Vendor Qualification Checklist for Procurement & QA Teams
- 7OHyea
- Aug 8
- 19 min read

TL;DR:
A vendor qualification checklist verifies supplier capability, compliance, and risk before awarding business. Vendors with access to sensitive data or regulated materials must pass full qualification against specific standards; low-risk vendors can undergo lightweight onboarding. Proper tiering, evidence management, and continuous re-evaluation are essential for effective supply chain risk management.
A vendor qualification checklist is a structured set of criteria, evidence requirements, and approval gates that procurement and quality assurance teams use to verify a supplier’s capability, compliance, and risk profile before awarding business or allowing materials into a regulated supply chain.
The short version: if a vendor touches your data, your product, or your regulatory status, they need to pass a documented qualification before you sign anything.
Quick-gate checklist — apply to every new vendor at intake:
Legal identity verified: business registration, DUNS/EIN, UBO disclosure, OFAC/UN/EU sanctions screening
Financial stability confirmed: credit report, audited financials (Tier 1: two years minimum), no active insolvency proceedings
Information security evidence collected: SOC 2 Type II report or ISO 27001 certificate with current scope; encryption and IAM controls confirmed
Privacy and data handling documented: signed Data Processing Agreement (DPA), sub-processor list, cross-border transfer mechanism (SCCs or adequacy decision)
Regulatory and quality certifications on file: ISO 9001, ISO 13485, GMP, FDA registration, or equivalent as applicable to the vendor’s category
Contract terms reviewed: MSA, SLA, breach notification window (72 hours or less), audit rights clause, exit and transition provisions
Tier assigned and gating items confirmed: Tier 1 vendors require SOC 2 Type II or ISO 27001 plus a signed DPA before approval; no exceptions without a documented waiver
Verdict: vendors with access to sensitive data, regulated materials, or critical production inputs require full qualification against SIG Lite (at minimum) or SIG Core, CSA STAR, NIST SP 800-161, and where applicable NYDFS Part 500.11 and OCC third-party risk guidance. Vendors with no data access and low spend can proceed through a lightweight onboarding with an SAQ and document review only.
Table of Contents
What does a complete vendor qualification checklist cover?
A vendor due diligence checklist organized across six categories gives procurement and QA teams a single working document they can copy into a supplier portal, spreadsheet, or TPRM platform. The table below spans 28 core line items calibrated to Tier 1 depth, with Tier 2 and Tier 3 collapses noted per row.
# | Category | Checklist Item | Tier 1 | Tier 2 | Tier 3 | Owner | Notes |
1 | Identity | Business registration / articles of incorporation | ✓ | ✓ | ✓ | Procurement | State or federal filing |
2 | Identity | DUNS number or EIN confirmation | ✓ | ✓ | ✓ | Procurement | Cross-check with SAM.gov |
3 | Identity | Ultimate Beneficial Owner (UBO) disclosure | ✓ | ✓ | — | Procurement | FinCEN CDD rule |
4 | Identity | OFAC, UN, EU, UK consolidated watchlist screening | ✓ | ✓ | ✓ | Compliance | Repeat annually |
5 | Financial | Audited financials (2 years) | ✓ | — | — | Procurement | Dun & Bradstreet or equivalent |
6 | Financial | Credit report / Dun & Bradstreet score | ✓ | ✓ | — | Procurement | Flag scores below threshold |
7 | Financial | No active insolvency / bankruptcy proceedings | ✓ | ✓ | ✓ | Legal | PACER search or equivalent |
8 | Security | SOC 2 Type II report (within 12 months) | ✓ | ✓ | — | InfoSec | Bridge letter if >12 months old |
— | Security | ISO 27001 certificate with current scope | ✓ | ✓ | — | InfoSec | Verify accreditation body |
10 | Security | Encryption standards confirmed (AES-256 at rest, TLS 1.2+ in transit) | ✓ | ✓ | — | InfoSec | Vendor attestation or SAQ |
11 | Security | IAM policy and MFA enforcement documented | ✓ | ✓ | — | InfoSec | SIG Lite domain 7 |
12 | Security | Incident response plan with defined notification SLA | ✓ | ✓ | — | InfoSec | 72-hour notification minimum |
— | Security | Penetration test results (within 12 months) | ✓ | — | — | InfoSec | Tier 1 only |
— | Privacy | Signed DPA (CCPA / CPRA / state law as applicable) | ✓ | ✓ | — | Legal | Gating item for Tier 1 and 2 |
15 | Privacy | Sub-processor list with names and locations | ✓ | ✓ | — | Legal | Update on change |
16 | Privacy | Cross-border transfer mechanism (SCCs or adequacy) | ✓ | ✓ | — | Legal | Required for EU data flows |
17 | Privacy | Data retention and deletion schedule | ✓ | ✓ | — | Legal | Confirm deletion certificate process |
18 | Compliance | ISO 9001 or ISO 13485 certificate | ✓ | ✓ | — | QA | Verify scope matches supply |
— | Compliance | GMP / FDA registration (where applicable) | ✓ | — | — | QA / Regulatory | APIs, pharma, medical devices |
20 | Compliance | Compliance evidence | ✓ | — | — | QA / Regulatory | Pharma and device only |
— | Compliance | ESG / sustainability disclosure | ✓ | ✓ | — | Procurement | Scope 3 reporting where required |
— | Compliance | Anti-bribery / FCPA attestation | ✓ | ✓ | — | Legal | Signed vendor code of conduct |
— | Contract | Master Services Agreement (MSA) executed | ✓ | ✓ | ✓ | Legal | Include IP ownership clause |
— | Contract | SLA with defined uptime / delivery / defect KPIs | ✓ | ✓ | — | Procurement | Tie to re-qualification triggers |
25 | Contract | Breach notification clause (72 hours or less) | ✓ | ✓ | — | Legal | NYDFS Part 500.11 alignment |
— | Contract | Audit rights clause (right to audit or third-party equivalent) | ✓ | ✓ | — | Legal | Cascade to sub-processors |
— | Contract | Exit / transition plan and data return provisions | ✓ | ✓ | — | Legal / Procurement | Include deletion certificate |
28 | Performance | Reference checks (2 minimum for Tier 1) | ✓ | — | — | Procurement | Peer industry references preferred |
— | Performance | Sample testing or first-article inspection | ✓ | ✓ | — | QA | |
30 | Performance | On-site or remote audit completed and documented | ✓ | ✓ | — | QA / Audit | See audit section below |
Timeline and cost: a Tier 1 full qualification typically takes 4–8 weeks from intake to approval, depending on vendor responsiveness and audit scheduling. Tier 2 vendor assessments are completed within several weeks relying mainly on document review. Tier 3 vendor qualification can be completed in a short time using self-assessment questionnaires and contract checks. Cost drivers include auditor fees for on-site visits, third-party screening subscriptions (Dun & Bradstreet, Refinitiv World-Check), and TPRM platform licensing.
Pro Tip: Copy this table into a Google Sheet or your TPRM platform, add a “Status” column (Not Started / In Progress / Complete / Waived), and assign an owner to each row at intake. A waived item must carry a written rationale and an approver signature — never leave it blank.
How do you tier vendors and right-size due diligence?
Tiering is the single most effective way to prevent your qualification program from collapsing under its own weight. Without it, every vendor gets the same 200-question intake, completion rates drop, and the risk scores you collect are useless because low-risk vendors game the process while high-risk vendors slip through on the same form.
The rubric below uses three lenses scored at intake: data sensitivity × spend × replaceability. Replaceability is defined as switching cost plus lead time — a vendor you could replace in 30 days with no data migration scores low; one with a 12-month transition and proprietary data integration scores high.
Tier 1: critical vendors
Tier 1 applies when a vendor scores high on at least two of the three lenses. Concrete thresholds: significant annual spend, access to PII or regulated data, or a switching timeline exceeding six months. API suppliers, cloud infrastructure providers, and any vendor processing health or financial data almost always land here. Gating items that cannot be waived: SOC 2 Type II or ISO 27001, a signed DPA, and a completed SIG Core questionnaire. On-site audit required at initial qualification and every 12 months thereafter.
Tier 2: significant vendors
Tier 2 covers vendors with moderate spend ($50,000–$500,000), limited data access (non-sensitive operational data), or moderate replaceability (3–6 months). A SIG Lite questionnaire, SOC 2 Type II or equivalent attestation, and a signed DPA are required. Remote documentation review is acceptable in place of an on-site audit. Routine re-qualification on a periodic basis or on a material change event.
When should you do an on-site audit vs. a remote review?
The decision between a remote documentation review and a full on-site audit is not a preference — it is a risk-based determination that regulated buyers must document. USP guidance on supplier oversight explicitly requires companies to record the rationale for choosing one approach over the other, and to confirm that auditors are qualified to conduct GxP assessments.
Remote documentation review is appropriate when the vendor is Tier 2 or Tier 3, has a clean prior audit history, holds a current third-party certification (SOC 2, ISO 27001, ISO 9001), and supplies non-critical materials or services. The review covers certificates, quality manuals, CAPA logs, and completed SAQ responses. It takes 1–5 days and requires no travel budget.
On-site audits are required for Tier 1 vendors, for any supplier of APIs, regulated raw materials, or medical devices, and for any vendor whose prior audit found critical findings. Pharmaceutical supplier qualification follows a four-step model — selection, qualification, monitoring, and re-qualification — and critical suppliers commonly require on-site audits at each re-qualification cycle. The audit scope for an on-site visit should cover:
Production environment and contamination controls
Quality management records (batch records, COAs, deviation logs)
CAPA system: open actions, closure rates, and root-cause documentation
Traceability: raw material receipt through finished goods release
Personnel training records and qualification logs
Document control and change management procedures
Laboratory equipment calibration and maintenance records
After the audit, score findings by severity: critical (process shutdown or regulatory action required), major (corrective action within 30 days), and minor (observation, no immediate action). Write a formal audit report within 10 business days, issue corrective action requests (CARs) for critical and major findings, and set a remediation deadline with a follow-up verification date. Store the report, CARs, and closure evidence in the vendor file with the auditor’s name, audit date, scope, and any exceptions noted.
Pro Tip: For reference material traceability in lab supply chains, require vendors to provide a chain-of-custody document alongside the audit report. This single addition satisfies most regulatory traceability expectations without adding a separate documentation step.
What security and privacy checks does a U.S. buyer need?
Information security and privacy controls are the area where qualification programs most often have gaps, particularly around sub-processor chains and 4th-party risk. The minimum evidence set for any vendor with data access is:
SOC 2 Type II report (AICPA Trust Services Criteria, issued within the last 12 months) or an ISO 27001 certificate from an accredited certification body, with a scope statement that covers the services you are procuring
Encryption standards: AES-256 at rest, TLS 1.2 or higher in transit, confirmed by vendor attestation or a SIG Lite response
Identity and access management (IAM): MFA enforced for all privileged access, least-privilege principle documented, access review cadence stated
Incident response plan: written plan with a defined notification SLA of 72 hours or less, aligned with NYDFS Part 500.11 requirements for covered entities
Vulnerability management: patch cadence policy and penetration test results from within the last 12 months (Tier 1 only)
Business continuity and disaster recovery: documented BCP/DR with tested recovery time objectives (RTOs)
SIG Lite vs. SIG Core: SIG Lite (published by Shared Assessments) covers 18 domains and roughly 200 questions — appropriate for Tier 2 vendors. SIG Core expands to the full domain set with deeper question depth and is the standard for Tier 1 vendors and any vendor subject to NYDFS Part 500.11 or OCC third-party risk management guidance. CSA STAR (Cloud Security Alliance) is the equivalent for cloud service providers and maps directly to ISO 27001 controls, making it a natural complement when a vendor holds both certifications.
Regulators are converging on the same expectations: risk-based tiering, ongoing monitoring, exit strategies, and concentration analysis. Mapping a single completed SIG Core or CSA STAR assessment to multiple regulatory frameworks — NYDFS, OCC, NIST SP 800-161 — reduces duplicate intake and saves qualification time for both buyer and vendor.
Privacy checks go beyond the DPA signature. Require the vendor to provide:
A current sub-processor list with the name, location, and processing purpose of each downstream processor
The cross-border transfer mechanism for any data leaving the U.S. or the EU (Standard Contractual Clauses, adequacy decision, or equivalent)
A data retention and deletion schedule, with a process for issuing a deletion certificate at contract end
Confirmation of CCPA / CPRA compliance where California residents’ data is involved
4th-party risk is where most programs have a blind spot. Your vendor’s sub-processors are your 4th parties, and a breach at that level is your regulatory problem. Require vendors to disclose all sub-processors in writing, flow down your audit rights contractually, and notify you within 48 hours of any material change to their sub-processor chain. For concentration risk, flag any situation where a single sub-processor (a major cloud provider, for example) supports more than 30% of your critical vendor base — a single outage at that level becomes a systemic risk.
Sample vendor questions to send during qualification:
“Please list all sub-processors who will handle our data, including their country of operation and the specific processing activity.”
“What is your maximum tolerable downtime for the service we are procuring, and when was your BCP/DR last tested?”
“Describe your process for notifying clients of a security incident and the timeline from detection to notification.”
“How do you enforce MFA for employees with access to client data environments?”
What regulatory checks and sanctions screening do U.S. organizations need?
Regulatory compliance verification is not a one-time checkbox — it is a living evidence file that must be refreshed on a defined schedule. The table below maps the most common regulatory requirements to the supplier categories they apply to, the evidence to collect, and the minimum metadata to retain.
Regulatory Requirement | Applicable Supplier Category | Evidence to Collect | Metadata to Retain | Refresh Frequency |
FDA registration (— CFR) | Pharma, food, medical device | FDA establishment registration number | Registration date, expiry, product scope | Annual |
GMP compliance | APIs, excipients, pharma raw materials | GMP certificate or audit report | Issuing body, audit date, scope, expiry | Per audit cycle |
ISO 9001 | General manufacturing, services | ISO 9001 certificate | Certification body, issue date, expiry, scope | 3-year cycle (annual surveillance) |
ISO 13485 | Medical devices, IVD | ISO 13485 certificate | Same as ISO 9001 | 3-year cycle |
— CFR Part 211 | Pharmaceutical manufacturing | Audit report or third-party GMP certificate | Auditor name, date, findings summary | Annual for Tier 1 |
— CFR Part 820 | Medical device manufacturing | Quality system audit report | Same as above | Annual for Tier 1 |
NYDFS Part 500.11 | Covered entities’ third parties | SOC 2 Type II, SIG Core, incident response plan | Assessment date, scope, findings | Annual |
OCC third-party risk | Bank-regulated entities | Risk assessment, contract review, audit rights | Assessment date, approver, tier | Annual or on material change |
OFAC sanctions screening | All vendors | Screening result with date and database version | Screener name, date, result, database | At onboarding and annually |
ESG / Scope 3 | Tier 1 and Tier 2 suppliers | Sustainability report or CDP disclosure | Reporting year, framework used | Annual |
For analytical-use labeling and regulatory compliance in lab supply chains, the same documentation discipline applies: every certificate must carry the issuing body’s name, the exact scope of accreditation, and an expiry date. A certificate without a scope statement is not evidence — it is a piece of paper.
Sanctions and watchlist screening must cover OFAC’s Specially Designated Nationals (SDN) list, the UN consolidated list, the EU consolidated list, and the UK financial sanctions list at a minimum. Screen at onboarding and repeat annually, or immediately on a material ownership change. Beneficial ownership checks should confirm UBO identity to at least 25% ownership threshold, consistent with FinCEN’s Customer Due Diligence rule.
Store all regulatory evidence in a centralized vendor file with a minimum metadata set: document type, issuing body, issue date, expiry date, scope, and the name of the person who collected and verified it. Set automated expiry alerts at 90 days before expiration so re-collection is never reactive.
How do you monitor vendor performance and manage offboarding?
Performance monitoring is where qualification programs most often stall. Teams invest heavily in onboarding diligence and then let vendors operate for years without a structured review. The four-step qualification lifecycle — selection, qualification, approval, monitoring, and re-qualification — only delivers value when the monitoring and re-qualification steps are as disciplined as the initial approval.
KPIs and SLA examples to track by vendor category:
On-time delivery rate targeting high performance levels for critical suppliers
Defect and non-conformance rates targeting very low levels for critical materials
System uptime targets consistent with industry best practices for SaaS and cloud vendors
Incident response time: time from detection to client notification (target: within 72 hours)
CAPA closure rate: percentage of corrective actions closed within the agreed deadline
Invoice accuracy rate monitored to ensure billing integrity
Re-qualification triggers and cadences:
Tier 1: annual re-qualification; immediate re-qualification on a security incident, regulatory action, ownership change, or critical quality failure
Tier 2: re-qualification every 18 months; triggered early by a major non-conformance or a change in service scope
Tier 3: re-qualification every 36 months or at contract renewal, whichever comes first
Any vendor whose KPI performance falls below the SLA threshold for two consecutive reporting periods should be placed on a formal corrective action plan (CAP) with a 60-day remediation window. Failure to close the CAP triggers an escalation to the vendor relationship owner and, if unresolved, initiates the offboarding process.
Offboarding checklist:
Issue formal termination notice per contract terms (typically 30–90 days)
Require data return in a portable format within 30 days of termination
Obtain a written deletion certificate confirming all client data has been purged from vendor and sub-processor systems
Confirm transition plan is in place, including knowledge transfer and service continuity provisions
Verify warranty claims and escrow arrangements are settled before final payment
Conduct a post-exit review and update the vendor risk register
Owner and escalation path: the vendor relationship owner (typically a category manager or QA lead) handles routine KPI reviews. SLA breaches escalate to the procurement director or VP of Quality. Security incidents escalate immediately to the CISO and Legal. Regulatory findings escalate to the Chief Compliance Officer.

Enterprise-grade vendor risk checklist: 28-domain appendix
For regulated and enterprise buyers, a 28-domain vendor risk assessment organized the way regulators review it satisfies NYDFS Part 500.11, EU DORA Article 28, and OCC third-party risk management expectations in a single completed assessment. The table below maps each domain to the required evidence, the tier where it applies, and the regulatory crosswalk.
Domain | Required Evidence | Tier | Regulatory Crosswalk |
1. Vendor identity and ownership | Business registration, UBO disclosure | 1, 2, 3 | OCC, FinCEN CDD |
2. Financial stability | Audited financials, credit report | 1, 2 | OCC |
3. Sanctions screening | OFAC/UN/EU/UK screening result | 1, 2, 3 | OFAC, FinCEN |
4. Information security governance | Security policy, CISO contact, governance structure | 1, 2 | NYDFS 500.11, NIST SP 800-161 |
5. Access control and IAM | IAM policy, MFA evidence, access review logs | 1, 2 | NYDFS 500.11, SOC 2 CC6 |
6. Encryption | Encryption standards attestation | 1, 2 | NYDFS 500.11, ISO 27001 A.10 |
7. Vulnerability management | Pen test results, patch policy | 1 | NIST CSF, SOC 2 CC7 |
8. Incident response | IR plan, notification SLA, tabletop exercise record | 1, 2 | NYDFS 500.11, DORA Art. 17 |
—. Business continuity / DR | BCP/DR plan, last test date and results | 1, 2 | OCC, DORA Art. 11 |
10. Physical security | Facility access controls, visitor logs | 1 | ISO 27001 A.11 |
11. Data classification | Data classification policy, handling procedures | 1, 2 | ISO 27001 A.8 |
12. Privacy and DPA | Signed DPA, CCPA/CPRA compliance attestation | 1, 2 | CCPA, GDPR (for EU data) |
—. Sub-processor disclosure | Sub-processor list with locations and purposes | 1, 2 | DORA Art. 28, GDPR Art. 28 |
—. Cross-border data transfers | SCCs or adequacy decision documentation | 1, 2 | GDPR, CCPA |
15. Data retention and deletion | Retention schedule, deletion certificate process | 1, 2 | CCPA, HIPAA (where applicable) |
16. Quality management | ISO 9001 / ISO 13485 certificate | 1, 2 | FDA, ISO |
17. Regulatory compliance | GMP, FDA registration, — CFR evidence | 1 | FDA, EMA (where applicable) |
18. ESG and sustainability | Sustainability report, Scope 3 disclosure | 1, 2 | SEC climate disclosure (where applicable) |
—. Anti-bribery and ethics | FCPA attestation, code of conduct signature | 1, 2 | DOJ, SEC |
20. Contract and SLA | Executed MSA, SLA with defined KPIs | 1, 2, 3 | OCC, DORA Art. 28 |
—. Audit rights | Audit rights clause, right-to-audit cascade | 1, 2 | NYDFS 500.11, OCC, DORA |
—. Exit and transition | Exit plan, data return and deletion provisions | 1, 2 | DORA Art. 28, OCC |
—. Concentration risk | Dependency analysis, alternative supplier identification | 1 | OCC, DORA Art. — |
—. 4th-party / sub-processor risk | Downstream processor disclosure, audit rights cascade | 1, 2 | DORA Art. 28, NYDFS 500.11 |
25. Performance monitoring | KPI dashboard, SLA breach history | 1, 2 | OCC, DORA |
—. Change management | Change notification process, material change triggers | 1, 2 | OCC, ISO 27001 A.12 |
—. Insurance | Cyber liability, E&O, general liability certificates | 1, 2 | OCC, contractual |
28. Scoring and approval | Completed risk score, approver sign-off, tier confirmation | 1, 2, 3 | All frameworks |
Scoring worksheet: use a 100-point rubric with weighted categories. A suggested weighting: information security (25 points), quality and compliance (20 points), financial stability (15 points), privacy and data handling (15 points), contract and legal (10 points), performance history (10 points), ESG (5 points). A score of 80 or above approves a Tier 1 vendor; 70 or above approves Tier 2. Scores below threshold require a documented risk acceptance or a remediation plan before approval.
For lab-grade chemical suppliers, ISO 17034 and ISO 17025 accreditation evidence maps directly to domains 16 and 17 in this table, providing a ready-made evidence source that satisfies both quality management and regulatory compliance checks simultaneously.
Pro Tip: When a vendor holds both a SOC 2 Type II report and a CSA STAR Level 2 certification, you can accept the CSA STAR as satisfying domains 4–11 in a single document, reducing your evidence collection burden significantly for cloud-based Tier 1 vendors.
What frameworks and tools help you operationalize the checklist?
The checklist is only as useful as the workflow it lives in. The frameworks below give you a starting structure; the tools give you a place to run it.
Questionnaire frameworks by use case:
SIG Lite (Shared Assessments): 18 domains, roughly 200 questions. Use for Tier 2 vendors and as a starting point for any vendor with data access. Freely available from Shared Assessments.
SIG Core: full domain coverage, 800+ questions. Use for Tier 1 vendors and any vendor subject to NYDFS Part 500.11 or OCC guidance. Maps directly to NIST CSF, ISO 27001, and DORA.
CAIQ (Consensus Assessments Initiative Questionnaire, CSA): cloud-specific, maps to CSA STAR controls. Use when qualifying SaaS, IaaS, or PaaS vendors. Pairs well with a vendor’s CSA STAR self-assessment or third-party certification.
CSA STAR: the cloud security registry. A vendor’s published STAR entry gives you a pre-completed CAIQ and a continuous monitoring signal without sending a separate questionnaire.
Template components to build:
SAQ (Self-Assessment Questionnaire): 10–15 questions for Tier 3; 30–50 for Tier 2. Cover identity, data access, security basics, and regulatory status. Keep it short enough that a vendor can complete it in under 30 minutes.
RFI/RFP security annex: attach a security and privacy requirements section to every RFP for Tier 1 and Tier 2 vendors. Require SOC 2 or ISO 27001 as a pass/fail criterion before scoring.
Audit report template: include fields for audit date, auditor name and qualification, scope, methodology (on-site/remote), findings by severity, CARs issued, and remediation deadlines.
One-page due diligence manifest: a single-page map of which of the 30 core checklist items apply to this specific vendor, with status (complete/waived/pending) and the name of the person who verified each item. This format, drawn from practical due diligence template guidance, is far more operationally effective than a long monolithic questionnaire because it gives reviewers an instant status view.
Automation priorities:
Evidence expiry alerts: configure your TPRM platform or a simple spreadsheet with conditional formatting to flag certificates and reports expiring within 90 days. This is the highest-value automation because it prevents the most common audit finding — expired evidence on file.
Tier routing: automate the assignment of the correct questionnaire based on intake answers. Most TPRM platforms (Prevalent, OneTrust, ProcessUnity, and similar enterprise tools) support conditional logic for this.
Scoring integration: connect questionnaire responses to a scoring engine so risk scores update automatically as vendors submit evidence. Manual scoring is a bottleneck that delays approvals.
Supplier portal: give vendors a self-service portal to upload documents, respond to questionnaires, and track their own qualification status. Completion rates improve materially when vendors can see their own progress.
Avoid the 200-question intake trap. Sending a flat, undifferentiated questionnaire to every vendor — regardless of tier — produces low completion rates and unusable risk data. Right-sized intakes by tier yield higher completion and scores you can actually act on.
Pro Tip: Start with a SIG Lite import into your TPRM platform rather than building a custom questionnaire from scratch. Most platforms support SIG Lite natively, and your vendors are more likely to have pre-completed responses ready, cutting your time-to-qualification by weeks.

Key Takeaways
A risk-based, tiered vendor qualification checklist — anchored by gating items, evidence expiry controls, and a 28-domain regulatory crosswalk — is the most reliable way to protect your supply chain and satisfy U.S. regulatory audit expectations.
Point | Details |
Tier at intake, not after | Assign Tier 1/2/3 at vendor intake using a five-question rubric; automate questionnaire routing from that point. |
Enforce gating items | SOC 2 Type II or ISO 27001 plus a signed DPA are non-waivable for Tier 1 and Tier 2 vendors with data access. |
Collect and expire evidence | Set 90-day expiry alerts for all certificates and reports; expired evidence on file is the most common audit finding. |
Map one assessment to many frameworks | A completed SIG Core or CSA STAR assessment satisfies NYDFS Part 500.11, OCC, and DORA expectations simultaneously. |
Monitor and re-qualify on cadence | Tier 1 annually, Tier 2 every 18 months, Tier 3 every 36 months; trigger early re-qualification on any security incident or ownership change. |
What most vendor qualification programs get wrong
The programs that fail share a pattern: they treat qualification as a one-time approval event rather than a continuous risk management discipline. The intake is thorough, the approval is documented, and then the vendor operates for three years with no structured review until something goes wrong.
The second most common failure is scope creep in the intake itself. A flat 200-question questionnaire sent to every vendor — the office supply company alongside the cloud infrastructure provider — produces exactly the wrong outcome. Low-risk vendors resent the burden and submit incomplete responses. High-risk vendors learn to answer the questions correctly without changing their actual controls. The result is a pile of completed forms that provide false assurance.
The third failure is treating a signed document as evidence of a control. A signed DPA does not mean the vendor has a functioning data deletion process. A signed code of conduct does not mean the vendor screens its employees. Evidence means a verifiable artifact — an audit report, a certificate from an accredited body, a penetration test result, a screenshot of an MFA enforcement policy. Signatures are contractual commitments, not operational proof.
Sub-processor chains are where the most serious gaps hide. Most qualification programs stop at the direct vendor. The vendor’s sub-processors, and their sub-processors, are where breaches actually originate in a significant share of third-party incidents. Requiring a sub-processor list and flowing down audit rights contractually costs almost nothing at the contracting stage and provides meaningful protection later.
The practical fix for all of these is the same: right-size the intake by tier, define gating items that cannot be waived, require verifiable evidence rather than attestations alone, and build a monitoring cadence that treats re-qualification as a scheduled event rather than a reactive one. Programs that do these four things consistently tend to surface real risks before they become incidents, rather than discovering them in a post-breach review.
Authoritative sources and further reading
The sources below are the primary references for the frameworks, checklists, and regulatory crosswalks in this article. Each one is worth bookmarking for ongoing program development.
For downloadable templates, the Shared Assessments SIG Lite and SIG Core questionnaires are available directly from the Shared Assessments website. CSA STAR’s CAIQ is available from the Cloud Security Alliance. Both are free to download and widely accepted by vendors who have completed them before.
FAQ
What is a vendor audit checklist?
A vendor audit checklist is a structured list of controls, documents, and process areas an auditor reviews during a supplier assessment, covering quality records, security controls, CAPA systems, traceability, and regulatory compliance. It provides a consistent, repeatable framework so audit findings can be compared across vendors and over time.
What are the key criteria for evaluating vendors?
The core vendor evaluation criteria are financial stability, information security posture (SOC 2 Type II or ISO 27001), quality certifications (ISO 9001, GMP, or equivalent), privacy and data handling practices, contractual terms (SLA, audit rights, breach notification), and performance history. Tier 1 vendors require evidence across all six; Tier 3 vendors need only identity, financial, and contract verification.
What should be included in a vendor list?
A vendor list (also called a supplier register or approved vendor list) should include the vendor’s legal name, tier assignment, primary contact, contract expiry date, last qualification date, next re-qualification date, current risk score, and the status of gating items (SOC 2, DPA, ISO certificate). Each entry should link to the vendor’s evidence file.
What are the 10 C’s of supplier evaluation?
The 10 C’s framework covers Competency, Capacity, Commitment, Control, Cash, Cost, Consistency, Culture, Clean (compliance/ethics), and Communication. While definitions vary by source, the framework is a useful memory aid for covering the full range of supplier evaluation dimensions beyond price and delivery alone.
How long does vendor qualification typically take?
Tier 1 full qualification typically takes 4–8 weeks from intake to approval, depending on vendor responsiveness and audit scheduling. Tier 2 vendor assessments are completed within several weeks relying mainly on document review, and Tier 3 can close in days with a short SAQ and a contract check.
Recommended

Comments