Vendor Due Diligence Checklist
Trust, then verify. In that order.Your security posture is bounded by your weakest vendor, and your auditor knows it — vendor management is sampled in every SOC 2 and ISO 27001 audit. This is the review process that scales from a two-person startup to a real TPRM program.
01 Tier before you review
- Classify the vendor by data access: none / internal data / customer data / production access
- Classify by criticality: would an outage stop your product or your payroll?
- Match review depth to tier — a full questionnaire for your cloud provider, a lightweight check for the swag vendor
- Record the tier and rationale; auditors ask how you decided
02 Collect the evidence
- Request the SOC 2 Type II report (under NDA) or ISO 27001 certificate — and actually read the exceptions
- Check the report's period and bridge letter if it's stale
- Review their sub-processor list and where your data will live
- Request the pen test summary or letter of attestation
- For AI vendors: ask how your data is used for training and retention
03 Evaluate what you read
- Scope check: does the report cover the product you're buying, or a different entity?
- Exception check: repeated access-review or change-management exceptions are a pattern, not noise
- Breach history: search public disclosures; ask directly
- Financial viability for critical vendors — a dead vendor is a data incident
04 Contract and monitor
- Execute a DPA (and BAA if PHI is involved) before data flows
- Include security requirements, breach notification timelines, and audit rights in the MSA
- Set the re-review cadence by tier: annually for critical, on renewal for the rest
- Track everything in a register: tier, documents, dates, owner — this register IS your audit evidence
The register matters more than the reviews. A modest review process, consistently recorded, passes audits and catches real risk. A rigorous process that lives in someone’s inbox does neither. Our vendor management module exists to be that register — reviews tracked, evidence attached, renewals scheduled.
vCISO Services
Virtual CISO services for startups and scaleups: security strategy, compliance roadmap, enterprise deal support, and board reporting — without the $300K hire.
Book a CallWhat if a vendor won't share their SOC 2 report?
Common for smaller vendors. Fall back to a completed CAIQ or SIG Lite, their public trust page, and contractual security terms. If a vendor handling customer data offers none of these, that's your answer.
How many vendors should we actually review?
All of them get tiered; only the top tiers get deep review. A typical startup has 5–15 vendors touching customer data or production — that's the population that needs real diligence. Tiering everything else takes minutes each.
Do auditors really test vendor management?
Yes — it's a standard SOC 2 sample: 'show me the review for these three vendors.' A register with dates and documents answers in seconds. A Slack archaeology expedition does not.