Skip to main content
Category: Third-Party and Supply Chain

Supplier Due Diligence

Also known as: Vendor Due Diligence, VDD, Third-Party Due Diligence
Simply put

Supplier due diligence is the process of investigating, verifying, and evaluating a supplier before entering into or maintaining a business relationship with them. It helps an organization understand who it is dealing with and identify potential risks associated with that third party. The process is generally structured and may involve ongoing evaluation rather than a one-time check.

Formal definition

Supplier due diligence is a structured process of investigating, verifying, and evaluating third-party suppliers or vendors before establishing, and often throughout the course of, a business relationship. It functions as a component of third-party governance and risk management, enabling an organization to assess supplier-related risks in a collaborative and comprehensive manner. The scope, depth, and frequency of due diligence typically vary by jurisdiction, sector, entity type, and the risk profile of the individual supplier, and specific legal or regulatory obligations to conduct it depend on the applicable framework. This entry is educational and not legal, audit, or compliance advice.

Why it matters

Suppliers and vendors extend an organization's operations beyond its own boundaries, and with that reach comes exposure to risks the organization does not directly control. Supplier due diligence matters because it gives an organization a structured way to understand who it is dealing with before committing to, or continuing, a business relationship. Without it, an organization may enter agreements without a clear view of the financial, operational, reputational, legal, or compliance risks a third party could introduce.

As a component of third-party governance and risk management, supplier due diligence supports informed decision-making at the point of onboarding and, in many cases, throughout the life of the relationship. Treating due diligence as an ongoing evaluation rather than a one-time check helps an organization detect changes in a supplier's risk profile over time. The appropriate depth and frequency generally scale to the risk a given supplier presents, so that higher-risk relationships receive more scrutiny than lower-risk ones.

It is important to note that whether, and to what extent, an organization is legally required to conduct supplier due diligence depends on the applicable framework, and obligations vary by jurisdiction, sector, and entity type. This entry is educational and not legal, audit, or compliance advice; organizations should determine their specific obligations based on their own facts and the regimes that apply to them.

Who it's relevant to

Chief Compliance and Risk Officers
These functions typically own the design and oversight of third-party risk and due diligence processes, setting the standards for how suppliers are evaluated and how findings are escalated. They are generally responsible for ensuring the depth of due diligence is calibrated to each supplier's risk profile and to any applicable obligations.
Procurement and Vendor Management Teams
As the functions that operate the supplier relationship day to day, these teams often carry out the practical work of gathering and verifying supplier information at onboarding and during the relationship. They generally apply the due diligence framework defined by risk and compliance to individual sourcing and vendor decisions.
General Counsel and Legal Teams
Legal advisers help determine whether and how due diligence obligations apply given the organization's jurisdiction, sector, and entity type, and how findings affect contracting decisions. Because specific requirements depend on the applicable framework, their involvement helps ensure the process reflects the relevant legal context.
Internal Audit and Assurance Functions
Internal audit and other assurance providers typically evaluate whether the supplier due diligence process is designed appropriately and operating effectively, providing independent assurance to management and the board rather than performing the due diligence itself.
The Board and Its Committees
Boards and relevant committees generally hold an oversight role, satisfying themselves that management has established a credible approach to third-party and supplier risk. They typically focus on the adequacy of the framework and reporting rather than on individual supplier assessments.

Inside Supplier Due Diligence

Identity and Ownership Verification
Confirming the legal identity, corporate structure, and ultimate beneficial ownership of a prospective or existing supplier. This often supports anti-money laundering and sanctions objectives, though the depth of verification typically depends on jurisdiction, sector, and the risk profile of the relationship.
Screening Against Sanctions, PEP, and Adverse Media Lists
Checking suppliers and their principals against applicable sanctions regimes, politically exposed persons databases, and negative news sources. The specific lists that are binding depend on the jurisdictions to which the entity is subject, and screening is generally a point-in-time exercise that may require periodic refresh.
Anti-Bribery and Corruption Assessment
Evaluating the corruption risk associated with a supplier, particularly where intermediaries, high-risk geographies, or government interactions are involved. In many jurisdictions this supports compliance with anti-bribery laws, but the applicable legal standard varies by the entity's footprint and the laws to which it is exposed.
Financial Stability and Operational Capability Review
Assessing whether a supplier is financially sound and operationally able to perform, which is primarily a commercial and operational risk concern rather than a compliance obligation. Depth typically scales with the criticality of the goods or services and potential business impact of failure.
ESG, Labor, and Human Rights Considerations
Reviewing environmental, social, and governance factors, including modern slavery and labor practices. Some of these areas are subject to binding disclosure or diligence requirements in certain jurisdictions, while others remain voluntary standards or best-practice expectations; applicability depends on the entity and its supply chain.
Risk-Based Segmentation and Tiering
Categorizing suppliers by risk so that diligence effort is proportionate. Lower-risk relationships may receive streamlined checks while higher-risk ones warrant enhanced diligence. This reflects a risk-based approach and requires the exercise of professional judgment against a defined methodology.
Ongoing Monitoring and Periodic Reassessment
Recognizing that due diligence is not solely an onboarding gate; residual risk can change over the life of a relationship. Ongoing monitoring, contract-driven audit rights, and periodic reassessment help keep the risk picture current, with cadence typically driven by risk tier.
Documentation and Audit Trail
Maintaining records of the diligence performed, findings, and decisions to demonstrate that a defined process was followed. Such records generally support accountability and may be relevant to demonstrating a program's design, though retention expectations vary by jurisdiction and policy.

Common questions

Answers to the questions practitioners most commonly ask about Supplier Due Diligence.

Is supplier due diligence the same as procurement's vendor selection process?
No, though the two often overlap and share information. Vendor selection is generally a procurement activity focused on commercial factors such as price, quality, capacity, and service levels. Supplier due diligence is a risk and compliance activity focused on identifying and assessing risks a supplier may pose, such as bribery and corruption, sanctions exposure, financial instability, data protection, modern slavery, or reputational concerns. In many organizations procurement owns the sourcing decision while compliance, legal, or risk functions define and review the due diligence requirements. Whether the two are formally integrated depends on how an organization designs its processes. This entry is educational and not legal or compliance advice.
Does completing supplier due diligence mean a supplier relationship is compliant and low risk?
Not by itself. Due diligence typically assesses risk at a point in time and informs a decision; it does not eliminate residual risk or guarantee ongoing compliance. A supplier's circumstances, ownership, or conduct can change after onboarding, which is why many programs pair initial due diligence with ongoing monitoring and periodic refresh. It is also important to distinguish the design of a due diligence control from its operating effectiveness: a well-designed process can still fail if it is not applied consistently. The appropriate depth and frequency of due diligence generally depend on the risk profile of the supplier and relevant legal or regulatory expectations, which vary by jurisdiction and sector.
How should an organization decide how much due diligence a given supplier requires?
Many programs apply a risk-based approach, tiering suppliers by factors such as the nature of the goods or services, spend, geography, sector, access to sensitive data or systems, and public-sector or intermediary involvement. Higher-risk relationships typically warrant enhanced due diligence, while lower-risk ones may receive a lighter review. The specific criteria and thresholds are matters of organizational judgment, informed by applicable legal requirements and internal risk appetite and tolerance. Some frameworks and regulatory expectations encourage a proportionate, risk-based method, but the details generally depend on the entity, its obligations, and its facts. This is educational information, not tailored advice.
Which function should own supplier due diligence, and where does accountability sit?
Ownership varies by organization. Under a three-lines model, the first line (often procurement or the business relationship owner) typically executes the process and owns the underlying risk day to day; the second line (such as compliance or risk management) generally sets policy, standards, and provides oversight and challenge; and internal audit, as the third line, may provide independent assurance over the process. Accountability for the overall control environment usually rests with management, with the board or a relevant committee providing oversight rather than performing the activity. Organizations should define these responsibilities explicitly to avoid gaps, and the appropriate structure depends on size, sector, and risk profile.
How often should supplier due diligence be refreshed after onboarding?
There is no single required frequency across all contexts. Many programs set refresh cycles based on risk tier, for example reviewing higher-risk suppliers more frequently than lower-risk ones, and trigger event-based reviews when circumstances change, such as ownership changes, adverse media, sanctions developments, or contract renewals. The appropriate cadence is generally a matter of organizational judgment informed by any applicable legal or regulatory expectations, which vary by jurisdiction and sector. Documenting the rationale for chosen intervals can support both the design and the demonstrable operating effectiveness of the control.
What should an organization do when due diligence identifies a red flag?
Programs commonly define an escalation and resolution path so that identified concerns are assessed, documented, and either mitigated or escalated before a relationship proceeds. Depending on the issue, responses may include seeking further information, applying enhanced due diligence, imposing contractual safeguards, requiring remediation, escalating to compliance, legal, or senior management, or declining or exiting the relationship. Who holds decision authority, and what thresholds require escalation, are matters an organization should establish in policy. Recording how red flags were evaluated and resolved generally supports accountability and later assurance. This is educational and not legal, audit, or compliance advice.

Common misconceptions

Supplier due diligence is a one-time onboarding check that is complete once a supplier is approved.
Onboarding diligence generally addresses inherent risk at a point in time, but supplier risk can shift over the life of the relationship. Ongoing monitoring and periodic reassessment are typically needed to manage residual risk, with frequency proportionate to the supplier's risk tier.
Every supplier requires the same depth of investigation.
A risk-based approach is generally preferred, applying proportionate effort. Enhanced diligence is typically reserved for higher-risk relationships, such as those involving high-risk geographies, government touchpoints, or critical dependencies, while lower-risk suppliers may warrant streamlined checks. The appropriate calibration depends on the entity's methodology and judgment.
Passing a sanctions or watchlist screen means a supplier is fully cleared of compliance risk.
Screening is generally a point-in-time check against specific lists and does not address ownership complexity, bribery exposure, ESG or labor concerns, or financial and operational risk. It is one component of due diligence rather than a comprehensive assurance, and applicable lists vary by jurisdiction.

Best practices

Establish a documented, risk-based methodology that tiers suppliers and defines proportionate diligence steps for each tier, so effort aligns with the risk each relationship presents.
Clarify accountability across functions, for example, distinguishing the operational and commercial assessment owned by procurement and business management from compliance-driven checks such as sanctions, anti-bribery, and beneficial ownership review.
Refresh screening and reassess higher-risk suppliers on a defined cadence rather than treating diligence as a one-time onboarding gate, so that changes in residual risk are captured over the life of the relationship.
Confirm which requirements are legally binding for the entity's specific jurisdictions and sectors versus which reflect voluntary frameworks or best practice, and document that distinction in the diligence approach.
Maintain a clear audit trail of findings, decisions, and rationale to demonstrate that the defined process was followed and to support later review.
Where relationships are critical or higher-risk, secure contractual rights, such as audit, information, and remediation rights, to enable ongoing monitoring and enhanced diligence when warranted.