Quick answerThird-party due diligence is the structured evaluation of an external party – supplier, processor, vendor, contractor – before and during the relationship. It typically combines questionnaires, evidence review, contract review and risk classification, scaled to the third party’s risk tier. Done well, it produces decisions; done badly, it produces paperwork.
What due diligence is
Due diligence is the act of looking before you commit. In third-party risk management, it is the structured process of evaluating an external party’s controls, practices and risk profile before entering or renewing a relationship – and continuing to evaluate them during the relationship. The depth scales to risk: a critical processor handling sensitive personal data warrants deep diligence; a one-off office-supplies vendor does not.
What it includes
- Questionnaires (security, privacy, AI-specific, sector-specific)
- Supporting evidence – certifications (SOC 2, ISO 27001, ISO 42001), audit reports, policies
- Risk classification – inherent risk before controls, residual risk after
- Contract and SLA review
- Reference checks where appropriate
- Sub-processor disclosure and review
- Financial-health checks for critical third parties
- Periodic reassessment on a defined cycle
Tiering the diligence
Tier 1 – critical
Material data access, operationally critical, regulatory exposure. Full diligence pack, annual reassessment, executive-level review. ~5-15% of third parties.
Tier 2 – material
Some data access, important but not critical. Standard diligence pack, 24-month reassessment. ~25-40% of third parties.
Tier 3 – light-touch
Minimal data access, easily replaceable. Lightweight checklist, contract-renewal-triggered review. ~50-70% of third parties.
Common questionnaires
- SIG (Standardized Information Gathering) – long-form security and privacy questionnaire
- SIG Lite – shorter version of SIG
- Cloud Security Alliance CAIQ – cloud-specific
- ISO 27001 / ISO 27701 / ISO 42001 statement of applicability where the third party is certified
- Sector-specific (FS-ISAC, HITRUST, NIST CSF)
- PrivIQ’s own privacy and AI third-party assessment templates
What to ask AI vendors specifically
- Model provenance – built in-house, foundation model, fine-tuned, vendor-licensed
- Training data sources and consent basis
- Model behaviour – accuracy, bias testing, hallucination handling
- Human-oversight responsibilities – yours, theirs, joint
- Sub-processors – including the underlying model provider
- Data retention and training opt-out arrangements
- Incident reporting commitments
When due diligence becomes paperwork
The failure mode of due diligence programmes is collecting evidence without making decisions. A 200-question SIG questionnaire returned with 200 answers is not, by itself, due diligence – it’s an input. The diligence is in the analysis: which answers indicate risk, what mitigations apply, what’s the residual position, sign-off decision. Programmes that stop at evidence collection produce paperwork; programmes that close with documented decisions produce risk management.
How PrivIQ supports due diligence
PrivIQ ships configured questionnaire templates across security, privacy, AI and sector-specific dimensions. Evidence is collected against each criterion. Risk classification and residual position are documented per third party. Sub-processor cascades are visible. Periodic reassessment runs automatically against the defined cycle.
- Due diligence scales to risk tier – not every third party needs the same depth.
- AI vendors need AI-specific questions: model provenance, training data, oversight, sub-processors.
- The failure mode is collecting evidence without making decisions.
- Periodic reassessment matters as much as onboarding diligence.
PrivIQ helps organisations and consultants put this into practice — with policies, controls, evidence, tasks, registers and reporting that survive audit.
More on Third-Party Risk.
Can I rely on a third party’s SOC 2 report?
As one input, yes. SOC 2 reports cover security and operational controls in defined scope. They do not cover privacy practices, AI behaviour, financial health or operational fit. Read the scope carefully and use the report as a signal, not a conclusion.
How long should third-party due diligence take?
Tier-1: 2-4 weeks. Tier-2: 1-2 weeks. Tier-3: hours. Programmes that take longer than this typically have process problems, not depth problems.
Who signs off on a third-party diligence result?
For tier-1: the accountable business owner plus the relevant control owners (privacy, security, risk). For tier-2: the accountable business owner plus a single control owner. For tier-3: the accountable business owner alone.
Do I need to do due diligence on existing third parties?
Yes. Most programmes start with a backlog of un-assessed legacy third parties. Risk-tier them, then do tier-1 diligence first. Tier-2 and tier-3 can roll out on contract renewal.
What if a third party refuses to complete a questionnaire?
Their willingness to engage with due diligence is itself a signal. For tier-1 third parties, refusal is typically a deal-breaker. For tier-3, you accept the higher unknown risk and document it.