fbq('init', '1337602038265402', { em: 'email@email.com', // Values will be hashed automatically by the pixel using SHA-256 ph: '1234567890', ... });
top of page
Search

Vendor Qualification Checklist for Procurement & QA Teams


Checklist on clipboard in laboratory office

TL;DR:  
  • A vendor qualification checklist verifies supplier capability, compliance, and risk before awarding business. Vendors with access to sensitive data or regulated materials must pass full qualification against specific standards; low-risk vendors can undergo lightweight onboarding. Proper tiering, evidence management, and continuous re-evaluation are essential for effective supply chain risk management.

 

A vendor qualification checklist is a structured set of criteria, evidence requirements, and approval gates that procurement and quality assurance teams use to verify a supplier’s capability, compliance, and risk profile before awarding business or allowing materials into a regulated supply chain.

 

The short version: if a vendor touches your data, your product, or your regulatory status, they need to pass a documented qualification before you sign anything.

 

Quick-gate checklist — apply to every new vendor at intake:

 

  • Legal identity verified: business registration, DUNS/EIN, UBO disclosure, OFAC/UN/EU sanctions screening

  • Financial stability confirmed: credit report, audited financials (Tier 1: two years minimum), no active insolvency proceedings

  • Information security evidence collected: SOC 2 Type II report or ISO 27001 certificate with current scope; encryption and IAM controls confirmed

  • Privacy and data handling documented: signed Data Processing Agreement (DPA), sub-processor list, cross-border transfer mechanism (SCCs or adequacy decision)

  • Regulatory and quality certifications on file: ISO 9001, ISO 13485, GMP, FDA registration, or equivalent as applicable to the vendor’s category

  • Contract terms reviewed: MSA, SLA, breach notification window (72 hours or less), audit rights clause, exit and transition provisions

  • Tier assigned and gating items confirmed: Tier 1 vendors require SOC 2 Type II or ISO 27001 plus a signed DPA before approval; no exceptions without a documented waiver

 

Verdict: vendors with access to sensitive data, regulated materials, or critical production inputs require full qualification against SIG Lite (at minimum) or SIG Core, CSA STAR, NIST SP 800-161, and where applicable NYDFS Part 500.11 and OCC third-party risk guidance. Vendors with no data access and low spend can proceed through a lightweight onboarding with an SAQ and document review only.

 

Table of Contents

 

 

What does a complete vendor qualification checklist cover?

 

A vendor due diligence checklist organized across six categories gives procurement and QA teams a single working document they can copy into a supplier portal, spreadsheet, or TPRM platform. The table below spans 28 core line items calibrated to Tier 1 depth, with Tier 2 and Tier 3 collapses noted per row.

 

#

Category

Checklist Item

Tier 1

Tier 2

Tier 3

Owner

Notes

1

Identity

Business registration / articles of incorporation

Procurement

State or federal filing

2

Identity

DUNS number or EIN confirmation

Procurement

Cross-check with SAM.gov

3

Identity

Ultimate Beneficial Owner (UBO) disclosure

Procurement

FinCEN CDD rule

4

Identity

OFAC, UN, EU, UK consolidated watchlist screening

Compliance

Repeat annually

5

Financial

Audited financials (2 years)

Procurement

Dun & Bradstreet or equivalent

6

Financial

Credit report / Dun & Bradstreet score

Procurement

Flag scores below threshold

7

Financial

No active insolvency / bankruptcy proceedings

Legal

PACER search or equivalent

8

Security

SOC 2 Type II report (within 12 months)

InfoSec

Bridge letter if >12 months old

Security

ISO 27001 certificate with current scope

InfoSec

Verify accreditation body

10

Security

Encryption standards confirmed (AES-256 at rest, TLS 1.2+ in transit)

InfoSec

Vendor attestation or SAQ

11

Security

IAM policy and MFA enforcement documented

InfoSec

SIG Lite domain 7

12

Security

Incident response plan with defined notification SLA

InfoSec

72-hour notification minimum

Security

Penetration test results (within 12 months)

InfoSec

Tier 1 only

Privacy

Signed DPA (CCPA / CPRA / state law as applicable)

Legal

Gating item for Tier 1 and 2

15

Privacy

Sub-processor list with names and locations

Legal

Update on change

16

Privacy

Cross-border transfer mechanism (SCCs or adequacy)

Legal

Required for EU data flows

17

Privacy

Data retention and deletion schedule

Legal

Confirm deletion certificate process

18

Compliance

ISO 9001 or ISO 13485 certificate

QA

Verify scope matches supply

Compliance

GMP / FDA registration (where applicable)

QA / Regulatory

APIs, pharma, medical devices

20

Compliance

Compliance evidence

QA / Regulatory

Pharma and device only

Compliance

ESG / sustainability disclosure

Procurement

Scope 3 reporting where required

Compliance

Anti-bribery / FCPA attestation

Legal

Signed vendor code of conduct

Contract

Master Services Agreement (MSA) executed

Legal

Include IP ownership clause

Contract

SLA with defined uptime / delivery / defect KPIs

Procurement

Tie to re-qualification triggers

25

Contract

Breach notification clause (72 hours or less)

Legal

NYDFS Part 500.11 alignment

Contract

Audit rights clause (right to audit or third-party equivalent)

Legal

Cascade to sub-processors

Contract

Exit / transition plan and data return provisions

Legal / Procurement

Include deletion certificate

28

Performance

Reference checks (2 minimum for Tier 1)

Procurement

Peer industry references preferred

Performance

Sample testing or first-article inspection

QA

30

Performance

On-site or remote audit completed and documented

QA / Audit

See audit section below

Timeline and cost: a Tier 1 full qualification typically takes 4–8 weeks from intake to approval, depending on vendor responsiveness and audit scheduling. Tier 2 vendor assessments are completed within several weeks relying mainly on document review. Tier 3 vendor qualification can be completed in a short time using self-assessment questionnaires and contract checks. Cost drivers include auditor fees for on-site visits, third-party screening subscriptions (Dun & Bradstreet, Refinitiv World-Check), and TPRM platform licensing.

 

Pro Tip: Copy this table into a Google Sheet or your TPRM platform, add a “Status” column (Not Started / In Progress / Complete / Waived), and assign an owner to each row at intake. A waived item must carry a written rationale and an approver signature — never leave it blank.

 

How do you tier vendors and right-size due diligence?

 

Tiering is the single most effective way to prevent your qualification program from collapsing under its own weight. Without it, every vendor gets the same 200-question intake, completion rates drop, and the risk scores you collect are useless because low-risk vendors game the process while high-risk vendors slip through on the same form.

 

The rubric below uses three lenses scored at intake: data sensitivity × spend × replaceability. Replaceability is defined as switching cost plus lead time — a vendor you could replace in 30 days with no data migration scores low; one with a 12-month transition and proprietary data integration scores high.

 

Tier 1: critical vendors

 

Tier 1 applies when a vendor scores high on at least two of the three lenses. Concrete thresholds: significant annual spend, access to PII or regulated data, or a switching timeline exceeding six months. API suppliers, cloud infrastructure providers, and any vendor processing health or financial data almost always land here. Gating items that cannot be waived: SOC 2 Type II or ISO 27001, a signed DPA, and a completed SIG Core questionnaire. On-site audit required at initial qualification and every 12 months thereafter.

 

Tier 2: significant vendors

 

Tier 2 covers vendors with moderate spend ($50,000–$500,000), limited data access (non-sensitive operational data), or moderate replaceability (3–6 months). A SIG Lite questionnaire, SOC 2 Type II or equivalent attestation, and a signed DPA are required. Remote documentation review is acceptable in place of an on-site audit. Routine re-qualification on a periodic basis or on a material change event.

 

When should you do an on-site audit vs. a remote review?

 

The decision between a remote documentation review and a full on-site audit is not a preference — it is a risk-based determination that regulated buyers must document. USP guidance on supplier oversight explicitly requires companies to record the rationale for choosing one approach over the other, and to confirm that auditors are qualified to conduct GxP assessments.

 

Remote documentation review is appropriate when the vendor is Tier 2 or Tier 3, has a clean prior audit history, holds a current third-party certification (SOC 2, ISO 27001, ISO 9001), and supplies non-critical materials or services. The review covers certificates, quality manuals, CAPA logs, and completed SAQ responses. It takes 1–5 days and requires no travel budget.

 

On-site audits are required for Tier 1 vendors, for any supplier of APIs, regulated raw materials, or medical devices, and for any vendor whose prior audit found critical findings. Pharmaceutical supplier qualification follows a four-step model — selection, qualification, monitoring, and re-qualification — and critical suppliers commonly require on-site audits at each re-qualification cycle. The audit scope for an on-site visit should cover:

 

  • Production environment and contamination controls

  • Quality management records (batch records, COAs, deviation logs)

  • CAPA system: open actions, closure rates, and root-cause documentation

  • Traceability: raw material receipt through finished goods release

  • Personnel training records and qualification logs

  • Document control and change management procedures

  • Laboratory equipment calibration and maintenance records

 

After the audit, score findings by severity: critical (process shutdown or regulatory action required), major (corrective action within 30 days), and minor (observation, no immediate action). Write a formal audit report within 10 business days, issue corrective action requests (CARs) for critical and major findings, and set a remediation deadline with a follow-up verification date. Store the report, CARs, and closure evidence in the vendor file with the auditor’s name, audit date, scope, and any exceptions noted.

 

Pro Tip: For reference material traceability in lab supply chains, require vendors to provide a chain-of-custody document alongside the audit report. This single addition satisfies most regulatory traceability expectations without adding a separate documentation step.

 

What security and privacy checks does a U.S. buyer need?

 

Information security and privacy controls are the area where qualification programs most often have gaps, particularly around sub-processor chains and 4th-party risk. The minimum evidence set for any vendor with data access is:

 

  • SOC 2 Type II report (AICPA Trust Services Criteria, issued within the last 12 months) or an ISO 27001 certificate from an accredited certification body, with a scope statement that covers the services you are procuring

  • Encryption standards: AES-256 at rest, TLS 1.2 or higher in transit, confirmed by vendor attestation or a SIG Lite response

  • Identity and access management (IAM): MFA enforced for all privileged access, least-privilege principle documented, access review cadence stated

  • Incident response plan: written plan with a defined notification SLA of 72 hours or less, aligned with NYDFS Part 500.11 requirements for covered entities

  • Vulnerability management: patch cadence policy and penetration test results from within the last 12 months (Tier 1 only)

  • Business continuity and disaster recovery: documented BCP/DR with tested recovery time objectives (RTOs)

 

SIG Lite vs. SIG Core: SIG Lite (published by Shared Assessments) covers 18 domains and roughly 200 questions — appropriate for Tier 2 vendors. SIG Core expands to the full domain set with deeper question depth and is the standard for Tier 1 vendors and any vendor subject to NYDFS Part 500.11 or OCC third-party risk management guidance. CSA STAR (Cloud Security Alliance) is the equivalent for cloud service providers and maps directly to ISO 27001 controls, making it a natural complement when a vendor holds both certifications.

 

Regulators are converging on the same expectations: risk-based tiering, ongoing monitoring, exit strategies, and concentration analysis. Mapping a single completed SIG Core or CSA STAR assessment to multiple regulatory frameworks — NYDFS, OCC, NIST SP 800-161 — reduces duplicate intake and saves qualification time for both buyer and vendor.

 

Privacy checks go beyond the DPA signature. Require the vendor to provide:

 

  • A current sub-processor list with the name, location, and processing purpose of each downstream processor

  • The cross-border transfer mechanism for any data leaving the U.S. or the EU (Standard Contractual Clauses, adequacy decision, or equivalent)

  • A data retention and deletion schedule, with a process for issuing a deletion certificate at contract end

  • Confirmation of CCPA / CPRA compliance where California residents’ data is involved

 

4th-party risk is where most programs have a blind spot. Your vendor’s sub-processors are your 4th parties, and a breach at that level is your regulatory problem. Require vendors to disclose all sub-processors in writing, flow down your audit rights contractually, and notify you within 48 hours of any material change to their sub-processor chain. For concentration risk, flag any situation where a single sub-processor (a major cloud provider, for example) supports more than 30% of your critical vendor base — a single outage at that level becomes a systemic risk.

 

Sample vendor questions to send during qualification:

 

  • “Please list all sub-processors who will handle our data, including their country of operation and the specific processing activity.”

  • “What is your maximum tolerable downtime for the service we are procuring, and when was your BCP/DR last tested?”

  • “Describe your process for notifying clients of a security incident and the timeline from detection to notification.”

  • “How do you enforce MFA for employees with access to client data environments?”

 

What regulatory checks and sanctions screening do U.S. organizations need?

 

Regulatory compliance verification is not a one-time checkbox — it is a living evidence file that must be refreshed on a defined schedule. The table below maps the most common regulatory requirements to the supplier categories they apply to, the evidence to collect, and the minimum metadata to retain.

 

Regulatory Requirement

Applicable Supplier Category

Evidence to Collect

Metadata to Retain

Refresh Frequency

FDA registration (— CFR)

Pharma, food, medical device

FDA establishment registration number

Registration date, expiry, product scope

Annual

GMP compliance

APIs, excipients, pharma raw materials

GMP certificate or audit report

Issuing body, audit date, scope, expiry

Per audit cycle

ISO 9001

General manufacturing, services

ISO 9001 certificate

Certification body, issue date, expiry, scope

3-year cycle (annual surveillance)

ISO 13485

Medical devices, IVD

ISO 13485 certificate

Same as ISO 9001

3-year cycle

— CFR Part 211

Pharmaceutical manufacturing

Audit report or third-party GMP certificate

Auditor name, date, findings summary

Annual for Tier 1

— CFR Part 820

Medical device manufacturing

Quality system audit report

Same as above

Annual for Tier 1

NYDFS Part 500.11

Covered entities’ third parties

SOC 2 Type II, SIG Core, incident response plan

Assessment date, scope, findings

Annual

OCC third-party risk

Bank-regulated entities

Risk assessment, contract review, audit rights

Assessment date, approver, tier

Annual or on material change

OFAC sanctions screening

All vendors

Screening result with date and database version

Screener name, date, result, database

At onboarding and annually

ESG / Scope 3

Tier 1 and Tier 2 suppliers

Sustainability report or CDP disclosure

Reporting year, framework used

Annual

For analytical-use labeling and regulatory compliance in lab supply chains, the same documentation discipline applies: every certificate must carry the issuing body’s name, the exact scope of accreditation, and an expiry date. A certificate without a scope statement is not evidence — it is a piece of paper.

 

Sanctions and watchlist screening must cover OFAC’s Specially Designated Nationals (SDN) list, the UN consolidated list, the EU consolidated list, and the UK financial sanctions list at a minimum. Screen at onboarding and repeat annually, or immediately on a material ownership change. Beneficial ownership checks should confirm UBO identity to at least 25% ownership threshold, consistent with FinCEN’s Customer Due Diligence rule.

 

Store all regulatory evidence in a centralized vendor file with a minimum metadata set: document type, issuing body, issue date, expiry date, scope, and the name of the person who collected and verified it. Set automated expiry alerts at 90 days before expiration so re-collection is never reactive.

 

How do you monitor vendor performance and manage offboarding?

 

Performance monitoring is where qualification programs most often stall. Teams invest heavily in onboarding diligence and then let vendors operate for years without a structured review. The four-step qualification lifecycle — selection, qualification, approval, monitoring, and re-qualification — only delivers value when the monitoring and re-qualification steps are as disciplined as the initial approval.

 

KPIs and SLA examples to track by vendor category:

 

  • On-time delivery rate targeting high performance levels for critical suppliers

  • Defect and non-conformance rates targeting very low levels for critical materials

  • System uptime targets consistent with industry best practices for SaaS and cloud vendors

  • Incident response time: time from detection to client notification (target: within 72 hours)

  • CAPA closure rate: percentage of corrective actions closed within the agreed deadline

  • Invoice accuracy rate monitored to ensure billing integrity

 

Re-qualification triggers and cadences:

 

  • Tier 1: annual re-qualification; immediate re-qualification on a security incident, regulatory action, ownership change, or critical quality failure

  • Tier 2: re-qualification every 18 months; triggered early by a major non-conformance or a change in service scope

  • Tier 3: re-qualification every 36 months or at contract renewal, whichever comes first

 

Any vendor whose KPI performance falls below the SLA threshold for two consecutive reporting periods should be placed on a formal corrective action plan (CAP) with a 60-day remediation window. Failure to close the CAP triggers an escalation to the vendor relationship owner and, if unresolved, initiates the offboarding process.

 

Offboarding checklist:

 

  • Issue formal termination notice per contract terms (typically 30–90 days)

  • Require data return in a portable format within 30 days of termination

  • Obtain a written deletion certificate confirming all client data has been purged from vendor and sub-processor systems

  • Confirm transition plan is in place, including knowledge transfer and service continuity provisions

  • Verify warranty claims and escrow arrangements are settled before final payment

  • Conduct a post-exit review and update the vendor risk register

 

Owner and escalation path: the vendor relationship owner (typically a category manager or QA lead) handles routine KPI reviews. SLA breaches escalate to the procurement director or VP of Quality. Security incidents escalate immediately to the CISO and Legal. Regulatory findings escalate to the Chief Compliance Officer.

 


How do you monitor vendor performance and manage offboarding? — overview diagram

Enterprise-grade vendor risk checklist: 28-domain appendix

 

For regulated and enterprise buyers, a 28-domain vendor risk assessment organized the way regulators review it satisfies NYDFS Part 500.11, EU DORA Article 28, and OCC third-party risk management expectations in a single completed assessment. The table below maps each domain to the required evidence, the tier where it applies, and the regulatory crosswalk.

 

Domain

Required Evidence

Tier

Regulatory Crosswalk

1. Vendor identity and ownership

Business registration, UBO disclosure

1, 2, 3

OCC, FinCEN CDD

2. Financial stability

Audited financials, credit report

1, 2

OCC

3. Sanctions screening

OFAC/UN/EU/UK screening result

1, 2, 3

OFAC, FinCEN

4. Information security governance

Security policy, CISO contact, governance structure

1, 2

NYDFS 500.11, NIST SP 800-161

5. Access control and IAM

IAM policy, MFA evidence, access review logs

1, 2

NYDFS 500.11, SOC 2 CC6

6. Encryption

Encryption standards attestation

1, 2

NYDFS 500.11, ISO 27001 A.10

7. Vulnerability management

Pen test results, patch policy

1

NIST CSF, SOC 2 CC7

8. Incident response

IR plan, notification SLA, tabletop exercise record

1, 2

NYDFS 500.11, DORA Art. 17

—. Business continuity / DR

BCP/DR plan, last test date and results

1, 2

OCC, DORA Art. 11

10. Physical security

Facility access controls, visitor logs

1

ISO 27001 A.11

11. Data classification

Data classification policy, handling procedures

1, 2

ISO 27001 A.8

12. Privacy and DPA

Signed DPA, CCPA/CPRA compliance attestation

1, 2

CCPA, GDPR (for EU data)

—. Sub-processor disclosure

Sub-processor list with locations and purposes

1, 2

DORA Art. 28, GDPR Art. 28

—. Cross-border data transfers

SCCs or adequacy decision documentation

1, 2

GDPR, CCPA

15. Data retention and deletion

Retention schedule, deletion certificate process

1, 2

CCPA, HIPAA (where applicable)

16. Quality management

ISO 9001 / ISO 13485 certificate

1, 2

FDA, ISO

17. Regulatory compliance

GMP, FDA registration, — CFR evidence

1

FDA, EMA (where applicable)

18. ESG and sustainability

Sustainability report, Scope 3 disclosure

1, 2

SEC climate disclosure (where applicable)

—. Anti-bribery and ethics

FCPA attestation, code of conduct signature

1, 2

DOJ, SEC

20. Contract and SLA

Executed MSA, SLA with defined KPIs

1, 2, 3

OCC, DORA Art. 28

—. Audit rights

Audit rights clause, right-to-audit cascade

1, 2

NYDFS 500.11, OCC, DORA

—. Exit and transition

Exit plan, data return and deletion provisions

1, 2

DORA Art. 28, OCC

—. Concentration risk

Dependency analysis, alternative supplier identification

1

OCC, DORA Art. —

—. 4th-party / sub-processor risk

Downstream processor disclosure, audit rights cascade

1, 2

DORA Art. 28, NYDFS 500.11

25. Performance monitoring

KPI dashboard, SLA breach history

1, 2

OCC, DORA

—. Change management

Change notification process, material change triggers

1, 2

OCC, ISO 27001 A.12

—. Insurance

Cyber liability, E&O, general liability certificates

1, 2

OCC, contractual

28. Scoring and approval

Completed risk score, approver sign-off, tier confirmation

1, 2, 3

All frameworks

Scoring worksheet: use a 100-point rubric with weighted categories. A suggested weighting: information security (25 points), quality and compliance (20 points), financial stability (15 points), privacy and data handling (15 points), contract and legal (10 points), performance history (10 points), ESG (5 points). A score of 80 or above approves a Tier 1 vendor; 70 or above approves Tier 2. Scores below threshold require a documented risk acceptance or a remediation plan before approval.

 

For lab-grade chemical suppliers, ISO 17034 and ISO 17025 accreditation evidence maps directly to domains 16 and 17 in this table, providing a ready-made evidence source that satisfies both quality management and regulatory compliance checks simultaneously.

 

Pro Tip: When a vendor holds both a SOC 2 Type II report and a CSA STAR Level 2 certification, you can accept the CSA STAR as satisfying domains 4–11 in a single document, reducing your evidence collection burden significantly for cloud-based Tier 1 vendors.

 

What frameworks and tools help you operationalize the checklist?

 

The checklist is only as useful as the workflow it lives in. The frameworks below give you a starting structure; the tools give you a place to run it.

 

Questionnaire frameworks by use case:

 

  • SIG Lite (Shared Assessments): 18 domains, roughly 200 questions. Use for Tier 2 vendors and as a starting point for any vendor with data access. Freely available from Shared Assessments.

  • SIG Core: full domain coverage, 800+ questions. Use for Tier 1 vendors and any vendor subject to NYDFS Part 500.11 or OCC guidance. Maps directly to NIST CSF, ISO 27001, and DORA.

  • CAIQ (Consensus Assessments Initiative Questionnaire, CSA): cloud-specific, maps to CSA STAR controls. Use when qualifying SaaS, IaaS, or PaaS vendors. Pairs well with a vendor’s CSA STAR self-assessment or third-party certification.

  • CSA STAR: the cloud security registry. A vendor’s published STAR entry gives you a pre-completed CAIQ and a continuous monitoring signal without sending a separate questionnaire.

 

Template components to build:

 

  • SAQ (Self-Assessment Questionnaire): 10–15 questions for Tier 3; 30–50 for Tier 2. Cover identity, data access, security basics, and regulatory status. Keep it short enough that a vendor can complete it in under 30 minutes.

  • RFI/RFP security annex: attach a security and privacy requirements section to every RFP for Tier 1 and Tier 2 vendors. Require SOC 2 or ISO 27001 as a pass/fail criterion before scoring.

  • Audit report template: include fields for audit date, auditor name and qualification, scope, methodology (on-site/remote), findings by severity, CARs issued, and remediation deadlines.

  • One-page due diligence manifest: a single-page map of which of the 30 core checklist items apply to this specific vendor, with status (complete/waived/pending) and the name of the person who verified each item. This format, drawn from practical due diligence template guidance, is far more operationally effective than a long monolithic questionnaire because it gives reviewers an instant status view.

 

Automation priorities:

 

  1. Evidence expiry alerts: configure your TPRM platform or a simple spreadsheet with conditional formatting to flag certificates and reports expiring within 90 days. This is the highest-value automation because it prevents the most common audit finding — expired evidence on file.

  2. Tier routing: automate the assignment of the correct questionnaire based on intake answers. Most TPRM platforms (Prevalent, OneTrust, ProcessUnity, and similar enterprise tools) support conditional logic for this.

  3. Scoring integration: connect questionnaire responses to a scoring engine so risk scores update automatically as vendors submit evidence. Manual scoring is a bottleneck that delays approvals.

  4. Supplier portal: give vendors a self-service portal to upload documents, respond to questionnaires, and track their own qualification status. Completion rates improve materially when vendors can see their own progress.

 

Avoid the 200-question intake trap. Sending a flat, undifferentiated questionnaire to every vendor — regardless of tier — produces low completion rates and unusable risk data. Right-sized intakes by tier yield higher completion and scores you can actually act on.

 

Pro Tip: Start with a SIG Lite import into your TPRM platform rather than building a custom questionnaire from scratch. Most platforms support SIG Lite natively, and your vendors are more likely to have pre-completed responses ready, cutting your time-to-qualification by weeks.

 


What frameworks and tools help you operationalize the checklist? — overview diagram

Key Takeaways

 

A risk-based, tiered vendor qualification checklist — anchored by gating items, evidence expiry controls, and a 28-domain regulatory crosswalk — is the most reliable way to protect your supply chain and satisfy U.S. regulatory audit expectations.

 

Point

Details

Tier at intake, not after

Assign Tier 1/2/3 at vendor intake using a five-question rubric; automate questionnaire routing from that point.

Enforce gating items

SOC 2 Type II or ISO 27001 plus a signed DPA are non-waivable for Tier 1 and Tier 2 vendors with data access.

Collect and expire evidence

Set 90-day expiry alerts for all certificates and reports; expired evidence on file is the most common audit finding.

Map one assessment to many frameworks

A completed SIG Core or CSA STAR assessment satisfies NYDFS Part 500.11, OCC, and DORA expectations simultaneously.

Monitor and re-qualify on cadence

Tier 1 annually, Tier 2 every 18 months, Tier 3 every 36 months; trigger early re-qualification on any security incident or ownership change.

What most vendor qualification programs get wrong

 

The programs that fail share a pattern: they treat qualification as a one-time approval event rather than a continuous risk management discipline. The intake is thorough, the approval is documented, and then the vendor operates for three years with no structured review until something goes wrong.

 

The second most common failure is scope creep in the intake itself. A flat 200-question questionnaire sent to every vendor — the office supply company alongside the cloud infrastructure provider — produces exactly the wrong outcome. Low-risk vendors resent the burden and submit incomplete responses. High-risk vendors learn to answer the questions correctly without changing their actual controls. The result is a pile of completed forms that provide false assurance.

 

The third failure is treating a signed document as evidence of a control. A signed DPA does not mean the vendor has a functioning data deletion process. A signed code of conduct does not mean the vendor screens its employees. Evidence means a verifiable artifact — an audit report, a certificate from an accredited body, a penetration test result, a screenshot of an MFA enforcement policy. Signatures are contractual commitments, not operational proof.

 

Sub-processor chains are where the most serious gaps hide. Most qualification programs stop at the direct vendor. The vendor’s sub-processors, and their sub-processors, are where breaches actually originate in a significant share of third-party incidents. Requiring a sub-processor list and flowing down audit rights contractually costs almost nothing at the contracting stage and provides meaningful protection later.

 

The practical fix for all of these is the same: right-size the intake by tier, define gating items that cannot be waived, require verifiable evidence rather than attestations alone, and build a monitoring cadence that treats re-qualification as a scheduled event rather than a reactive one. Programs that do these four things consistently tend to surface real risks before they become incidents, rather than discovering them in a post-breach review.

 

Authoritative sources and further reading

 

The sources below are the primary references for the frameworks, checklists, and regulatory crosswalks in this article. Each one is worth bookmarking for ongoing program development.

 

 

For downloadable templates, the Shared Assessments SIG Lite and SIG Core questionnaires are available directly from the Shared Assessments website. CSA STAR’s CAIQ is available from the Cloud Security Alliance. Both are free to download and widely accepted by vendors who have completed them before.

 

FAQ

 

What is a vendor audit checklist?

 

A vendor audit checklist is a structured list of controls, documents, and process areas an auditor reviews during a supplier assessment, covering quality records, security controls, CAPA systems, traceability, and regulatory compliance. It provides a consistent, repeatable framework so audit findings can be compared across vendors and over time.

 

What are the key criteria for evaluating vendors?

 

The core vendor evaluation criteria are financial stability, information security posture (SOC 2 Type II or ISO 27001), quality certifications (ISO 9001, GMP, or equivalent), privacy and data handling practices, contractual terms (SLA, audit rights, breach notification), and performance history. Tier 1 vendors require evidence across all six; Tier 3 vendors need only identity, financial, and contract verification.

 

What should be included in a vendor list?

 

A vendor list (also called a supplier register or approved vendor list) should include the vendor’s legal name, tier assignment, primary contact, contract expiry date, last qualification date, next re-qualification date, current risk score, and the status of gating items (SOC 2, DPA, ISO certificate). Each entry should link to the vendor’s evidence file.

 

What are the 10 C’s of supplier evaluation?

 

The 10 C’s framework covers Competency, Capacity, Commitment, Control, Cash, Cost, Consistency, Culture, Clean (compliance/ethics), and Communication. While definitions vary by source, the framework is a useful memory aid for covering the full range of supplier evaluation dimensions beyond price and delivery alone.

 

How long does vendor qualification typically take?

 

Tier 1 full qualification typically takes 4–8 weeks from intake to approval, depending on vendor responsiveness and audit scheduling. Tier 2 vendor assessments are completed within several weeks relying mainly on document review, and Tier 3 can close in days with a short SAQ and a contract check.

 

Recommended

 

 
 
 

Comments


bottom of page