Vendor Due Diligence
Vendor due diligence is the process of investigating and evaluating a third-party vendor before, and sometimes during, a business relationship to make an informed decision about whether to engage them. It helps organizations understand a vendor's characteristics and risks so they can reduce the likelihood of problems arising from the relationship. Note that the term is used in more than one sense: in some contexts it refers to a buyer's pre-contract evaluation of a supplier, while in others it refers to a seller-side exercise conducted as part of a sale process.
Vendor due diligence (VDD) commonly refers to the structured investigation and evaluation of a third-party vendor conducted prior to and during engagement to inform contracting and onboarding decisions and to identify and mitigate risks arising from the relationship. In much of the risk-management literature it denotes the buyer-side, pre-contract and onboarding assessment of a specific vendor's suitability. In transactional and sell-side contexts, the same term can denote a seller-commissioned exercise intended to provide transparency and reduce risk in a sale process; practitioners should confirm which sense applies in a given setting. As a risk control, VDD reduces or manages exposure rather than eliminating it. The evidence provided does not specify AI- or model-specific due-diligence procedures, so any application to AI vendors or model providers should be treated as an extension of the general concept rather than as an established, separately defined practice here.
Why it matters
Vendor due diligence matters because organizations increasingly depend on third parties for functions that can carry material operational, legal, security, and reputational exposure. A structured evaluation before entering a relationship helps a business make an informed decision about whether to engage a vendor and understand the risks that relationship may introduce. Without it, an organization may discover problems only after contracting and onboarding, when remediation is more costly and options are narrower.
It is important to recognize that the term carries more than one meaning, and conflating them can lead to scoping errors. In much of the risk-management literature, VDD refers to a buyer-side, pre-contract and onboarding assessment of a specific vendor's suitability. In transactional and sell-side contexts, the same term can denote a seller-commissioned exercise intended to provide transparency and reduce risk in a sale process. Practitioners should confirm which sense applies in a given setting before designing or relying on a due-diligence workflow, because the objectives, audience, and deliverables differ.
As a risk control, vendor due diligence reduces or manages exposure rather than eliminating it. It informs decisions and helps identify issues, but it does not guarantee that a relationship will be free of problems. Treating a completed due-diligence exercise as a one-time assurance rather than as an input to ongoing risk management is a common pitfall; the evidence indicates the process can occur both before and during a relationship.
Who it's relevant to
Inside VDD
Common questions
Answers to the questions practitioners most commonly ask about VDD.