A guide to Vendor Due Diligence Questionnaires

The key factor in such a decision is the vendor’s ability and willingness to remediate or mitigate any identified risks to your business.

This article discusses an approach commonly used to create vendor due diligence questionnaires, covering:

FREE VRM CHECKLIST Your Vendor Risk Management Checklist 15 vendor risk management activities that your business should complete Insights into why each step matters and who should be involved Discover how a VCLM platform can help

Why use a Vendor Due questionnaire?

Benefits for your business:

Benefits for your vendors

How much due diligence is necessary and how often?

You should perform some level of due diligence on every vendor you contract with.

The extent of that effort should be based on:

Minimal due diligence might be enough for a low-cost office supplies vendor. However, a thorough assessment is crucial for a vendor managing your sensitive data, providing critical infrastructure services, or accessing your internal technology infrastructure to install or administer software.

A simple low-medium-high scale can rank a vendor’s position for each factor. Most of your vendors will require minimal due diligence, a few will need moderate effort, and strategic vendors will need thorough and more frequent reviews.

It's advisable to have a basic vendor due diligence questionnaire that describes the essential data to be obtained from and any that might need to be provided to, your existing and potential vendors.

This can be supplemented with extensions for more in-depth data collection when needed for the few essential vendors you rely on.

Timing for due diligence activities can be: