Vendor Due Diligence
What is Vendor Due Diligence?
The investigation and evaluation of a potential vendor's security practices, financial stability, and compliance posture before establishing a business relationship.
Terms that appear alongside vendor due diligence
Each of these is named in at least one of the same controls as vendor due diligence. The number is how many controls name both.
- due diligence 6 shared controls
- audit 5 shared controls
- gdpr 4 shared controls
- privacy notice 4 shared controls
- data subject 4 shared controls
- consent 4 shared controls
- compliance 3 shared controls
- genetic data 3 shared controls
Frameworks that govern vendor due diligence
What the standards actually require on vendor due diligence
Requirements naming vendor due diligence across 6 standards, quoted from the control text.
Sections 24-26 of the Jamaica DPA 2020 establish the framework for Joint Controllers + Processors + Sub-Processors + and Records of Processing Activities.
JM-DPA2020-Joint-Controller-Processor-Sec24-25-26-Arrangements-Allocation-Responsibilities-Contracts · Jamaica DPA 2020 Joint Controllers + Processors + Sections 24-26 + Arrangements + Allocation of Responsibilities + Contracts + Records of Processing Activities (ROPA) + Sub-Processors + Vendor Management →Greece Law 4624/2019 implementation roadmap. ORGANIZATIONAL ROLES: (a) DATA PROTECTION OFFICER (DPO) - mandatory for public authorities + bodies with large-scale processing of special category data + criminal data + systematic monitoring (Greek Article 6);
GR-DPA-Implementation-Roles-DPO-Sectoral · Greece Law 4624/2019 Implementation Roadmap, Organizational Roles, DPO and Sectoral Application →NSS-17 + NSS-42-G require supply chain + third party + OEM security across CBS lifecycle. Vendor due diligence: cyber maturity assessment + ISO 27001 / IEC 62443 / IEC 27036 alignment + cybersecurity governance + secure development + incident history + foreign...
IAEA-NSS17-SupplyChain-ThirdParty-OEM-Trust · IAEA NSS-17 - Supply Chain + Third Party + OEM + Vendor Security + Trustworthy Components →Third-Party AI Supplier Assurance addresses the complex AI supply chain where most enterprises consume foundation models + cloud AI services + AI-enabled SaaS rather than build from scratch.
JP-AIG-Third-Party-AI-Supplier-Assurance-Foundation-Model-Provider-AISI-Evaluation-Voluntary-Audit · Japan AI Guidelines Third-Party AI Supplier Assurance + Foundation Model Provider + AISI Evaluation + Voluntary Audit + ISO/IEC 42001 AI Management System + Sub-Processor + Cloud AI Service Provider + Open Source AI Governance →Articles 6 and 8 of the Jordan PDPL establish enhanced protections for Sensitive Personal Data and children's data. (1) Article 6 Sensitive Personal Data Categories: (a) Racial or ethnic origin; (b) Political opinion or party membership;
JO-PDPL-Sensitive-Data-Children-Article6-Article8-Health-Genetic-Biometric-Religious-Political · Jordan PDPL Sensitive Data + Article 6 + Article 8 + Children's Data + Health + Genetic + Biometric + Racial + Religious + Political + Trade Union + Sexual Orientation + Criminal + Enhanced Protections + Age 16 Parental Consent →Section 4(4)(a) of Kentucky CDPA establishes the heightened consent requirement for sensitive data processing. (1) Section 2 Sensitive Data Definition - 8 Categories: (a) Racial or ethnic origin; (b) Religious beliefs; (c) Mental or physical health diagnosis;
KY-CDPA-Sensitive-Data-Affirmative-Consent-Race-Religious-Health-Genetic-Biometric-Children-Citizenship · Kentucky CDPA Sensitive Data + Affirmative Consent + Race/Ethnicity + Religious + Mental/Physical Health + Sexual Orientation + Citizenship/Immigration + Genetic + Biometric + Children's Data + Precise Geolocation (1,750 ft) + Section 4 Heightened Consent Standard →Questions people ask about vendor due diligence
What is Vendor Due Diligence?
Why is Vendor Due Diligence important for compliance?
Which compliance frameworks address Vendor Due Diligence?
Where can I learn more about Vendor Due Diligence?
See how Vendor Due Diligence applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.