Vendor due diligence is the structured review performed before onboarding or renewing a supplier relationship. It examines risk posture, control evidence, regulatory alignment, and business criticality to determine whether the organisation can safely share data or depend on the vendor for an important service.
How vendor due diligence works
Vendor due diligence is not a single questionnaire or a procurement formality. It is a structured review of the supplier’s security posture, control environment, financial or operational stability, legal obligations, and delivery capacity, with the goal of deciding whether the relationship can be trusted at the required level.
In practice, the review starts with the service the vendor will provide and the data or systems it may touch. A low-impact commodity tool needs far less scrutiny than a provider that will process sensitive records, host customer workflows, or sit inside a business-critical chain of dependencies.
The best due diligence programs separate marketing claims from evidence. They ask for policies, independent attestations, architecture details, incident history, subcontractor information, and remediation commitments, then weigh those against the actual business use case rather than treating every vendor as equal.
For identity-heavy and secret-bearing integrations, the same logic should extend to how the vendor handles access tokens, API keys, certificates, and other secrets. NHIMG’s State of Secrets Sprawl 2025 is a useful reminder that access pathways often become the weakest point in a supplier relationship, especially when credentials are buried in code or CI/CD systems.
What due diligence should assess
The strongest due diligence reviews usually cover four questions: can the vendor protect the data it will receive, can it keep the service available, can it meet contractual and regulatory obligations, and can it recover cleanly if something goes wrong. Those questions matter because vendor failure can become your failure when the service is embedded in core operations.
Security controls are only one part of the picture. Organisations should also test whether the vendor’s scope of work creates hidden concentration risk, such as overdependence on a single platform, opaque subcontracting, or unclear exit terms. A vendor can look compliant on paper while still being too fragile, too opaque, or too hard to replace.
Due diligence is also where organisations confirm whether a vendor’s assurances are specific to the service being bought. A generic SOC 2 summary may be useful, but it does not automatically prove fit for purpose if the actual integration involves privileged access, sensitive datasets, or regulated processing.
For third-party relationships that extend into identity and access, the distinction between policy and operational control matters. NHIMG’s State of Non-Human Identity Security and 2025 State of NHIs and Secrets in Cybersecurity both help frame why access governance, offboarding, and rotation are not theoretical concerns when a vendor is handling machine-access material.
Why vendor due diligence is a control, not a procurement ritual
Vendor due diligence is a control because it determines who is allowed into your trust boundary. The decision affects what data may be shared, what systems may be connected, what obligations must be monitored, and how quickly the organisation can safely disengage if the relationship deteriorates.
This is also why due diligence should be proportional to business criticality. A vendor that merely improves convenience is not the same as a vendor that can interrupt trading, impair customer service, or expose regulated records. The more the vendor can influence confidentiality, integrity, or availability, the more the review must examine actual operational evidence rather than generic assurances.
Due diligence also creates an accountability record. It documents why a vendor was accepted, what residual risk was left in place, and which compensating controls were required. That record becomes important later when an incident, audit, renewal, or exit decision forces the organisation to justify its original choice.
Where a supplier relationship involves exposed credentials, shared secrets, or delegated access, the supplier review should be treated as part of the access-control story rather than as a separate paperwork track. NHIMG’s 2024 State of Secrets Management Survey and State of Secrets in AppSec are relevant because vendor integrations often fail at the boundary between approved trust and uncontrolled secret handling.
How organisations should think about renewal and ongoing review
Vendor due diligence should not end at onboarding. A supplier that was acceptable last year may no longer be acceptable after a breach, an ownership change, a scope increase, or a shift in data sensitivity. Renewal is therefore the point at which the original assumptions should be revalidated, not simply rolled forward.
Ongoing review should focus on drift. Control evidence can go stale, support models can change, subcontractors can expand, and the actual service can become more central to the business than it was when first approved. The vendor may still be “the same company,” while the risk relationship has changed materially.
For that reason, due diligence works best when it is tied to clear ownership for reassessment, offboarding readiness, and dependency mapping. That gives procurement, security, legal, and business owners a shared basis for deciding whether to renew, restrict, remediate, or exit the relationship.
If the vendor relationship depends on machine-access material, visibility and lifecycle discipline become especially important. NHIMG’s Critical Gaps in Machine Identity Management report and Machine-to-Machine Identity Maturity Model provide a useful lens on rotation, attestation, and the kind of lifecycle control that supplier reviews often miss when they focus only on questionnaires.
Risk and Threat Considerations
Vendor due diligence matters because suppliers can become a direct path to data exposure, service disruption, and inherited control failure. A weak vendor may introduce compliance gaps, but a compromised vendor can also become an attacker’s foothold into your environment or your customers’ data.
Failure mechanism: Organisations overtrust questionnaire responses, fail to validate real control operation, or overlook subcontractor and credential handling weaknesses, then grant access that exceeds the vendor’s actual security maturity.
Impact: The result can be third-party breach propagation, unauthorized access, regulatory exposure, delayed incident response, and difficult, costly disengagement when the relationship has to be terminated.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the technical controls, while SOC 2 (AICPA) define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS Control 15 — Service Provider Management | Vendor due diligence directly evaluates third-party security posture and contractual controls. |
| Recommendation — Assess and continuously monitor supplier controls before and during onboarding. | ||
| NIST CSF 2.0 | GV.SC — Cyber Supply Chain Risk Management | Due diligence governs supplier risk, dependency, and assurance across the supply chain. |
| Recommendation — Apply supply-chain risk governance to approve, monitor, and reassess vendors. | ||
| SOC 2 (AICPA) | Trust Services Criteria | Vendor evidence often maps to security, availability, confidentiality, and privacy assurance. |
| Recommendation — Request independent assurance evidence that matches the service and data sensitivity. | ||
Practitioner Guidance
Governance implication: Treat vendor due diligence as a risk decision with an owner, an evidence standard, and an expiry date. Procurement may coordinate the process, but security, legal, privacy, and the business sponsor should each own part of the decision because the consequences are shared.
What to watch for: Pay close attention to vendors that request broad access, resist evidence requests, rely on opaque subcontractors, or cannot explain how they revoke access and isolate customer data. Those are often the warning signs that a relationship is safe on paper but brittle in operation.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 23, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org