Vendor Selection Due Diligence

Quick Answer

Due diligence at selection asks whether a vendor is capable of performing a function for the firm. The firm looks at the vendor's standing, regulatory fit, incentives, people, controls, and resilience. The review's depth scales with risk, and it can reach the vendor's sub-contractors when they touch sensitive information or critical systems.

A vendor can perform a business function for the firm. Due diligence asks whether the vendor is capable of performing it.


What Does Due Diligence Ask at Selection?

Due diligence is the evaluation the firm performs before it engages a vendor. It asks whether the vendor is capable of performing the function.

The firm's review commonly looks at:

AreaWhat the firm evaluates
StandingFinancial condition, experience, and reputation
Regulatory fitFamiliarity with the regulatory requirements that apply to the function
IncentivesFee structure and the incentives it creates
PeopleThe background of the vendor's principals
ControlsRisk management programs and information security controls
ResilienceThe vendor's ability to keep performing through a disruption
  • The depth of the review can vary with the risk. A vendor performing a business-critical role or fulfilling a regulatory requirement warrants more than one performing a minor support task.
  • The firm also considers the vendor's own review of its sub-contractors, especially when a sub-contractor could reach sensitive firm or customer nonpublic information or a critical firm system.

Exam Tip: Gotchas

No rule sets a fixed vendor-selection checklist, a required form, or a mandatory number of steps. These are areas a firm considers, not a prescribed procedure. An answer describing a required standard vendor procedure is describing something the rules do not set.

What Should You Check on Exam Day?

  • Treat due diligence at selection as a capability question about the vendor.
  • Expect areas of review rather than a required checklist or form.
  • Scale the review to the risk, and reach the vendor's sub-contractors when they touch sensitive information or critical systems.