The Vendor Due Diligence Checklist for Finance Teams
A vendor due diligence checklist is the fixed set of documents, questions, and controls you work through before signing a vendor that will hold your data or move your money. Its job is to make the review repeatable, so the outcome doesn't depend on who happened to run it that quarter.
Most finance teams inherit this work without asking for it. There's no dedicated third-party risk function, procurement wants a signature before quarter end, IT will look at the architecture if you ask nicely, and the security questionnaire lands on the controller's desk. You aren't a security auditor, and you're still the person whose name goes on the approval.
The exposure has shifted enough to justify the discomfort. Verizon's 2026 Data Breach Investigations Report found that 48% of all breaches involved a third party, a 60% year-over-year increase. Roughly half of the breach problem now arrives through an organization you signed a contract with.
Key Takeaways
Vendor due diligence is the pre-signature review of a vendor's documents and controls, while vendor management is the ongoing relationship that follows it.
Seven artifacts cover most of the ground, and each one proves something narrower than its name suggests.
A SOC 2 Type II report is only as good as its scope, its period, its exception table, and its subservice carve-outs.
Payments vendors need questions the generic templates skip, starting with how supplier banking details get validated and changed.
Tiering keeps the workload honest, because a vendor that can move money deserves scrutiny that a vendor selling training videos does not.
Findings that never become contract language quietly evaporate at signature.
What is vendor due diligence, and when does finance own it?
Vendor due diligence is the review you run before signing to confirm that a vendor's security, financial stability, and operational controls are adequate for what you're about to hand them. It ends at signature, and everything after that is vendor management.
The two get conflated constantly, which is how a company ends up with a thick onboarding file and no idea whether the vendor's controls still hold three years later. The vendor lifecycle work that follows the contract covers master-data setup, banking verification, performance review, and offboarding. Diligence is narrower and happens once, under time pressure, with the leverage you'll never have again.
Direction of travel supports doing it properly. SecurityScorecard's 2025 Global Third-Party Breach Report found that 35.5% of breaches in 2024 involved third-party or vendor access, up from 29% in 2023. The two studies count differently and shouldn't be read as one trend line, but they point the same way.
How is due diligence different from ongoing vendor management?
Due diligence is a decision process with a yes or no at the end. Vendor management is a monitoring process with no end at all, and the controls it depends on are the ones diligence was supposed to verify in the first place.
The practical difference is leverage. Before you sign, a vendor will answer a 90-question security questionnaire, produce a subservice list, and put a breach notification window in writing. After you sign, the same request goes to a support queue and comes back in six weeks with a marketing PDF. Anything you actually need to know, you ask for now.
There's a sequencing consequence people miss. If diligence surfaces a gap you decide to accept, that acceptance belongs in the vendor management program as a monitored item with a named owner, not in a folder nobody opens. Otherwise the gap becomes institutional knowledge that leaves with the person who found it.
Which vendors need a security review, and which do not?
Any vendor that can access your financial systems, hold supplier or employee data, or initiate a payment needs a security review. Everything else can usually be handled with a contract and an insurance certificate.
The trigger points that pull finance into the review are fairly consistent:
The vendor will hold or change supplier banking details.
The vendor can initiate, approve, or release a payment.
An outage at the vendor would stop your month-end close.
The vendor stores personal data on your employees or your customers.
The contract renews automatically and nobody has looked at it since the original signature.
The vendor is replacing a control your team used to perform manually.
That last one gets skipped and it's the one I'd argue matters most. When software absorbs a control, the control's failure mode changes from "someone forgot" to "nobody can see it," which is a harder problem to audit later.
Scale explains why finance keeps getting pulled in. More than three-quarters of organizations (76%) experienced attempted or actual payments fraud, according to the Association for Financial Professionals' 2026 Payments Fraud and Control Survey covering the 2025 fraud year. Fraud arriving through a vendor relationship lands in AP, and AP reports to you.
Who signs off, and what are they signing off on?
Whoever signs the contract owns the residual risk, which in mid-market finance usually means the CFO or the VP Finance. What they're signing off on is the gap between what the vendor demonstrated and what the business needs, not a clean bill of health.
Write that gap down. A one-page memo naming the artifacts reviewed, the exceptions found, the compensating controls added, and the risks accepted turns a vague approval into a defensible one. Your auditors will ask for exactly this document, and the questions an AP audit works through map closely onto it.
Some perspective on what's being accepted. The FBI's Internet Crime Complaint Center recorded roughly $20.8 billion in total reported cybercrime losses across more than one million complaints in 2025, per its 2025 Internet Crime Report as summarized by Barracuda. Not all of that is vendor-related, and nobody should pretend it is. It does set the scale of the environment a signature is being issued into.
Which documents should you request from a payments vendor?
Request seven artifacts from any vendor that touches money or financial data. Each one answers a narrow question, and the value of the review comes from knowing which question it answers and which it leaves alone.
Two of these carry most of the market's weight. Secureframe's 2026 Cybersecurity and Compliance Benchmark Report found that 73% of organizations share a SOC 2 report and 70% complete security questionnaires or RFPs as their primary way of demonstrating or assessing security posture, from a modest sample of 255 respondents fielded in late October 2025. Both sit at the center of the artifact list, which suggests the list matches how buyers already work.
SOC 2 Type II report covering a period that ends within the last twelve months, including the auditor's exception table and the complementary user entity controls section.
Penetration test summary from an external tester, with the scope statement and the remediation status of anything rated high or critical.
Data processing agreement setting out what the vendor may do with your data, where it lives, who it moves to, and what happens on deletion.
Business continuity and disaster recovery test results, meaning the report from an exercise that was genuinely run, since a policy describing one proves nothing.
Certificate of insurance including cyber cover, with the limit, the retention, and the named insured checked against the entity on your contract.
Subservice organization list, naming the cloud providers, payment processors, and banks that sit behind the vendor and carry part of the control set.
Completed security questionnaire, answered by a named person who will still be there when you have follow-up questions.
Artifact | What it proves | What it does not prove |
SOC 2 Type II report | An independent auditor tested the stated controls across a defined window and documented exceptions | That the audited system is the one you're buying, or that the period is current |
Penetration test summary | An external tester attempted to break in within an agreed scope, and the vendor knows what was found | That the findings were fixed, or that the tested scope included your product |
Data processing agreement | Contractual limits on how your data is used, stored, transferred, and destroyed | That day-to-day practice matches the document |
Continuity and recovery test results | The vendor ran a recovery exercise and measured the result against a stated objective | That your workload was in scope, or that recovery times hold at your volume |
Certificate of insurance with cyber cover | A policy existed at a stated limit on a stated date | That your loss scenario is covered, or that the limit is meaningful against your exposure |
Subservice organization list | Which providers sit behind the vendor and hold part of the control environment | That those providers were audited to a comparable standard |
Completed security questionnaire | The vendor's own account of its controls, on the record and attributable | Anything independently verified |
Column three is where the diligence work actually happens. Columns one and two are collection.
What does a SOC 2 Type II report prove, and what does it leave out?
A SOC 2 Type II report proves that an independent auditor tested the vendor's controls over a period, usually six or twelve months, and reported where those controls failed. It doesn't prove the vendor is secure, and it doesn't prove the report covers the product you're buying.
Four things decide whether the report is worth anything to you. Check the system description to confirm the audited boundary includes the service you'll use, since a vendor with six products often audits three. Check the period end date, because a report ending fourteen months ago describes a company that has since changed its stack. Read the exception table before the opinion paragraph, since that's where the auditor records what went wrong. Then read the subservice organizations section, where the vendor carves out the controls it hands to its cloud host or its bank and tells you those controls weren't tested here.
The carve-out trap catches experienced buyers. A vendor can present a clean report while the controls that matter most to you sit entirely inside a carved-out subservice provider, which means you need that provider's report too. Working through what a SOC 2 attestation covers and how to verify one is worth doing once properly, because the same reading applies to every vendor afterward.
What should a security questionnaire ask a payments vendor specifically?
A vendor security questionnaire for a payments platform has to cover the movement of money and supplier banking data, which the standard templates treat as ordinary confidential information. That framing misses the entire attack.
Add these to whatever template you started from:
How is a supplier's bank account validated at onboarding, and against which external source?
What happens when a supplier requests a banking change, and which of those steps runs without human involvement?
Who inside the vendor can view or export a full supplier banking record, and how is that access logged?
Which roles can initiate a payment, and can any single role both create a payee and release funds to it?
How are payment files transmitted and encrypted, and what happens when a file fails validation?
Which payment rails does the vendor execute on, and which are handled by a subservice provider?
At termination, what is returned, what is deleted, and on what timetable?
The banking-change question is the one that earns its place. Vendor and supplier impersonation as a business email compromise tactic rose to 45% from 34% in 2023, according to AFP's 2025 Payments Fraud and Control Survey covering 2024 data, as reported by First Business Bank. The attacker's preferred disguise is your vendor, and the mechanics of that impersonation explain why email-only confirmation of a banking change is worthless.
The pattern that keeps turning up in practitioner accounts is worth describing precisely. An attacker sits inside a supplier's mailbox for weeks without touching anything, waits for a genuine invoice thread to open, replies inside that thread with updated banking details, and asks for processing before month end. Nothing about the message looks forged, because nothing about it is forged. The versions that end in a six-figure loss usually share one root cause, which is that nobody voice-verified the new instructions against a phone number already on file. Ask the vendor which of its controls would have caught that, and listen for whether the answer describes a control or a training reminder.
Where the platform holds banking data directly, the ownership question changes shape. A supplier portal moves the record into the supplier's hands, which removes an internal fraud path and creates a new authentication problem, so ask how portal identity gets established before you assume the portal solved anything.
Protect cash flow with modern AP
Modernize AP to cut costs, speed approvals, and mitigate payment risk — gaining the real-time visibility to protect cash flow and scale with confidence.
Download the whitepaperWhich documents signal a vendor is not ready for your business?
Some answers should stop the review outright, with no follow-up question needed. The pattern to watch for is a vendor substituting confidence for evidence.
A SOC 2 Type I offered in place of a Type II, which tests control design on a single day and says nothing about operation over time.
A "SOC 2 in progress" claim with no auditor named and no target date.
A refusal to name subservice organizations, on the grounds that the list is confidential.
A penetration test summary with the scope section removed.
A security questionnaire answered by the account executive instead of someone in engineering or compliance.
An insurance certificate naming a different legal entity than the one on your contract.
No documented process for supplier banking changes, or a process that ends at "we call the number on the invoice."
None of these is automatically fatal for a low-risk vendor. All of them are disqualifying for a vendor that can move your money, and saying so early saves everyone the procurement cycle.
How do you tier vendors so the effort matches the risk?
Tier vendors by what they can reach and what they can do, then match the depth of the review to the tier. A vendor risk assessment that treats a payments platform and a webinar tool identically will either exhaust your team or wave through the one that mattered.
Regulated buyers already work from a framework here. The FFIEC's third-party risk guidance and the OCC's supervisory expectations both organize diligence around criticality, and they're worth reading even if neither applies to you, because the tiering logic is sound and your auditors recognize it.
Risk concentration is the dimension people underweight. SecurityScorecard's Third-Party Breach Report 2025, covering 2024 data and read via a secondary summary, found that 41.4% of ransomware and extortion incidents began through third-party access. One vendor deep inside your payment flow is a different exposure from ten vendors at the edges, and spreading payments across multiple providers trades concentration risk for a wider review burden.
Tier | What puts a vendor here | Diligence depth | Re-review |
Tier 1, critical | Can initiate or redirect payments, holds supplier banking data, or an outage stops the close | Full artifact set, payments-specific questionnaire, reference call with a customer of similar size, legal review of the contract | Annually, plus on any material change |
Tier 2, elevated | Holds confidential financial or personal data but has no payment authority | SOC 2 Type II, data processing agreement, insurance certificate, shortened questionnaire | Every two years |
Tier 3, routine | No sensitive data, no payment authority, replaceable within a quarter | Insurance certificate and standard contract terms | At renewal |
What makes a vendor high risk in a payments context?
Payment authority makes a vendor high risk, followed closely by custody of supplier master data. Both give an attacker a route to money that doesn't require touching your ERP at all.
Business email compromise is the loss mechanism finance teams recognize, and it keeps growing. The FBI's Internet Crime Complaint Center recorded $3.04 billion in reported BEC losses in 2025, against $2.77 billion in 2024 and $2.94 billion in 2023, per its 2025 Internet Crime Report as summarized by Red Sift. The dollars move through invoice and banking-change requests, which is precisely the surface a payments vendor sits on.
Segregation of duties deserves its own question at this tier. One of the sharpest descriptions of a broken AP environment I've read came from a controller whose company let treasury, procurement, and the general ledger team all enter invoices, with nobody owning the boundary between them. When you buy a platform, you're buying its permission model, so ask whether the roles it ships with can enforce a separation your current process can't.
How often should each tier be re-reviewed?
Re-review Tier 1 vendors annually, Tier 2 every two years, and Tier 3 at contract renewal. Attach the review to a named calendar owner instead of a renewal date, because renewals get processed by people who aren't looking at the security file.
Material change should override the calendar in both directions. A vendor acquisition, a change of cloud provider, a reported breach, or a shift in what the vendor does for you all reset the clock. So does a change on your side, since a tool that was Tier 3 when it handled expense receipts becomes Tier 1 the moment someone routes reimbursements through it. The same practical security measures a finance team can verify apply to the re-review, so the annual pass mostly confirms what you already believe to be true.
What do you do when a critical vendor fails part of the review?
Failing part of the review is common and doesn't automatically end the deal. Decide whether a compensating control on your side closes the gap, and if it does, write both the gap and the control into the file.
The compensating controls that tend to work are unglamorous. Dual approval on any banking change regardless of what the platform allows. A callback to a phone number taken from your own records, never from the invoice. A payment threshold above which a second person must release. Exception reporting on new payees created within a set window of their first payment, which is also the control that catches the duplicate and near-duplicate vendor records that produce misdirected payments with no fraud involved at all.
What doesn't work is accepting a gap with a promise. A vendor roadmap commitment isn't a control, and a remediation date that falls after your go-live date is a risk you've accepted without saying so.
What belongs in the contract, the SLA, and the exit plan?
Contract language, service levels, and exit terms are where diligence findings become enforceable. A finding that stays in the evaluation file has no effect on anything once the relationship starts.
The instrument mix belongs in this conversation too. Check-fraud Suspicious Activity Reports filed by depository institutions exceeded 500,000 in 2022, roughly double the approximately 250,000 filed in 2021, according to FinCEN data reported by American Banker. If the vendor's default disbursement path leaves you writing checks, that's a contractual question about supported rails, and it gets harder to raise once the ink is dry. Provider selection carries a set of pitfalls that show up after signature, and most of them are contract terms nobody negotiated.
Which service levels should be written down rather than assumed?
Write down anything you'd escalate about. Support responsiveness is the single most common post-purchase complaint across payments and AP software, which promotes it from soft preference to diligence item, and the vendors buyers reward are the ones that make month-end close and audits more efficient in practice.
The service levels worth negotiating:
Breach notification window, stated in hours from vendor discovery, with a named notification method.
Payment processing and settlement timing by rail, including what happens on a failed file.
Support response and resolution targets by severity, with a defined path to a human during your close window.
A named account contact and a documented escalation ladder that doesn't start at a shared inbox.
Audit rights, including your ability to request the current SOC 2 report each year.
Notice period for subcontractor changes, so a new subservice provider doesn't appear without your knowledge.
Uptime commitment with a measurement definition, since a vendor measuring at the infrastructure layer can report 99.9% during an outage you experienced.
Ask for before-and-after processing metrics from a reference customer of roughly your size and transaction complexity, not from a demo environment. The gap between those two numbers tells you more about implementation risk than any section of the questionnaire.
What does a clean exit from a payments vendor look like?
A clean exit returns your data in a usable format, deletes the vendor's copy on a stated timetable, and leaves you able to pay suppliers on day one with a different tool. Negotiate it before you sign, because the exit clause is the term with the least resistance at contract stage and the most at termination.
Three specifics carry the weight. Supplier master data, including validated banking records, comes back in a documented, importable format, and a screen export doesn't count. Historical payment and remittance records stay accessible for your retention period, which is usually seven years and is longer than most standard clauses assume. Deletion is certified in writing, covering backups and subservice providers, on a defined schedule. How the vendor handles data governance inside the payments platform during the relationship is a fair predictor of how it will handle the wind-down.
Automate AP end to end
Replace manual approvals, check runs, and reconciliation with a single automated workflow that syncs to your ERP — so your AP team spends time on strategy, not paperwork.
Explore AP AutomationHow do you keep diligence findings from going stale after signing?
Convert findings into monitored items with owners and dates, then review them on the same cadence as the tier. Findings decay because they live in a document nobody re-opens, and the vendor changes underneath them.
Three mechanisms keep them alive without creating a program you can't staff. Put the accepted risks in the quarterly close checklist as a single review line. Require the vendor to notify you of subservice changes, then read those notices, since a new payment processor behind your vendor is a new vendor you never reviewed. Re-request the SOC 2 report annually and read the exception table against last year's, because the delta is more informative than either report alone. The same discipline applies further down the chain where subcontractors introduce payment risk your direct diligence never touched, and where basic security hygiene inside your own team determines whether a vendor's controls have anything to work with.
One loose end worth naming honestly. Nobody has a good answer for fourth-party risk at mid-market scale, because the diligence effort required to review your vendor's vendors exceeds what a finance team of any realistic size can perform. The workable answer is contractual notice plus concentration awareness. Nobody should mistake that for a solution.
How does Corpay hold up against this checklist?
Run the security review against us. Corpay is SOC 2 Type II compliant, and where payment card data specifically is in scope, Comdata, a Corpay company, is a PCI DSS Level 1 service provider. Those are the two attestations worth stating, and neither substitutes for the due diligence work described above.
What a payments platform adds beyond the ERP is the part worth examining. An ERP records the payable and stops there. It doesn't validate that a supplier's bank account belongs to that supplier, control who can release funds, or reconcile settlement back to the invoice. Corpay's AP automation covers validated supplier banking, MFA-protected supplier portals, managed supplier enrollment, and payment execution across virtual card, ACH, check, and cross-border rails, with 180+ ERP integrations spanning NetSuite, Sage Intacct, Dynamics 365, Acumatica, and QuickBooks. The Corpay AP automation platform is the right thing to point the Tier 1 version of this checklist at, questionnaire included.
Corpay (NYSE: CPAY), the Corporate Payments and Expense Management Company, is an S&P 500 company with three solution sets: Spend Management provides corporate and virtual card programs, Procure-to-Pay automates invoices and payments, and Cross-Border moves money in foreign currencies and manages foreign bank accounts. With Corpay, the more a business controls, the less it spends.
Frequently Asked Questions
What is included in vendor due diligence?
Vendor due diligence includes a document review, a security questionnaire, and a financial stability check. Reference conversations and a contract review complete it. For a payments vendor the document review covers seven artifacts, of which the SOC 2 Type II report and the subservice organization list carry the most weight.
What should be included in a due diligence checklist?
A usable checklist has four parts. You need the artifacts to request, the questions to ask, a risk tier that sets how deep to go, and the contract terms your findings have to become. Checklists that stop at the document list produce a full folder and no decision.
What is the due diligence questionnaire for vendors?
A vendor due diligence questionnaire is a structured set of security, privacy, and operational questions the vendor answers in writing. Standard templates exist from SIG and CAIQ, and for a payments vendor they need supplemental questions on supplier bank validation, banking-change handling, payment initiation roles, and file transmission.
What is a vendor due diligence report?
A vendor due diligence report is the written summary of what you reviewed, what you found, what you accepted, and who approved it. It typically runs one to three pages, names the artifacts examined with their dates, lists exceptions with compensating controls, and records the signer. Auditors ask for it more often than buyers expect.
What are the 4 P's of due diligence?
The 4 P's are a general commercial diligence framing most commonly given as People, Processes, Performance, and Projections, though the fourth term varies by source. It grew out of mergers and acquisitions practice, which makes it a reasonable structure for assessing whether a vendor is a viable business and a poor one for assessing whether its controls work.
How long should a vendor security review take?
A Tier 1 payments vendor review typically runs three to six weeks from document request to signed memo, most of which is waiting on the vendor. Tier 2 takes one to two weeks. Anyone quoting a precise average is usually selling software that promises to shorten it.
Is SOC 2 the same as being secure?
No. A SOC 2 report confirms an auditor tested the controls the vendor described, within a scope the vendor defined, over a period that has already ended. It's evidence of a functioning control program, several steps short of proof that the system is secure, and reading the exceptions and carve-outs is what separates the two.
Switch to Corpay
Discover how making the move to Corpay streamlines payments and strengthens your business.
Talk to an ExpertSmarter payments. Stronger growth. Keep business moving.
Corpay powers payments for 800,000+ businesses worldwide. Let’s build what’s next for yours.