Vendor due diligence, sized to the vendor rather than applied to everybody

Vendor due diligence goes wrong in two directions and both are expensive. Run the heavy version on every supplier and the programme is abandoned within a quarter. Run the light version on all of them and the vendor holding your customer data got the same scrutiny as the one selling envelopes. The way out is to size it, and the sizing is simple enough to do in your head once you know the inputs.

A baseline for everybody, then points

Three checks for every supplier: it exists and is who it says it is, you know the legal entity you are contracting with, and you have written terms. On top of that, points for what it touches. Customer or employee data adds two, site access adds two, being your only source adds three, and annual spend adds one per $25,000. The worked example lands on ten checks against a baseline of three.

Single-sourcing is the risk that scores highest

A supplier you can replace in a week is a commercial problem when it fails. A supplier nobody else can substitute is an operational one, and no amount of contractual protection changes that. It scores three points here, more than data access or site access, because it is the risk with no fallback and the one most often missed in a checklist built around information security.

Record the evidence against the vendor, not in an inbox

Checks completed, by whom, when, and what they found. The value shows up when an insurer, a customer or an auditor asks a year later and the answer is a page rather than an afternoon of searching sent items. Diligence that happened but was never recorded is, for every practical purpose, diligence that did not happen.

Proportionate means some suppliers get almost nothing

The failure mode of diligence is applying the heavy version to everybody, which is abandoned within a quarter. A supplier that never comes on site, holds no data and can be replaced next week gets the baseline three and nothing else. Reserving the effort is what makes the programme survivable, and survivability is worth more than thoroughness that lapses.

Questions people ask about vendor due diligence

What are the three baseline checks?

That the company exists and is who it says it is, that you know the legal entity you are contracting with, and that you have written terms. Everything beyond that is proportionate to what the vendor touches and what you pay it.

How much diligence does a small supplier need?

Often just the baseline. The free worksheet on this site sizes it from data access, site access, single-sourcing and annual spend, and tells you how many checks are outstanding.

Is this a risk assessment?

No. It sizes how much diligence is proportionate and tracks how much you have done. What your regulator, insurer or customers require of your suppliers is a question for your own advisers.

Sources

Related answers

Keep this vendor record in Venbix Pro, $49 a monthStop finding out about renewals in the bank statement. $49 a month, whole team.