OpenDD
← All articles

Third-Party & Vendor Due Diligence Checklist

Vendor Risk · Updated July 2026

Onboarding a vendor means inheriting a slice of their risk. Their security incident becomes your breach notification; their sanctions violation becomes your compliance problem; their insolvency becomes your supply disruption. Third-party due diligence is how you understand what you're taking on before you sign the master services agreement — and it draws on nearly every other kind of diligence at once.

Confirm they are who they say they are

Start with the basics that everyone skips: the exact legal entity you're contracting with, its good standing, its ownership and its corporate family. If the operating company is a thinly-capitalized subsidiary and the balance sheet lives with the parent, your contract and your recourse need to account for that.

Test financial stability

A vendor that folds mid-contract is its own kind of incident. For public vendors, the financial trend and debt load are in their SEC filings. For private ones, you're asking for statements and reading them skeptically. The question isn't just "are they profitable" but "will they still be operating, and investing in the product, in three years."

Screen for compliance exposure

Run the vendor and its principals against sanctions and restricted-party lists, check for regulatory enforcement history, and screen adverse media. A vendor under active enforcement, or one whose owners appear on a watchlist, is a risk you want to know about before it becomes yours. These checks are quick and the downside of skipping them is severe.

Assess security and privacy posture

If the vendor will touch your data or systems, their security and privacy practices are effectively yours. Look for independent assurance — SOC 2, ISO 27001 — rather than marketing claims, understand how they handle personal data under GDPR and CCPA, and know their subprocessors and data-residency arrangements. The audited report beats the trust-page copy every time.

Check the licenses and the litigation

For regulated vendors, confirm they hold the licenses their service requires. And search litigation history — a vendor with a pattern of being sued by customers is telling you how the relationship tends to end. Neither check takes long, and both surface problems that references never will.

Run every vendor check in one place. OpenDD packages corporate, financial, sanctions, enforcement, litigation, security and privacy diligence into guided modules with downloadable reports. Start a vendor check →

Right-size the effort

Not every vendor warrants the full treatment — a coffee supplier and a payments processor sit at very different risk levels. Match the depth of diligence to the criticality of the vendor and the sensitivity of what they'll access, re-screen periodically because risk isn't static, and document what you checked. This is general guidance, not legal advice.

Related guides

Corporate Due Diligence: Verify a Company → SOC 2 vs ISO 27001 → Privacy Due Diligence: GDPR & CCPA →