Due diligence
Vendor due diligence: asking questions, assessing evidence
A completed questionnaire is a claim. Only matching evidence, scope and recency turn it into a reliable assessment.
9 minute read · Content as of 21.07.2026
The assessment follows the risk scenario
Questions and evidence are derived from access, data, technology, continuity and the context of use. A generic catalogue of 300 identical questions for every provider creates effort, but not a better decision.
Evidence needs scope, date and substance
Certificates, audit reports, pentest summaries or policies can be relevant. Check whether the specific service and location are covered, which exceptions exist and how current the evidence is.
- record the claim and the required evidence separately
- document validity and scope
- decide gaps as a risk or a measure
- name the approval and the accepted residual risk
Sources used
- Best practice recommendations for supplier requirements · UP KRITIS / BSI · Version 4.0, 2023
- ISO/IEC 27036-2:2022 – Requirements · ISO · 2022
- Bhatti, Mubarak & Nagalingam: Information Security Risk Management in IT Outsourcing – A Quarter-century Systematic Literature Review · Academia
- Vendor, due diligence and exit patterns · KaitoSec