Vendor Due Diligence Framework
Overview
Comprehensive vendor assessment and due diligence framework for IT service providers, technology vendors, and third-party service providers. Creates structured risk assessments, evaluation reports, and ongoing monitoring frameworks across financial, operational, compliance, security, and reputational dimensions.
LEGAL DISCLAIMER
IMPORTANT: This skill provides general information and frameworks for vendor assessment purposes only. It does NOT constitute legal, financial, or professional advice. Users should:
- Consult qualified legal counsel for specific legal requirements in their jurisdiction
- Engage appropriate financial and security professionals for detailed assessments
- Verify all regulatory requirements independently
- Adapt all frameworks to their specific organizational needs and risk tolerance
- Not rely on this skill as a substitute for professional due diligence services
The frameworks provided are templates only. Actual vendor assessments require expertise in law, finance, cybersecurity, and risk management. Neither the skill creator nor Claude/Anthropic assumes any liability for decisions made based on this skill's output.
When to Use This Skill
Use this skill when you need to:
- Evaluate new vendors, technology providers, or service partners
- Conduct third-party risk assessments for procurement decisions
- Perform critical vendor due diligence for regulatory compliance (DORA, NIS2, GDPR, SOX, etc.)
- Create vendor onboarding documentation and assessment frameworks
- Establish ongoing vendor monitoring and review processes
- Assess vendor concentration risk and business continuity implications
- Generate executive-level vendor risk reports
Core Capabilities
1. Three-Phase Assessment Process
Phase 1: Initial Screening (Days 1-5)
- Financial stability assessment (credit ratings, financial statements, market position)
- Basic compliance verification (certifications, licenses, regulatory status)
- Preliminary security posture review (ISO 27001, SOC 2, cyber insurance)
- Reputational check (news screening, litigation history, sanctions lists)
- Business continuity basics (disaster recovery, backup systems)
Phase 2: Detailed Assessment (Days 5-15)
- In-depth security evaluation (penetration testing, vulnerability management, incident response)
- Operational deep-dive (SLAs, performance metrics, capacity planning, change management)
- Compliance audit (GDPR, industry-specific regulations, data residency, cross-border transfers)
- Financial analysis (cash flow stability, debt ratios, insurance coverage, bonding capacity)
- Contractual risk review (liability caps, indemnification, IP ownership, termination rights)
- Subcontractor and fourth-party risk assessment
Phase 3: Final Evaluation & Decision (Days 15-20)
- Comprehensive risk scoring and rating (1-5 scale across all dimensions)
- Executive summary with recommendation (approve, approve with conditions, reject)
- Risk mitigation plan for identified gaps
- Onboarding roadmap with specific requirements
- Ongoing monitoring framework and KPIs
2. Multi-Factor Risk Scoring System
Each vendor receives scores (1=Low Risk to 5=Critical Risk) across:
- Financial Risk: Creditworthiness, revenue stability, insurance adequacy, concentration risk
- Operational Risk: Service delivery capability, business continuity, dependency/single points of failure
- Compliance Risk: Regulatory adherence, audit findings, data protection practices, certification status
- Security Risk: Cyber resilience, access controls, incident response, data encryption, vulnerability management
- Reputational Risk: Public perception, litigation history, ethical practices, ESG factors
- Strategic Risk: Service criticality, exit/transition difficulty, vendor lock-in, innovation capability
Enhanced Feature: Weighted risk calculations based on service criticality. Critical services (payment processing, customer data systems) receive 2x weight on security and compliance factors.
3. Regulatory Compliance Checklists
Pre-built assessment templates for:
- GDPR: Data processing agreements, sub-processor management, cross-border transfers, breach notification
- DORA (Digital Operational Resilience Act): ICT third-party risk management, concentration risk, exit strategies
- NIS2: Supply chain security, incident reporting, security measures for essential/important entities
- SOX: Internal controls for financial reporting, audit trail requirements
- PCI DSS: Payment card data security (if applicable)
- ISO 27001/SOC 2: Information security management, control frameworks
- Industry-specific: HIPAA (healthcare), FINMA (financial services), FedRAMP (government)
Enhanced Feature: Regulatory gap analysis that identifies which requirements the vendor currently fails to meet and severity classification (blocker, major concern, minor gap, acceptable with mitigation).
4. Document Request Lists
Comprehensive documentation requirements organized by assessment phase:
- Financial: Audited financials (3 years), D&B reports, insurance certificates, bank references
- Legal/Compliance: Certifications (ISO, SOC 2), audit reports, privacy policies, DPAs, sub-processor lists
- Security: Penetration test results, vulnerability scan reports, incident response plans, disaster recovery documentation
- Operational: SLA templates, performance metrics, customer references, org charts, escalation procedures
- Contractual: Standard agreements, liability caps, indemnification terms, IP assignment provisions
5. Vendor Interview Frameworks
Structured interview guides for:
- Executive Leadership: Strategic vision, financial outlook, growth plans, M&A activity
- Security/IT Teams: Architecture reviews, access controls, encryption practices, patch management
- Compliance Officers: Regulatory adherence, audit processes, remediation tracking
- Operations Managers: Service delivery, incident management, change control, capacity planning
- Legal/Contracts: Negotiation flexibility, standard terms, liability frameworks
Enhanced Feature: Red flag detection prompts - specific questions designed to uncover hidden risks (e.g., "Describe your three most recent security incidents and response," "What percentage of revenue comes from your top 3 clients?")
6. Ongoing Monitoring Frameworks
Post-onboarding continuous oversight:
- Quarterly Reviews: Performance metrics, security updates, compliance status, financial health
- Annual Assessments: Full re-evaluation of risk scores, certification renewals, contract renegotiation
- Event-Triggered Reviews: M&A activity, security breaches, regulatory violations, leadership changes, service disruptions
- KPI Dashboards: Uptime, response times, security metrics, compliance status, financial indicators
Enhanced Feature: Early warning indicators (EWIs) that trigger immediate re-assessment - bankruptcy filings, mass layoffs, major customer losses, data breaches, audit failures, regulatory fines.
Output Formats
Vendor Risk Report
Comprehensive assessment report including:
- Executive summary with risk rating and recommendation
- Detailed findings by risk category with evidence
- Risk score matrix (visual heat map)
- Gap analysis against regulatory requirements
- Mitigation recommendations with priority levels
- Onboarding requirements and conditions
- Monitoring and review schedule
Vendor Comparison Matrix
Side-by-side evaluation of multiple vendors:
- Risk scores across all dimensions
- Compliance coverage comparison
- Cost-benefit analysis
- Strengths/weaknesses summary
- Recommended vendor with justification
Onboarding Checklist
Structured requirements list:
- Pre-contract deliverables (certifications, insurance, references)
- Contract negotiation priorities (liability, SLAs, termination rights)
- Integration requirements (APIs, data formats, security controls)
- Ongoing obligations (reporting, audit rights, performance reviews)
Enhanced Feature: Risk-based onboarding paths - higher risk vendors face stricter requirements (more frequent reviews, additional certifications, enhanced SLAs, stronger termination rights).
Best Practices
Proportional Assessment: Scale diligence depth to service criticality and risk exposure
- Critical/High Risk: Full Phase 1-3 assessment with external expert validation
- Medium Risk: Phase 1-2 with selective Phase 3 elements
- Low Risk: Phase 1 with streamlined Phase 2
Document Everything: Maintain audit trail of assessment decisions, risk acceptances, and mitigation measures
Involve Stakeholders: Include Legal, IT/Security, Procurement, Business Units, and Compliance in assessment process
Challenge Vendor Claims: Verify certifications independently, request evidence, conduct site visits for critical vendors
Plan for Exit: Always assess vendor replaceability, data portability, and transition complexity before signing
Continuous Monitoring: Due diligence is not one-time - reassess regularly and after triggering events
Concentrate Risk Management: Track total vendor exposure across organization to identify dangerous concentration
Enhanced Feature: Third-party validation recommendations - when to engage external auditors, security firms, or legal counsel for independent verification (critical vendors, regulated services, high-value contracts).
Risk Mitigation Strategies
Common approaches to address identified gaps:
- Financial: Require parent company guarantees, increase insurance requirements, shorten payment terms, implement performance bonds
- Security: Mandate specific controls, require penetration testing, implement enhanced monitoring, restrict data access
- Compliance: Require certification achievement within timeframe, implement audit rights, add regulatory breach termination clauses
- Operational: Define stricter SLAs, require redundancy, implement escrow for critical IP/code, establish backup vendor relationships
- Strategic: Limit contract term, build exit provisions, avoid proprietary lock-in, maintain dual-source options
Limitations and Disclaimers
This skill does NOT:
- Replace professional due diligence services (legal, financial, technical audits)
- Provide legal advice on specific contracts or regulatory requirements
- Guarantee vendor performance or eliminate all risks
- Substitute for organization-specific risk frameworks and policies
- Fulfill regulatory obligations without expert validation
- Create attorney-client, fiduciary, or advisory relationships
Users must:
- Adapt all frameworks to their specific industry, jurisdiction, and risk tolerance
- Engage qualified professionals for regulated assessments
- Verify all regulatory requirements independently
- Obtain necessary internal approvals before vendor engagement
- Maintain documentation for audit and compliance purposes
- Update assessment criteria as regulations and threats evolve
Regulatory Context
While this skill references common regulations (GDPR, DORA, NIS2, etc.), users must:
- Verify current regulatory requirements in their jurisdiction
- Consult legal counsel for compliance obligations
- Not rely on this skill for legal interpretation
- Understand that regulatory landscapes change constantly
- Recognize that enforcement varies by regulator and jurisdiction
Last Updated Framework Version: January 2025 (Regulatory references may become outdated)
Example Use Cases
- Financial Institution under DORA: Assessing cloud service provider for critical payment systems
- Healthcare Organization: Evaluating SaaS vendor handling protected health information (HIPAA)
- Manufacturing Company: Third-party risk assessment for industrial control system provider
- E-commerce Platform: Payment processor due diligence under PCI DSS requirements
- Government Agency: FedRAMP compliance assessment for cloud infrastructure provider
- Startup: Rapid vendor screening for limited-risk, non-critical services
FINAL REMINDER: This is an educational framework and starting point only. Professional due diligence requires expertise in law, finance, cybersecurity, and risk management. Always engage qualified professionals for critical vendor assessments and do not rely solely on this skill for decision-making.
1---2name: vendor-due-diligence-patrick-munro3description: Framework for assessing IT service providers, technology vendors, and third-party partners. Creates structured risk assessments across financial, operational, compliance, security, and reputational dimensions with regulatory checklists (GDPR, DORA, NIS2, SOX). Use when: (1) Evaluating new vendors or technology providers, (2) Conducting third-party risk assessments for procurement, (3) Performing critical vendor due diligence for regulatory compliance, (4) Creating vendor onboarding documentation, (5) Establishing ongoing vendor monitoring processes, (6) Assessing vendor concentration risk, or (7) Generating executive-level vendor risk reports.4---5
6# Vendor Due Diligence Framework
7
8## Overview
9Comprehensive vendor assessment and due diligence framework for IT service providers, technology vendors, and third-party service providers. Creates structured risk assessments, evaluation reports, and ongoing monitoring frameworks across financial, operational, compliance, security, and reputational dimensions.
10
11## LEGAL DISCLAIMER
12**IMPORTANT: This skill provides general information and frameworks for vendor assessment purposes only. It does NOT constitute legal, financial, or professional advice. Users should:**
13- Consult qualified legal counsel for specific legal requirements in their jurisdiction
14- Engage appropriate financial and security professionals for detailed assessments
15- Verify all regulatory requirements independently
16- Adapt all frameworks to their specific organizational needs and risk tolerance
17- Not rely on this skill as a substitute for professional due diligence services
18
19**The frameworks provided are templates only. Actual vendor assessments require expertise in law, finance, cybersecurity, and risk management. Neither the skill creator nor Claude/Anthropic assumes any liability for decisions made based on this skill's output.**
20
21## When to Use This Skill
22Use this skill when you need to:
23- Evaluate new vendors, technology providers, or service partners
24- Conduct third-party risk assessments for procurement decisions
25- Perform critical vendor due diligence for regulatory compliance (DORA, NIS2, GDPR, SOX, etc.)
26- Create vendor onboarding documentation and assessment frameworks
27- Establish ongoing vendor monitoring and review processes
28- Assess vendor concentration risk and business continuity implications
29- Generate executive-level vendor risk reports
30
31## Core Capabilities
32
33### 1. Three-Phase Assessment Process
34**Phase 1: Initial Screening (Days 1-5)**
35- Financial stability assessment (credit ratings, financial statements, market position)
36- Basic compliance verification (certifications, licenses, regulatory status)
37- Preliminary security posture review (ISO 27001, SOC 2, cyber insurance)
38- Reputational check (news screening, litigation history, sanctions lists)
39- Business continuity basics (disaster recovery, backup systems)
40
41**Phase 2: Detailed Assessment (Days 5-15)**
42- In-depth security evaluation (penetration testing, vulnerability management, incident response)
43- Operational deep-dive (SLAs, performance metrics, capacity planning, change management)
44- Compliance audit (GDPR, industry-specific regulations, data residency, cross-border transfers)
45- Financial analysis (cash flow stability, debt ratios, insurance coverage, bonding capacity)
46- Contractual risk review (liability caps, indemnification, IP ownership, termination rights)
47- Subcontractor and fourth-party risk assessment
48
49**Phase 3: Final Evaluation & Decision (Days 15-20)**
50- Comprehensive risk scoring and rating (1-5 scale across all dimensions)
51- Executive summary with recommendation (approve, approve with conditions, reject)
52- Risk mitigation plan for identified gaps
53- Onboarding roadmap with specific requirements
54- Ongoing monitoring framework and KPIs
55
56### 2. Multi-Factor Risk Scoring System
57Each vendor receives scores (1=Low Risk to 5=Critical Risk) across:
58- **Financial Risk**: Creditworthiness, revenue stability, insurance adequacy, concentration risk
59- **Operational Risk**: Service delivery capability, business continuity, dependency/single points of failure
60- **Compliance Risk**: Regulatory adherence, audit findings, data protection practices, certification status
61- **Security Risk**: Cyber resilience, access controls, incident response, data encryption, vulnerability management
62- **Reputational Risk**: Public perception, litigation history, ethical practices, ESG factors
63- **Strategic Risk**: Service criticality, exit/transition difficulty, vendor lock-in, innovation capability
64
65**Enhanced Feature**: Weighted risk calculations based on service criticality. Critical services (payment processing, customer data systems) receive 2x weight on security and compliance factors.
66
67### 3. Regulatory Compliance Checklists
68Pre-built assessment templates for:
69- **GDPR**: Data processing agreements, sub-processor management, cross-border transfers, breach notification
70- **DORA (Digital Operational Resilience Act)**: ICT third-party risk management, concentration risk, exit strategies
71- **NIS2**: Supply chain security, incident reporting, security measures for essential/important entities
72- **SOX**: Internal controls for financial reporting, audit trail requirements
73- **PCI DSS**: Payment card data security (if applicable)
74- **ISO 27001/SOC 2**: Information security management, control frameworks
75- **Industry-specific**: HIPAA (healthcare), FINMA (financial services), FedRAMP (government)
76
77**Enhanced Feature**: Regulatory gap analysis that identifies which requirements the vendor currently fails to meet and severity classification (blocker, major concern, minor gap, acceptable with mitigation).
78
79### 4. Document Request Lists
80Comprehensive documentation requirements organized by assessment phase:
81- **Financial**: Audited financials (3 years), D&B reports, insurance certificates, bank references
82- **Legal/Compliance**: Certifications (ISO, SOC 2), audit reports, privacy policies, DPAs, sub-processor lists
83- **Security**: Penetration test results, vulnerability scan reports, incident response plans, disaster recovery documentation
84- **Operational**: SLA templates, performance metrics, customer references, org charts, escalation procedures
85- **Contractual**: Standard agreements, liability caps, indemnification terms, IP assignment provisions
86
87### 5. Vendor Interview Frameworks
88Structured interview guides for:
89- **Executive Leadership**: Strategic vision, financial outlook, growth plans, M&A activity
90- **Security/IT Teams**: Architecture reviews, access controls, encryption practices, patch management
91- **Compliance Officers**: Regulatory adherence, audit processes, remediation tracking
92- **Operations Managers**: Service delivery, incident management, change control, capacity planning
93- **Legal/Contracts**: Negotiation flexibility, standard terms, liability frameworks
94
95**Enhanced Feature**: Red flag detection prompts - specific questions designed to uncover hidden risks (e.g., "Describe your three most recent security incidents and response," "What percentage of revenue comes from your top 3 clients?")
96
97### 6. Ongoing Monitoring Frameworks
98Post-onboarding continuous oversight:
99- **Quarterly Reviews**: Performance metrics, security updates, compliance status, financial health
100- **Annual Assessments**: Full re-evaluation of risk scores, certification renewals, contract renegotiation
101- **Event-Triggered Reviews**: M&A activity, security breaches, regulatory violations, leadership changes, service disruptions
102- **KPI Dashboards**: Uptime, response times, security metrics, compliance status, financial indicators
103
104**Enhanced Feature**: Early warning indicators (EWIs) that trigger immediate re-assessment - bankruptcy filings, mass layoffs, major customer losses, data breaches, audit failures, regulatory fines.
105
106## Output Formats
107
108### Vendor Risk Report
109Comprehensive assessment report including:
110- Executive summary with risk rating and recommendation
111- Detailed findings by risk category with evidence
112- Risk score matrix (visual heat map)
113- Gap analysis against regulatory requirements
114- Mitigation recommendations with priority levels
115- Onboarding requirements and conditions
116- Monitoring and review schedule
117
118### Vendor Comparison Matrix
119Side-by-side evaluation of multiple vendors:
120- Risk scores across all dimensions
121- Compliance coverage comparison
122- Cost-benefit analysis
123- Strengths/weaknesses summary
124- Recommended vendor with justification
125
126### Onboarding Checklist
127Structured requirements list:
128- Pre-contract deliverables (certifications, insurance, references)
129- Contract negotiation priorities (liability, SLAs, termination rights)
130- Integration requirements (APIs, data formats, security controls)
131- Ongoing obligations (reporting, audit rights, performance reviews)
132
133**Enhanced Feature**: Risk-based onboarding paths - higher risk vendors face stricter requirements (more frequent reviews, additional certifications, enhanced SLAs, stronger termination rights).
134
135## Best Practices
136
1371. **Proportional Assessment**: Scale diligence depth to service criticality and risk exposure
138 - Critical/High Risk: Full Phase 1-3 assessment with external expert validation
139 - Medium Risk: Phase 1-2 with selective Phase 3 elements
140 - Low Risk: Phase 1 with streamlined Phase 2
141
1422. **Document Everything**: Maintain audit trail of assessment decisions, risk acceptances, and mitigation measures
143
1443. **Involve Stakeholders**: Include Legal, IT/Security, Procurement, Business Units, and Compliance in assessment process
145
1464. **Challenge Vendor Claims**: Verify certifications independently, request evidence, conduct site visits for critical vendors
147
1485. **Plan for Exit**: Always assess vendor replaceability, data portability, and transition complexity before signing
149
1506. **Continuous Monitoring**: Due diligence is not one-time - reassess regularly and after triggering events
151
1527. **Concentrate Risk Management**: Track total vendor exposure across organization to identify dangerous concentration
153
154**Enhanced Feature**: Third-party validation recommendations - when to engage external auditors, security firms, or legal counsel for independent verification (critical vendors, regulated services, high-value contracts).
155
156## Risk Mitigation Strategies
157Common approaches to address identified gaps:
158- **Financial**: Require parent company guarantees, increase insurance requirements, shorten payment terms, implement performance bonds
159- **Security**: Mandate specific controls, require penetration testing, implement enhanced monitoring, restrict data access
160- **Compliance**: Require certification achievement within timeframe, implement audit rights, add regulatory breach termination clauses
161- **Operational**: Define stricter SLAs, require redundancy, implement escrow for critical IP/code, establish backup vendor relationships
162- **Strategic**: Limit contract term, build exit provisions, avoid proprietary lock-in, maintain dual-source options
163
164## Limitations and Disclaimers
165
166**This skill does NOT:**
167- Replace professional due diligence services (legal, financial, technical audits)
168- Provide legal advice on specific contracts or regulatory requirements
169- Guarantee vendor performance or eliminate all risks
170- Substitute for organization-specific risk frameworks and policies
171- Fulfill regulatory obligations without expert validation
172- Create attorney-client, fiduciary, or advisory relationships
173
174**Users must:**
175- Adapt all frameworks to their specific industry, jurisdiction, and risk tolerance
176- Engage qualified professionals for regulated assessments
177- Verify all regulatory requirements independently
178- Obtain necessary internal approvals before vendor engagement
179- Maintain documentation for audit and compliance purposes
180- Update assessment criteria as regulations and threats evolve
181
182## Regulatory Context
183While this skill references common regulations (GDPR, DORA, NIS2, etc.), users must:
184- Verify current regulatory requirements in their jurisdiction
185- Consult legal counsel for compliance obligations
186- Not rely on this skill for legal interpretation
187- Understand that regulatory landscapes change constantly
188- Recognize that enforcement varies by regulator and jurisdiction
189
190**Last Updated Framework Version**: January 2025 (Regulatory references may become outdated)
191
192## Example Use Cases
193
1941. **Financial Institution under DORA**: Assessing cloud service provider for critical payment systems
1952. **Healthcare Organization**: Evaluating SaaS vendor handling protected health information (HIPAA)
1963. **Manufacturing Company**: Third-party risk assessment for industrial control system provider
1974. **E-commerce Platform**: Payment processor due diligence under PCI DSS requirements
1985. **Government Agency**: FedRAMP compliance assessment for cloud infrastructure provider
1996. **Startup**: Rapid vendor screening for limited-risk, non-critical services
200
201---
202
203**FINAL REMINDER**: This is an educational framework and starting point only. Professional due diligence requires expertise in law, finance, cybersecurity, and risk management. Always engage qualified professionals for critical vendor assessments and do not rely solely on this skill for decision-making.