Skip to main content
Category: Assessment and Due Diligence

Due Diligence

Also known as: DD, Third-party due diligence, Vendor due diligence
Simply put

Due diligence is the process of investigating and verifying information about a person, company, or transaction before entering into a business relationship or agreement. In practical terms, it is the reasonable care an organization takes to understand who it is dealing with and what risks that relationship may carry before committing to it. It is a decision-support activity, not a guarantee that a relationship will be free of problems.

Formal definition

In a third-party risk context, due diligence is the structured investigation and evaluation of a prospective or existing third party, such as a supplier, service provider, or business partner, to assess relevant risks before or during a business relationship. It reflects the standard of care a reasonable business is normally expected to exercise before entering into an agreement, and typically involves collecting and verifying information across areas that may include legal, financial, operational, security, and reputational dimensions, though the scope varies by risk tier and program design. Due diligence is often concentrated at onboarding and is inherently point-in-time; unless paired with ongoing monitoring, its findings can become stale, and reliance on self-reported information without independent verification limits the assurance it provides. Depth of investigation is generally proportionate to the assessed inherent risk of the relationship rather than uniform across all third parties.

Why it matters

Due diligence is the point at which an organization decides, on the basis of evidence rather than assumption, whether and how to enter a relationship with a third party. Because it reflects the reasonable care a business is normally expected to exercise before committing to an agreement, it functions both as a risk-reduction activity and as a demonstrable record of that care. When performed well, it surfaces legal, financial, operational, security, and reputational concerns while they can still shape the decision, whether to proceed, to proceed with conditions, or to decline. It is decision support, however, not a guarantee: a completed due diligence process does not ensure a relationship will be free of problems.

The practical stakes come from due diligence's inherent limitations. It is typically concentrated at onboarding and is point-in-time by nature, so its findings describe a third party as it was at the moment of assessment, not as it evolves. A supplier's financial position, ownership, control environment, or geopolitical exposure can change materially after onboarding, and without ongoing monitoring the original findings become stale. Reliance on self-reported information without independent verification further constrains the assurance due diligence provides, an attestation that a control exists is not the same as independent confirmation that it operates effectively.

For these reasons, due diligence is best understood as the entry stage of a broader lifecycle rather than a standalone safeguard. Programs that treat a passed onboarding review as durable assurance risk carrying unexamined exposure for the life of the relationship. Depth proportionate to inherent risk, verification where the stakes warrant it, and pairing with continued monitoring are what allow due diligence to remain meaningful over time.

Who it's relevant to

Procurement and Sourcing Teams
Procurement professionals rely on due diligence to inform supplier selection and contracting decisions before commitments are made. Scaling investigation depth to the inherent risk of each relationship helps them allocate effort where it matters most and avoid treating a completed onboarding review as permanent assurance.
Third-Party Risk and Vendor Management Functions
These teams own the design of due diligence within the broader risk lifecycle. Their central concern is ensuring that point-in-time onboarding findings are verified where warranted and paired with ongoing monitoring, since self-reported information without independent confirmation and stale findings both limit the assurance the process provides.
Compliance and Legal Teams
Compliance and legal stakeholders view due diligence as evidence of the reasonable care a business is expected to exercise before entering an agreement, and as a documented basis for risk decisions. They also track how expectations for scope and rigor can differ across regions and sectors rather than following a single global standard.
Security and Operational Risk Assessors
Security and operational reviewers use due diligence to examine a prospective party's control environment before a relationship begins. They are attentive to the distinction between an attestation that a control exists and independent verification that it operates, and to the fact that a security review at onboarding does not by itself address financial, geopolitical, or later-emerging exposure.

Inside DD

Entity and ownership verification
Confirmation of the counterparty's legal identity, corporate structure, beneficial ownership, and control relationships. This establishes who the organization is actually contracting with, but by itself does not assess operational, financial, or security posture.
Financial and viability review
Examination of financial statements, credit ratings, or other indicators of solvency and going-concern viability. This addresses financial risk specifically and does not substitute for assessments of information security, operational resilience, or compliance.
Compliance and regulatory screening
Checks against sanctions lists, watchlists, anti-bribery and corruption exposure, and applicable regulatory obligations. The specific screening required typically varies by jurisdiction and sector rather than following a single global standard.
Security and control assessment
Evaluation of the third party's information security, privacy, and control environment, often supported by questionnaires (such as SIG-style questionnaires) or reports like a SOC 2. A questionnaire captures self-reported information and, unless independently validated, is an attestation rather than verification, and a SOC 2 report is an audit report rather than a certification.
Risk tiering and scoping
Classification of the counterparty by criticality and inherent risk to determine the depth of diligence applied. Higher-risk tiers typically warrant deeper investigation, while lower tiers may receive a lighter review.
Onboarding versus ongoing coverage
The distinction between diligence performed before contracting or engagement and diligence sustained over the relationship. Point-in-time diligence establishes a baseline but does not, on its own, provide continuous assurance.

Common questions

Answers to the questions practitioners most commonly ask about DD.

Is due diligence the same as ongoing monitoring?
No. Due diligence typically refers to the investigation and assessment conducted before or at the point of engaging a third party (onboarding), whereas ongoing monitoring is the continuous or periodic reassessment of a relationship throughout its lifecycle. A common weakness is treating due diligence as a one-time gate; because it is often point-in-time, its findings can become stale as the third party's financial condition, ownership, controls, or risk exposure change. Many programs pair onboarding due diligence with a separate ongoing monitoring process precisely because the former does not, on its own, capture changes after engagement.
Does receiving a completed questionnaire or attestation from a supplier mean their controls have been verified?
Not necessarily. A completed assessment questionnaire and a supplier attestation are typically self-reported representations, not independent verification. Due diligence that relies solely on self-attestation confirms what the third party claims, not what an independent party has tested. Depending on the risk tier, programs may seek independent evidence, such as third-party audit reports or other external validation, to corroborate self-reported responses. Distinguishing an attestation from independent verification is important because the two provide different levels of assurance.
How should the depth of due diligence be matched to a given third party?
In many programs, due diligence depth is calibrated to the third party's risk tier, which reflects factors such as the criticality of the service, the sensitivity of data accessed, spend, and potential operational or regulatory impact. Lower-risk relationships may warrant streamlined review, while higher-risk or critical relationships typically justify more extensive investigation and independent evidence. Applying uniform depth across all third parties can either over-burden low-risk relationships or under-scrutinize critical ones.
What risk domains should due diligence cover beyond information security?
Due diligence scope should be defined explicitly, because a review focused only on information security may not address financial, operational, geopolitical, ESG, legal, or reputational risk. Depending on the nature of the relationship and applicable regulatory expectations, a program may need to extend due diligence across several of these domains. Stating what a given due diligence effort covers, and what it does not, helps avoid the assumption that one assessment addresses the full range of relevant risks.
Can due diligence provide visibility into a supplier's own subcontractors?
Direct due diligence generally centers on the organization's contractual counterparty and often has limited visibility beyond that first tier. Fourth-party or Nth-party risk, arising from the third party's own suppliers, is typically not fully captured by standard due diligence on the direct third party. Programs concerned with these dependencies may need to obtain information about downstream relationships through the contract, request subcontractor disclosures, or extend assessment approaches, while recognizing that visibility tends to diminish with each tier.
When should due diligence be repeated after onboarding?
Because due diligence is often point-in-time, many programs establish triggers for repeating or refreshing it rather than relying only on the initial review. Common triggers include periodic reassessment cycles set by risk tier, contract renewal, material changes such as ownership or leadership changes, significant incidents, or shifts in the services provided or data accessed. The appropriate cadence and triggers vary by program, sector, and jurisdiction, and refreshed due diligence complements rather than replaces ongoing monitoring.

Common misconceptions

Completing due diligence at onboarding means the third party has been fully vetted for the life of the relationship.
Due diligence is typically a point-in-time exercise, and its findings can become stale as the counterparty's ownership, financial condition, security posture, or regulatory status changes. Sustained assurance depends on ongoing monitoring, which is a distinct activity from onboarding diligence.
A completed questionnaire, attestation, or SOC 2 report demonstrates that a third party's controls have been independently verified and are compliant.
Self-reported questionnaires and attestations reflect what the counterparty states rather than independently confirmed fact, and a SOC 2 is an audit report rather than a certification or compliance guarantee. Independent validation is a separate step from receiving these documents.
Due diligence on a direct third party provides visibility into the risks posed by that party's own subcontractors and suppliers.
Diligence typically centers on the direct contractual counterparty and offers limited visibility beyond the first tier. Fourth-party and Nth-party exposure generally requires additional scoping and cannot be assumed covered by direct third-party diligence alone.

Best practices

Calibrate the depth of due diligence to the counterparty's risk tier and criticality, applying deeper investigation to higher-risk relationships rather than a uniform level of effort across all parties.
Treat questionnaires and attestations as self-reported inputs and, for higher-risk tiers, corroborate them with independent evidence such as audit reports, testing, or documentation review rather than accepting them at face value.
Scope diligence to cover the specific risk domains relevant to the engagement, and document explicitly which domains (for example financial, security, compliance, operational, geopolitical, or ESG) were and were not assessed.
Pair onboarding diligence with a defined ongoing monitoring cadence so that findings are refreshed as the counterparty's circumstances change, recognizing that point-in-time results become stale.
Extend scoping to consider fourth-party and Nth-party dependencies where they are material, rather than assuming direct third-party diligence covers subcontractors and downstream suppliers.
Align screening and compliance checks with the jurisdictions and sectors in which the relationship operates, rather than applying a single regime as though it were globally applicable.
Promotional banner for the Penetration Report Template Kit