Skip to content
  • Fundamentals
  • Checklist
  • Vendor vetting

How to vet a vendor: a ten-step vendor vetting checklist

Updated 9 min read

Vetting a vendor means finding out, before you depend on them, whether they are who they say they are, whether anyone has barred them, whether they will look after your data and your customers’ data, and whether you could leave if you had to. None of it is difficult. What goes wrong is skipping a step for the vendor that turns out to matter, or doing every step and keeping no record.

This guide is the vendor vetting process in ten steps, from the first conversation to the approval, sized for a business without a procurement or GRC department. Each step says what to check, how deep to go by risk tier, and the one record to keep. The same steps are in a free spreadsheet you can copy for every vendor.

The vendor vetting checklist at a glance

  • 1. Describe the service and the data the vendor will see
  • 2. Assign a risk tier and write down why
  • 3. Verify the legal entity and who owns it
  • 4. Screen for sanctions and adverse media
  • 5. Check financial stability (critical vendors)
  • 6. Assess information security
  • 7. Assess privacy and data protection
  • 8. Review the contract
  • 9. Verify the bank account before the first payment
  • 10. Record the decision and schedule the next review

Step 1: Describe what the vendor will do and see

Write one paragraph: what the vendor provides, which of your systems it connects to, what data it will hold or see (customer personal data, employee records, payment data, source code, nothing sensitive), and who internally asked for it. Every later decision is sized by this paragraph, and it is the first thing an auditor reads.

Record: the service description, data categories and internal owner.

Step 2: Assign a risk tier

Three questions place almost every vendor: how sensitive is the data they will access, how badly would their failure hurt you, and how hard would they be to replace? Most programmes use four tiers — critical, high, medium, low — and let the tier decide the depth of every step that follows. Vetting a stationery supplier like a cloud host wastes a week; vetting a cloud host like a stationery supplier is how breaches start. Vendor risk tiering: how to classify third parties and set a review cadence sets out criteria that hold up in an audit.

Record: the tier and the reasoning in a sentence.

Step 3: Verify the legal entity and its owners

Confirm the registered name, registration number and address in the company registry of the vendor’s country, and that the entity is active. Check that the entity on the contract is the one that will invoice you and process your data; it is often a subsidiary rather than the brand. For critical and high-tier vendors, identify the beneficial owners, because sanctions and conflicts of interest attach to people.

In the US that means the Secretary of State record for the state of formation, plus a Form W-9; US vendor onboarding: W-9, SAM.gov, OFAC, insurance and bank verification covers the US-specific checks. In the UK it is Companies House; elsewhere, the national business register and a VAT or tax number check.

Record: the registry extract, dated.

Step 4: Screen for sanctions and adverse media

Screen the entity and its owners against the sanctions lists that apply to you. For a US business that is at least the OFAC Specially Designated Nationals list; a UK business uses the UK Sanctions List; an EU business the EU consolidated list; and many businesses are bound by more than one, because obligations follow the payer and the currency as well as the vendor. A name match is a candidate, not a finding: record how you resolved it. Then search for adverse news — fraud, regulatory action, breaches, litigation.

Record: lists screened, result and date; how each match was resolved.

Step 5: Check financial stability where it matters

For a vendor whose failure would stop your business, look at filed accounts, a credit report or funding announcements, or ask a young company directly about runway. The purpose is not to refuse startups; it is to know whether you need an exit plan on day one. Ask critical vendors that hold your data for evidence of cyber and professional indemnity insurance as well.

Record: what you reviewed and your conclusion.

Step 6: Assess information security

Send a security questionnaire sized to the tier — a full one for critical and high, a short form for medium, nothing for low — and ask for independent evidence: a SOC 2 Type II report, an ISO 27001 certificate with its scope, a recent penetration test summary. Then read what comes back. The value of a SOC 2 report is in its scope, its period and its exceptions, not its cover page. Vendor risk assessment questionnaire: what to ask, and how to score the answers lists the questions that matter by tier and how to score the answers; SOC 2 vendor management: what auditors expect from your third-party programme explains what a SOC 2 report does and does not cover. If the vendor uses AI on your data, add the questions in AI vendor due diligence: a checklist for vendors that use AI on your data.

Record: the questionnaire, the evidence, a dated review note and the score.

Step 7: Assess privacy and data protection

If the vendor will process personal data on your behalf, map the data, sign a data processing agreement and check it against the law that applies. Under the GDPR and UK GDPR that is Article 28: you must choose processors that provide sufficient guarantees, and the contract must contain the eight terms in Article 28(3). GDPR Article 28 processor due diligence: vetting vendors that handle personal data walks through each clause. If personal data leaves the EEA or UK, settle the transfer mechanism. In US healthcare, a vendor handling protected health information needs a business associate agreement first; see HIPAA vendor risk assessment: vetting business associates under the Security Rule.

Record: the data map entry, the signed DPA with your clause check, and the transfer mechanism.

Step 8: Review the contract

Before signature you can still change the contract; afterwards every fix is a renegotiation. Check it against a minimum clause set for the tier: security obligations, confidentiality, breach notification within a fixed number of hours, notice of sub-processor changes, audit or assessment rights, service levels, and what happens at the end — data return, deletion, transition help. Watch the liability cap: one that excludes data breaches for a vendor holding your customer records leaves you carrying the most likely loss.

Record: the clause check, every gap, and how each was resolved.

Step 9: Verify the bank account

Payment redirection fraud — an email that looks like it comes from a real supplier, announcing new bank details — is among the most expensive mistakes a small business can make. Verify the account at onboarding with a bank letter, and confirm it by calling a number you already held, never one in the email. In the UK use Confirmation of Payee; in the euro area, Verification of Payee. On any later change request, block payment until the callback is redone.

Record: who called, when, on which number, and who confirmed.

Step 10: Record the decision and schedule the next review

End with one of three outcomes — approved, approved with conditions, or rejected — a sentence on why, and who decided. Each condition gets an owner and a due date. Hard stops (a sanctions match, a company that is not active, an unverified bank change) block even a conditional approval. Then add the vendor to your register with its tier and the date it is next due for review; that date is what turns one-off vetting into ongoing due diligence.

Record: the decision, approver and date; the register entry.

How deep to go, by tier

StepCritical / highMediumLow
Entity and ownersEntity and beneficial ownersEntityEntity
Sanctions and mediaBothBothSanctions
Financial stabilityYes (critical); if hard to replace (high)NoNo
SecurityFull questionnaire and independent evidenceShort formNone
PrivacyDPA, clause check, transfersIf personal dataIf personal data
ContractFull clause setCore clause setCore clause set
Bank verificationYesYesYes
Review cadence6–12 months18 months24 months

Vendor vetting software: when a spreadsheet stops being enough

A spreadsheet works for a handful of vendors. It stops working when you cannot remember which reviews are overdue, when questionnaires live in email threads, or when a customer or auditor asks you to show what you checked and when. VendorVett runs the same ten steps as a workflow: vendors complete the questionnaire through a secure link without creating an account, answers are scored the same way every time with the working shown, evidence and decisions land in a tamper-evident audit trail, and each vendor comes back for review on its tier’s schedule. A GDPR Article 28 questionnaire, US vendor onboarding (W-9, SAM.gov, OFAC) and ISO 9001 supplier evaluation are included on every plan; see pricing, including the free plan.

For the terms used on this page — fourth party, sub-processor, SCCs, bridge letter — see the vendor risk management glossary.

Where to go next

For the contract-stage detail of each check, owner by owner, read Vendor onboarding checklist: the checks to finish before the contract is signed. If you are building the programme these checks sit in, start with Third-party risk management for small businesses: a programme without a GRC team. For manufacturing and physical-goods suppliers measured on quality and delivery, see ISO 9001 supplier evaluation: meeting clause 8.4 with an approved supplier list.

Frequently asked questions

How do you vet a vendor?
Describe what the vendor will do and see, assign a risk tier, then verify the legal entity, screen it and its owners for sanctions and adverse media, check financial stability if the service is critical, assess security and privacy with a questionnaire and independent evidence, review the contract, verify the bank account, and record a written decision with a next review date. The tier decides how deep each step goes.
What is a vendor vetting checklist?
A list of the checks to complete before a vendor is approved, each with the evidence to keep: entity verification, sanctions screening, financial review, security questionnaire, independent assurance such as SOC 2 or ISO 27001, data protection agreement, contract terms, bank verification and the approval decision. VendorVett publishes a free Excel version with US and international sections.
What is the difference between vendor vetting and vendor due diligence?
In practice they are the same work. Vendor vetting usually means the checks done before approving a new vendor; vendor due diligence is the broader term and also covers repeating those checks on a schedule for the life of the relationship.
How long does it take to vet a vendor?
Under an hour for a low-risk vendor that sees no sensitive data: confirm the entity, screen it, check the contract and record the decision. Two to four weeks of elapsed time for a critical vendor, most of it waiting for the vendor to return a questionnaire and evidence. Start the security review when the vendor is shortlisted, not after procurement has finished.
Do I need vendor vetting software?
Not for a handful of vendors: a spreadsheet and a shared folder can work. Software earns its place when you have more vendors than you can remember the review dates for, when an auditor or customer asks you to prove what you checked and when, or when chasing questionnaires by email takes more time than reading them.