Home › Cybersecurity & GRC Career Guides › Vendor Due Diligence Skills
Vendor Due Diligence Skills

Due diligence is the assessment you perform before signing. It is one stage of the wider third-party risk lifecycle, and confusing the two is why so many programs assess a vendor thoroughly at onboarding and then never look again.
This page is about the pre-signature work. For tiering, ongoing monitoring, concentration risk and exit planning, see the third-party risk material.
Diligence is bounded by leverage
Everything you can obtain, you obtain now. Before signature the vendor wants the deal, so the questions get answered, the report gets shared and the clause gets accepted. After signature you are asking for favors from a counterparty with no commercial reason to help.
That single fact should drive the sequencing. Deal teams routinely bring assessors in after the terms are agreed, which is the moment the assessment stops being able to change anything. Pushing to be involved earlier is a large part of doing this job well.
Proportionality, or the queue eats you
The same assessment cannot be right for a payroll processor holding bank details and for an office supplier. Scope the diligence to what the vendor can actually cost you, and be willing to say that a low-impact supplier needs a short form and nothing more.
Over-assessment is not caution. It produces a backlog, and a backlog produces pressure to wave things through, which is how the genuinely risky vendor slips past.
What you are actually looking for
Financial viability, because a supplier that fails commercially is an availability risk regardless of how good its security is. Security posture, evidenced rather than asserted. Data handling: what they hold, where it sits, who else touches it, how long they keep it, what happens on termination. Regulatory standing and any enforcement history. Insurance, and whether the limits bear any relation to the exposure. Subprocessors, because their supply chain becomes yours.
The one most often skipped is the fourth-party question. Ask directly which subprocessors are used and whether you are notified before they change. A vendor that cannot answer has not thought about it.
Reading what they send you
A SOC 2 Type II is worth more than any questionnaire, but only if you read it properly. Check the opinion, since a qualified opinion means the auditor found something. Read the exceptions in the testing section, which is where the real findings live. Read the complementary user entity controls, which list what the report assumes you are doing at your end. And check the period, because a report ending last June reviewed this May leaves most of a year unexamined.
An ISO 27001 certificate is a narrower claim than most people assume. What matters is the scope statement on it, which frequently covers one data center or one product line rather than the service you are buying.
Write the conclusion, not the file
A diligence report that lists everything you gathered and stops is not a decision. State the risk, whether it is acceptable, what conditions would make it acceptable, and what should go in the contract. Name the person who accepts anything you are not recommending.
An assessment that ends in a recommendation gets acted on. One that ends in a summary gets filed.
Where to go next
- Browse the jobs that use these skills
- Follow a career roadmap into the role you want
- Hiring for this? Start from a job description template
- Free certification study games, 592 practice questions
Frequently Asked Questions
What is vendor due diligence?
The assessment carried out before a contract is signed, covering financial viability, security, data handling, regulatory standing, insurance and subprocessors. It is one stage of third-party risk management, not the whole of it.
How is due diligence different from third-party risk management?
Due diligence is the pre-signature assessment. Third-party risk management is the full lifecycle including tiering, ongoing monitoring, concentration risk and exit planning. Programs that treat them as the same thing assess thoroughly at onboarding and never look again.
Why does timing matter so much in due diligence?
Because all leverage exists before signature. While the vendor wants the deal, questions get answered and clauses get accepted. Afterwards you are asking a counterparty with no commercial reason to help. Being brought in after terms are agreed means the assessment cannot change anything.
How deep should a vendor assessment go?
In proportion to what the vendor can cost you. Over-assessment is not caution: it creates a backlog, the backlog creates pressure to wave things through, and that is how a genuinely risky vendor gets approved without scrutiny.
What should I check in a SOC 2 Type II report?
The opinion, since a qualified opinion means something was found. The exceptions in the testing section. The complementary user entity controls, which are the things the report assumes you do at your end. And the period covered, because reports are frequently most of a year out of date by the time they are reviewed.
Is an ISO 27001 certificate enough?
Not by itself. The scope statement on the certificate is what matters, and it often covers one data center or one product line rather than the service you are purchasing. A certificate with a narrow scope tells you very little about your specific exposure.
What are subprocessors and why do they matter?
They are your vendor's vendors, and their weaknesses become yours. Ask directly which subprocessors are used and whether you are notified before they change. A vendor that cannot answer has not thought about its own supply chain.
What should a due diligence report conclude with?
A recommendation, not a summary. State the risk, whether it is acceptable, what conditions would make it acceptable, what belongs in the contract, and who accepts anything you are not recommending. Reports that end in a summary get filed rather than acted on.
What jobs use vendor due diligence skills?
Third-party risk analyst, vendor risk manager, procurement risk, supplier assurance, and GRC analysts in regulated sectors where supervisors expect documented pre-contract assessment.
More in this series
- 9 Essential Data Governance Skills for the AI Era
- 10 Internal Audit Skills for Modern Assurance Careers
- 12 Transferable GRC Skills You May Already Have
- Technical vs. Nontechnical GRC Skills: What Employers Actually Need
- AI Governance Skills Employers Actually Hire For
- GRC Analyst Skills: What the Job Actually Requires
- Compliance Analyst Skills
- Risk Assessment Skills
- Controls Testing Skills
- Policy Writing Skills
- Regulatory Change Management Skills
- Third-Party Risk Skills
- Model Risk Management Skills
- AI Impact Assessment Skills
- AI Auditing Skills
- AI Evaluation and Testing Skills for Governance Careers
- Data Lineage Skills
- Data Quality Skills
- Privacy Engineering Skills
- AI Security Skills
- AI Incident Response Skills
- Governance Program Management Skills
- Stakeholder Communication Skills
- Executive Risk Reporting Skills
- Evidence Documentation Skills
- Control Mapping Skills
- Framework Crosswalking Skills
- Responsible AI Skills
- GRC Tools and Automation Skills
- How to Build the 9 Data Governance Skills: A 12-Month Career Plan
- Founder of ExecSearches and GRC Careers
- Executive search across corporate, higher education, financial services, and nonprofit sectors
- Focus on AI governance and GRC hiring
- More than a decade in risk advisory and internal audit in financial services
- Led SOX and regulatory audits for Citi, Goldman Sachs, Morgan Stanley, and McKesson
- Public Accounting Certification, Cornell University