Supplier due diligence and third-party risk onboarding, done once and evidenced
Tier every supplier, collect the right evidence for that tier, put the risk in your register and schedule the reassessment — all inside the same workspace that holds your controls, policies and audit trail.
Why third-party risk onboarding breaks down
No consistent tiering
Evidence scattered across inboxes
Onboarding without reassessment
No named owner
Supplier due diligence checklist
A five-stage onboarding checklist you can run as written. Scale stages 2 and 3 by supplier tier; stages 1, 4 and 5 apply to everyone.
1. Intake and tiering
- Record the supplier, business owner, service description and contract value.
- Classify the data the supplier will touch (public, internal, confidential, personal, special category).
- Confirm whether the supplier has access to production systems, admin credentials or customer data.
- Assign a tier — critical, high, medium or low — that sets the depth of the checks below.
2. Security and compliance evidence
- Request certification evidence: ISO 27001 certificate plus Statement of Applicability, SOC 2 Type II report, or Cyber Essentials Plus.
- Check the certificate scope covers the service you are buying, not just a head-office function.
- Collect the latest penetration test summary and remediation status.
- Review the supplier's business continuity and disaster recovery arrangements, including tested RTO/RPO.
- Confirm incident notification timescales in writing (72 hours or better for personal data breaches).
3. Data protection and legal
- Identify processing roles (controller, processor, joint controller) and put a data processing agreement in place.
- Map international transfers and the transfer mechanism relied upon (UK IDTA/Addendum, EU SCCs).
- Record sub-processors and require notice of changes.
- Check retention and secure deletion commitments at end of contract.
- Confirm right-to-audit, security schedule and liability provisions are in the contract.
4. Operational onboarding
- Provision least-privilege access; require MFA and SSO where supported.
- Add the supplier's systems to your asset and system register with a named internal owner.
- Log residual risks in the risk register with treatment owners and dates.
- Add the supplier to the incident contact list and test the escalation path.
5. Ongoing assurance
- Set a reassessment date driven by tier — annually for critical suppliers, at renewal for low tier.
- Track certificate expiry dates and chase renewals before they lapse.
- Monitor performance and security incidents against agreed service levels.
- Run an offboarding checklist at exit: access revoked, data returned or destroyed, evidence retained.
Tiering model
| Tier | Typical supplier | Assessment depth | Review cycle |
|---|---|---|---|
| Critical | Hosting, production data processors | Full questionnaire, certificate scope check, pen test, BCDR evidence | Annual + on change |
| High | SaaS holding personal data | Questionnaire, certification evidence, DPA | Annual |
| Medium | Internal tooling, limited data | Short questionnaire, certificate on file | At renewal |
| Low | No system or data access | Register entry and contract only | By exception |
Evidence your own buyers will ask for
You are someone's third party too
One evidence set, both directions
Related reading: vendor onboarding security, risk management software and GRC platform.
Answers buyers, procurement and auditors want
What is supplier due diligence?+
Supplier due diligence is the structured assessment you carry out before and during a third-party relationship to understand the risk that supplier introduces. It covers security posture, data protection, resilience, financial stability and legal terms, and is proportionate to the tier the supplier sits in — a payroll processor holding personal data gets far deeper scrutiny than a stationery vendor.
How does supplier due diligence relate to ISO 27001?+
ISO 27001:2022 Annex A 5.19 to 5.22 require information security in supplier relationships, security within supplier agreements, management of ICT supply chain risk, and monitoring and review of supplier services. An auditor will ask to see your supplier register, the criteria you used to select and assess suppliers, the security clauses in agreements, and evidence of periodic review.
How often should suppliers be reassessed?+
Drive the frequency from the tier. Critical suppliers — those touching production data or underpinning a core service — are typically reviewed annually and on any material change. Medium tier at contract renewal, low tier by exception. Record the rationale so the schedule is defensible rather than arbitrary.
What evidence should we ask a supplier for?+
A current ISO 27001 certificate with the Statement of Applicability, a SOC 2 Type II report where available, a penetration test summary, business continuity test results, the data processing agreement with a sub-processor list, and a completed security questionnaire. Always check the certificate scope statement covers the service you are buying.
Can we skip due diligence for small suppliers?+
Not entirely — but you can scale it. A short tiering step is the control: if the supplier has no access to data or systems, a lightweight record and a signed contract may be sufficient. What you cannot defend to an auditor is having no consistent method for deciding which suppliers get scrutiny.
How does ISO-STANDARD.app support supplier due diligence?+
Suppliers sit in the same workspace as your risks, controls and evidence. Each supplier gets a tier, an owner, linked risks, stored certificates with expiry reminders, questionnaire responses and a reassessment date — so the supplier section of your internal audit or certification audit is produced from live data rather than assembled from spreadsheets.
Onboard your next supplier with the evidence attached
Tier the supplier, store the certificate, log the residual risk and set the reassessment date — in one place, ready for your next audit.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.