Vendor due diligence is the evidence-gathering step before contracting a supplier. It tests whether a provider can actually deliver what it has claimed, covering financial stability, security posture, delivery capability, data handling, subcontractors and contractual obligations. The point is verification rather than reassurance.
What is vendor due diligence?
Vendor due diligence is the evidence-gathering step before contracting a supplier. It tests whether a provider can actually deliver what it has claimed, covering financial stability, security posture, delivery capability, data handling, subcontractors and contractual obligations. The point is verification rather than reassurance.
How is due diligence different from a security questionnaire?
A questionnaire collects a supplier statement about itself. Due diligence tests those statements against evidence such as certifications, audit reports, references, architecture documentation and demonstrations. A questionnaire is an input to due diligence, not a substitute for it.
This distinction matters because a completed questionnaire creates a paper record that can look like assurance while establishing very little.
A questionnaire collects assertions. Due diligence tests them against something external. In Australia the reference points are published: APRA CPS 234 requires regulated entities to assess the information security capability of parties that manage their information assets, APRA CPS 230 extends that to material service providers and the concentration risk they carry, and the ASD Essential Eight Maturity Model gives a maturity level a vendor can be asked to evidence rather than claim. Asking which maturity level a control has been independently assessed at, and by whom, separates due diligence from a completed form.
What should vendor due diligence cover?
At minimum: financial viability, security controls and certifications, where data is stored and processed, the use of subcontractors and fourth parties, delivery track record with comparable clients, support and escalation arrangements, and exit terms including data return and transition assistance.
Exit terms are the most commonly skipped item and the most expensive to fix afterwards, because your negotiating position disappears the moment the contract is signed.
What evidence should you ask a vendor for?
Independent audit reports such as SOC 2 or ISO 27001 certificates with their scope statements, penetration test summaries, named references at comparable organisations, documented incident history, subcontractor lists, and the actual contract terms rather than a summary of them.
Read the scope statement on any certificate. A certification covering a single product line says nothing about the service you are buying.
Sources
- Prudential Standard CPS 234 Information Security, APRA.
- Prudential Standard CPS 230 Operational Risk Management, APRA.
- Essential Eight Maturity Model, Australian Signals Directorate.
Where to read more
See guided vendor evaluations, what is third-party risk management, and APRA CPS 230 due diligence.
Also relevant: market analysis tools for procurement teams and SBOM evidence in vendor due diligence.



