Checklists

Vendor Due Diligence Checklist Template

Updated Jun 2026
DOCX, PDF
Free — no email required
Operations
Overview

Free vendor due diligence checklist covering legal, financial, security, operational, and compliance verification. 80+ checklist items for pre-contract vendor assessment. DOCX and Excel.

Definition

A vendor due diligence checklist is a pre-contract verification framework used to assess a vendor’s legal standing, financial stability, security posture, operational capability, and compliance status before entering into a formal agreement. Due diligence reduces the risk of engaging a vendor that cannot deliver or poses unacceptable risk.

What’s Included in This Template

Skipping vendor due diligence is one of the most common — and costly — procurement mistakes. This checklist provides a comprehensive, 80+ item framework for verifying every critical dimension of a vendor relationship before any contract is signed.

Section Type
Legal & Corporate Verification — Business registration, ownership structure, litigation history Checklist
Financial Due Diligence — Financial statements, credit checks, insurance verification Checklist
Cybersecurity Assessment — Security certifications, pen test results, incident history Checklist
Operational Capability — Capacity verification, key person risk, subcontractor use Checklist
Regulatory Compliance — Industry-specific certifications, regulatory history, audits Checklist
ESG & Ethics — Environmental policy, labor practices, anti-bribery compliance Checklist
Supply Chain Transparency — Subcontractor disclosure, conflict minerals, geographic risk Checklist
Reference Verification — Customer reference calls, online reputation, case studies Checklist

5 Steps to Use This Template

  1. Apply due diligence proportionally to vendor risk tier — Full 8-domain due diligence is appropriate for Tier-1 critical vendors. Tier-2 vendors may require 5 domains. Low-risk, low-spend vendors may need only legal and financial verification.
  2. Request documents before the due diligence call — Send a document request list at least 5 business days before your due diligence review meeting. Vendors who cannot provide standard documentation are a risk signal.
  3. Conduct independent verification — don’t just rely on vendor-supplied materials — Verify business registration independently through official registries. Run financial checks through Dun & Bradstreet or equivalent. Don’t rely solely on vendor-provided documents.
  4. Document every finding, positive and negative — Due diligence is only defensible if documented. Record what was checked, what evidence was reviewed, any concerns raised, and the final risk assessment for each domain.
  5. Obtain sign-off from legal, IT, and finance before contract award — Due diligence findings should be formally reviewed by legal, IT security, and finance before a contract is awarded. Any open concerns should be resolved or accepted as residual risk.

Frequently Asked Questions

What is vendor due diligence?

Vendor due diligence is the process of verifying a vendor’s legal standing, financial health, security posture, operational capabilities, and compliance status before entering into a contract. It reduces the risk of engaging a vendor that cannot perform or poses unacceptable risk.

What is the difference between vendor due diligence and vendor onboarding?

Due diligence is a pre-contract activity focused on risk assessment before deciding to engage a vendor. Onboarding happens after contract execution and focuses on setting up the operational relationship.

How long does vendor due diligence take?

For a Tier-1 vendor, thorough due diligence typically takes 2–4 weeks. For standard vendors, a focused 1-week process covering key domains is usually sufficient.

What financial documents should I request during vendor due diligence?

Request: 2 years of audited financial statements, most recent management accounts, proof of business insurance (general liability, E&O, cyber), and a D&B or equivalent credit report.

Is ESG due diligence required?

ESG due diligence is increasingly required for large-enterprise supply chains under emerging regulations (EU Corporate Sustainability Due Diligence Directive, UK Modern Slavery Act). Even where not legally required, it is considered best practice for Tier-1 vendors.

Details

What's Included

Format DOCX, PDF
Sections 8 domains sections
Last updated March 2026
Tags Due Diligence, Risk, Compliance, Pre-Contract

Evaluating CLM platforms to manage these contracts?

Compare vendor contract management platforms on our neutral marketplace — no paid rankings, no sponsored listings.

Gift this article