initial engagement and, in many programs, revisited periodically across the vendor lifecycle. The specific evidence collected and the risk thresholds applied vary by organization, sector, and applicable regulatory regime, so a process that is adequate in one context may be insufficient in another.

Who it's relevant to

Risk and Compliance Professionals
Those responsible for third-party risk management use vendor onboarding due diligence to establish consistent criteria for evaluating and approving vendors, and to embed the assessment within an ongoing TPRM program. They are typically concerned with defining risk thresholds, ensuring that evidence collection satisfies applicable regulatory expectations, and scheduling periodic reassessment across the vendor lifecycle.
Chief Information Security Officers and Security Teams
Security leaders rely on the information-security dimension of due diligence to understand the controls, access, and data exposure a prospective vendor introduces. Because a vendor's security posture can change after onboarding, security teams generally treat diligence as a repeatable control rather than a one-time clearance, and coordinate its findings with incident response and broader resilience planning.
Procurement and Vendor Management Functions
Teams that source and manage suppliers use due diligence to evaluate financial stability and operational capability before committing to a relationship, and to inform decisions about whether and how to engage a vendor. They typically balance the cost and time of assessment against the criticality of the vendor being onboarded.
Insurance Brokers and Underwriters
For those assessing an organization's cyber or related risk, the maturity of a vendor due diligence process can be an indicator of the insured's broader risk-management discipline. It is important to note that due diligence is a risk-mitigation practice and not a coverage term; whether any vendor-related loss is insured depends on the specific policy wording, endorsements, exclusions, and conditions, not on the diligence process itself.
Legal Professionals
Legal and contracting teams use due diligence findings to shape vendor agreements, allocate responsibilities, and address compliance and reputational risk before a relationship is formalized. Because requirements differ across regulatory regimes, they help ensure the scope of diligence aligns with the obligations applicable to the organization and sector.

Inside VDD

Security and Control Assessment
Review of a prospective vendor's technical and organizational controls, often mapped against recognized frameworks or standards (such as those addressing information security or business continuity). This is a risk mitigation and resilience activity, not an insurance mechanism; it evaluates the likelihood and potential impact of a vendor-related incident but does not transfer any resulting loss.
Financial and Operational Viability Review
Evaluation of the vendor's financial stability, operational maturity, and ability to sustain service delivery. This assesses continuity risk but does not, by itself, guarantee that a vendor failure or its downstream effects would be covered under any policy.
Compliance and Regulatory Verification
Confirmation that the vendor meets applicable legal, regulatory, and contractual obligations relevant to the engagement. Requirements and their definitions can vary across jurisdictions and regulatory regimes, so verification is context-specific rather than universal.
Contractual and Liability Terms
Negotiation of agreements addressing responsibilities, data handling, indemnification, and allocation of liability. These terms shape where third-party exposure sits but are distinct from the insured's own first-party coverage; whether a resulting claim is covered depends on the specific policy wording, endorsements, and exclusions.
Business Continuity and Recovery Expectations
Documentation of the vendor's continuity and recovery capabilities, which may reference objectives such as recovery time objective (RTO) and recovery point objective (RPO). These are resilience metrics describing recovery targets, not coverage triggers, sublimits, retentions, or waiting periods under a policy.
Ongoing Monitoring Provisions
Arrangements for reassessing the vendor over the life of the relationship, since onboarding due diligence captures a point-in-time view. Continued monitoring supports risk mitigation but does not alter or constitute risk transfer.

Common questions

Answers to the questions practitioners most commonly ask about VDD.

Does completing vendor onboarding due diligence mean a vendor-related loss will be covered by our cyber policy?
No. Due diligence is a risk-mitigation and vendor-management activity, not a coverage trigger. Whether a loss arising from a vendor (for example, a breach at a service provider) is covered depends on the specific policy wording, including any contingent business interruption or dependent-system endorsements, exclusions, retentions, and conditions precedent. Some policies contain warranties or representations about your vendor-vetting practices, so weak due diligence could in some forms affect coverage, but strong due diligence does not itself create or guarantee coverage. Insurance transfers financial consequences; it does not reduce the likelihood of a vendor incident, which is what due diligence addresses.
Is vendor onboarding due diligence the same as ongoing third-party risk monitoring?
No. Onboarding due diligence is a point-in-time assessment performed before or at the start of a vendor relationship. It reflects the vendor's posture at that moment and does not capture changes over the life of the contract, such as new subprocessors, deteriorating security controls, or the vendor's own supply-chain exposures. Continuous or periodic monitoring, reassessment, and contractual audit rights are separate, ongoing activities. Treating onboarding as a one-time gate rather than the start of a lifecycle is a common gap; the two functions are complementary, not interchangeable.
What information should we typically request from a vendor during onboarding due diligence?
Common requests include the vendor's security control documentation, any independent audit or attestation reports the vendor makes available, descriptions of how it handles and stores your data, its incident response and notification practices, use of subprocessors, and evidence of its own insurance where relevant. The precise scope should be proportionate to the criticality of the service and the sensitivity of the data involved. Higher-risk vendors typically warrant deeper review than low-risk ones; the goal is to inform a risk decision, not to collect documentation for its own sake.
How should due diligence findings feed into contract terms?
Findings commonly inform contractual provisions such as security requirements, data-handling obligations, breach-notification timelines, audit and assessment rights, subprocessor controls, and indemnification and liability terms. Where due diligence surfaces gaps, organizations often negotiate remediation commitments or compensating controls as conditions of engagement. Aligning the contract with identified risks is a mitigation step; it does not substitute for risk transfer through insurance, nor does a favorable indemnity guarantee recovery if the vendor is insolvent or the loss exceeds negotiated caps.
How do we prioritize which vendors receive the deepest due diligence?
Prioritization is typically risk-based, weighing factors such as the vendor's access to sensitive or regulated data, its role in critical business processes, the potential business-interruption impact if it fails, and the degree of your operational dependence on it. Vendors that could cause significant disruption or that hold large volumes of personal data generally warrant more rigorous review. This tiering should be documented so the rationale is defensible; note that criticality for resilience purposes and materiality for coverage purposes may not perfectly align, and both perspectives can be relevant.
Who should be involved in the onboarding due diligence process?
Effective due diligence is usually cross-functional, involving security or IT to assess controls, legal and compliance to review contractual and regulatory obligations, procurement to manage the commercial relationship, and business owners who understand the operational dependency. Risk and insurance stakeholders may also be engaged where a vendor materially affects the organization's risk profile or where coverage considerations, such as contingent business interruption exposure, are relevant. The specific roles vary by organization; the point is that no single function typically has full visibility into all dimensions of vendor risk.

Common misconceptions

Completing vendor onboarding due diligence means vendor-related losses are covered by insurance.
Due diligence is a risk mitigation and assessment activity that may reduce the likelihood or severity of an incident; it is separate from risk transfer. Whether a vendor-related loss is covered depends on the specific policy wording, applicable endorsements, exclusions, and conditions precedent, which may include requirements to maintain certain standards.
A vendor that passes a security assessment is resilient, so the engaging organization is protected.
A favorable control assessment reflects a point-in-time evaluation and does not by itself constitute resilience for either party. It does not eliminate incident likelihood, and it does not substitute for the organization's own continuity and recovery planning or for any insurance arrangement.
Due diligence requirements are the same everywhere, so one standardized checklist suffices.
Compliance obligations and their definitions can differ across regulatory regimes and contractual contexts, and controls may be assessed against different frameworks or standards. Due diligence typically must be tailored to the jurisdiction, the nature of the engagement, and the specific risks involved.

Best practices

Tailor the depth of due diligence to the vendor's risk profile and the sensitivity of the data or systems involved, rather than applying a single uniform checklist across all vendors.
Keep the security and control assessment distinct from any coverage analysis; treat due diligence as risk mitigation and separately confirm how vendor-related losses would be addressed under the applicable policy wording, endorsements, and exclusions.
Document the vendor's continuity and recovery expectations, including any stated RTO and RPO, and verify they are consistent with your own recovery objectives rather than assuming alignment.
Clarify liability allocation, indemnification, and data-handling responsibilities in the contract, and review with legal and coverage advisors how those terms interact with first-party and third-party exposures.
Verify compliance and regulatory obligations against the specific jurisdictions and regulatory regimes that apply to the engagement, since requirements vary.
Establish ongoing monitoring and periodic reassessment, recognizing that onboarding captures only a point-in-time view of the vendor's posture.
Promotional banner for the Pentest Readiness checklist download