Supplier Due Diligence: Process, Checklist and Best Practices
Supplier due diligence helps organisations assess the capability, reliability, and compliance of suppliers before entering a commercial relationship - and ensure they continue to meet the required standards over time.
Supplier due diligence helps organisations assess the capability, reliability, and compliance of suppliers before entering a commercial relationship - and ensure they continue to meet the required standards over time.
Every supplier introduces some degree of risk.
A financially unstable supplier could fail without warning. Weak cybersecurity controls could expose sensitive information. Poor working practices could damage organisational reputation, while inadequate business continuity arrangements could disrupt the delivery of essential products or services.
Supplier due diligence helps organisations identify these risks, verify supplier information and make more informed sourcing decisions.
However, it should not be treated as a one-off onboarding exercise. Effective supplier due diligence continues throughout the relationship, helping organisations respond as suppliers, regulations and risk levels change.
What Is Supplier Due Diligence?
Supplier due diligence is the process of gathering, verifying and assessing information about a supplier before and during a commercial relationship.
It helps an organisation determine whether a supplier:
-
Has the capability and capacity to deliver
-
Is financially stable
-
Meets relevant legal and regulatory requirements
-
Has appropriate operational and security controls
-
Can maintain services during disruption
-
Meets required ethical and sustainability standards
-
Presents an acceptable level of risk
Supplier due diligence sits within the broader category of third-party due diligence. While third-party due diligence can cover contractors, consultants, agents, partners and other external organisations, supplier due diligence focuses specifically on businesses providing goods or services through a procurement relationship.
Why Is Supplier Due Diligence Important?
Modern organisations depend on suppliers for everything from essential components and professional services to critical technology and infrastructure.
As these relationships become more interconnected, a problem within one supplier can quickly affect the organisations it supports.
Effective supplier due diligence can help organisations:
-
Identify risks before contracts are awarded
-
Reduce the likelihood of operational disruption
-
Protect sensitive systems and information
-
Meet legal and regulatory responsibilities
-
Improve supply chain resilience
-
Protect organisational reputation
-
Make more consistent sourcing decisions
-
Build stronger supplier relationships
Due diligence cannot remove every risk. Its purpose is to give decision-makers reliable evidence about a supplier, allowing them to determine whether the risks are acceptable and what controls may be required.
When Should Supplier Due Diligence Be Carried Out?
Supplier due diligence should begin before a supplier is appointed or given access to organisational systems, sites, data or resources.
It should then continue at key points throughout the relationship, including:
-
During sourcing and supplier selection
-
Before onboarding or contracting
-
When the scope of a product or service changes
-
When access to systems or data increases
-
Before a contract is renewed or extended
-
Following a change in ownership
-
When new subcontractors are introduced
-
Following an incident or warning sign
-
When regulations or internal requirements change
-
As part of periodic supplier reviews
This ongoing approach helps ensure the information supporting the original approval remains accurate and that emerging risks are identified promptly.
Taking a Risk-Based Approach
A risk-based approach adjusts the scope and depth of due diligence according to the potential exposure created by each supplier.
Before deciding what information and evidence to request, organisations should understand the proposed relationship. Relevant factors may include:
-
The criticality of the product or service
-
Contract value and duration
-
Access to systems, sites or sensitive data
-
Regulatory significance
-
Geographic location
-
Reliance on subcontractors or fourth parties
-
Availability of alternative suppliers
-
The potential impact of disruption or failure
A supplier supporting critical operations or processing sensitive information will usually require a more detailed assessment than a low-value supplier providing a non-essential product.
This initial classification allows organisations to apply proportionate checks, reducing unnecessary administration while directing greater scrutiny towards suppliers that present the most significant risk.
What Should Supplier Due Diligence Cover?
A structured checklist helps organisations define the information to collect, the evidence to verify and the findings to record. It can also coordinate requirements across procurement, finance, legal, cybersecurity, operations and sustainability teams.
The checklist should guide assessment rather than become a fixed questionnaire applied identically to every supplier. Receiving a document or questionnaire response does not complete a check: the evidence must be reviewed, validated and used to support a decision.

Key areas to consider when conducting supplier due diligence. The checks required should be proportionate to the supplier’s risk and the nature of the relationship.
The Supplier Due Diligence Process
Although organisations will adapt the process to their own requirements, supplier due diligence typically follows eight core steps.
1. Understand the Relationship
Begin by establishing what the supplier will provide, how critical the product or service is, what information or systems it can access and what would happen if it failed.
This provides the context needed to determine the appropriate level of assessment.
2. Classify the Supplier’s Risk
Assess factors such as criticality, spend, data access, location, regulatory exposure, concentration risk and reliance on subcontractors.
The resulting risk classification should determine the scope and depth of the due diligence required.
3. Gather Relevant Information
Request the information and evidence needed to assess the identified risks. This may include questionnaires, policies, financial records, certifications, insurance documentation and continuity plans.
Requests should be relevant, proportionate and clearly explained. Conditional questions or tiered assessments can help tailor requirements to different supplier types.
4. Validate the Evidence
Check that the information received is complete, accurate, current and consistent. Important claims should be confirmed through supporting evidence or independent and authoritative sources where appropriate.
The level of verification should reflect the significance of the information. Evidence that materially affects the risk decision requires greater scrutiny than lower-impact information.
Any gaps, inconsistencies or unexplained responses should be investigated.
5. Assess the Risks
Consider the likelihood and potential impact of each identified risk, taking account of the supplier’s existing controls.
The findings should be compared with defined organisational requirements, risk thresholds and approval criteria. Where specialist knowledge is required, the relevant internal teams should contribute to the review.
6. Agree Remediation
Where gaps are identified, agree the actions needed to address them. Each action should have:
-
A clear description of the issue
-
A responsible owner
-
A target completion date
-
An evidence requirement
-
Any necessary interim controls
-
A defined escalation route
Some issues may need to be resolved before appointment. Others may be managed through contractual conditions, monitoring or time-bound improvement plans.
7. Make and Record the Decision
Possible outcomes may include approval, conditional approval, escalation, delayed approval or a decision not to proceed.
The organisation should document the findings, risk ratings, outstanding actions, approval conditions, decision and rationale. This creates a clear audit trail and helps demonstrate that the appropriate process was followed.
8. Monitor the Supplier
Due diligence should continue after onboarding. Monitoring may cover:
-
Financial health
-
Insurance and certification expiry dates
-
Supplier performance
-
Cybersecurity indicators
-
Incidents and data breaches
-
Regulatory developments
-
Sanctions and adverse media
-
Ownership or leadership changes
-
New subcontractors
-
Changes to services, locations or data access
-
Progress against remediation actions
-
Updated policies and supporting evidence
The frequency of review should reflect the supplier’s risk and criticality. Higher-risk suppliers may require frequent or continuous monitoring, while lower-risk suppliers may be reviewed periodically or following a significant event.
Best Practices for Effective Supplier Due Diligence
Keep Requirements Relevant and Proportionate
Every question and evidence request should support a defined risk assessment or decision.
Applying the same requirements to every supplier can create unnecessary work and may place an excessive burden on smaller businesses. The assessment should adapt to the supplier’s size, service, location and risk profile.
Use Clear and Consistent Language
Avoid overlapping questions, unexplained technical terms and wording that suppliers may interpret differently.
Clear instructions improve the quality of responses and reduce the need for follow-up requests.
Coordinate Internal Requirements
Different internal teams often need similar information from the same supplier. Bringing these requirements into one coordinated process reduces duplication and gives reviewers access to a shared evidence base.
Define Responsibilities
Make it clear who reviews each area, who can approve exceptions, who makes the final decision and who owns outstanding actions.
Clear accountability helps prevent delays and ensures significant risks reach the appropriate specialists.
Translate Findings Into Contractual Protections
Where appropriate, due diligence findings should be reflected in the contract through requirements covering matters such as service levels, information security, data protection, business continuity, insurance, incident notification, subcontractors, audit rights and remediation commitments.
This turns assessment findings into clear responsibilities and enforceable expectations.
Keep Information Current
Record document expiry dates, review dates and event-based triggers. A complete assessment becomes less useful if its supporting information is allowed to become outdated after onboarding.
Due diligence requirements should also be reviewed as regulations, organisational expectations and supplier risks evolve.
Common Supplier Due Diligence Challenges
Supplier due diligence can become difficult to manage when information is spread across teams, systems, questionnaires and spreadsheets.
Common challenges include:
-
Incomplete or inaccurate responses
-
Outdated supporting documents
-
Repeated requests from different teams
-
Inconsistent assessment criteria
-
Limited internal resources
-
Slow supplier onboarding
-
Poor visibility after approval
-
Difficulty monitoring large supplier populations
-
Unclear ownership of risks and actions
-
Disproportionate requirements for smaller suppliers
These challenges can leave teams spending more time chasing information than assessing risks and making decisions.
Standardised processes, coordinated information requests, clear responsibilities and proportionate assessments can make due diligence easier to manage and scale.
How Technology Supports Supplier Due Diligence
Technology can improve the efficiency and consistency of supplier due diligence by helping organisations:
-
Centralise supplier information
-
Standardise questionnaires and evidence requirements
-
Tailor assessments according to supplier risk
-
Track document and certification expiry dates
-
Identify missing or inconsistent responses
-
Create clearer audit trails
-
Share information across internal teams
-
Monitor changes throughout the relationship
-
Track remediation actions
Technology alone does not guarantee effective due diligence. Information must still be accurate, validated and interpreted by the right people.
The greatest value comes from combining appropriate technology with consistent standards, specialist review and effective supplier engagement.
How Shared Assurance Simplifies Supplier Due Diligence
In a traditional model, multiple buying organisations - and sometimes multiple teams within the same organisation - ask suppliers for similar information independently.
This creates duplication for buyers and suppliers while producing separate versions of information that must each be maintained and reviewed.
Shared assurance provides a more collaborative approach. Supplier information is collected, validated and maintained once before being made available to participating buying organisations.
This can help:
-
Reduce repeated questionnaires
-
Improve the quality and consistency of supplier information
-
Reduce administrative effort for buyers and suppliers
-
Support faster sourcing and onboarding
-
Give internal teams access to the same evidence
-
Keep information current throughout the relationship
Buying organisations retain responsibility for their own risk assessments, thresholds and decisions. Shared assurance provides a trusted and consistent evidence base from which to work.
Key Takeaway: Supplier Due Diligence Is an Ongoing Process
Supplier due diligence helps organisations understand whether suppliers are capable, reliable, compliant and resilient enough to support the business.
A structured checklist can improve consistency and reduce the likelihood of important risks being overlooked, but it should remain proportionate to the supplier and the relationship.
By applying risk-based requirements, validating evidence, involving the right teams, documenting decisions and monitoring change, organisations can make more confident sourcing decisions and build stronger, more resilient supply chains.
Curious to see how shared assurance could help?
Discover how Hellios collects, validates, and maintains supplier information once - reducing duplicated effort and giving your teams access to consistent, trusted data.
