← Industry Insights
KYB

Supplier Due Diligence (SDD): Process, Checklist and Software Guide

Updated Jun 2026 · 11 min read
SHAREinXf
Supplier Due Diligence: A Comprehensive Guide for 2025

Supplier due diligence (SDD) is the structured check a business runs on a supplier before signing. It then keeps running while the relationship is live. Is the supplier financially sound? Legally clean? Free of hidden ownership and safe to bring into your supply chain? SDD answers those questions. You decide who to trust with evidence, not a sales deck.

This guide is built for the people who actually run these checks. You will find what SDD covers and the process step by step. We get into the checklist and onboarding questionnaire teams rely on. There are the red flags that should stop a deal, plus where enhanced checks apply. Then come the regulations now driving the work, and how supplier due diligence software pulls it all into one place.

What Is Supplier Due Diligence (SDD)?

Supplier due diligence is the investigation of a potential or existing supplier. The point is to gauge the risk they could bring into your business. A proper review looks at financial stability and regulatory and legal compliance. It covers beneficial ownership too, along with operational capability and reputation, all before any commitment is made. Done properly, it replaces assumption with proof.

The work also goes by other names. You will see it written as Know Your Supplier (KYS) or vendor due diligence. More broadly, people call it third-party due diligence. The labels overlap and the underlying job is the same: understand who you are buying from before they become your problem.

Take a simple example. A tech company planning to outsource its customer service would first verify the provider's financial health, data security, service quality and compliance with data-protection law before signing anything. That check, run end to end, is supplier due diligence.

Why Supplier Due Diligence Matters

Every supplier you onboard inherits a slice of your risk. Picture a supplier with weak controls, undisclosed owners or sanctions exposure. That supplier can pull your firm into regulatory trouble, financial loss or reputational damage, even when the failing was entirely theirs. SDD is how you find that out first.

The exposure is not hypothetical. SecurityScorecard's 2025 Global Third-Party Breach Report found that 35.5% of breaches were linked to a third party in 2024, up 6.5 percentage points on the year before, and that 41.4% of ransomware and extortion incidents started through third-party access. The average organization now shares confidential data with close to 300 vendors, according to figures cited in industry third-party risk research. Each one of those relationships is a door.

Regulators have pushed in the same direction. Anti-money laundering and anti-bribery rules make you responsible for the third parties acting in your name, and a growing set of supply-chain laws now expect documented checks rather than good intentions. Here is what the discipline buys you:

  • Risk mitigation: SDD surfaces financial instability, non-compliance and unethical practice early, while you still have room to act.
  • Regulatory compliance: With laws like the UK's Modern Slavery Act and the US Foreign Corrupt Practices Act, you answer for your suppliers. Diligence is your evidence that you looked.
  • Reputation protection: A supplier caught in fraud, sanctions or labor abuse drags your brand in with it. Vetting first keeps that distance.
  • Quality assurance: Checking operational capability and standards confirms a supplier can actually deliver what the contract promises.

The Supplier Due Diligence Process

A workable SDD process moves through clear stages, with depth scaled to how risky and how critical each supplier is. A payments partner touching customer funds faces a far deeper review than a stationery vendor. These steps reflect how most risk and procurement teams run it.

1. Scope and risk-tier the supplier. Decide what the supplier will access, such as funds, customer data or critical systems, and assign a risk tier. The tier sets how deep the rest of the process goes.

2. Collect information. Send a supplier due diligence questionnaire and gather supporting documents: financial statements, licenses, certifications, policies and ownership records.

3. Verify and screen. Confirm the legal entity against official registries, map beneficial ownership, and screen the company and its owners against sanctions, watchlists, politically exposed person (PEP) data and adverse media.

4. Assess and score. Weigh financial health, compliance history, operational resilience and reputation into a decision. Approve, approve with conditions, or walk away.

5. Document the decision. Record what you checked, what you found and why you proceeded. This audit trail is what regulators and auditors later ask to see.

6. Monitor continuously. Re-screen and reassess on a schedule, and trigger an ad hoc review the moment a material change appears.

A common failure is spending the same effort on every supplier. That over-checks low-risk vendors while under-checking the ones that can actually hurt you. A risk-based approach fixes the imbalance. As a bonus, a risk-based model also improves the experience for the low-risk suppliers who clear quickly.

If you would rather run these stages from one system than across spreadsheets and inboxes, see how KYC Hub automates supplier vetting end to end.

Supplier Types: One Size Does Not Fit All

Not every supplier carries the same risk. The depth of SDD should follow that. A few common types make the point:

  • Manufacturers produce the goods you sell, so diligence centers on quality control, production capacity and ethical labor practices.
  • Wholesalers and distributors buy in bulk and resell, so the focus shifts to storage, handling, delivery reliability and financial stability.
  • Service providers supply expertise rather than goods, so diligence weighs service quality, data security and compliance with sector-specific rules.

Read the supplier type first. It tells you where to spend the review. It also tells you which questions actually matter for that relationship.

Supplier Due Diligence Checklist

A checklist keeps the review consistent and defensible. You should adapt the weighting to your sector and the specific supplier. Even so, most supplier due diligence checklists end up covering the same core areas. Use this as a baseline.

  • Corporate and legal: registration details, licenses, permits, group structure and ultimate beneficial owners.
  • Financial: audited statements, revenue and liability profile, credit standing and signs of distress.
  • Compliance: AML and anti-bribery policies, past regulatory actions, and sanctions and PEP screening results.
  • Operational: delivery capacity, supply-chain dependencies, business continuity and quality controls.
  • Data and security: certifications, breach history, incident response and how the supplier handles your data.
  • Reputation and ESG: adverse media, litigation, and environmental, social and governance conduct.
  • Contractual: terms, audit rights, exit provisions and sub-contractor arrangements.

Tier the depth to the supplier. High-risk and business-critical suppliers warrant every line plus enhanced checks. Low-risk suppliers can move through a lighter version.

Supplier Onboarding and the Due Diligence Questionnaire

Supplier onboarding is the process of bringing an approved supplier into your systems, contracts and payment runs. Due diligence is the gate that onboarding has to pass through. Skip it and you are just letting an unvetted counterparty straight into your supply chain.

A supplier onboarding questionnaire is the standardized set of questions you send to collect the checklist information in one pass. It drives consistency. It creates a written record. Best of all, it surfaces the gaps a supplier would rather not raise. Core sections usually mirror the checklist:

  • Financial standing: audited statements, main revenue streams, outstanding liabilities and any going-concern doubts.
  • Legal and compliance: licenses, past sanctions or regulatory actions, anti-bribery policy and data-protection practice.
  • Ownership and governance: ultimate beneficial owners, directors, and how decisions and ethics are governed.
  • Operations and continuity: production or service processes, quality controls, supply-chain dependencies and recovery plans.
  • Security: which systems hold your data, how it is protected, and the supplier's incident history.

How a supplier answers is itself a signal. Prompt, complete responses point to mature governance. What about vague replies, refusals or repeated delays? Those are a red flag in their own right, before you have checked a single document.

Supplier Due Diligence Red Flags

Some findings should pause or stop an onboarding. Watch for these in particular:

  • Information that does not reconcile. Stated figures or history that clash with official registry records or audited accounts.
  • Reluctance to disclose. A supplier that dodges the questionnaire, refuses audits or withholds ownership detail may be hiding something.
  • Hidden or layered ownership. Nominee directors, shell layers or offshore structures that obscure who really controls the company.
  • Sanctions or adverse media hits. Any tie to a sanctioned party, a watchlisted individual, or credible reporting of fraud or corruption.
  • Past compliance violations. Prior breaches across data privacy, labor or financial-crime rules.
  • Financial distress. Mounting liabilities or solvency doubts that put delivery at risk.

No single flag is automatically fatal. Several together, or one serious enough on its own, is reason to escalate to enhanced due diligence before going any further.

Enhanced Due Diligence: Which Suppliers Need a Deeper Check

Enhanced due diligence (EDD) is the deeper review reserved for higher-risk suppliers. Standard checks confirm who a supplier is. EDD goes further. It digs into where their money comes from, who ultimately controls them, and what reputational baggage they carry, with closer ongoing monitoring on top.

You apply it when risk is elevated. Typical triggers include a supplier based in or operating through a FATF-listed high-risk jurisdiction, a beneficial owner who is a PEP, significant adverse media, opaque ownership, or exposure to sanctioned regions. FATF refreshes its lists through the year, most recently in February and June 2026, so a supplier that looked low-risk last quarter can move up.

In practice, an enhanced review adds several layers beyond the standard pass: full UBO mapping through every ownership layer, source-of-funds and source-of-wealth checks, expanded adverse media in local languages, senior sign-off to take on or keep the supplier, and tighter, more frequent monitoring. Some events cannot wait for the next cycle. A change of director, a fresh regulatory action or a shift into a monitored jurisdiction should each trigger an immediate EDD refresh.

Supplier Risk Management (SRM)

Supplier risk management is the broader program that supplier due diligence sits inside. SDD is the assessment at a point in time. SRM is the ongoing discipline of identifying, scoring, monitoring and responding to supplier risk across the whole relationship and the whole supplier base.

The case for treating it as a program is in the numbers. Industry research reported that 97% of organizations experienced at least one supply-chain breach in 2025, and that supply-chain attacks rose to an average of 16 a month over late 2024 and into 2025. Concentration makes it worse. Picture many critical suppliers clustered in one region, one technology or one sub-contractor. A single failure there can ripple across all of them at once. Mapping that concentration is part of SRM, not an afterthought to it.

Resourcing is the quiet problem. Third-party risk research found that 73% of financial institutions run vendor risk with two or fewer full-time staff, even though more than half oversee 300-plus vendors. At that ratio, manual review simply cannot keep pace. That gap is exactly where automation earns its place.

Supplier Due Diligence Regulations in 2026

Supplier checks have moved firmly onto the regulatory agenda. Several frameworks now expect documented diligence across the supply chain.

The EU's Corporate Sustainability Due Diligence Directive (CSDDD) was published as Directive (EU) 2026/470 on 26 February 2026 and entered into force on 18 March 2026. After the Omnibus I changes, it now has a single application date of 26 July 2029 for all in-scope companies, EU companies with more than 5,000 employees and over €1.5 billion in net worldwide turnover, or non-EU companies with more than €1.5 billion in EU turnover. Member states must transpose it by 26 July 2028, and the Commission is due to issue its guidelines by 26 July 2027. In scope, it requires firms to identify and address adverse human-rights and environmental impacts across their chain of activities, using a risk-based approach.

In Germany, the Supply Chain Due Diligence Act (LkSG) still applies to companies with 1,000 or more employees and is enforced by BAFA. A September 2025 cabinet amendment moved to scrap the annual reporting obligation and limit sanctions to serious human-rights failings, and the national regime is expected to run until the CSDDD is transposed.

The financial-crime side is tightening too. The EU's Anti-Money Laundering Regulation (Regulation (EU) 2024/1624) applies directly across all 27 member states from 10 July 2027, widening the list of obliged entities and setting the beneficial-ownership threshold at 25% or more, with the option to lower it to 15% for higher-risk sectors. For any supplier you onboard, that makes UBO checks much harder to skip.

Supplier Due Diligence Software: How to Choose

Supplier due diligence software brings the questionnaire, verification, screening, scoring and monitoring into one workflow. The alternative is scattering them across spreadsheets, inboxes and separate tools. The right platform turns a slow, manual review into a repeatable, audit-ready one. When you compare options, weigh a few things that actually separate them:

  • Entity and UBO verification. Can it confirm the legal entity against registries and map beneficial ownership through layered structures, not just check a name?
  • Screening breadth. Does it cover global sanctions, watchlists, PEPs and adverse media, and re-screen automatically as those sources change?
  • Continuous monitoring. Does it watch suppliers after onboarding for event-based changes, rather than relying on a periodic file review?
  • Audit trail. Does every check, document and decision land in one place a regulator or auditor can inspect on demand?
  • Workflow fit. Can it tier suppliers by risk and route the right depth of review automatically, so low-risk suppliers clear fast?

A SDD report is the output that pulls this together: a single record of what was verified, what was screened, what was found and what was decided. Generate it from a platform rather than assembling it by hand. Then it stays current and consistent across every supplier in the book.

How KYC Hub Helps With Supplier Due Diligence

Manual work is the bottleneck. Run SDD across questionnaires, spreadsheets and email threads, and that is where programs slow down. Records drift out of date. The gaps auditors later find quietly open up. KYC Hub's Know Your Supplier (KYS) solution brings the work into one platform, built around what compliance and procurement teams need from supplier risk:

  • Vet suppliers continuously, so a supplier cleared at onboarding keeps being checked as sanctions lists, ownership and risk signals change.
  • Catch concealed ownership by mapping beneficial owners and unpicking layered or nominee structures to find who really controls a supplier.
  • Block sanctions and adverse media risk through screening of suppliers and their owners against global watchlists and negative news.
  • Centralise supplier records, keeping every check, document and decision in one audit-ready place.

It also fits the firms where supplier risk bites hardest, from trade finance and investment management to banking, payments and lending, where a single unchecked counterparty can carry real regulatory weight. The payoff is twofold. That combination shortens onboarding. At the same time, it strengthens the evidence trail supervisors now expect on demand rather than reconstructed after the fact. To see it applied to your own supplier base, request a Know Your Supplier demo.

Conclusion

Supplier due diligence is how a business decides which suppliers it can safely rely on. Get the process right, scaled by risk and repeated over the life of the relationship, and you catch the financial, ownership, sanctions and security problems before they become yours. And the work pays for itself the first time it stops a bad supplier at the door.

[ FREQUENTLY ASKED QUESTIONS ]

Any questions? We got you.

What is supplier due diligence?

Supplier due diligence is the structured assessment of a supplier or third party to measure the risk they could bring into your business. It reviews financial stability, legal and regulatory compliance, beneficial ownership, operational capability and reputation before and during the relationship. The aim is to base the decision on evidence rather than assumption.

What is the difference between supplier due diligence and vendor due diligence?

In day-to-day third-party risk work, the terms are used interchangeably and describe the same process applied to the organizations in your supply chain. "Supplier" tends to appear in procurement and supply-chain contexts, "vendor" in IT and services, but the checks are the same. Note that in mergers and acquisitions, "vendor due diligence" can also mean a report a seller commissions on itself, which is a separate use of the phrase.

How do you conduct supplier due diligence?

Scope and risk-tier the supplier, collect information through a due diligence questionnaire and documents, then verify the legal entity and screen it and its owners against sanctions, PEP and adverse-media data. From there you assess and score the findings into a decision, document the audit trail, and monitor the supplier continuously for any material change.

Which suppliers require enhanced due diligence?

Enhanced due diligence applies to higher-risk suppliers. Common triggers are a supplier in a FATF-listed high-risk jurisdiction, a beneficial owner who is a politically exposed person, complex or hidden ownership, significant adverse media, or exposure to sanctioned regions. It adds full UBO mapping, source-of-funds checks, deeper adverse-media searches and closer monitoring.

What is included in a supplier due diligence questionnaire?

A supplier due diligence questionnaire gathers information on financial standing, legal and regulatory compliance, ownership and governance, operational resilience, and data security. It standardizes the request, creates a written record, and surfaces gaps early. How completely and promptly a supplier responds is itself a signal of how well the business is run.

What are the red flags in supplier due diligence?

Key red flags include information that does not match official records, reluctance to share documents or allow audits, hidden or layered ownership, sanctions or adverse-media hits, prior compliance violations, and signs of financial distress. No single flag is automatically fatal, but one serious finding, or several together, should escalate the review to enhanced due diligence.

How often should supplier due diligence be conducted?

Supplier due diligence is not a one-time check. Re-screen and reassess suppliers on a schedule set by risk, with higher-risk suppliers reviewed more frequently than low-risk ones. On top of the schedule, run a triggered review whenever ownership, sanctions status, financial health or regulatory exposure changes.

What is supplier due diligence software?

Supplier due diligence software brings the questionnaire, entity and UBO verification, sanctions and adverse-media screening, risk scoring and ongoing monitoring into one workflow. It replaces scattered spreadsheets and inboxes with a repeatable, audit-ready process, and produces a single SDD report of what was checked, found and decided for each supplier.

What is the difference between supplier due diligence and supplier risk management?

Supplier due diligence is the assessment of a supplier at a point in time, usually before onboarding and at set review points. Supplier risk management is the wider, ongoing program that identifies, scores, monitors and responds to supplier risk across the whole base. SDD is a component of SRM, not a replacement for it.

How does KYC Hub help with supplier due diligence?

KYC Hub's Know Your Supplier solution runs supplier due diligence from one platform. It vets suppliers continuously, maps beneficial ownership to catch concealed control, screens suppliers and their owners against sanctions and adverse media, and centralises every check into an audit-ready record.

[ KYC HUB ]

Verify businesses and their owners in minutes

Automated corporate verification, UBO discovery and ongoing due diligence for B2B onboarding.

Explore the KYB solutionBook a demo
[ RELATED READING ]
KYC vs eKYC: Which Method Should Your Institution Use in 2026?
[ KYC ]

KYC vs eKYC: Which Method Should Your Institution Use in 2026?

KYC vs eKYC isn't just a compliance choice, it's a cost and risk decision. Learn which method fits your product under RBI's 2025 guidelines.

Mar 2026 · 7 min read
KYC Requirements in Saudi Arabia: A Comprehensive Guide for Financial Institutions
[ KYC ]

KYC Requirements in Saudi Arabia: A Comprehensive Guide for Financial Institutions

Complete guide to KYC requirements in Saudi Arabia. Learn about SAMA regulations, compliance obligations, required documents, and penalties for financial institutions

Jan 2026 · 9 min read
Aadhar Card OCR API for KYC & Document Verification
[ KYC ]

Aadhar Card OCR API for KYC & Document Verification: A Buyer's Guide

An Aadhar card OCR API reads name, DOB, gender, and a masked Aadhaar number straight off the card so your KYC flow skips manual data entry. Here is how it works and how to evaluate one.

Dec 2025 · 10 min read