Blog
Top tips on how to do supplier due diligence
Read this to discover what is supplier due diligence, what business need to know about it, and top tips for getting the best outcomes.


Supplier due diligence is the process of gathering information to understand the credibility and suitability of a prospective partner or vendor. It aims to assess their security posture to identify any potential risks.
Performing checks is a standard approach to nearly all facets in life, e.g. family, work, education et al, so supplier due diligence should not be foreign concept. Conducting supplier due diligence can help guide decision-making when choosing the right vendor, detect risks with potential suppliers and protect customer data in the process. It's also considered good business practice and can help mitigate future financial and reputational damage caused by a data breach.
We live in a world where your business security could be theoretically perfect, and yet your data is still exposed. How? Through a supplier. Interconnected services and data sharing means that their risks are your risks, and vice versa.
The risks of not conducting supplier due diligence are significant. If a third-party vendor is breached, your organisation could be exposed to a number of risks, including:
The loss of sensitive data
Financial losses
Damage to your reputation
Regulatory fines
Every business must surely have noticed the increasing importance being placed on supply chain security. The extra time spent filling in supplier due diligence questionnaires can’t have gone unnoticed, and it’s a key driver behind the increased ISO 27001 adoption. Though it might mean you spend more time on these activities, the reasons behind them are good: it means everyone’s assessing the risks and, I’d hope, taking steps to address them. In short, the whole supply chain is levelling up together.
MOVEit, a popular file transfer software, was exploited by hackers which impacted the security of hundreds of companies world-wide, exposing the data of hundreds of thousands of people. Hackers exploited a zero-day SQL exploit, and the severity of data the cyber criminals potentially have access to is notable: bank details, identification data and contact information, among much more.
The attacks follow a pattern of targeting key services within an organisation’s supply chain. For example, British Airways weren’t themselves attacked, but their customer data was still leaked thanks to a provider of theirs using MOVEit.
It’s essential that the risks posed by your partners and providers is identified, codified, managed and mitigated. Be proactive and positive, but also make sure you get the assurance you need: ask to see evidence of recent penetration tests from a reputable pen test provider, and likewise for ISO 27001. If you identify a supplier as being high-risk, then don’t be afraid to insist on your own audits. Your partner will understand – afterall, they might make the same requests of you!
Many organisations can easily fall into the trap of neglecting the data protection side of the procurement process due to a lack of due diligence. Whilst ‘cyber security’ takes more of the headlines, data protection has its own regulations and requirements that cannot be ignored. Article 28 of the GDPR states that a data controller must only use a data processor that can provide “sufficient guarantees” (particularly in terms of its expertise, resources and reliability) to comply with the UK GDPR and protect the rights of individuals.
Onboarding vendors to process your customers' or employees' data is implicitly stating that you trust them to process your personal data. This must be agreed upon by both parties by signing a Data Processing Agreement (DPA), which we talked more about in this blog.
It's recommended and best practice for supplier due diligence to be an ongoing process with data controllers reviewing a processor's compliance on a continual basis. Effective and regular due diligence can help safeguard a company from risks to its functionality, reputation, and finances.

Having a clear understanding of the vendor's business operations and how they interact with your organisation will help you to identify the specific risks that they pose. For example, if a vendor is providing cloud computing services, you will need to understand how they store and protect your data – asking for evidence of regular penetration testing and log monitoring or SIEM would be appropriate here. If they’ll process personal data, then asking about their GDPR policies and procedures, DPIAs and DPAs is relevant. And if these acronyms are a mystery to you, no need to worry – just reach out to a data protection officer for a helping hand.
This information can be gathered through a variety of sources, including:
The vendor's website
Publicly available records
Interviews with the vendor's management team
Security assessments
The need to assess the vendor's compliance with industry regulations and best practices is important because this will help you to ensure that they are taking the necessary steps to protect your data. For example, if a vendor is required to comply with the Payment Card Industry Data Security Standard (PCI DSS), you will need to verify that they are in compliance.
The importance of having a strong contract in place that outlines the vendor's security obligations is that this will give you legal recourse if they fail to meet their obligations. For example, your contract should specify the vendor's responsibility for data breaches and the steps they will take to notify you if a breach occurs.
Even after you have conducted due diligence on a third-party vendor, it is important to continue to monitor their security posture on an ongoing basis. This is because the security landscape is constantly changing, and a vendor that was considered to be secure today could be breached tomorrow.
Supplier due diligence is an essential process when seeking new vendors as it allows organisations to make an informed decision on whether to proceed with a business partnership and should form part of business compliance strategies Only by identifying and mitigating the risks posed by third-party vendors can you prevent a data breach.
Share your challenge with us and we’ll help you find the right level of support for your business.














