☰ Contents
📥 Free Download
This 50-point vendor due diligence checklist is available as a free downloadable Excel template at ProcurementVMS.com — with tiered versions for Tier 1, 2, and 3 vendors, built-in scoring, and completion tracking.
How to Use This Checklist
Assign each checklist item a status: Not Applicable / Not Started / In Progress / Complete / Flagged for Review. Items flagged for review require a documented risk treatment decision before the vendor can proceed to contract execution. Use the tiered summary (below) to determine which items apply to each vendor tier — do not apply all 50 items to every vendor.
Domain 1: Company & Legal Verification (10 Items)
- › ✓ Legal entity name verified — exact match to IRS records and state registration
- › ✓ Secretary of State good standing — active registration confirmed in state of incorporation
- › ✓ EIN / TIN verified — IRS TIN matching confirmation
- › ✓ OFAC sanctions screening — vendor legal name and principal owners screened against OFAC SDN list
- › ✓ UN and EU sanctions screening — for internationally-operating vendors
- › ✓ OIG / SAM exclusion screening — government contractors and healthcare vendors
- › ✓ Beneficial ownership verified — ultimate beneficial owners identified for Tier 1 vendors
- › ✓ Conflict of interest disclosed — no relationships between vendor principals and your employees
- › ✓ Corporate structure documented — parent, subsidiary, and affiliate relationships identified
- › ✓ Adverse media screening — recent news and legal records checked for material issues
Domain 2: Financial Health (8 Items — Tier 1 & 2)
- › ✓ D&B credit score obtained — current Dun & Bradstreet financial health score
- › ✓ Years in business verified — minimum 2–3 years for standard vendors; 5+ for critical
- › ✓ Revenue size appropriate — vendor revenue supports the scope of your contract
- › ✓ Financial statements reviewed — last 2 years audited financials (Tier 1 only)
- › ✓ Revenue concentration assessed — no single customer >30% of vendor revenue for critical vendors
- › ✓ Liens and judgements checked — no undisclosed material liens or court judgements
- › ✓ Bankruptcy history disclosed — no pending or recent bankruptcy proceedings
- › ✓ Cyber liability insurance current — minimum coverage limits verified for Tier 1 data-access vendors
Domain 3: Cybersecurity & Data Privacy (12 Items)
- › ✓ SOC 2 Type II report current — within 18 months; Tier 1 technology vendors
- › ✓ ISO 27001 certificate current — alternative or supplement to SOC 2; international vendors
- › ✓ Security questionnaire completed and scored — CAIQ or custom questionnaire by tier
- › ✓ Cyber risk score obtained — BitSight or SecurityScorecard for Tier 1 technology vendors
- › ✓ Data Processing Agreement (DPA) executed — for any vendor accessing personal data
- › ✓ HIPAA BAA executed — healthcare organisations only; all vendors accessing PHI
- › ✓ Penetration testing policy confirmed — annual pen testing for vendors with system access
- › ✓ Breach notification obligation confirmed — contractual 48-hour notification requirement
- › ✓ Fourth-party data controls documented — subcontractors handling your data identified and controls confirmed
- › ✓ Access control policy reviewed — least-privilege access; multi-factor authentication
- › ✓ Incident response plan confirmed — vendor has documented, tested IR plan
- › ✓ Data retention and deletion policy confirmed — vendor will delete your data on contract termination
Track Due Diligence Completion in Procurement VMS
Join US procurement leaders who replaced manual processes with intelligent automation. Live in 4–8 weeks.
Domain 4: Regulatory & Compliance (10 Items)
- › ✓ Applicable licences current — professional, state, or industry-specific licences verified
- › ✓ FCPA / anti-bribery acknowledgment signed
- › ✓ Code of conduct signed — vendor acknowledges your supplier standards
- › ✓ Export control compliance confirmed — EAR/ITAR for relevant technology vendors
- › ✓ CCPA / CPRA data handling confirmed — for vendors processing California consumer data
- › ✓ PCI DSS compliance confirmed — for vendors in payment data scope
- › ✓ Regulatory enforcement history disclosed — no undisclosed material enforcement actions in past 5 years
- › ✓ Anti-money laundering (AML) policy confirmed — financial services vendors
- › ✓ Environmental compliance confirmed — EPA and state environmental regulation adherence
- › ✓ Employment law compliance confirmed — no material wage, discrimination, or safety violations
Domain 5: Operational Resilience & ESG (10 Items)
- › ✓ Business continuity plan documented — BCP available and tested within 12 months
- › ✓ Disaster recovery capability confirmed — RTO and RPO defined for critical service delivery
- › ✓ Key person dependency assessed — no single-person risk for critical capabilities
- › ✓ Alternative supplier documented — Tier 1 vendors: back-up sourcing option identified
- › ✓ Geographic concentration assessed — primary operations and data centres identified
- › ✓ Modern slavery statement current — annual disclosure for vendors with international supply chains
- › ✓ Environmental policy documented — relevant environmental certifications or commitments
- › ✓ Diversity and inclusion policy confirmed — where relevant to procurement programme
- › ✓ Worker safety record reviewed — OSHA recordable incident rate for on-site vendors
- › ✓ Subcontractor use disclosed — all material subcontractors identified; flow-down obligations confirmed