Third-Party Risk Management (TPRM) & Vendor Due Diligence
Onboarding a vendor means inheriting a slice of their risk. Their security incident becomes your breach notification, their sanctions violation becomes your compliance problem, and their insolvency becomes your supply disruption.
Third-party due diligence is how you understand what you're taking on before you sign the master services agreement. It draws on nearly every other kind of diligence at once — corporate, financial, security, privacy, sanctions and litigation.
Where due diligence fits: third-party risk management (TPRM)
Third-party risk management, or TPRM, is the broader program that governs how an organization identifies, assesses and monitors the risk introduced by vendors, suppliers, contractors and other outside parties. Due diligence is one phase of that program — the assessment step — but it only delivers value when it sits inside a repeatable lifecycle rather than a one-time form at signing.
A typical TPRM lifecycle runs in five stages. First you identify and tier the vendor by how critical it is and how sensitive the data or access it needs; then you assess it through due diligence proportionate to that tier.
The final three stages are where most programs fall short. You contract for the risk with the right security, privacy, audit and termination clauses; you monitor the vendor continuously because a clean assessment at onboarding says nothing about its posture a year later; and you offboard cleanly, revoking access and confirming data is returned or destroyed when the relationship ends.
Tiering is what keeps a TPRM program realistic. A critical vendor that processes customer data earns deep diligence and continuous monitoring, while a low-risk supplier with no data access needs only a light touch — the sections below scale to whichever tier a vendor lands in.
Confirm they are who they say they are
Start with the basics that everyone skips: the exact legal entity you're contracting with, its good standing, its ownership and its corporate family. If the operating company is a thinly-capitalized subsidiary and the balance sheet lives with the parent, your contract and your recourse need to account for that.
Test financial stability
A vendor that folds mid-contract is its own kind of incident. For public vendors, the financial trend and debt load are in their SEC filings. For private ones, you're asking for statements and reading them skeptically. The question isn't just "are they profitable" but "will they still be operating, and investing in the product, in three years."
Screen for compliance exposure
Run the vendor and its principals against sanctions and restricted-party lists, check for regulatory enforcement history, and screen adverse media. A vendor under active enforcement, or one whose owners appear on a watchlist, is a risk you want to know about before it becomes yours. These checks are quick and the downside of skipping them is severe.
Assess security and privacy posture
If the vendor will touch your data or systems, their security and privacy practices are effectively yours. Look for independent assurance — SOC 2, ISO 27001 — rather than marketing claims, understand how they handle personal data under GDPR and CCPA, and know their subprocessors and data-residency arrangements. The audited report beats the trust-page copy every time.
Check the licenses and the litigation
For regulated vendors, confirm they hold the licenses their service requires. Then search litigation history — a vendor with a pattern of being sued by customers is telling you how the relationship tends to end.
Neither check takes long, and both surface problems that references never will. A single reference call is curated; the public record is not.
Monitor continuously, not just at onboarding
The most common TPRM failure is treating diligence as a gate you pass once. A vendor's ownership can change, a breach can surface, a sanction can land, and financial health can deteriorate — all after you've signed and none of it visible in last year's assessment.
Continuous monitoring closes that gap by re-screening critical vendors on a schedule and alerting you when something material changes. Tie the cadence to the tier: monthly or continuous for critical vendors, annually for lower-risk ones.
Right-size the effort
Not every vendor warrants the full treatment — a coffee supplier and a payments processor sit at very different risk levels. Match the depth of diligence to the criticality of the vendor and the sensitivity of what they'll access, re-screen periodically because risk isn't static, and document what you checked. This is general guidance, not legal advice.