PageCrawl.io

Free Template

Vendor Due Diligence Checklist

How to use this checklist

This checklist walks a procurement, security, or risk owner through the evidence a new vendor should provide before they are approved to handle your data or run in your environment. Work through each domain in order, check off every item once you have seen and verified the supporting evidence (not just a verbal claim), and record the date and a note next to anything that needs follow-up.

A box should only be checked when you have documented proof on file: a signed contract clause, a downloaded report, a dated certificate, or a screenshot from the vendor's trust center. Where an item does not apply to this vendor (for example, a vendor that never touches personal data), mark it N/A and write one line explaining why. Items left blank are treated as gaps and must be resolved or formally risk-accepted before sign-off.

Set the risk tier first, because it determines how deep you go. A vendor that processes customer personal data, connects to production systems, or is critical to your uptime is high risk and needs every domain completed. A low-risk vendor (no sensitive data, easily replaceable, no system access) can use a lighter pass, but the Company, Security, and Offboarding domains still apply.

Vendor and owner header block

FieldDetail
Vendor / company name[Legal entity name]
Product or service under review[Product / service name and brief description]
Vendor primary contact[Name, title, email, phone]
Vendor security / compliance contact[Name, title, email]
Risk tier[High / Medium / Low]
Data sensitivity[None / Internal / Confidential / Personal data / Regulated]
Internal business owner[Name, department]
Security / risk reviewer[Name, department]
Review start date[YYYY-MM-DD]
Target decision date[YYYY-MM-DD]
Annual contract value[Amount and currency]
Renewal / next review date[YYYY-MM-DD]

Company and commercial

Confirm the vendor is a real, stable, legally accountable business before you assess anything technical. A vendor that cannot prove its legal identity, financial footing, or insurance is a commercial risk regardless of how good the product looks.

Legal entity and standing

References and reputation

Financial stability and insurance

Security certifications and reports

Independent attestations are the fastest way to confirm a vendor's security program is real and audited rather than self-asserted. Always check the date and scope, not just the existence of a logo. An expired SOC 2 or an ISO certificate that excludes the product you are buying is not valid evidence.

SOC 2

ISO 27001 and other standards

Penetration testing and assessments

Data protection and privacy

If the vendor will process personal data on your behalf, the contractual and operational privacy controls must be in place before any data flows. Confirm the paperwork is signed and the data map is understood, not merely promised.

Contracts and processing terms

Sub-processors and data flow

Data residency and breach handling

Technical and application security

Verify the controls that protect the data and access in day-to-day operation. These should be evidenced by the SOC 2 / ISO report, security documentation, or direct confirmation from the vendor's security team.

Encryption and data handling

Access and authentication

Vulnerability and secure development

Business continuity and reliability

Confirm the vendor can keep the service running and recover from failure within limits your business can tolerate. Uptime promises must be backed by contractual remedies and tested recovery procedures.

MetricVendor commitmentYour requirementAcceptable?
Uptime SLA (%)[e.g. 99.9%][Your minimum][Y / N]
RTO (recovery time objective)[e.g. 4 hours][Your maximum][Y / N]
RPO (recovery point objective)[e.g. 1 hour][Your maximum][Y / N]
Support response (critical)[e.g. 1 hour][Your requirement][Y / N]

Access and offboarding

Plan the exit before you start. Confirm you can grant minimal access, revoke it cleanly, and get your data back (or destroyed) when the relationship ends. Offboarding gaps are a common source of orphaned access and data exposure.

Onboarding access controls

Deprovisioning and exit

Ongoing monitoring

Due diligence is not a one-time event. A vendor that was compliant at onboarding can let a certificate lapse, change sub-processors, or suffer an incident. Set up continuous monitoring so you find out when something changes instead of discovering it at the next annual review.

Review sign-off

Record the final decision once every applicable domain above is complete. Any unchecked or N/A items that carry residual risk must be listed as conditions or formally risk-accepted by the named approver.

FieldDetail
Overall residual risk rating[Low / Medium / High]
Open items / conditions[List outstanding gaps and required follow-ups]
Risk acceptance owner (if any risk accepted)[Name, title]
Security reviewer name and signature[Name / signature]
Business owner name and signature[Name / signature]
Approver name and signature[Name / signature]
Decision date[YYYY-MM-DD]
Next review date[YYYY-MM-DD]

Decision

Decision rationale: [Summarize the basis for the decision, key risks, and any conditions or compensating controls.]

Stop checking by hand

Due diligence is a snapshot. PageCrawl turns it into a feed: it monitors each vendor's certifications, security pages, and breach disclosures, and alerts you when something changes after onboarding.

Start monitoring free →

This free template is provided by PageCrawl.io, website change monitoring and alerts. Reuse and adapt it freely.