The Due Diligence Process: A Step-By-Step Guide
The due diligence process helps organisations gather and verify information, assess potential risks, and make informed decisions about suppliers, third parties, investments, and commercial relationships.
The due diligence process helps organisations gather and verify information, assess potential risks, and make informed decisions about suppliers, third parties, investments, and commercial relationships.
Although every organisation will adapt its approach, effective due diligence usually follows a consistent series of steps.
A structured process helps ensure the right information is collected, important risks are not overlooked, and decisions can be clearly explained and evidenced. It also creates a repeatable framework that can be applied proportionately across different suppliers and third parties.
Due diligence should not end once a relationship is approved. Information, circumstances, and risks can change, making ongoing monitoring an essential part of the process.
Step 1: Understand The Proposed Relationship
Before requesting information, the organisation needs to understand what the supplier or third party will do.
This provides the context needed to determine which risks are relevant and how detailed the assessment should be.
Questions may include:
-
What product or service will be provided?
-
How critical is it to the organisation?
-
What is the value and duration of the contract?
-
Will the third party access sensitive data or internal systems?
-
Will it operate from company premises?
-
Is the service regulated?
-
Will subcontractors or other fourth parties be involved?
-
Which countries or regions will support delivery?
-
What would happen if the supplier failed?
Without this context, organisations may request too little information from high-risk suppliers or impose unnecessary requirements on lower-risk relationships.
Step 2: Define The Scope Of The Assessment
Once the relationship is understood, the organisation can determine which types of due diligence are required.
Depending on the risk, the scope may include:
-
Financial due diligence
-
Legal and regulatory compliance
-
Operational capability
-
Cybersecurity and data protection
-
Business continuity
-
ESG and sustainability
-
Human rights and ethical practices
-
Reputational checks
-
Sanctions and anti-bribery screening
The assessment should be proportionate to the supplier’s risk and criticality.
A tiered approach can help organisations determine the appropriate level of scrutiny. Lower-risk suppliers may complete a shorter assessment, while critical or higher-risk suppliers may need to provide more detailed evidence and undergo enhanced checks.
The scope should also establish:
-
What information is required
-
Which teams need to contribute
-
Who owns the assessment
-
What standards or thresholds apply
-
When the assessment must be completed
-
What would require escalation
Setting these expectations at the beginning makes the process more consistent for internal teams and clearer for suppliers.
Step 3: Gather Information And Supporting Documentation
The next step is to collect the information needed to assess the relationship.
This may be gathered through:
-
Due diligence questionnaires
-
Supplier registration forms
-
Policies and procedures
-
Financial statements
-
Insurance certificates
-
Accreditations and certifications
-
Business continuity plans
-
Cybersecurity documentation
-
ESG and Modern Slavery policies
-
Contracts and legal records
-
Independent databases and screening services
The information requested should be directly relevant to the risks being assessed.
Asking every supplier to complete the same extensive questionnaire can create unnecessary work without improving the quality of the assessment. A risk-based process allows organisations to collect detailed evidence from higher-risk suppliers while applying lighter requirements to lower-risk relationships.
Clear instructions and consistent terminology can also reduce incomplete responses and repeated communication.
Step 4: Verify The Information Provided
Collecting information is not the same as completing due diligence.
The information must be checked to establish whether it is accurate, current, complete, and supported by appropriate evidence.
Verification may involve:
-
Checking company registration and ownership details
-
Confirming certifications with the issuing body
-
Reviewing the validity and scope of insurance documents
-
Comparing questionnaire answers with supporting policies
-
Screening for sanctions, enforcement action, or adverse media
-
Examining financial information and credit records
-
Checking document issue and expiry dates
-
Requesting clarification where responses are inconsistent
-
Conducting independent assessments or site visits
Verification helps identify missing information, outdated documents, unsupported claims, and discrepancies that may otherwise affect the final decision.
It also creates greater confidence that suppliers are being assessed against reliable evidence rather than self-declared information alone.
Step 5: Assess And Prioritise The Risks
Once the information has been verified, the organisation can assess the risks associated with the relationship.
This commonly involves considering:
-
The likelihood of a risk occurring
-
The potential impact on the organisation
-
The strength of the supplier’s existing controls
-
Whether the risk exceeds agreed thresholds
-
Whether additional controls could reduce the exposure
-
How the supplier compares with required standards
Risks may be rated using categories such as low, medium, or high, or scored through a more detailed methodology.
The assessment should consider both the supplier’s inherent risk and the controls it has in place.
For example, a cloud provider may create high inherent risk because it handles sensitive information. Strong security controls, recognised certifications, and tested incident response arrangements may reduce the remaining risk to an acceptable level.
A consistent assessment method helps organisations compare suppliers fairly and focus attention on the most significant concerns.
Step 6: Identify Gaps And Agree Remediation
Due diligence does not always produce a simple pass-or-fail result.
An assessment may identify gaps that need to be addressed before the relationship can proceed or within an agreed period after appointment.
Possible actions include:
-
Requesting missing or updated evidence
-
Asking the supplier to clarify inconsistent responses
-
Requiring improvements to policies or controls
-
Agreeing a formal remediation plan
-
Introducing additional contractual protections
-
Restricting access to systems or data
-
Increasing insurance requirements
-
Applying more frequent monitoring
-
Selecting an alternative supplier
Remediation actions should have clear owners, deadlines, and evidence requirements.
The organisation should also decide whether the issue must be resolved before approval or whether it can be accepted temporarily with appropriate controls and oversight.
This allows businesses to manage risk proportionately while helping capable suppliers improve where appropriate.
Step 7: Review The Findings And Make A Decision
Once the assessment and any immediate remediation are complete, the findings should be brought together for review.
The decision may be to:
-
Approve the relationship
-
Approve it subject to conditions
-
Escalate it for specialist or senior review
-
Delay approval until further action is completed
-
Reject the relationship
The appropriate decision-maker will depend on the nature and severity of the risks identified.
Procurement may coordinate the process, but specialist teams such as legal, compliance, finance, cybersecurity, TPRM, and sustainability may need to review risks within their areas of expertise.
The decision should take account of:
-
The overall risk profile
-
Any unresolved gaps
-
Agreed remediation actions
-
Contractual protections
-
The importance of the relationship
-
Available alternatives
-
The organisation’s risk appetite
Clear approval routes help prevent significant risks from being accepted informally or without the appropriate authority.
Step 8: Document The Decision
Due diligence decisions should be recorded clearly and consistently.
The record should show:
-
What information was reviewed
-
How the information was verified
-
Which risks were identified
-
How risks were rated
-
What remediation was agreed
-
Who approved the relationship
-
Why the decision was made
-
When the relationship should be reviewed
This creates an audit trail and demonstrates that the organisation followed an appropriate process.
Good documentation also makes future reviews more efficient because teams can understand the original decision without reconstructing it from emails, spreadsheets, and disconnected systems.
Step 9: Embed Requirements Into The Contract
Relevant findings should inform the terms of the commercial agreement.
Depending on the risks identified, contractual requirements may cover:
-
Information security and data protection
-
Service levels and performance measures
-
Regulatory compliance
-
Insurance
-
Business continuity and disaster recovery
-
Audit and information rights
-
Notification of incidents or material changes
-
Use of subcontractors
-
Remediation commitments
-
Termination rights
Embedding these requirements into the contract turns due diligence findings into clear and enforceable responsibilities.
The contract should also require suppliers to notify the organisation when significant information changes rather than waiting until the next scheduled review.
Step 10: Monitor Risks Throughout The Relationship
Approval is not the end of due diligence.
Financial conditions, ownership structures, cyber threats, regulations, certifications, and operational arrangements can all change after the relationship begins.
Ongoing monitoring may include:
-
Periodic supplier reviews
-
Financial and credit monitoring
-
Cybersecurity monitoring
-
Sanctions and adverse media screening
-
Tracking insurance and certification expiry dates
-
Reviewing performance and incidents
-
Monitoring agreed remediation
-
Updating questionnaires and documentation
-
Reassessing the supplier when the service changes
The frequency and depth of monitoring should reflect the risk and criticality of the relationship.
High-risk or business-critical suppliers may require frequent oversight, while lower-risk suppliers may be reviewed less often or when a specific change occurs.
Who Should Be Involved In The Process?
Due diligence often requires input from multiple business functions.
Responsibilities may include:
-
Procurement: Coordinates supplier engagement and commercial requirements
-
Third-party risk management: Defines the assessment framework and oversees risk
-
Finance: Reviews financial stability and credit risk
-
Legal and compliance: Assesses contractual and regulatory obligations
-
Cybersecurity: Reviews information security controls and technical risks
-
Data protection: Evaluates the handling of personal and sensitive information
-
Operations: Assesses capability, performance, and continuity
-
Sustainability: Reviews environmental, social, and ethical practices
Each function should apply its expertise while working from a consistent evidence base.
Clear ownership is important. Without it, suppliers may receive repeated requests from different teams while significant risks fall between organisational responsibilities.
Common Due Diligence Process Mistakes
Even well-established processes can become ineffective if they focus on administration rather than decision-making.
Common mistakes include:
-
Applying the same assessment to every supplier
-
Requesting information without explaining why it is needed
-
Collecting evidence without verifying it
-
Reviewing each risk area in isolation
-
Failing to track incomplete actions
-
Allowing unclear or inconsistent approval decisions
-
Storing evidence across disconnected systems
-
Treating approval as the end of the process
-
Failing to update assessments when circumstances change
A consistent, risk-based approach helps organisations reduce these weaknesses and direct resources towards the relationships that matter most.
Key Takeaway: Due Diligence Is A Continuous Process
The due diligence process begins by understanding the proposed relationship and defining the appropriate scope.
Organisations then gather and verify information, assess the risks, address any gaps, and make a documented decision. Relevant controls should be included in the contract, with the relationship monitored throughout its lifecycle.
Following a consistent, proportionate process helps businesses improve governance, reduce duplicated effort, and make more confident decisions about suppliers and third parties.
Does managing all this due diligence feel overwhelming?
Hellios can take a significant portion of the work off your plate. We collect, validate, and maintain supplier information on your behalf, giving your teams consistent, trusted data without the endless questionnaires, spreadsheets, and follow-ups.
