A library for evidence-based Vendor Due Diligence
The Governly Knowledge Center is a permanent, vendor-neutral library of guidance for organisations performing due diligence on software suppliers. Articles are organised by topic and designed to be referenced over time — evergreen reference material, not a chronological blog.
We educate first. Where Governly is genuinely useful, we say so — but the purpose of this library is to help you do vendor due diligence well, regardless of the tools you use.
Browse by category
Vendor Due Diligence
The structured process of verifying whether a software supplier meets your organisation's security, privacy, legal and operational requirements before approval.
2 articlesThird-Party Risk Management
The ongoing programme for governing risk across every third-party relationship throughout its lifecycle.
1 articleRegulatory Frameworks
The frameworks and regulations that shape supplier evaluation — GDPR, ISO 27001, SOC 2, NIS2, DORA and related standards.
5 articlesSecurity Documentation & Evidence
The documents suppliers publish or provide that make claims verifiable — and how to read, evaluate and work with them.
2 articlesSaaS Procurement
Integrating due diligence into the SaaS buying process so security and compliance reviews support the business rather than block it.
1 article
Latest articles
- Vendor Due Diligence
What is Vendor Due Diligence?
What vendor due diligence is, who owns it, what to review, and how to make it repeatable.
9 min readRead - Vendor Due Diligence
Why Security Questionnaires Are Not Enough
What questionnaires can and cannot prove, the failure modes, and how to combine them with evidence.
7 min readRead - TPRM
What is Third-Party Risk Management?
The five parts of a TPRM programme, how it differs from one-off assessments, and what regulators expect.
8 min readRead - Regulatory Frameworks
How to Review a SOC 2 Report
What sections actually matter, which exceptions are red flags, and how to handle CUECs and carve-outs.
11 min readRead - Regulatory Frameworks
SOC 2 vs ISO 27001
Audit model, scope, output and the right way to combine them in a vendor assessment.
9 min readRead - Regulatory Frameworks
GDPR Processor Assessments
What Article 28 actually requires, the eight areas to verify, and how to keep the assessment defensible.
9 min readRead - Regulatory Frameworks
NIS2 Supplier Requirements
Scope, personal liability, the seven supplier areas to cover, and what defensible records look like.
8 min readRead - Regulatory Frameworks
DORA ICT Supplier Requirements
The register, the mandatory contract clauses, concentration risk, and what an exit strategy actually contains.
9 min readRead - Documentation & Evidence
Evidence-Based Vendor Assessments
Why evidence beats opinions, the four-step workflow, and what 'traceable' really means.
8 min readRead - Documentation & Evidence
What Counts as Strong Supplier Evidence?
The five dimensions of evidence strength, and why they decide whether an assessment holds up under scrutiny.
7 min readRead - SaaS Procurement
Security Review in SaaS Procurement
Why reviews fail, the four properties of an integrated process, and the real measure of a good one.
8 min readRead
How articles are structured
Every Knowledge Center article follows the same structure so it is easy to scan and reference:
- What is it?
- Why does it matter?
- Common challenges
- Best practice
- How Governly supports this area
- Related articles
The last two sections keep articles connected — to each other and, where genuinely useful, to the parts of Governly that put the guidance into practice. Educate first, sell second.