They need both, but ongoing monitoring usually matters more after onboarding because risk changes over time. Due diligence screens the initial decision, while monitoring checks whether the vendor still meets the organisation’s trust threshold. If a programme stops at procurement, it misses patch drift, service changes, and new exposure paths.
Why Due Diligence and Monitoring Are Different Jobs
vendor due diligence answers a point-in-time question: should you trust this provider enough to start the relationship? Ongoing monitoring answers a different question: does that trust still hold after integration, contract changes, patch cycles, ownership shifts, and service expansion? The distinction matters because third-party risk is not static, and the control objective changes once the vendor is in production.
Due diligence is strongest when the organisation is still deciding, because it reduces the chance of onboarding an obviously unsuitable provider. Monitoring becomes more valuable once the vendor has access to data, systems, or business processes, because the risk surface keeps moving. That is why mature programmes treat due diligence as the gate and monitoring as the operating control.
What Changes After Onboarding
After onboarding, the risk picture rarely stays the same. A vendor may add new subprocessors, alter hosting arrangements, fall behind on patching, change its incident response posture, or expand the scope of the service without a fresh review. Those changes can create new exposure even when the original assessment was sound.
This is where ongoing review of cloud and control posture becomes materially different from procurement screening. A useful benchmark is the CSA Cloud Controls Matrix, which is often used to structure third-party assessments across IAM, audit, data protection, and supply chain expectations. For broader control baselines, teams also use CIS Controls v8 and NIST SP 800-53 Rev 5 Security and Privacy Controls to turn “monitoring” into specific, testable control expectations.
In practice, the question is not whether the vendor passed review once. It is whether the vendor still meets the organisation’s minimum control threshold as the relationship, threat environment, and dependency profile evolve.
How to Decide What Deserves the Most Attention
The right prioritisation depends on where the risk is greatest. If the vendor is not yet approved, due diligence is the first decision point. If the vendor is already live, monitoring usually deserves more operational attention because it is the only control that can catch drift, degradations, and emerging exposure before they become incidents.
For financial crime, onboarding checks and continuing oversight are both expected, but the same logic applies more broadly: initial review establishes entry, while continuing review detects change. The EBA AML/CFT Guidance and the FATF Recommendations both reflect this broader principle of initial checks plus ongoing review in regulated relationships.
A strong programme therefore treats vendor criticality as the deciding factor for monitoring intensity. High-impact suppliers need more frequent review, tighter evidence thresholds, and faster escalation when control signals change.
Risk and Threat Considerations
Vendor risk often fails at the monitoring stage, not the intake stage. A provider can look acceptable at procurement and still become unsafe later through patch drift, service reconfiguration, access creep, ownership changes, or weak subcontractor governance. That creates a blind spot where the organisation believes it has accepted a known risk, when in fact the risk has mutated.
Failure mechanism: The organisation over-relies on the onboarding assessment, then loses visibility into changes that affect security, resilience, or compliance once the vendor is connected to live systems or data.
Impact: Material exposure can persist unnoticed, including service interruption, data compromise, control failure, and loss of assurance over a critical third party.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CSA Cloud Controls Matrix, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | Vendor trust hinges on access governance and control review across third parties. |
| Recommendation — Review vendor IAM controls and revalidate access paths whenever the service or risk profile changes. | ||
| CIS Controls v8 | CIS-15 — Service Provider Management | This question is about third-party risk governance over time, not just onboarding. |
| Recommendation — Maintain an active service-provider review process and track control drift after onboarding. | ||
| NIST SP 800-53 Rev 5 | SA-9 — External System Services | The subject is ongoing assurance over third-party services that affect security and operations. |
| Recommendation — Define security requirements and monitor external service performance throughout the relationship. | ||
| ISO/IEC 27001:2022 | A.5.19 — Information security in supplier relationships | Supplier governance is central because vendor trust must be managed across the lifecycle. |
| Recommendation — Set supplier security expectations and review them throughout the contract lifecycle. | ||
Practitioner Guidance
What to prioritise: Put monitoring effort where the vendor can change your exposure, not just where procurement was difficult. High-trust integrations, sensitive data sharing, and operationally critical services deserve the shortest review cadence and the clearest escalation path.
What to verify: Confirm that monitoring is tied to observable signals, such as control attestations, patch status, incident notifications, subcontractor changes, and scope changes. If you cannot name the signals, you are not monitoring, you are hoping.
Decision rule: If the vendor can affect production systems, customer data, or regulated processes, ongoing monitoring should outweigh one-time due diligence in day-to-day governance, even though both remain necessary.
Practitioner takeaway: Due diligence is the admission check, but monitoring is the control that keeps the trust decision true after the relationship goes live.
Related resources from NHI Mgmt Group
- When should organisations prioritise contract amendments for AI vendor risk over point-in-time due diligence?
- What do organisations get wrong when they skip ongoing third-party due diligence after onboarding a vendor?
- Should organisations prioritise external exposure or internal credential governance first?
- Why does enhanced due diligence need ongoing monitoring after onboarding?