- Checklist
- Onboarding
Vendor onboarding checklist: the checks to finish before the contract is signed
Updated 7 min read
The moment a contract is signed, the questions get harder to ask. Before it, a vendor will send you their SOC 2 report, correct the sub-processor clause, and agree to a breach-notification window; afterwards, each of those is a renegotiation. Vendor onboarding is the set of checks done while you still have leverage, and the records that show they were done.
This checklist has twelve checks in five groups, each with the person who naturally owns it and the single record to keep. Run all twelve for a critical vendor; for lower tiers, the table at the end says which to skip.
Business checks — owned by finance or procurement
1. Verify the legal entity
Confirm the registered name, company number, registered address and the entity you are actually contracting with — often a subsidiary rather than the brand. Check that the entity on the contract is the one that will process your data and invoice you.
Record: registry extract or equivalent, with date checked.
2. Screen for sanctions and adverse media
Screen the entity and its beneficial owners against sanctions lists and for adverse news — fraud, regulatory action, major breaches. This is a legal obligation in some sectors and a sensible one in all of them; paying a sanctioned party is an offence regardless of intent.
Record: screening result, source and date; any hits and how they were resolved.
3. Assess financial stability where the service is critical
For a vendor whose failure would stop your business, check that they will be around: filed accounts, funding announcements, credit reports, or for early-stage companies a frank conversation about runway. The purpose is to plan an exit, not to refuse startups.
Record: what was reviewed and the conclusion; exit plan if the risk is material.
Legal checks — owned by whoever signs contracts
4. Review the contract against your minimum clause set
Every tier has a minimum set of terms; for a critical vendor it includes security obligations proportionate to the data, confidentiality, breach notification within a fixed number of hours, sub-processor notice and objection rights, audit or assessment rights, service levels, and obligations on termination — return, deletion, transition assistance. Check the vendor’s paper against the set and log every gap.
Record: the clause check with gaps and their resolution — an addendum, an accepted risk with approver, or a compensating control.
5. Confirm liability and insurance are proportionate
Liability caps set at one year’s fees are normal; a cap that excludes data breach entirely for a vendor holding your customer records is not. Ask for evidence of cyber and professional indemnity insurance for critical vendors.
Record: liability position and insurance certificate, with expiry.
Security checks — owned by security or compliance
6. Tier the vendor and run the assessment for that tier
Assign a tier from data access, criticality and substitutability (the criteria are here), then run the assessment the tier requires: a full questionnaire with evidence for critical and high, a short form for medium, a contract check for low. Vendor risk assessment questionnaire: what to ask, and how to score the answers covers the questions and the scoring.
Record: tier and reasoning; questionnaire, score and decision with approver and date.
7. Review the independent evidence
Obtain and read the SOC 2 Type II report, ISO 27001 certificate and statement of applicability, and most recent penetration test summary as applicable. Note the scope, period, exceptions, and any controls the report expects you to operate.
Record: a dated review note per document, with the conclusion.
8. Design the access before granting it
Decide what the vendor will access, through which accounts, with what privileges, and how those accounts are reviewed and removed. Vendor accounts belong in your access review population from the first day. If the vendor needs an integration, record the scopes granted.
Record: access design; accounts created and their owner; integration scopes.
Privacy checks — owned by the data protection lead
9. Map the personal data and the flow
Which categories of personal data, whose, for what purpose, stored where, kept how long, deleted how. If special-category data or large volumes are involved, decide whether a data protection impact assessment is needed before the processing starts.
Record: data map entry; DPIA decision; update to the Article 30 record.
10. Sign a compliant DPA and settle transfers
Check the data processing agreement against the Article 28(3) terms, confirm the sub-processor list and notice mechanism, and establish the transfer mechanism for any party outside the EEA or UK. The GDPR guide lists the clauses and the transfer options.
Record: signed DPA; clause check; sub-processor list as at signature; transfer mechanism and impact assessment where required.
Continuity checks — owned by the service owner
11. Agree service levels and support
Availability commitment, support hours and response times, maintenance windows, and what happens when the SLA is missed. For critical services, ask for the vendor’s recovery objectives and when they were last tested.
Record: SLA terms; RTO/RPO and last test date.
12. Plan the exit on the way in
How you get your data out, in what format, within what period; how deletion is confirmed; what transition assistance is provided; and, for a critical service, what you would switch to. An exit plan written at onboarding takes an hour; one written during a dispute takes a month.
Record: exit note — export method and format, deletion confirmation, alternative provider if critical.
Which checks apply, by tier
| Check | Critical | High | Medium | Low |
|---|---|---|---|---|
| 1. Legal entity | Yes | Yes | Yes | Yes |
| 2. Sanctions and adverse media | Yes | Yes | Yes | Yes |
| 3. Financial stability | Yes | If hard to replace | No | No |
| 4. Contract clause check | Full set | Full set | Core set | Core set |
| 5. Liability and insurance | Yes | Yes | Liability only | No |
| 6. Tier and assessment | Full questionnaire | Full questionnaire | Short form | Tier only |
| 7. Independent evidence | Required | Required | If available | No |
| 8. Access design | Yes | Yes | If access granted | If access granted |
| 9. Data map and DPIA decision | Yes | Yes | If personal data | If personal data |
| 10. DPA and transfers | Yes | Yes | If personal data | If personal data |
| 11. SLAs | Yes | Yes | Standard terms | No |
| 12. Exit plan | Yes | Yes | Export method only | No |
Where to go next
Onboarding is the first pass of the process described in Vendor due diligence: a practical guide for small and mid-sized businesses; the reassessment cycle that follows it is set by Vendor risk tiering: how to classify third parties and set a review cadence. For the whole programme these checks sit inside, read Third-party risk management for small businesses: a programme without a GRC team.
Frequently asked questions
- What should a vendor onboarding checklist include?
- Checks in five groups: business (identity, ownership, financial stability, sanctions), legal (contract terms, liability, insurance), security (assessment, evidence, access design), privacy (data mapping, DPA, transfers) and continuity (SLAs, exit and data return). Each check produces one record for the vendor's file.
- Who owns vendor onboarding in a small company?
- Typically the person who owns compliance or security coordinates it, but each check has a natural owner: finance for identity and financial checks, whoever signs contracts for the legal group, security for the assessment and access, the data protection lead for privacy. The checklist names the owner so nothing waits on the coordinator.
- Should vendor onboarding happen before or after the contract is signed?
- Before. Once the contract is signed and data is flowing, the leverage to fix a gap is gone. If commercial pressure forces signature first, record the outstanding checks as conditions with dates and a named approver who accepted the risk of proceeding.
- How long does vendor onboarding take?
- For a low-risk vendor, an hour: identity, contract check, register entry. For a critical vendor, two to four weeks of elapsed time, most of it waiting for the vendor to return a questionnaire and evidence. Start the security checks as soon as the vendor is shortlisted, not when procurement is finished.
Related guides
- Fundamentals
- Checklist
Vendor due diligence: a practical guide for small and mid-sized businesses
The end-to-end process — scoping, questionnaires, evidence, scoring, review cadence — sized for a team of one.
9 min read
- Questionnaires
- Scoring
Vendor risk assessment questionnaire: what to ask, and how to score the answers
The questions that matter by risk tier, mapped to the controls auditors recognise, with a scoring method you can explain.
8 min read
- Programme design
- SMB
Third-party risk management for small businesses: a programme without a GRC team
Enterprise TPRM assumes a department. This is the version for a company with none — and what it still must not skip.
7 min read