← Industry Insights
KYB

Vendor Due Diligence: A Complete Guide to Third-Party Risk

Updated Jun 2026 · 10 min read
SHAREinXf
What is Vendor Due Diligence (VDD)?

Vendor due diligence is the structured review a business runs on a supplier or third party before signing a contract. The review then repeats while the relationship stays live. Is that party financially sound and legally clean? Does hidden ownership lurk behind it? Can it deliver without exposing you to fraud, sanctions or a data breach? Diligence answers those questions. The goal is simple. You decide who to trust with proof, not a sales pitch.

This guide is practical. It walks through what vendor due diligence covers and how the process runs end to end. You get the checklist and questionnaire teams rely on. It flags the warning signs that should stop a deal, then shows where enhanced checks kick in for higher-risk vendors.

What Is Vendor Due Diligence?

Vendor due diligence (VDD) is the assessment of a potential or existing vendor to gauge the risk they could bring into your business. Before any commitment is made, the review looks across financial health, regulatory and legal compliance, beneficial ownership, cybersecurity posture, operational resilience and ethical conduct. Done well, it hands you an objective read on a counterparty. Proof replaces assumption.

The term carries two meanings in practice, and it helps to separate them early. In third-party risk management, VDD is the buyer-side process of vetting suppliers and intermediaries before and during onboarding. In mergers and acquisitions, "vendor due diligence" instead refers to a seller commissioning its own diligence report to hand to prospective buyers. This guide focuses mainly on the first meaning. That is the day-to-day work of compliance, procurement and risk teams. The M&A sense gets its own section below.

What Does VDD Stand For?

VDD stands for Vendor Due Diligence. You will also see it written as supplier due diligence or, more broadly, third-party due diligence. The labels overlap heavily and the underlying work is the same.

Why Vendor Due Diligence Matters

Every supplier you onboard inherits a slice of your risk surface. Picture a vendor with weak controls, undisclosed owners or a sanctions exposure. That vendor can drag your firm into regulatory trouble, financial loss or reputational damage. The failing was entirely theirs, yet the consequences land on you. Diligence is how you find that out first.

The exposure is not theoretical. According to the Verizon 2025 Data Breach Investigations Report, third-party involvement in breaches reached roughly 30%, double the share recorded the year before. Regulators have moved in the same direction. The SEC's updated Regulation S-P now stresses oversight of vendors that touch customer data, and supervisors increasingly expect evidence of controls rather than remediation promises.

There is a compliance driver too. Anti-money laundering and anti-bribery rules make you responsible for the third parties acting in your name. Say a supplier turns out to be a front for a sanctioned entity or a bribery scheme. "We did not know" is rarely a defense that holds.

When Should Vendor Due Diligence Be Initiated?

Start before you sign. The right moment is during vendor selection, ahead of any contract or final negotiation, so you have time to act on what you find. Diligence does not stop at signature, though. Ownership shifts. Sanctions lists update. Breaches surface. Because risk keeps moving, the strongest programs treat onboarding as the first checkpoint, not the only one.

The Vendor Due Diligence Process

A workable process moves through clear stages. Scale the depth to how risky and how critical the vendor is. A payments partner handling customer data faces a far deeper review than a low-impact supplier. The steps below reflect how most risk teams run it.

1. Scope and risk-tier the vendor. Decide what the vendor will access, such as funds, customer data, or critical systems, and assign a risk tier. A cloud provider handling personal data sits far higher than a stationery supplier.

2. Collect information. Send a vendor due diligence questionnaire and gather supporting documents: financial statements, licenses, certifications, policies and ownership records.

3. Verify and screen. Confirm the legal entity, map beneficial ownership, and screen the company and its owners against sanctions, watchlists, politically exposed person (PEP) data and adverse media.

4. Assess and score. Weigh financial stability, compliance history, security posture and operational resilience into a risk decision. Approve, approve with conditions, or decline.

5. Document the decision. Record what you checked, what you found and why you proceeded. This audit trail is what regulators and auditors ask to see.

6. Monitor continuously. Re-screen and reassess on a schedule, and trigger an ad hoc review whenever a material change appears.

A common failure is applying identical effort to every vendor. That spreads teams thin. They over-check low-risk suppliers and under-check the ones that can actually hurt you. A risk-based approach fixes the imbalance.

If you would rather run these stages from one system than across spreadsheets and inboxes, see how KYC Hub automates supplier vetting end to end.

Vendor Due Diligence Checklist

A checklist keeps the review consistent and defensible. Adapt the weighting to your sector and to the specific vendor. Even so, most vendor due diligence checklists end up covering the same core areas listed below. Use it as a baseline.

  • Corporate and legal: registration details, licenses, permits, group structure and ultimate beneficial owners.
  • Financial: audited statements, revenue and liability profile, credit standing and signs of distress.
  • Compliance: AML and anti-bribery policies, past regulatory actions, sanctions and PEP screening results.
  • Cybersecurity and data: security certifications, breach history, incident response and data-handling practices.
  • Operational: delivery capacity, supply chain dependencies, business continuity and quality controls.
  • Reputation and ESG: adverse media, litigation, and environmental, social and governance conduct.
  • Contractual: terms, audit rights, exit provisions and sub-contractor arrangements.

Tier the depth to the vendor. High-risk and business-critical suppliers warrant every line plus enhanced checks. Low-risk vendors can move through a lighter version.

Vendor Due Diligence Questionnaire

A vendor due diligence questionnaire (VDDQ) is the standardized set of questions you send a vendor to gather the information above in one go. It drives consistency and creates a written record. Better still, it surfaces gaps the vendor would rather not raise. Core sections usually mirror the checklist.

Financial performance. Can you share audited statements for the past three years? What are your main revenue streams and outstanding liabilities?

Legal and regulatory compliance. Have you faced legal disputes, sanctions or regulatory actions? Are all licenses current? How do you handle data protection?

Ownership and governance. Who are your ultimate beneficial owners and directors? How are decisions and ethical conduct governed?

Operational resilience. What are your production and supply chain processes, quality controls and continuity plans?

Security and technology. What systems hold our data, how is it secured, and what is your incident response history?

How a vendor responds is itself a signal. Prompt, complete answers point to mature governance. Watch the opposite pattern too. Vague replies, flat refusals or repeated delays are a flag in their own right.

Vendor Due Diligence Red Flags

Some findings should pause or stop an onboarding. Watch for these in particular.

  • Information that does not reconcile. Stated history or figures that clash with official registry records or audited accounts.
  • Reluctance to disclose. A vendor that dodges the questionnaire, refuses audits or withholds ownership detail may have something to hide.
  • Hidden or layered ownership. Nominee directors, shell layers or offshore structures that obscure who really controls the company.
  • Sanctions or adverse media hits. Any link to a sanctioned party, watchlisted individual, or credible reporting of fraud or corruption.
  • Past compliance violations. Prior breaches spanning data privacy, labor or financial-crime rules.
  • Financial distress. Mounting liabilities or going-concern doubts that threaten delivery.

No single flag is automatically fatal. But several together, or one serious enough on its own, is reason to escalate to enhanced due diligence before going further.

Enhanced Due Diligence for High-Risk Vendors

Enhanced due diligence (EDD) is the deeper review reserved for higher-risk third parties. Standard checks confirm who a vendor is. EDD goes further. Where does their money come from? Who ultimately controls them? What reputational baggage do they carry? Closer ongoing monitoring sits on top of all three.

You apply EDD when risk is elevated. Typical triggers include a vendor based in or operating through a FATF-listed high-risk jurisdiction, a beneficial owner who is a PEP, significant adverse media, complex or opaque ownership, or exposure to sanctioned regions. FATF refreshes its high-risk and increased-monitoring lists through the year, most recently in February and June 2026, so a vendor that was low-risk last quarter can move up.

In practice, an enhanced review adds several layers beyond the standard pass:

  • Source of funds and wealth. Establish how the entity and its owners generate and hold money.
  • Full UBO mapping. Trace ownership through every layer, including trusts and nominee arrangements, to the real individuals behind the entity.
  • Expanded adverse media. Search open and subscription sources, in local languages, often across a multi-year lookback.
  • Senior sign-off. Require management approval to take on or keep a high-risk vendor.
  • Tighter monitoring. Re-screen more frequently and review on any material change.

Triggered reviews matter as much as the schedule. A change of director or UBO, a new regulatory action, fresh adverse media, or a shift of operations into a monitored jurisdiction should all prompt an immediate EDD refresh rather than waiting for the next periodic cycle.

Financial Due Diligence Within VDD

Financial due diligence is the strand of vendor due diligence focused on solvency. It reviews audited financial statements, revenue and liability structure, cash position and credit standing, reading them together to catch the early signs of distress that a single document would hide. For a critical vendor, financial fragility is an operational risk: if they fail, your service or supply fails with them. That is why financing and financial due diligence sit alongside compliance checks, not apart from them.

Banking and Compliance Considerations

For regulated firms, vendor oversight is not optional housekeeping. It is a supervised obligation. In the EU, the Digital Operational Resilience Act (DORA) has applied across financial services since 17 January 2025, requiring firms to assess ICT third parties before contracting, monitor critical providers continuously, and keep a register of those arrangements. In November 2025, EU supervisors published the first list of 19 designated Critical ICT Third-Party Providers, signaling how seriously concentration risk in the supplier base is now treated. So banking and compliance teams need vendor due diligence that is repeatable, evidenced and audit-ready. A one-off questionnaire, filed and forgotten, will not clear that bar.

VDD vs CDD and KYC

These terms get mixed up. It helps to separate them. Vendor due diligence evaluates a supplier's suitability and risk as a business partner. Customer due diligence (CDD) and Know Your Customer (KYC) instead verify the identity of your customers and assess their activity to prevent money laundering. The methods rhyme, since both lean on identity verification, ownership mapping and screening. The subject differs: one points outward at who you buy from, the other at who you serve. EDD is the high-risk tier of either.

Vendor Due Diligence in M&A Transactions

There is a second, distinct use of the phrase. In mergers and acquisitions, vendor due diligence is a report the seller (the "vendor" of the business) commissions on itself before going to market, then shares with prospective buyers. It serves a different purpose from third-party VDD.

Done early, a sell-side VDD report surfaces issues on the seller's terms and supports a credible valuation. It also speeds negotiations, handing buyers a vetted view of the financials, legal standing and operations up front. Surprises later in the deal drop away. Trust between the parties builds, and both sides reach a fair, well-informed outcome. The discipline is the same, even though the party paying for it flips.

How KYC Hub Helps With Vendor Due Diligence

Manual work is the bottleneck. Running vendor due diligence across questionnaires, spreadsheets and email threads is where programs slow down, records drift out of date, and the gaps that auditors later find quietly open up. KYC Hub's Know Your Supplier (KYS) solution brings the work into one platform.

It is built around what compliance and procurement teams actually need from supplier risk:

  • Vet suppliers continuously, so a vendor cleared at onboarding keeps being checked as sanctions lists, ownership and risk signals change.
  • Catch concealed ownership by mapping beneficial owners and unpicking layered or nominee structures to find who really controls a supplier.
  • Block sanctions and adverse media risk through screening of entities and their owners against global watchlists and negative news.
  • Centralise supplier records, keeping every check, document and decision in one audit-ready place.

The payoff is twofold. That combination shortens onboarding. At the same time, it strengthens the kind of evidence trail supervisors now expect firms to produce on demand rather than reconstruct after the fact. To see it applied to your own supplier base, request a Know Your Supplier demo.

Conclusion

Vendor due diligence is how a business decides which third parties it can safely rely on. Get the process right. Scale it by risk, and repeat it over the life of the relationship. Do that, and you catch the financial, ownership, sanctions and security problems before they become yours. The work pays for itself the first time it stops a bad supplier at the door.

[ FREQUENTLY ASKED QUESTIONS ]

Any questions? We got you.

What is vendor due diligence?

Vendor due diligence is the structured assessment of a supplier or third party to measure the risk they could introduce to your business. It reviews financial health, legal and regulatory compliance, beneficial ownership, cybersecurity and operational resilience before and during the relationship.

What does VDD stand for?

VDD stands for Vendor Due Diligence. It is also called supplier due diligence or, more broadly, third-party due diligence.

What is the difference between vendor due diligence and customer due diligence?

Vendor due diligence evaluates a supplier's suitability and risk as a business partner, looking at finances, compliance and ownership. Customer due diligence verifies the identity of your customers and assesses their activity to prevent money laundering. One looks at who you buy from; the other at who you serve.

When should vendor due diligence be conducted?

Conduct it during vendor selection, before you sign a contract, so there is time to act on the findings. It should not end there. Re-screen and reassess vendors on a schedule, and run a triggered review whenever ownership, sanctions status or risk profile changes.

What is included in a vendor due diligence questionnaire?

A vendor due diligence questionnaire gathers information on financial performance, legal and regulatory compliance, ownership and governance, operational resilience, and data security. The vendor's responsiveness and completeness are themselves a signal of how well the business is governed.

When is enhanced due diligence required for a vendor?

Enhanced due diligence applies to higher-risk third parties. Common triggers are a vendor in a FATF-listed high-risk jurisdiction, a beneficial owner who is a politically exposed person, complex or hidden ownership, significant adverse media, or exposure to sanctioned regions.

What is the difference between standard and enhanced due diligence?

Standard due diligence confirms a vendor's identity and runs baseline screening. Enhanced due diligence adds source-of-funds checks, full beneficial ownership mapping, deeper adverse media searches, senior management sign-off and more frequent monitoring, and is reserved for high-risk vendors.

What are the red flags in vendor due diligence?

Key red flags include information that does not match official records, reluctance to share documents or allow audits, hidden or layered ownership, sanctions or adverse media hits, prior compliance violations, and signs of financial distress. One serious flag, or several together, should escalate the review.

How does KYC Hub help with vendor due diligence?

KYC Hub's Know Your Supplier solution runs vendor due diligence from one platform. It vets suppliers continuously, maps beneficial ownership to catch concealed control, screens against sanctions and adverse media, and centralises every record into an audit-ready trail.

[ KYC HUB ]

Automate KYC from onboarding to ongoing review

KYC Hub verifies identities, screens against global watchlists and monitors risk continuously — in one platform.

Explore the KYC solutionBook a demo
[ RELATED READING ]
KYB Verification in the UAE: Complete Guide to Process, Regulations & Compliance
[ KYB ]

KYB Verification in the UAE: Process, Regulations, and Compliance Guide

A practical guide to KYB verification in the UAE: the regulators, the documents, UBO identification, and the verification steps businesses follow to stay compliant.

Nov 2025 · 10 min read
Know Your Vendor: An Essential Guide for Vendor Risk Management
[ KYB ]

Know Your Vendor (KYV): Third-Party Due Diligence for Compliance Teams

Know Your Vendor (KYV) is the due diligence process compliance teams use to vet suppliers and third parties, verify beneficial ownership, screen for sanctions and adverse media, and monitor vendor risk over the life of the relationship.

Mar 2025 · 6 min read
How to Implement a Robust Know Your Supplier (KYS) Process?
[ KYB ]

Know Your Supplier (KYS): Supplier Due Diligence and Risk Guide

A practical guide to Know Your Supplier (KYS) for compliance and procurement teams: supplier due diligence, risk screening, how KYS relates to KYC and KYB, and continuous monitoring.

Jan 2025 · 6 min read