---
name: vendor-due-diligence-memo
description: Assesses a vendor from security questionnaires, certifications, contracts, privacy materials, financial evidence, service records, and risk registers, producing cited risk ratings, evidence gaps, and conditional onboarding or renewal requirements. Use for third-party risk review, supplier onboarding, procurement diligence, security assessment, and renewal approval packs.
license: Apache-2.0
metadata:
  adlass.categories: "legal-compliance/third-party-due-diligence"
  adlass.industries: ""
  adlass.tags: "vendor-due-diligence,third-party-risk,questionnaire,security,procurement,renewal"
  adlass.adaptation: "reference-doc"
  adlass.source: "original"
  adlass.version: "1"
---

# Vendor due diligence memo

## Purpose

Give a procurement, security, privacy, or business owner a traceable view of a vendor’s suitability and unresolved exposure. The memo connects each risk conclusion to supplied evidence and states the condition, owner, or missing proof required before the company’s decision point.

## Scope

Cover vendor identity, service and data handled, criticality, questionnaire answers, certifications, audit reports, contract clauses, subprocessors, hosting and transfer locations, access controls, incident history, business continuity, insurance, financial signals, performance issues, and renewal dependencies. **Excluded:** independently certifying a control, granting approval, negotiating terms, contacting the vendor, or making a jurisdiction-specific legal conclusion.

## Data basis

- Vendor questionnaire, security policies, SOC or ISO evidence, penetration-test summary, privacy addendum, DPA, MSA, order form, and subprocessor list.
- Supplier master, purchase history, criticality assessment, service tickets, incidents, SLA reports, financial statements, and prior review.
- Company third-party-risk policy, control framework, severity matrix, contract standards, and escalation rules.
- Optional `review_scope` input for onboarding, renewal, product, or materiality tier.

## Result

Write a vendor due-diligence memo with service profile, evidence inventory, risk-by-domain assessment, decision recommendation, conditions, expiry dates, and open points. Add a risk sheet with domain, control question, answer, evidence citation, severity, confidence, remediation condition, accountable role, and review date.

## Quality criteria

- Every in-scope domain and required evidence item has a pass, gap, contradiction, or unavailable status.
- Certifications and reports include issuer, scope, coverage period, and exceptions where documented.
- Risk ratings use the company matrix and show impact, likelihood, evidence quality, and calculation or rule.
- Contract and questionnaire claims are not treated as operating proof without supporting evidence.
- Conditions have measurable closure evidence and do not promise approval before the decision owner acts.

## Instructions

Use the company risk framework before general security practice. Keep vendor assertions separate from independently described evidence and from analyst inference. Check that the service scope matches the certification scope and that dates cover the review period. Treat an expired certificate, missing subprocessor list, unresolved critical incident, or contract conflict according to the supplied escalation matrix; never downgrade it silently. Cite document title, section, page, or row for each material finding and preserve the vendor’s answer when it is disputed.

## Adapt before use

- Add the third-party-risk policy, control matrix, contract standards, severity scale, and required evidence checklist.
- Define criticality tiers, evidence-age limits, expiry handling, remediation owners, and escalation roles.
- Map supplier, service, contract, system, incident, and review identifiers to the company records.
