Research methods
Vendor due diligence: questions to ask and a reference-call checklist
How to vet a vendor before you sign: sizing the review to risk, due diligence questions drawn from U.S. regulators' guidance, and a reference-call checklist.
Vendor due diligence is the checking you do before you sign with a supplier or service provider: can it do the work, will it still be around, how does it protect your data, and what happens when something goes wrong? The depth should match what the vendor will touch. A new office-snacks supplier needs a phone call. A system that will run your warehouse or hold your customers' data needs documents, a security review and reference calls with customers you picked yourself.
A detailed public list of vendor due diligence questions comes from U.S. banking regulators. Their 2023 interagency guidance on third-party relationships is written for banks, but its checklist works for any business choosing a critical vendor. Interagency Guidance on Third-Party Relationships This page turns that list into plain questions and adds a reference-call checklist.
A worked example: choosing a warehouse management system
Suppose a regional food distributor with three warehouses is choosing a new warehouse management system. The company and vendors are hypothetical. Two vendors are left. Both demo well, both send three happy references, and both say they are "enterprise-grade." The system will run picking, receiving and inventory every day, so an outage would stop shipments. That makes it a high-risk vendor, and it deserves the full review below.
Size the review to the risk
The guidance says the scope and depth of due diligence should match the risk and complexity of the relationship, with more thorough work for critical activities. It also says relying only on past experience with a vendor is not a substitute for diligence. Interagency guidance
A simple way to apply that is three tiers:
| Tier | Example | Review |
|---|---|---|
| Low | Office supplies, one-off design work | Basic checks and a contract |
| Medium | A marketing tool with limited customer data | Questions below, security summary, one reference call |
| High | Systems that run operations or hold sensitive data | Everything below, including reference calls you source yourself |
Vendor due diligence questions
These follow the factors in the interagency guidance, rewritten as questions.
Strategy and stability
- Is the vendor planning a merger, acquisition or major change to its business model that could affect this product?
- How is it doing financially? Ask for audited financial statements, or, for a public company, read its SEC filings. The guidance also mentions pending litigation and unfunded liabilities as things to consider.
Legal and compliance
- Who owns the company, and does it hold the licenses the work requires?
- Is the vendor or any owner on a sanctions list? OFAC's Sanctions List Service includes a free search tool.
- Has it had regulatory actions or violations, and how did it respond?
Experience and people
- How long has it done this exact work, for customers like you?
- How has it handled complaints and lawsuits?
- Who are the key people on your account, and what happens if they leave?
- Does it run background checks on staff who can reach your systems or data?
Controls and security
- Is the vendor audited independently? If it has a SOC report, get the full report. SOC 2 reports, issued by CPAs, cover controls relevant to security, availability, processing integrity, confidentiality or privacy. AICPA SOC suite The guidance says to check whether the report's scope and results are relevant to the work you are hiring the vendor for.
- How does it protect your data: multi-factor authentication, encryption, and control over who can see what?
- What did its last penetration test find, and what did it fix?
Resilience and incidents
- What are its disaster recovery and business continuity plans, and how long will it take to resume service and recover data?
- How did it perform during its last real outage?
- How quickly will it tell you about an incident, and who will it tell?
Subcontractors, insurance and other commitments
- Which parts of the service are subcontracted, to whom and where?
- What insurance does it carry, such as cyber and liability coverage?
- Do its agreements with other parties create risks for you?
If the vendor will not answer something, the guidance says to write down the gap, understand the risk it leaves and consider alternatives, such as other evidence, extra monitoring or a different vendor. Interagency guidance
A reference-call checklist
References the vendor gives you are its happiest customers. They are still worth a call, but add at least one or two you find yourself: a customer of similar size, one that has been live for more than a year and, if you can find one, a former customer.
Before the call
- Confirm what the person's company uses the product for and for how long.
- Pick the two or three claims you most need tested, for example "go-live in 12 weeks."
On the call
- How long did implementation take compared with the plan, and what caused the difference?
- What did you have to change in your own process to make it work?
- How has support responded to a serious problem? Walk me through the last one.
- What surprised you after signing, including costs?
- Has the vendor's account team changed, and did service change with it?
- If you were choosing again, would you pick the same vendor? What would you negotiate differently?
- Who else should I talk to?
Limits
Do not ask a reference for the terms of their contract or anything else they are bound to keep confidential. Ask how the price or renewal went for them in general terms instead. What to do when an expert cannot share confidential information covers how to handle a refusal.
After the call
Write down what each reference said about each claim, and note who introduced them. When references disagree, what to do when two experts disagree helps you decide what to check next.
Your next step
Put your vendor in a tier. For a high-risk vendor, send the questions above in writing, request the SOC report and financials, and book at least one reference call with a customer the vendor did not pick.
To find that customer, Instant Expert finds people who match a description, such as "warehouse operations managers at food distributors who use a cloud warehouse management system." You review who it finds, it sends your invitations, and you pay only for calls that get booked. The directory pages for operations professionals in food distribution and IT professionals in food distribution are a place to start. If the vendor review is part of buying a company, see the due diligence checklist.