
Vendor due diligence beyond the questionnaire
A vendor questionnaire records what a supplier is prepared to put in writing, usually answered by whoever in their sales or compliance team received the spreadsheet. It is a reasonable index of where to look, and we would keep using it. The diligence happens afterwards, when someone checks a few of those answers against something real.
Since DORA started applying on 17 January 2025, firms in scope have kept a register of information on their ICT third-party arrangements, and those obligations flow down by contract to the providers they use. UAE-based firms serving EU-regulated clients see the same clauses arrive in their own agreements. We wrote about preparing for that when most of your stack is vendors. Ten months in, the register has told a lot of firms which suppliers matter. The checks below are how you find out whether the answers next to their names hold up.
Five answers worth testing
-
The incident contact
Use it. Send a test notification on a weekday afternoon and again at a weekend, cleared in advance with your account manager but not with their on-call team, and record how long it takes to reach a person who can act. Then ask for a redacted copy of the last incident notice they sent a customer. That tells you what you will actually receive at 3am, and whether it contains anything you could act on.
-
The last continuity test
Ask for the date, scope and summary result of the most recent continuity or recovery test, including what failed. Every real test finds something. A report where everything passed suggests either a very small test or a heavily edited document, and both are worth a conversation before renewal.
-
The subcontractors
Ask which parties touch your data or your service: hosting, outsourced support desks, the data sources behind identity checks, the screening list provider. Ask where they sit and how you will be told when one of them changes, including whether you can object. Your supplier's outage is often their hosting provider's outage, and you want that on paper before the incident call.
-
The assurance report
If they send a SOC 2 report or an ISO 27001 certificate, check that the scope covers the service you buy, delivered from the locations that deliver it. In a SOC 2 report, read the exceptions the auditor recorded and the complementary user entity controls. Those are the controls the supplier assumes you are running at your end. Operations teams sometimes meet that list for the first time when their own auditor asks about it.
-
The exit
Ask how your data comes back: in what format, how quickly and at what cost. Ask whether they have done it for a departing customer before. Then check that the contract says the same thing. Exit assistance that exists only in a sales conversation will not survive a dispute, and the moment you need it is rarely a calm one.
None of this takes long for one supplier. Across a whole supplier list it becomes a project of its own, which is why the list has to be tiered first.
Size the effort to what breaks
Say a PSP carries sixty suppliers on its books. Perhaps a dozen could stop payments or onboarding within a business day if they failed. Those get the full treatment above, annually, with an operations person in the room. The rest get a questionnaire, a contract review and a note in the register.
A simple sorting question works better than a scoring matrix: if this supplier were unavailable for a working day, what would we stop doing, and would a customer or a regulator notice? Procurement can run the process, but the person asking that question should be someone who has sat through an incident at 3am and knows which screen goes blank. It is worth comparing the answer with the criticality already recorded in the register. Where the two disagree, the register is usually the optimistic one, because it was filled in from the contract value.
One more thing worth checking early: concentration. Four suppliers with four names can still sit in one cloud region, or route through one identity data provider. The register makes that visible if somebody reads down the column instead of across the row.
After the signature
Diligence decays. Suppliers get acquired, replace subcontractors, lose the engineer who understood your integration, or move support to a new location with a new set of hours. A file from the procurement process eighteen months ago describes a company that may no longer exist in the same form.
Review the critical ones annually with the same five checks, and set triggers for an earlier look: a change of ownership, a notified subcontractor change, two incidents in a quarter, a missed service level, or the quiet disappearance of the account team you knew. Use your own performance data in those reviews. If your service levels are written the way we suggested in service levels your partners can actually measure, you already have the measurement points and do not have to argue about whose report is right.
Keep the evidence with the register entry: the response times from the contact test, the continuity test summary, the subcontractor list with its date, the exit clause reference. Next year's review then compares against something specific, and the year after that you can see a trend.
For the next critical renewal on your calendar, start with the incident contact test. It costs one email and a phone call, and it tells you more about how the relationship will behave under pressure than the rest of the questionnaire put together.
Discuss your operations
