Supplier Due Diligence Checklist
A practical, risk-based checklist for verifying a supplier’s identity, finances, integrity, delivery capability, and key risks before and during a contract.
Use a documented, risk-based process to verify who the supplier is, whether it can deliver the contract at the proposed price, and what risks need mitigation or ongoing monitoring. Check identity and ownership, financial standing, integrity and relevant performance, capability and resilience, contract understanding, and any category-specific risks. Corroborate material claims with independent evidence and apply the same disclosed evaluation criteria to comparable suppliers.
This is a practical checklist, not a universal legal standard. The applicable exclusion grounds, sanctions obligations, privacy rules, security requirements, and human-rights laws depend on the jurisdiction and procurement. The official guidance cited here spans New Zealand, the United Kingdom, Canada, the European Commission, and United States ICT supply-chain guidance.
1. Set the scope and level of checking
Start with the purchase and the consequences of supplier failure. Due diligence should be proportionate to the value, complexity, and risk of the procurement, and should be revisited through the procurement lifecycle. New Zealand Government Procurement’s Rule 25 describes this approach. Read Rule 25.
- Define the goods or services, locations, contract term, service levels, and delivery dependencies.
- Identify subcontractors and lower-tier suppliers whose failure could affect delivery.
- Record criticality, how easily the supplier could be replaced, access to sensitive data or systems, geographic exposure, and the impact of interruption.
- Set the checks, evidence, evaluation criteria, and escalation route before reviewing bids. Put relevant requirements in tender documents where applicable.
- For each check, state what decision it informs. Avoid requesting paperwork that does not answer a risk question.
For ICT suppliers, NIST’s July 2026 final SP 1326 guide provides additional due-diligence dimensions: foreign ownership, control or influence; provenance; resilience; foundational cybersecurity practices; and supply-chain tiers. It is an ICT-focused guide, not a universal statutory checklist. NIST SP 1326.
2. Verify legal identity, ownership, and eligibility
- Confirm the legal name, registration number, legal structure, and operating locations against authoritative company or charity registers where available.
- Identify beneficial owners and relevant control relationships; resolve differences between the bid, registry records, and supporting documents.
- Check applicable exclusion or debarment grounds under the rules that govern this procurement. Record the source, date, result, and any review needed.
- For cross-border suppliers or transactions, assess whether sanctions screening or export-control diligence applies. Use the relevant jurisdiction’s requirements.
Do not treat one country’s exclusion list or legal test as globally applicable. For export-related sanctions, the European Commission’s guidance addresses due diligence and circumvention red flags; it does not replace jurisdiction-specific advice or cover every sanctions obligation. European Commission guidance.
3. Assess financial ability to perform
- Review financial history and, where proportionate, audited accounts, credit information, and other evidence of financial standing.
- Assess the supplier’s capacity for this contract specifically. Consider dependence on important subcontractors or concentrated revenue when reliable information is available.
- Relate financial concerns to contract duration, payment profile, replacement difficulty, and the consequences of interrupted service.
- Decide whether the risk needs mitigation or post-award monitoring, and document the decision.
Do not turn one ratio or credit score into an undisclosed universal pass/fail threshold. The research sources do not establish a universal threshold. UK guidance on supplier economic and financial standing recommends assessment before and after award within its stated central-government scope; check its current scope and applicability before relying on it. UK guidance collection.
4. Check integrity, conduct, and relevant past performance
- Review credible indicators of bribery, corruption, or other adverse conduct relevant to the contract.
- Check relevant delivery performance, health and safety, employment practices, ethics, and management practices.
- Request recent customer references when useful. Ask about comparable work, missed commitments, issue handling, and whether the named team performed the work.
- Compare supplier claims with performance reports, published records, case studies, and other independent evidence where available.
- Apply past-performance evidence objectively. Record facts and relevance; do not let personal preference stand in for evidence.
5. Test capability, capacity, systems, and price
- Confirm that the supplier has the people, expertise, equipment, systems, and processes needed for the full contract term.
- Check key staff qualifications and availability. Request CVs, performance reports, compliance certificates, or audit and accreditation reports when they address a stated requirement.
- Test the assumptions behind the bid: volumes, dependencies, transition effort, staffing, service levels, and exclusions.
- Assess whether the proposed price can realistically deliver the requirement, including ongoing support and contract obligations.
- Confirm the supplier understands deliverables, reporting duties, service levels, acceptance criteria, and remedies.
- Use interviews, presentations, site visits, or client interviews when appropriate and included in the procurement process.
Keep assessment tied to disclosed criteria and the same process for comparable bidders. New Zealand guidance describes using evidence against fit for purpose, ability to deliver, and value for money. Conducting due diligence checks.
6. Add checks for the risks that apply
ICT and cybersecurity suppliers
Use the five SP 1326 dimensions where relevant: foreign ownership, control or influence; provenance; resilience; foundational cyber practices; and supply-chain tiers. Ask for evidence that addresses the actual service and access involved. Map dependencies that could affect security or continuity. NIST SP 1326.
Human rights and supply-chain visibility
Map relevant suppliers, subcontractors, locations, and sourcing relationships. Identify and prioritize potential forced-labour, human-trafficking, and child-labour risks, then plan mitigation and remediation appropriate to the issue. Canadian government guidance notes that smaller organizations may take targeted steps such as adopting policies, researching suppliers before entering a partnership, and seeking responsible-business commitments. Public Services and Procurement Canada guidance.
Sanctions and export controls
Where the parties, goods, or transaction make it relevant, assess business partners and look for export-sanctions circumvention red flags. Determine the rules that apply to the actual jurisdictions and transaction; the European Commission’s export-related guidance is not a substitute for that analysis. European Commission guidance.
7. Collect evidence and keep an audit trail
Corroborate important claims using more than one source when the risk warrants it. New Zealand Government Procurement identifies supplier documents, the buyer’s own research, referees, and third-party confirmation as evidence sources. Examples include audited accounts, credit checks, company-register records, references, insurance and compliance certificates, site visits, staff CVs, client interviews, and current performance reports. Evidence and due-diligence guidance.
For each check, keep a compact record:
- Criterion and risk: What requirement or exposure does this check address?
- Evidence: What was requested, received, and independently verified?
- Source and date: Where did the information come from, and when was it checked?
- Finding: What does the evidence support, contradict, or leave unresolved?
- Decision: Who owns the finding, and does it mean accept, seek clarification, mitigate, escalate, or reject under the applicable rules?
- Follow-up: What action, owner, and review date are needed?
This record format is a practical way to connect evidence to the evaluation and document the rationale; tailor retention and access to applicable requirements.
8. Compare suppliers consistently and decide what findings mean
Use a verification matrix to connect evidence to the decision. Compare candidates across these dimensions, using the same disclosed criteria for comparable bidders while tailoring the depth of checking to risk:
- Legal identity, ownership, and eligibility
- Financial capacity for this contract
- Integrity and relevant conduct
- Relevant delivery history
- Capability, capacity, and resilience
- Compliance and risk exposure
- Price assumptions and value
- Subcontractor visibility and dependency risk
- Quality and independence of evidence
If new information could change an evaluation, route it to the evaluation panel. A serious issue may support exclusion or non-award under the applicable rules. For a less serious gap, seek appropriate evidence or define a mitigation before proceeding. Do not create an improvised scoring threshold after seeing bidder results.
9. Monitor material risks after award
Due diligence is not only a pre-award form. Keep contract-critical risks under review and match the response to the consequences of change or deterioration.
- Monitor financial standing when deterioration could threaten delivery.
- Reassess significant changes in ownership, subcontractors, delivery locations, cyber posture, performance, or exposure where they affect the contract.
- Track agreed mitigations, evidence due dates, owners, and escalation triggers.
- Document reassessments and update the relevant contract or procurement decision-makers.
UK central-government financial-standing guidance addresses both pre-award assessment and monitoring during contract performance within its defined scope. UK guidance.
Supplier due diligence checklist
- [ ] Scope, criticality, dependencies, and proportional check depth are recorded.
- [ ] Legal identity, registration, operating locations, beneficial ownership, and applicable eligibility checks are verified.
- [ ] Financial evidence is relevant to the supplier’s ability to perform this contract.
- [ ] Integrity, conduct, references, and relevant past performance have been assessed objectively.
- [ ] People, systems, capacity, resilience, and subcontractor dependencies are understood.
- [ ] Bid assumptions, realistic pricing, deliverables, and contract obligations have been tested.
- [ ] ICT, human-rights, sanctions, export-control, or other specialist checks are added where relevant.
- [ ] Material claims are corroborated, findings are documented, and unresolved risks have an owner and disposition.
- [ ] Comparable bidders are assessed consistently against the disclosed criteria.
- [ ] Material post-award risks have monitoring actions and review triggers.
Or skip the browser setup
If your supplier review includes collecting website evidence, you can use ScreenshotNeo, a website screenshot API and MCP server for developers, to capture a page with one GET request. See the ScreenshotNeo API documentation.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Cookie banners, newsletter popups, and chat widgets are removed before the shot. Bot checks, blank pages, and failed loads are never billed. An MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000.
Sign up for 1,000 free screenshots a month, with no card.
Troubleshooting your due-diligence process
| Problem | Likely cause | What to do |
|---|---|---|
| The supplier’s name or registration does not match the bid. | Trading name, outdated records, group-company structure, or an unresolved identity issue. | Ask for an explanation and authoritative supporting records; verify the contracting entity and ownership before award. |
| Accounts or credit data are missing or difficult to compare. | The requested evidence may not fit the entity, jurisdiction, or contract risk. | Request proportionate alternative evidence, document limitations, and assess the effect on contract-specific ability. Do not invent a universal ratio threshold. |
| References are positive but unsupported. | Only supplier-selected testimonials were considered. | Seek current referees for comparable work and corroborate material claims with performance records or independent sources where available. |
| Pricing appears unusually low or omits delivery assumptions. | Scope, staffing, transition, volume, or ongoing support assumptions may differ. | Clarify assumptions and exclusions against the requirement and evaluate whether the price can deliver the obligations. |
| Subcontractor or sourcing information is incomplete. | Lower-tier dependencies were not defined or requested. | Identify which tiers and locations are material to delivery, security, or human-rights risks; request targeted information and record residual uncertainty. |
| A new issue appears late in evaluation. | Evidence surfaced after initial assessment or a claim was contradicted. | Bring potentially material information to the evaluation panel, apply the published process, and document the decision and rationale. |
| Risk checks are repeated without changing a decision. | The check lacks a stated criterion or decision purpose. | For each request, name the risk question and intended action; remove checks that have no decision use unless a rule requires them. |
Performance, reliability, and cost considerations
- Scale effort to exposure: Spend more verification effort where interruption, sensitive access, or replacement difficulty would have greater consequences.
- Use evidence efficiently: Reuse reliable, current evidence where permitted, and request targeted updates when information may have changed.
- Plan for uncertainty: A missing document is not automatically proof of failure. Decide what alternative evidence can answer the risk question and record residual uncertainty.
- Account for lifecycle cost: Test whether the bid’s assumptions cover the full term and obligations. A price comparison alone does not establish value.
- Budget monitoring: Include owners and review effort for material post-award risks, particularly where financial or supply-chain changes could affect delivery.
Frequently asked questions
When should supplier due diligence happen?
Plan it before the procurement, perform checks at the stages set out in the process, and revisit material risks during contract performance.
Is there one standard set of documents every supplier must provide?
No universal document set is established by the sources here. Choose evidence that fits the contract, risk, and applicable procurement rules.
Can a small organization do proportionate checks?
Yes. The depth can reflect value, complexity, and risk. Targeted policies, supplier research, and responsible-business commitments are examples discussed in Canadian government human-rights guidance.
Does this checklist determine legal compliance?
No. Confirm the current rules for the procurement’s jurisdiction and category, including eligibility, sanctions, export controls, privacy, security, and human-rights obligations.


