What is supplier due diligence?

Supplier due diligence is the process of checking a supplier's financial health, security posture, legal standing, and compliance record before you sign a contract with them, and at regular intervals afterwards. It exists to catch problems, such as a vendor about to go bankrupt or one with a history of data breaches, before those problems become your problems. Most companies run it during vendor onboarding, then repeat lighter checks at renewal or when a supplier's risk profile changes.

Last Updated
August 12, 2026

Supplier due diligence is the structured review a company carries out on a vendor before doing business with them, covering areas like financial stability, information security, data privacy, sanctions exposure, and regulatory compliance. The goal is simple: know who you are buying from before their risk becomes yours. Third parties played a part in 30% of data breaches, double the share from the previous year (Verizon Data Breach Investigations Report, 2025), so the checks matter more than they used to.

What does supplier due diligence actually check?

The exact checks depend on what the supplier does for you. A vendor handling customer data needs far deeper scrutiny than one supplying office furniture. Most due diligence programmes cover some combination of the following.

Financial checks

Can the supplier stay in business for the length of your contract? Teams review credit ratings, filed accounts, and payment histories. If your payroll provider goes under mid-contract, you have a payroll problem, not a procurement problem.

Security and data privacy checks

If a supplier will touch your systems or your customers' data, the security review is the one that matters most. This typically means reviewing certifications like SOC 2 or ISO 27001, sending a security questionnaire, and confirming a Data Processing Agreement (the contract clause governing how they handle personal data) is in place before any data moves.

Legal and compliance checks

These cover sanctions screening (is the supplier or its owners on a government watchlist?), anti-bribery checks, litigation history, and industry-specific regulation. Financial services firms, for example, face regulatory requirements like DORA in the EU and the FCA's operational resilience rules in the UK, both of which make third-party oversight a legal obligation rather than good practice.

ESG and reputational checks

Larger buyers increasingly screen suppliers for environmental impact, labour practices, and modern slavery risk. In some jurisdictions this is law: Germany's Supply Chain Due Diligence Act requires companies above a headcount threshold to audit their supply chains for human rights violations.

Why does supplier due diligence matter for procurement and risk teams?

Because the alternative is finding out about a supplier's problems from the news. When a vendor suffers a breach, becomes insolvent, or lands on a sanctions list, the companies buying from them inherit the fallout: service outages, regulatory fines, and awkward questions from the c-suite or board about why nobody checked.

Here’s an example of how this could play out. A team signs a new software vendor in a hurry to hit a project deadline. Six months later, the security team discovers the vendor stores customer data in a region the company's privacy policy prohibits. Now legal is renegotiating a contract that nobody should have signed in that form, and the project stalls anyway.

Due diligence exists to move that discovery from month six to day one, when you still have bargaining power. Before signature, you can demand fixes, negotiate protections, or walk away. After signature, you are negotiating from a much weaker position.

There is also a scaling argument. A company with 50 suppliers can run due diligence over email and spreadsheets. A company with 800 suppliers cannot, at least not consistently. That is where checks get skipped, questionnaires go unanswered, and a certificate that expired eight months ago sits unnoticed in a shared drive.

How should due diligence work in practice?

The teams that do this well follow three principles.

Tier suppliers by risk, and scale the checks to the tier. Running a 200-question security review on a £3,000 stationery supplier wastes everyone's time and trains the business to route around procurement. A sensible model applies light checks to low-risk vendors and reserves deep reviews for suppliers handling sensitive data, delivering critical services, or holding large contract values.

Run checks in parallel, not in sequence. The slowest version of due diligence passes the vendor from security to legal to finance to privacy, one desk at a time, adding weeks to onboarding. The faster version triggers every relevant review at once, based on answers the requester gives at intake. This is where an intake and orchestration platform like Omnea changes the economics: when someone requests a new vendor, the system reads the risk signals in the request and routes it to security, legal, and finance simultaneously, so a review that took three weeks over email finishes in days.

Treat due diligence as ongoing, not one-off. A supplier that passed every check at onboarding can fail them two years later. Certifications lapse, ownership changes, financial health deteriorates. Mature programmes monitor suppliers continuously and re-run assessments at renewal or when risk signals change, rather than assuming the day-one snapshot still holds.

Due diligence versus vendor onboarding

People often conflate the two terms, but they are not the same. Vendor onboarding is the full process of setting a supplier up to work with you: collecting bank details, signing contracts, creating them in your ERP (the finance system of record). Due diligence is the risk-assessment layer within that process. You can onboard a vendor without proper due diligence, and plenty of companies do, which is exactly how unvetted suppliers end up with access to production systems.

If you are building or fixing a due diligence programme, start by answering one question: for each supplier you added in the last quarter, can you say who reviewed them, what they checked, and where the evidence lives? If the answer involves searching someone's inbox, the process needs a system, not another policy document.