Vendor Due Diligence
Vendor due diligence is how organisations decide, with evidence, whether a supplier can be trusted with their data, users and processes. Articles in this category explain what to assess, who should be involved, and how to make the process repeatable.
Other categories
- Third-Party Risk ManagementThe ongoing programme for governing risk across every third-party relationship throughout its lifecycle.
- Regulatory FrameworksThe frameworks and regulations that shape supplier evaluation — GDPR, ISO 27001, SOC 2, NIS2, DORA and related standards.
- Security Documentation & EvidenceThe documents suppliers publish or provide that make claims verifiable — and how to read, evaluate and work with them.
- SaaS ProcurementIntegrating due diligence into the SaaS buying process so security and compliance reviews support the business rather than block it.