02 Due Diligence
Vendor Risk Management provides the overall lifecycle.
Due Diligence is where the organization investigates whether the vendor can actually meet its security, privacy, compliance, operational, and contractual expectations.
The core question is:
What evidence supports the vendor’s claims, and what risk remains if we use this vendor?
A practical due diligence workflow looks like:
Vendor Request ↓Inherent Risk ↓Due Diligence Scope ↓Questionnaire ↓Evidence Collection ↓Security Review ↓Privacy Review ↓Compliance Review ↓Resilience Review ↓Finding Identification ↓Residual Risk ↓Recommendation ↓ApprovalLearning Objectives
Section titled “Learning Objectives”By the end of this lesson, you will be able to:
-
Explain vendor due diligence.
-
Understand when due diligence should occur.
-
Determine the appropriate assessment depth.
-
Build a vendor due diligence questionnaire.
-
Request and evaluate supporting evidence.
-
Review security governance.
-
Review IAM and privileged access.
-
Assess vulnerability and patch management.
-
Review secure development practices.
-
Assess encryption and key management.
-
Evaluate logging and monitoring.
-
Review incident-response capabilities.
-
Assess privacy controls.
-
Evaluate subprocessors.
-
Review compliance certifications.
-
Review SOC reports.
-
Assess ISO certifications.
-
Evaluate business continuity and disaster recovery.
-
Understand financial and operational due diligence.
-
Identify vendor findings.
-
Determine residual vendor risk.
-
Build a vendor recommendation.
-
Maintain an auditable due diligence evidence pack.
1. What Is Vendor Due Diligence?
Section titled “1. What Is Vendor Due Diligence?”Vendor due diligence is the structured investigation of a third party before or during a business relationship.
It evaluates whether the vendor has appropriate:
Governance
Cybersecurity
Privacy
Compliance
Operational Controls
Resilience
Financial Stabilityto support the service safely.
2. Due Diligence Is More Than a Questionnaire
Section titled “2. Due Diligence Is More Than a Questionnaire”Weak:
Vendor Questionnaire ↓Vendor Answers "Yes" ↓ApprovedStrong:
Vendor Questionnaire ↓Supporting Evidence ↓Validation ↓Findings ↓Risk Assessment ↓DecisionThe critical word is:
Evidence
3. When Should Due Diligence Occur?
Section titled “3. When Should Due Diligence Occur?”Due diligence should normally occur:
Before Contract
Before Production Access
Before Sensitive Data Processingand later when required through:
Periodic Reassessment
Contract Renewal
Major Scope Change
Security Incident
New Subprocessor
Material Service Change4. Due Diligence Starts With Inherent Risk
Section titled “4. Due Diligence Starts With Inherent Risk”Do not send every vendor the same 300-question assessment.
First determine:
What Service?
What Data?
What Access?
How Critical?
Which Regulations?Then define assessment depth.
5. Risk-Based Assessment Depth
Section titled “5. Risk-Based Assessment Depth”Example:
| Vendor | Risk | Due Diligence |
|---|---|---|
| Office supplier | Low | Basic screening |
| Training provider | Low | Limited review |
| Marketing SaaS | Medium | Standard assessment |
| HR SaaS | High | Detailed assessment |
| Cloud hosting | Critical | Full due diligence |
| Identity provider | Critical | Full due diligence |
6. Create Due Diligence Case
Section titled “6. Create Due Diligence Case”Create:
DD-YYYY-####Example:
DD-2026-0035Record:
Vendor
Service
Business Owner
Risk Tier
Assessment Owner
Start Date
Target Completion7. Define Due Diligence Scope
Section titled “7. Define Due Diligence Scope”Create:
01 Due Diligence ScopeDetermine whether the assessment will cover:
Security
Privacy
Compliance
Resilience
Financial
Legal
AI
Operational Risk8. Example Scope Decision
Section titled “8. Example Scope Decision”Vendor:
CloudHRProcesses:
Employee Data
Salary Information
Bank Information
Government IdentifiersAssessment should include:
Security+Privacy+Resilience+Compliance+Subprocessors9. Vendor Due Diligence Questionnaire
Section titled “9. Vendor Due Diligence Questionnaire”Create:
02 Vendor Due Diligence QuestionnaireSuggested domains:
01 Organization & Governance
02 Security Governance
03 Asset Management
04 IAM
05 Encryption
06 Network Security
07 Vulnerability Management
08 Secure Development
09 Logging & Monitoring
10 Incident Response
11 Business Continuity
12 Privacy
13 Compliance
14 Subprocessors
15 Cloud Security
16 AI Governance
17 Personnel Security10. Organization & Governance
Section titled “10. Organization & Governance”Ask:
Who Owns Security?
Is There a FormalSecurity Program?
Are Policies Approved?
How Often ArePolicies Reviewed?
Is Risk AssessmentPerformed?11. Evidence Requests
Section titled “11. Evidence Requests”Do not request documents randomly.
Build:
03 Vendor Evidence Request ListExample:
| Domain | Evidence |
|---|---|
| Governance | Security policy |
| IAM | Access-control policy |
| Vulnerability | Scan / remediation summary |
| Security Testing | Pen-test summary |
| Compliance | SOC 2 / ISO certificate |
| Privacy | Privacy policy / DPA |
| BCP | Business-continuity plan |
| DR | Recovery-test evidence |
| Incident Response | IR plan |
| Training | Awareness evidence |
12. Evidence Classification
Section titled “12. Evidence Classification”Evidence may be:
Public
Confidential
RestrictedHandle vendor assurance documents appropriately.
13. Evidence Freshness
Section titled “13. Evidence Freshness”Always check:
Evidence Date
Assessment Period
Expiration Date
Current Service ScopeA five-year-old penetration test is weak evidence for today’s environment.
14. Security Governance Assessment
Section titled “14. Security Governance Assessment”Review whether vendor security governance includes:
Security Leadership
Policies
Risk Management
Control Ownership
Metrics
Security Training
Internal Reviews15. Security Policy Review
Section titled “15. Security Policy Review”Verify:
Policy Approved?
Version Current?
Scope Appropriate?
Review Frequency?
Owner Defined?16. Vendor Risk Management
Section titled “16. Vendor Risk Management”Ask whether the vendor itself manages third parties.
Your Vendor ↓Their VendorsThis becomes:
Fourth-Party Risk17. Asset Management
Section titled “17. Asset Management”Assess whether the vendor maintains:
Hardware Inventory
Software Inventory
Cloud Assets
Critical Systems
Data Assets18. Data Inventory
Section titled “18. Data Inventory”For privacy-sensitive vendors ask:
What Customer DataDo You Process?
Where?
How Is It Classified?
Who Can Access It?19. IAM Due Diligence
Section titled “19. IAM Due Diligence”Review:
User Provisioning
MFA
SSO
RBAC
Privileged Access
Service Accounts
Access Reviews
Offboarding20. MFA
Section titled “20. MFA”Ask:
Is MFA Requiredfor Administrators?
Employees?
Remote Access?
Production Access?21. Privileged Access
Section titled “21. Privileged Access”For administrators verify controls such as:
Named Accounts
MFA
PAM
Logging
Approval
Periodic Review22. Joiner / Mover / Leaver
Section titled “22. Joiner / Mover / Leaver”Assess:
Join ↓Access Approved
Role Change ↓Access Updated
Termination ↓Access Removed23. Vendor Personnel Access
Section titled “23. Vendor Personnel Access”If vendor staff can access your environment, determine:
Who?
Why?
How Often?
Which Privileges?
How Is Access Logged?24. Encryption
Section titled “24. Encryption”Assess:
Encryption at Rest
Encryption in Transit
Backup Encryption
Database Encryption
Key Management25. Encryption Evidence
Section titled “25. Encryption Evidence”Evidence may include:
Architecture
Configuration Statement
Audit Report
Encryption Standard
Independent Assessment26. Key Management
Section titled “26. Key Management”Review:
Key Storage
Key Rotation
Key Access
Separation of Duties
HSM / KMS
Key Revocation27. Network Security
Section titled “27. Network Security”Assess:
Network Segmentation
Firewall Management
Remote Access
IDS / IPS
Zero Trust Controls
Production Isolation28. Internet-Facing Assets
Section titled “28. Internet-Facing Assets”Ask:
How AreInternet-Facing SystemsInventoried?
Scanned?
Monitored?
Patched?29. Vulnerability Management
Section titled “29. Vulnerability Management”Assess:
Scanning Frequency
Severity Methodology
Remediation SLA
Patch Management
Exceptions
Validation30. Example Remediation SLA
Section titled “30. Example Remediation SLA”A vendor may define:
Critical→ 15 Days
High→ 30 Days
Medium→ 90 DaysThe important question is whether those timelines meet your risk expectations.
31. Vulnerability Findings
Section titled “31. Vulnerability Findings”If vendor says:
Critical FindingsCan Remain Openfor 180 Daysthat may create a material risk depending on the service.
32. Penetration Testing
Section titled “32. Penetration Testing”Ask:
Is Penetration TestingPerformed Annually?
Is It Independent?
What Is in Scope?
Are Critical FindingsRemediated?33. Pen-Test Evidence
Section titled “33. Pen-Test Evidence”Prefer:
Executive Summary
Scope
Date
Tester
Finding Severity
Remediation Statusrather than full sensitive technical reports unless required.
34. Secure Development Lifecycle
Section titled “34. Secure Development Lifecycle”For software vendors assess:
Secure Coding
Code Review
SAST
DAST
Dependency Scanning
Secrets Scanning
Threat Modeling
Security Testing35. Software Supply Chain
Section titled “35. Software Supply Chain”Assess:
Open-Source Dependencies
SBOM
Package Integrity
Third-Party Components
Build Security
Code Signing36. Secrets Management
Section titled “36. Secrets Management”Check whether developers store:
Passwords
API Keys
Tokens
Private Keysin:
Source Codeor managed secret systems.
37. Logging and Monitoring
Section titled “37. Logging and Monitoring”Assess whether the vendor logs:
Authentication
Administrative Activity
Security Events
Data Access
Configuration Changes
API Activity38. Log Retention
Section titled “38. Log Retention”Ask:
How LongAre Logs Retained?
Are Logs Protected?
Who Can Access Them?39. SOC / Security Monitoring
Section titled “39. SOC / Security Monitoring”Determine whether vendor has:
SOC
SIEM
MDR
24×7 Monitoringwhere appropriate.
40. Incident Response
Section titled “40. Incident Response”Review:
IR Plan
Roles
Escalation
Customer Notification
Forensics
Lessons Learned41. Incident Notification
Section titled “41. Incident Notification”Ask:
How QuicklyWill You Notify Usif Our Dataor ServiceIs Affected?42. Incident Testing
Section titled “42. Incident Testing”Evidence may include:
Tabletop Exercises
Simulation
Lessons Learned
Testing Schedule43. Business Continuity Assessment
Section titled “43. Business Continuity Assessment”Create:
04 Business Continuity AssessmentReview:
Business Continuity Plan
Disaster Recovery
Backups
RTO
RPO
Alternate Sites
Failover
Testing44. Critical Service Analysis
Section titled “44. Critical Service Analysis”Ask:
What happens to our business if this vendor is unavailable for 24 hours?
45. RTO Assessment
Section titled “45. RTO Assessment”Vendor RTO:
24 HoursBusiness requirement:
4 HoursResult:
Resilience Gap46. RPO Assessment
Section titled “46. RPO Assessment”Vendor RPO:
24 HoursBusiness tolerance:
1 HourPotential:
Data Loss Risk47. Backup Assessment
Section titled “47. Backup Assessment”Check:
Backup Frequency
Encryption
Separation
Immutability
Restore Testing
Retention48. Privacy Due Diligence
Section titled “48. Privacy Due Diligence”Create:
05 Privacy Due Diligence ChecklistAssess:
Personal Data
Sensitive Data
Purpose
Location
Retention
Deletion
Subprocessors
Rights Support
Incident Notification
International Transfers49. Processing Purpose
Section titled “49. Processing Purpose”Ask:
Why Does the VendorNeed the Data?Ensure:
Data ↓Specific Purpose50. Data Minimization
Section titled “50. Data Minimization”Challenge:
Does the VendorNeed Every FieldWe Plan to Send?51. Data Location
Section titled “51. Data Location”Record:
Primary Region
Backup Region
Support Location
Subprocessor Location52. Retention
Section titled “52. Retention”Ask:
How Long IsCustomer Data Retained?
What HappensAfter ContractTermination?53. Deletion Capability
Section titled “53. Deletion Capability”Verify whether the vendor can delete:
Primary Data
Replicas
Archives
Backups
Logsaccording to applicable requirements and technical capabilities.
54. Privacy Rights Support
Section titled “54. Privacy Rights Support”Determine whether vendor can assist with:
Access
Correction
Deletion
Export
Restriction55. Subprocessors
Section titled “55. Subprocessors”Request current:
Subprocessor ListReview:
Service
Country
Data
Purpose56. International Transfers
Section titled “56. International Transfers”Assess whether vendor processing introduces:
New Countries
New Regions
New Subprocessorsrequiring legal/privacy analysis.
57. Compliance Due Diligence
Section titled “57. Compliance Due Diligence”Create:
06 Compliance Evidence MatrixReview relevant:
SOC 1
SOC 2
ISO 27001
ISO 27017
ISO 27018
PCI DSS
HIPAA
Other Sector Requirements58. SOC 2 Review
Section titled “58. SOC 2 Review”For SOC 2 assess:
Type I or Type II?
Audit Period?
Scope?
Relevant Services?
Exceptions?
Subservice Organizations?
CUECs?59. Type I vs Type II
Section titled “59. Type I vs Type II”Type I generally evaluates control design at a point in time.
Type II generally evaluates controls over a period.
For ongoing assurance, Type II usually provides more operating-effectiveness information.
60. SOC Exceptions
Section titled “60. SOC Exceptions”Do not ignore:
Exceptions
Deviations
Qualified ResultsReview whether they affect your use of the vendor.
61. CUECs
Section titled “61. CUECs”Extract:
ComplementaryUser Entity ControlsCreate:
07 CUEC RegisterUse:
| CUEC | Internal Owner | Implemented? | Evidence |
|---|
62. ISO Certificate Review
Section titled “62. ISO Certificate Review”Verify:
Vendor Legal Name
Scope
Services
Locations
Certificate Date
Expiration
Certification Body63. Statement of Applicability
Section titled “63. Statement of Applicability”For higher-risk ISO-certified vendors, additional evidence such as applicable scope or control information may provide better assurance.
64. PCI DSS
Section titled “64. PCI DSS”If payment card information is involved, determine:
Vendor PCI Role
Service Provider?
Scope?
Attestation?
Responsibility?65. HIPAA
Section titled “65. HIPAA”If PHI is involved, assess:
Business Associate Role
BAA
Security Controls
Subcontractors
Incident Requirements66. Cloud Provider Due Diligence
Section titled “66. Cloud Provider Due Diligence”Cloud providers require additional consideration around:
Shared Responsibility
Regions
IAM
Encryption
Logging
Service Availability
Customer Configuration67. Shared Responsibility
Section titled “67. Shared Responsibility”Do not expect a cloud vendor to control:
Your IAM
Your Security Groups
Your Data Classification
Your Applicationwhen those are customer responsibilities.
68. SaaS Due Diligence
Section titled “68. SaaS Due Diligence”For SaaS assess:
Tenant Isolation
Admin Access
Authentication
Data Export
Deletion
Logging
API Security
Configuration69. Tenant Isolation
Section titled “69. Tenant Isolation”Ask:
What prevents Customer A from seeing Customer B’s data?
Evidence can include:
Architecture
Security Testing
SOC Evidence
Pen-Test Scope70. AI Vendor Due Diligence
Section titled “70. AI Vendor Due Diligence”AI vendor assessments should include:
Prompt Retention
Training Usage
Model Improvement
Fine-Tuning
Data Location
Subprocessors
Vector Storage
Output Controls
Model Security71. AI Training Question
Section titled “71. AI Training Question”Always ask:
Is customer data used to train, fine-tune, or improve models?
72. AI Retention
Section titled “72. AI Retention”Assess:
Prompt Retention
Conversation History
Uploaded Files
Model Logs
Embeddings73. AI Tenant Isolation
Section titled “73. AI Tenant Isolation”Evaluate whether enterprise customer data is isolated across:
Accounts
Projects
Models
Vector Stores
Logs74. AI Data Deletion
Section titled “74. AI Data Deletion”Ask whether deletion removes:
Prompt Data
Uploaded Files
Embeddings
Vector Entries
Conversation History75. Personnel Security
Section titled “75. Personnel Security”Assess:
Background Screening
Confidentiality Agreements
Security Training
Privileged Personnel Controls
Termination76. Remote Workforce
Section titled “76. Remote Workforce”Where vendor employees work remotely, consider:
Endpoint Security
VPN
Device Management
Physical Privacy
Data Download Restrictions77. Financial Due Diligence
Section titled “77. Financial Due Diligence”For critical vendors, evaluate:
Financial Stability
Revenue Trends
Debt
Funding
Bankruptcy Risk
Insurancewith the appropriate Finance or Procurement team.
78. Cyber Insurance
Section titled “78. Cyber Insurance”Where relevant assess:
Coverage
Limits
Expiry
Incident Typesbut do not treat insurance as a substitute for security controls.
79. Operational Due Diligence
Section titled “79. Operational Due Diligence”Assess:
Staffing
Support Model
Service Capacity
Customer Support
Change Management
Release Management
Service Dependencies80. Geographic Risk
Section titled “80. Geographic Risk”Consider whether the service depends heavily on:
Single Country
Single Region
Single Data Center81. Concentration Risk
Section titled “81. Concentration Risk”Ask:
Do We Already Dependon This VendorElsewhere?Example:
Cloud Provider ↓Hosting
Identity
Backup
AnalyticsA single outage could affect multiple services.
82. Build Findings Register
Section titled “82. Build Findings Register”Create:
08 Due Diligence Findings RegisterUse:
| ID | Finding | Risk | Severity | Owner | Status |
|---|
83. Finding Example — MFA
Section titled “83. Finding Example — MFA”Condition:
Vendor AdministratorsDo Not Use MFARisk:
Privileged AccountCompromiseSeverity:
Critical84. Finding Example — Retention
Section titled “84. Finding Example — Retention”Condition:
Vendor RetainsCustomer DataIndefinitelyRisk:
Over-Retention+Data Exposure85. Finding Example — DR
Section titled “85. Finding Example — DR”Business requires:
RTO:4 HoursVendor provides:
RTO:24 HoursRisk:
OperationalResilience Gap86. Finding Example — SOC Report
Section titled “86. Finding Example — SOC Report”Vendor SOC 2 includes repeated exception relating to:
User Access ReviewsAssess whether this could affect your service.
87. Determine Control Effectiveness
Section titled “87. Determine Control Effectiveness”For each control determine:
Strong
Adequate
Partial
Weak
Not Implementedbased on evidence.
88. Determine Residual Risk
Section titled “88. Determine Residual Risk”Start with:
Inherent Riskthen consider:
Vendor Controls
Contract Controls
Customer Controls
Compensating Controlsto determine:
Residual Risk89. Example
Section titled “89. Example”Inherent risk:
CriticalVendor controls:
StrongCustomer controls:
StrongResidual:
Mediumdepending on the defined methodology.
90. Risk Treatment Options
Section titled “90. Risk Treatment Options”Use:
Accept
Mitigate
Transfer
Avoid91. Mitigate
Section titled “91. Mitigate”Example:
Vendor Does NotSupport MFAPossible outcome:
Require MFABefore Production92. Compensating Control
Section titled “92. Compensating Control”If vendor cannot immediately remediate:
Restrict Network Access
IP Allowlisting
Time-Limited Accounts
Enhanced Monitoringmay reduce risk while a permanent fix is pursued.
93. Risk Acceptance
Section titled “93. Risk Acceptance”Risk acceptance should include:
Risk
Business Impact
Compensating Controls
Owner
Approval
Expiry94. Build Vendor Risk Recommendation
Section titled “94. Build Vendor Risk Recommendation”Create:
09 Vendor Risk RecommendationPossible decisions:
APPROVE
APPROVE WITH CONDITIONS
REMEDIATION REQUIRED
ESCALATE
REJECT95. Approval Recommendation Example
Section titled “95. Approval Recommendation Example”APPROVE WITH CONDITIONSConditions:
1 MFA enabled for privileged access
2 Prompt retention reduced
3 BCP testing evidence provided
4 Contract updated for incident notification
5 Critical findings remediated before production96. Pre-Contract Conditions
Section titled “96. Pre-Contract Conditions”Separate:
Must CompleteBefore Contractfrom:
Must CompleteBefore Productionand:
Post-OnboardingImprovement97. Due Diligence Evidence Pack
Section titled “97. Due Diligence Evidence Pack”Create:
10 Due Diligence Evidence PackSuggested structure:
01 Intake
02 Inherent Risk
03 Questionnaire
04 Security Evidence
05 Privacy Evidence
06 Compliance Evidence
07 Resilience Evidence
08 Financial Review
09 Findings
10 Remediation
11 Risk Decision
12 Approval98. Evidence Traceability
Section titled “98. Evidence Traceability”Every finding should be traceable to:
Question
Evidence
Analysis
Risk
Decision99. Evidence Review Log
Section titled “99. Evidence Review Log”Create:
| Evidence | Version | Date | Reviewer | Result |
|---|
100. Handling Restricted Vendor Evidence
Section titled “100. Handling Restricted Vendor Evidence”Security reports may contain:
Architecture
Security Findings
Customer Controls
Infrastructure InformationStore them with appropriate access restrictions.
101. Due Diligence Completion Criteria
Section titled “101. Due Diligence Completion Criteria”Do not complete the assessment until:
-
inherent risk confirmed.
-
assessment scope defined.
-
questionnaire completed.
-
required evidence obtained.
-
evidence reviewed.
-
security review completed.
-
privacy review completed where applicable.
-
compliance evidence reviewed.
-
resilience reviewed.
-
findings documented.
-
residual risk determined.
-
remediation requirements assigned.
-
recommendation documented.
-
approval recorded.
102. Missing Evidence
Section titled “102. Missing Evidence”If evidence is unavailable:
No Evidenceshould not automatically become:
Control ExistsPossible outcome:
Unable to Validatewhich may increase residual risk.
103. Vendor Refuses Security Evidence
Section titled “103. Vendor Refuses Security Evidence”Example:
Vendor:"We Do Not ShareSecurity Documentation."Alternative assurance may include:
Independent Reports
Certifications
Security Portal
Controlled Review Session
Contractual RepresentationsBut the inability to obtain sufficient assurance should be documented.
104. Security Evidence Under NDA
Section titled “104. Security Evidence Under NDA”Some vendors may provide reports only after:
NDACoordinate with:
Legal
Procurementrather than skipping evidence review.
105. Follow-Up Questions
Section titled “105. Follow-Up Questions”Due diligence is iterative.
Workflow:
Initial Questionnaire ↓Evidence Review ↓Questions ↓Vendor Clarification ↓Additional Evidence ↓Final Assessment106. Vendor Response Tracking
Section titled “106. Vendor Response Tracking”Create:
11 Due Diligence Request TrackerUse:
| Request | Sent | Due | Received | Status |
|---|
107. Vendor SLA
Section titled “107. Vendor SLA”Set internal target dates for:
Questionnaire
Evidence
Clarifications
Remediation108. Due Diligence Aging
Section titled “108. Due Diligence Aging”Monitor cases:
0–15 Days
16–30 Days
31–60 Days
60+ Days109. Escalation
Section titled “109. Escalation”Escalate when:
Vendor Unresponsive
Critical Evidence Missing
Critical Finding Identified
Launch Date Approaching
High Residual Risk
Contract Signed Prematurely110. Due Diligence Metrics
Section titled “110. Due Diligence Metrics”Track:
Assessments Completed
Average Completion Time
Critical Findings
Evidence Completeness
Risk Acceptances
Vendor Response Time111. KPI — Assessment Completion
Section titled “111. KPI — Assessment Completion”Due DiligenceCompleted on Time──────────────── × 100Due Diligence Due112. KPI — Evidence Coverage
Section titled “112. KPI — Evidence Coverage”Required EvidenceReceived─────────────── × 100Evidence Requested113. KPI — Finding Closure
Section titled “113. KPI — Finding Closure”Vendor FindingsClosed On Time────────────── × 100Findings Due114. KRI — Critical Gaps
Section titled “114. KRI — Critical Gaps”Vendors Approvedwith OpenCritical Findings115. KRI — Missing Evidence
Section titled “115. KRI — Missing Evidence”High-Risk VendorsWithout SufficientControl Evidence116. KRI — Unresolved Risk Acceptance
Section titled “116. KRI — Unresolved Risk Acceptance”Expired VendorRisk Acceptances117. Due Diligence Dashboard
Section titled “117. Due Diligence Dashboard”Create:
12 Vendor Due Diligence DashboardExample:
| Metric | Target |
|---|---|
| High-risk due diligence complete | 100% |
| Required evidence received | 100% |
| Critical gaps before production | 0 |
| Overdue assessments | 0 |
| Expired risk acceptances | 0 |
| Critical findings overdue | 0 |
118. Practical Activity — Cloud SaaS Vendor
Section titled “118. Practical Activity — Cloud SaaS Vendor”Assess fictional:
CloudCRMCloudCRM:
Stores Customer PI
Uses AWS
Uses Subprocessors
Offers SSO
Provides SOC 2Determine:
Risk Tier
Evidence Required
Security Questions
Privacy Questions
Residual Risk
Approval Decision119. Practical Activity — Missing MFA
Section titled “119. Practical Activity — Missing MFA”CloudCRM uses:
Username + Passwordfor privileged administrators.
No MFA.
Determine:
Finding
Risk
Severity
Required Remediation
Approval Impact120. Practical Activity — SOC Report
Section titled “120. Practical Activity — SOC Report”SOC 2 report contains:
3 Exceptionsincluding failure to remove terminated employee access promptly.
Assess:
Relevance
Risk
Customer Impact
Follow-Up Questions
Compensating Controls121. Practical Activity — AI Provider
Section titled “121. Practical Activity — AI Provider”Vendor processes:
Customer Support Promptsand retains prompts for:
180 Dayswith provider model improvement enabled.
Determine:
Privacy Risk
Security Risk
Required Contract Change
Technical Setting
Approval Recommendation122. Practical Activity — BCP Gap
Section titled “122. Practical Activity — BCP Gap”Critical vendor:
RTO:24 HoursCloudPay requirement:
RTO:4 HoursDetermine:
Residual Risk
Alternative Controls
Business Approval
Exit Considerations123. Practical Activity — Subprocessor Risk
Section titled “123. Practical Activity — Subprocessor Risk”Vendor uses an unlisted support provider in another country with access to customer data.
Determine:
Privacy Impact
Contract Impact
Transfer Impact
Vendor Finding
Required ActionVendor Due Diligence Operational Checklist
Section titled “Vendor Due Diligence Operational Checklist”Intake
Section titled “Intake”-
vendor request received.
-
business owner identified.
-
service understood.
-
inherent risk completed.
-
risk tier assigned.
-
security scope defined.
-
privacy scope defined.
-
compliance scope defined.
-
resilience scope defined.
-
AI scope defined where applicable.
Questionnaire
Section titled “Questionnaire”-
questionnaire sent.
-
response received.
-
unanswered items followed up.
-
contradictory responses investigated.
Evidence
Section titled “Evidence”-
security policies reviewed.
-
audit reports reviewed.
-
certifications validated.
-
penetration testing reviewed.
-
BCP evidence reviewed.
-
privacy evidence reviewed.
-
evidence freshness verified.
-
MFA assessed.
-
privileged access assessed.
-
access reviews assessed.
-
termination assessed.
-
service accounts assessed.
Security
Section titled “Security”-
encryption reviewed.
-
vulnerability management reviewed.
-
patching reviewed.
-
secure development reviewed.
-
logging reviewed.
-
incident response reviewed.
Privacy
Section titled “Privacy”-
personal data identified.
-
purpose reviewed.
-
minimization reviewed.
-
location reviewed.
-
retention reviewed.
-
deletion reviewed.
-
rights support assessed.
-
subprocessors reviewed.
Compliance
Section titled “Compliance”-
SOC report reviewed where relevant.
-
CUECs captured.
-
ISO certificate validated.
-
PCI evidence reviewed where applicable.
-
HIPAA evidence reviewed where applicable.
Resilience
Section titled “Resilience”-
BCP reviewed.
-
DR reviewed.
-
RTO assessed.
-
RPO assessed.
-
recovery testing reviewed.
-
backup controls assessed.
Findings
Section titled “Findings”-
findings documented.
-
severity assigned.
-
vendor response obtained.
-
remediation assigned.
-
compensating controls identified.
-
inherent risk documented.
-
control effectiveness assessed.
-
residual risk determined.
-
risk acceptance documented where required.
Decision
Section titled “Decision”-
recommendation documented.
-
pre-contract conditions identified.
-
pre-production conditions identified.
-
approval recorded.
Evidence Pack
Section titled “Evidence Pack”-
questionnaire retained.
-
supporting evidence retained.
-
analysis retained.
-
findings retained.
-
remediation retained.
-
decision retained.
124. Common Due Diligence Mistakes
Section titled “124. Common Due Diligence Mistakes”Mistake 1 — Questionnaire Only
Section titled “Mistake 1 — Questionnaire Only”Vendor responses should be validated with evidence.
Mistake 2 — Same Assessment for Every Vendor
Section titled “Mistake 2 — Same Assessment for Every Vendor”Assessment depth should follow risk.
Mistake 3 — Collect Evidence Without Reviewing It
Section titled “Mistake 3 — Collect Evidence Without Reviewing It”Downloading a SOC report is not due diligence.
You must read and assess it.
Mistake 4 — Ignore Report Scope
Section titled “Mistake 4 — Ignore Report Scope”Vendor may have a certification covering:
Corporate Officewhile your service runs from:
Different PlatformMistake 5 — Ignore CUECs
Section titled “Mistake 5 — Ignore CUECs”Some controls remain the customer’s responsibility.
Mistake 6 — Accept Old Evidence
Section titled “Mistake 6 — Accept Old Evidence”Stale evidence may no longer represent current operations.
Mistake 7 — Ignore Privacy
Section titled “Mistake 7 — Ignore Privacy”Cybersecurity controls alone do not address data-purpose, retention, deletion, and transfer risks.
Mistake 8 — Ignore Resilience
Section titled “Mistake 8 — Ignore Resilience”A secure vendor can still create major risk if its service cannot recover.
Mistake 9 — Missing Subprocessors
Section titled “Mistake 9 — Missing Subprocessors”Fourth parties can create hidden security and privacy risks.
Mistake 10 — Ignore AI Training Terms
Section titled “Mistake 10 — Ignore AI Training Terms”AI providers may use submitted data differently from traditional SaaS vendors.
Mistake 11 — No Residual Risk Decision
Section titled “Mistake 11 — No Residual Risk Decision”Due diligence should end with a risk recommendation, not a pile of documents.
Mistake 12 — Approve Before Critical Findings Are Resolved
Section titled “Mistake 12 — Approve Before Critical Findings Are Resolved”Business urgency should not silently override risk governance.
125. Weak Due Diligence
Section titled “125. Weak Due Diligence”Questionnaire ↓Vendor Says Yes ↓Certificate ↓Approve126. Strong Due Diligence
Section titled “126. Strong Due Diligence”Inherent Risk ↓Risk-Based Scope ↓Questionnaire ↓Evidence ↓Validation ↓Security Review ↓Privacy Review ↓Compliance Review ↓Resilience Review ↓Findings ↓Residual Risk ↓Remediation ↓Recommendation ↓Approval127. GRC Analyst Responsibilities
Section titled “127. GRC Analyst Responsibilities”A GRC professional performing vendor due diligence may:
-
review vendor intake.
-
confirm inherent risk.
-
define assessment scope.
-
issue security questionnaires.
-
request supporting evidence.
-
review policies and assurance reports.
-
analyze SOC reports.
-
validate ISO certificates.
-
review CUECs.
-
review penetration-test summaries.
-
evaluate IAM controls.
-
review vulnerability management.
-
assess privacy controls.
-
assess subprocessors.
-
evaluate BCP and DR.
-
document findings.
-
assess residual risk.
-
coordinate remediation.
-
prepare vendor recommendations.
-
maintain evidence.
-
escalate critical risks.
-
support procurement and contractual decisions.
GRC works closely with:
Security
Privacy
Legal
Procurement
Business Owners
Cloud
Architecture
Resilience
Finance
AI Governance128. Due Diligence Maturity Model
Section titled “128. Due Diligence Maturity Model”Level 1 — Basic
Section titled “Level 1 — Basic”Vendor Questionnaire
Manual ReviewLevel 2 — Documented
Section titled “Level 2 — Documented”Risk Tiers
Standard Questionnaires
Evidence Lists
Approval ProcessLevel 3 — Evidence-Based
Section titled “Level 3 — Evidence-Based”SOC Review
ISO Validation
Privacy Review
Findings
Residual RiskLevel 4 — Integrated
Section titled “Level 4 — Integrated”Automated Intake
Evidence Portals
Procurement Integration
Workflow
Risk AnalyticsLevel 5 — Continuous Assurance
Section titled “Level 5 — Continuous Assurance”Continuous Evidence
Dynamic Risk
External Security Signals
Automated Control Validation
Continuous Vendor Assurance129. Due Diligence Mindset
Section titled “129. Due Diligence Mindset”For every vendor ask:
What Is the Service?
What Risk Doesthe Service Create?
What EvidenceDo We Need?
Does the EvidenceMatch the Service?
Is It Current?
Do Their SecurityControls Work?
Do They ProtectOur Data?
Can They DeleteOur Data?
Who Are TheirSubprocessors?
What HappensDuring an Incident?
Can They Recoverfrom an Outage?
What CertificationsDo They Have?
What Do ThoseCertifications Actually Cover?
What FindingsRemain Open?
What Is theResidual Risk?
What Must BeFixed Before Contract?
What Must BeFixed Before Production?
Who AcceptsRemaining Risk?
Can We DefendOur Decision Later?That is the practical due diligence mindset.
Key Takeaways
Section titled “Key Takeaways”-
Due diligence is the evidence-based assessment phase of Vendor Risk Management.
-
Assessment depth should follow inherent vendor risk.
-
Questionnaires alone do not provide sufficient assurance.
-
Evidence must be reviewed for relevance, freshness, scope, and reliability.
-
IAM, MFA, privileged access, encryption, vulnerability management, logging, incident response, and secure development are important security domains.
-
Privacy due diligence should cover purpose, data, location, retention, deletion, subprocessors, and privacy-rights support.
-
SOC reports should be reviewed for scope, exceptions, subservice organizations, and CUECs.
-
ISO certificates should be checked for legal entity, scope, services, locations, and validity.
-
Critical vendors should undergo business continuity and disaster recovery review.
-
RTO and RPO should be compared against business requirements.
-
AI vendors introduce additional questions about prompts, retention, training, model improvement, and vector data.
-
Missing evidence should increase uncertainty rather than automatically being treated as a control pass.
-
Vendor findings should have risk ratings, owners, remediation, and evidence.
-
Residual risk should be explicitly determined.
-
Due diligence should end with a documented vendor recommendation.
-
GRC converts vendor claims into evidence-based risk decisions.
Knowledge Check
Section titled “Knowledge Check”Before continuing, make sure you can answer:
-
What is vendor due diligence?
-
How is due diligence different from vendor risk management?
-
Why should due diligence be risk-based?
-
What is an inherent risk assessment?
-
Why is a questionnaire insufficient by itself?
-
What makes strong vendor evidence?
-
Why does evidence freshness matter?
-
What IAM controls should be reviewed?
-
What should be assessed in vendor vulnerability management?
-
What evidence can support penetration testing?
-
What should be reviewed in a secure SDLC?
-
Why does vendor logging matter?
-
What should be reviewed in incident response?
-
Why should RTO and RPO be compared with business requirements?
-
What privacy areas should due diligence cover?
-
Why must subprocessors be identified?
-
What is a CUEC?
-
What should be reviewed in a SOC 2 report?
-
How should an ISO certificate be validated?
-
What additional considerations apply to AI vendors?
-
What is residual vendor risk?
-
What are the main risk-treatment options?
-
What is a compensating control?
-
When should risk acceptance be used?
-
What are possible vendor recommendation outcomes?
-
Why should critical conditions be separated into pre-contract and pre-production actions?
-
What belongs in a due diligence evidence pack?
-
What should happen when a vendor cannot provide evidence?
-
Why is due diligence an iterative process?
-
What role does GRC play in vendor due diligence?
What’s Next?
Section titled “What’s Next?”➡️ Next: 03 — Supplier Security
In the next lesson, you will move from assessing whether a vendor has an acceptable control environment to understanding how organizations define and enforce security requirements for suppliers throughout the relationship.
You will examine:
Supplier Classification ↓Security Requirements ↓Access Requirements ↓Data Protection ↓Secure Development ↓Incident Obligations ↓Business Continuity ↓Contractual Security ↓Supplier Monitoring ↓Security Findings ↓Remediation ↓Ongoing AssuranceYou will also build practical artifacts including a Supplier Security Standard, Supplier Security Requirements Matrix, Supplier Access Register, Supplier Data Protection Checklist, Contract Security Schedule, Supplier Incident Requirements, Supplier Assurance Tracker, and Supplier Security Dashboard.