Back to library

Vendor due diligence memo

Assesses a vendor from security questionnaires, certifications, contracts, privacy materials, financial evidence, service records, and risk registers, producing cited risk ratings, evidence gaps, and conditional onboarding or renewal requirements. Use for third-party risk review, supplier onboarding, procurement diligence, security assessment, and renewal approval packs.

by adlass TemplatesVersion 1Uses adlass toolsUniversal

Published Aug 21, 2026 · Updated Aug 26, 2026

Helpful · 0View raw SKILL.md

Requirements

Map vendor due diligence memo source identifiers, columns, and reference fields. Add the governing vendor due diligence memo policy, taxonomy, thresholds, or reference documents. Define vendor due diligence memo ownership, periods, tolerances, and output vocabulary.

Skill document

The full SKILL.md your agent reads and follows.

Vendor due diligence memo

Purpose

Give a procurement, security, privacy, or business owner a traceable view of a vendor’s suitability and unresolved exposure. The memo connects each risk conclusion to supplied evidence and states the condition, owner, or missing proof required before the company’s decision point.

Scope

Cover vendor identity, service and data handled, criticality, questionnaire answers, certifications, audit reports, contract clauses, subprocessors, hosting and transfer locations, access controls, incident history, business continuity, insurance, financial signals, performance issues, and renewal dependencies. Excluded: independently certifying a control, granting approval, negotiating terms, contacting the vendor, or making a jurisdiction-specific legal conclusion.

Data basis

  • Vendor questionnaire, security policies, SOC or ISO evidence, penetration-test summary, privacy addendum, DPA, MSA, order form, and subprocessor list.
  • Supplier master, purchase history, criticality assessment, service tickets, incidents, SLA reports, financial statements, and prior review.
  • Company third-party-risk policy, control framework, severity matrix, contract standards, and escalation rules.
  • Optional review_scope input for onboarding, renewal, product, or materiality tier.

Result

Write a vendor due-diligence memo with service profile, evidence inventory, risk-by-domain assessment, decision recommendation, conditions, expiry dates, and open points. Add a risk sheet with domain, control question, answer, evidence citation, severity, confidence, remediation condition, accountable role, and review date.

Quality criteria

  • Every in-scope domain and required evidence item has a pass, gap, contradiction, or unavailable status.
  • Certifications and reports include issuer, scope, coverage period, and exceptions where documented.
  • Risk ratings use the company matrix and show impact, likelihood, evidence quality, and calculation or rule.
  • Contract and questionnaire claims are not treated as operating proof without supporting evidence.
  • Conditions have measurable closure evidence and do not promise approval before the decision owner acts.

Instructions

Use the company risk framework before general security practice. Keep vendor assertions separate from independently described evidence and from analyst inference. Check that the service scope matches the certification scope and that dates cover the review period. Treat an expired certificate, missing subprocessor list, unresolved critical incident, or contract conflict according to the supplied escalation matrix; never downgrade it silently. Cite document title, section, page, or row for each material finding and preserve the vendor’s answer when it is disputed.

Adapt before use

  • Add the third-party-risk policy, control matrix, contract standards, severity scale, and required evidence checklist.
  • Define criticality tiers, evidence-age limits, expiry handling, remediation owners, and escalation roles.
  • Map supplier, service, contract, system, incident, and review identifiers to the company records.

Related skills

  • Claim chronology builder

    Builds a dated chronology from claim notices, correspondence, contracts, invoices, incident records, and evidence logs, preserving source citations and disputed dates. Use for insurance claims, commercial disputes, incident files, demand packages, litigation chronologies, and internal fact reviews.

  • Compliance training refresh

    Updates compliance training modules against revised policies, identifies changed learner obligations, and creates source-linked lesson text, scenario questions, and an answer key. Use for annual compliance refreshes, policy changes, code-of-conduct training, and controlled learning-content updates.

  • Contract obligation register

    Extracts dated and recurring duties from signed contracts into an obligation register with parties, triggers, notice windows, service levels, payment terms, evidence, and owners. Use for contract lifecycle management, renewal tracking, vendor obligations, or inherited agreement cleanup.

  • Contract playbook review

    Reviews a commercial contract against a company playbook, records missing or non-standard clauses with exact citations, and proposes fallback positions. Use for procurement, sales, SaaS, services, and contract redline preparation.