What is Vendor Due Diligence?
Vendor due diligence is the process organisations use to evaluate a supplier’s security, privacy, legal and ethical practices before they buy or share data. It checks whether a vendor can safely handle the organisation’s information and meet regulatory and community obligations.
Vendor due diligence means assessing a third‑party product or service to make sure it won’t expose your organisation or the people you serve to privacy, security, legal or ethical risks. For non‑experts, it’s a structured set of checks — documents to request, questions to ask and tests to run — that show how a vendor stores and processes data, who else can access it, how incidents are handled, and whether their practices meet applicable laws (for example GDPR, UK data protection rules or state privacy laws).
Typical checks include reviewing security certifications (SOC 2, ISO 27001), the vendor’s Data Processing Agreement (DPA), data flow diagrams and hosting location, encryption and access controls, subprocessors list, breach notification procedures, data retention and deletion policies, and any AI/ML model use (how translations are generated, whether data is used to improve models). For public‑facing community work, due diligence also covers accessibility, fairness and whether translation or automated tools could harm trust with communities.
Usage example
Before launching a multilingual consultation, the council ran vendor due diligence on Hearo: they reviewed the DPA, confirmed UK/EU hosting, checked SOC 2 compliance, clarified how AI translation is used and whether participants’ free‑text answers would be translated or stored for model training.
Practical application
Vendor due diligence matters because it reduces legal, reputational and operational risk. It helps you ensure that participant data — often sensitive in community surveys — is handled lawfully and securely, that translations and AI processes won’t introduce bias or privacy leakage, and that you can meet transparency and accountability requirements (for example proving you gave communities a reasonable opportunity to participate). Good due diligence also speeds procurement and procurement approvals by gathering the evidence decision‑makers need, and it creates clear controls (contract clauses, retention limits, audit rights) you can rely on if something goes wrong.
FAQ
How much due diligence do I need for a small vendor?
Scale checks to the risk. For low‑risk tools (no personal data or only minimal contact details) a shorter checklist and a signed DPA may be enough. For tools handling personal, sensitive or cross‑border data — like multilingual surveys with open‑text responses — you should verify security controls, subprocessors, hosting location, incident response and model use. When in doubt, treat it as higher risk.
What should I ask if the vendor uses AI for translation?
Ask whether participant text is sent to third‑party models, whether data is stored or used to train models, whether translations are logged (and how long), and whether participants can opt out of model training. Also check how the vendor allows review and correction of translations, and whether there’s human oversight for sensitive content.
Can vendor due diligence replace legal or procurement review?
No. Due diligence provides the factual and technical evidence procurement and legal teams need, but it doesn’t replace their contract negotiation or legal sign‑off. Use due diligence to gather the documents and answers those teams require (DPA, security reports, data flow diagrams, insurance certificates) so procurement and legal can make a timely decision.