A common mistake is treating due diligence as a one-time precontract check. Third-party risk changes over time as ownership, controls, locations, sanctions exposure, and media attention shift. Without ongoing review, organisations can miss new vulnerabilities and compliance issues that emerge after onboarding, when the third party already has access to systems, data, or business processes.
When Third-Party Due Diligence Should Continue After Onboarding
Skipping ongoing review turns vendor risk into a stale assumption. A supplier can look acceptable at contract signature and still become high risk later because controls weaken, sub-processors change, key personnel leave, sanctions exposure shifts, or the service is repurposed in ways that alter your actual exposure.
The practical mistake is assuming that onboarding evidence proves ongoing trust. It usually only proves a point in time. For vendor relationships that touch customer data, authentication flows, or production business processes, the due diligence question has to stay alive for the full relationship, not just procurement.
That is why many teams pair vendor review with IAM and IGA basics and Joiner-Mover-Leaver (JML) Guide thinking: access should be reviewed as conditions change, not left to drift after the initial approval.
What Changes After Onboarding That Organisations Commonly Miss
Third-party risk is not static. Ownership changes, new hosting regions appear, security incidents at the vendor or its dependencies alter confidence, and the vendor may add integrations that broaden the trust boundary. Even if the contract stays the same, the exposure behind it may not.
This is especially important where the vendor has access to secrets, API tokens, customer records, or operational workflows. The risk is not only that a third party can be compromised, but that the compromise can persist undetected because no one is rechecking whether the access, purpose, or safeguards still make sense.
Organisations also miss the difference between due diligence and monitoring. A pre-onboarding review can validate baseline controls, but it does not tell you whether those controls are still operating, whether obligations are still being met, or whether the vendor now depends on a weaker subcontractor. Continuous oversight is what closes that gap.
When the relationship includes technical access, NHI Lifecycle Management Guide is a useful parallel: credentials, ownership, and offboarding all need review over time because the control breaks down when lifecycle management stops at issuance.
How Ongoing Due Diligence Prevents Hidden Exposure
Good ongoing review links governance to observable change. The key is to watch for events that materially alter the vendor’s risk profile, then decide whether the existing approval still holds. That includes control changes, incident disclosures, ownership or location shifts, sanctions or legal developments, and changes in what the vendor can reach inside your environment.
Practically, that means treating due diligence as part of vendor operations, not a procurement artifact. Security, legal, privacy, risk, and business owners should have a shared trigger model for when a vendor requires reassessment, when access should be narrowed, and when the relationship should be paused pending review.
For teams managing privileged or machine access, the lesson aligns with Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs: governance is strongest when review, renewal, and revocation are built into the operating rhythm rather than handled only at intake.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST CSF 2.0 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | SR-6 — Supply Chain and External Dependencies | Third-party due diligence tracks supplier and dependency risk over time. |
| Recommendation — Review supplier controls periodically and require reassessment when external dependency risk changes. | ||
| NIST CSF 2.0 | GV.SC-01 — Supply Chain Risk Management Strategy | Ongoing vendor review is a supply-chain governance activity. |
| Recommendation — Maintain a supplier risk strategy that includes continuous monitoring after onboarding. | ||
| ISO/IEC 27001:2022 | A.5.19 — Information security in supplier relationships | Supplier relationships need continuing security oversight, not just onboarding checks. |
| Recommendation — Define ongoing supplier security review requirements across the full relationship lifecycle. | ||
| SOC 2 (AICPA) | CC9.2 — Vendor Risk Management | Vendor oversight and reassessment are central to trust services assurance. |
| Recommendation — Monitor vendors continuously and reassess trust when their risk profile changes. | ||
| CSA Cloud Controls Matrix | STA — Supply Chain & Transparency Assurance | Cloud and SaaS vendors require ongoing transparency into third-party risk changes. |
| Recommendation — Track supplier changes and revalidate trust assumptions throughout the engagement. | ||
Practitioner Guidance
What to verify: Reconfirm the vendor’s access scope, sub-processor chain, data handling locations, and incident history on a schedule tied to risk, not a blanket annual checkbox. If the vendor can influence production data or business-critical flows, require a more frequent review cadence.
Decision rule: If a vendor change could increase blast radius, regulatory exposure, or recovery time, reopen due diligence before the next renewal or access review. If the relationship is low impact and fully isolated, a lighter monitoring model may be sufficient.
Common mistake: Teams often track questionnaire completion but not control drift. The better signal is whether the vendor’s current operating state still matches the trust decision that was originally made.
Practitioner takeaway: Ongoing due diligence matters because vendor approval is only valid while the vendor’s risk profile, access footprint, and control environment remain consistent with the original decision.
Related resources from NHI Mgmt Group
- What do teams get wrong about ongoing customer due diligence after onboarding?
- What do organisations get wrong when they treat vendor due diligence as a one-time questionnaire?
- What do organisations get wrong when they assume their identity tools already cover third-party risk?
- How should organisations prioritise third-party due diligence when they have thousands of vendors to assess?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org