A vendor due diligence platform is usually sold on the breadth of its external data: sanctions lists, adverse media, financial health, cyber ratings. Those are real and they matter at scale. For a small business the binding constraint is different and much duller: knowing which suppliers warrant which checks, and being able to show a year later that the checks were done.
A baseline for everybody, then points
Three checks for every supplier: it exists and is who it says it is, you know the legal entity you are contracting with, and you have written terms. On top of that, points for what it touches. Customer or employee data adds two, site access adds two, being your only source adds three, and annual spend adds one per $25,000. The worked example lands on ten checks against a baseline of three.
Single-sourcing is the risk that scores highest
A supplier you can replace in a week is a commercial problem when it fails. A supplier nobody else can substitute is an operational one, and no amount of contractual protection changes that. It scores three points here, more than data access or site access, because it is the risk with no fallback and the one most often missed in a checklist built around information security.
Record the evidence against the vendor, not in an inbox
Checks completed, by whom, when, and what they found. The value shows up when an insurer, a customer or an auditor asks a year later and the answer is a page rather than an afternoon of searching sent items. Diligence that happened but was never recorded is, for every practical purpose, diligence that did not happen.
Proportionate means some suppliers get almost nothing
The failure mode of diligence is applying the heavy version to everybody, which is abandoned within a quarter. A supplier that never comes on site, holds no data and can be replaced next week gets the baseline three and nothing else. Reserving the effort is what makes the programme survivable, and survivability is worth more than thoroughness that lapses.
Questions people ask about vendor due diligence platform
What are the three baseline checks?
That the company exists and is who it says it is, that you know the legal entity you are contracting with, and that you have written terms. Everything beyond that is proportionate to what the vendor touches and what you pay it.
How much diligence does a small supplier need?
Often just the baseline. The free worksheet on this site sizes it from data access, site access, single-sourcing and annual spend, and tells you how many checks are outstanding.
Is this a risk assessment?
No. It sizes how much diligence is proportionate and tracks how much you have done. What your regulator, insurer or customers require of your suppliers is a question for your own advisers.