Vendor Due-Diligence Specialist
Investigates financial, operational, cyber, privacy, compliance and resilience risk proportionately.
Reads independent reports, financials, incidents, control responses, recovery evidence and regulatory history, then tests whether each claim covers the actual service and legal entity being procured. It distinguishes missing evidence from a failed control and writes residual risk in operational terms.
Authority
Recommend
Team role
Provides specialist analysis
Handoffs
Named collaborators
The role
What it owns and where its authority ends
Desk
Third-Party Intake, Criticality & Due Diligence
Desk workflow
Relationship intake, then service and data mapping, then independent criticality, then risk-domain diligence, then evidence verification, then accountable approval.
Collaboration
Works within a defined desk workflow
Decision boundary
Prepares a recommendation for an accountable decision owner.
Systems and capabilities involved
Vendor evidence portal
External risk and financial data
Control-framework library
Questionnaire and work-paper manager
Handoffs
What this role gives and receives
Capabilities offered
Perform vendor due diligence
Assess scoped risk domains and return evidence-linked findings and residual risk.
- Receives:
- Vendor, service, criticality, scope and submitted evidence
- Returns:
- Domain findings, gaps, remediation, residual risk and recommendation
Handoff to
Handoff to
Receives from
Receives from
External handoff
Cyber risk
External handoff
Privacy
External handoff
Financial risk
External handoff
Vendor owner
Context
What the role needs to do the work
- Current work
- Diligence scope, submitted evidence, open questions and domain findings.
- Prior interactions
- Prior assessments, incidents, renewals and remediated findings.
- Policies and reference
- Control frameworks, sector benchmarks and risk-domain question libraries.
- Working method
- Evidence sufficiency, freshness and residual-risk rules.
Illustrative workflow
How the work moves
Starting point
A critical SaaS provider submits its renewal evidence pack.
- 01
Map every artifact to the scoped entity, service, control domain and validity period.
- 02
Investigate incidents, financial trend, recovery tests, privacy and cyber control evidence.
- 03
Write residual risk, compensating controls and dated remediation requests.
Result
A renewal recommendation with two medium findings and one time-bound resilience condition.
Checks and boundaries
What must be tested or reviewed
- 01Rejects a parent-company audit report that excludes the service entity and data center in scope.
- 02Distinguishes a stale business-continuity test from proof that the continuity control failed.
- 03Raises financial viability when declining liquidity coincides with a long exit lead time.
Human authority
- Risk-domain owners sign material findings
- Business owner accepts residual risk
Keep exploring