1. Define the decision
State what the organisation is deciding: whether to onboard, contract, grant access, renew or expand scope. The evidence required for a low-value office supplier should not automatically equal that required for a critical cloud processor, construction contractor or payments intermediary.
2. Score inherent risk
Assess the exposure before vendor controls: service criticality, spend and concentration, substitutability, geography, regulated activity, data and system access, site and safety exposure, subcontracting, financial dependency and interaction with public officials or customers.
3. Assign due-diligence modules
All vendors receive identity, authority, conflict and payment controls. Trigger financial, cyber, privacy, HSE, ownership, sanctions, ESG, insurance, business-continuity or technical modules from explicit rules. Document why a module is required or omitted.
4. Evaluate evidence strength
Distinguish authoritative verification, independently corroborated evidence, vendor-provided evidence, self-declaration, expired evidence, contradiction and missing information. A completed questionnaire is not equivalent to verified evidence.
5. Calculate residual risk
Assess how effectively verified controls reduce the inherent exposure. Keep risk domains visible rather than hiding them in one composite score. A mandatory legal, safety or sanctions failure should not be averaged away by strong performance elsewhere.
6. Govern decisions and exceptions
Define approval authority per tier and domain. AI may extract, classify, compare and surface gaps, but material approvals, confirmed matches and exceptions should remain attributable to authorised reviewers. Record overrides, rationale and model or policy version.
7. Set reassessment triggers
Use both time and events: document expiry, material scope or ownership change, incident, adverse finding, deteriorating performance, new data access, regulatory change or contract renewal. Critical vendors need more frequent and targeted review.
Related resources
Sources and research basis
This guide distinguishes general control recommendations from legal requirements. It is general information, not legal advice; applicability varies by entity, sector, jurisdiction and contract.