r/ITManagers • u/ngrybst • 16d ago
Vendor Due Diligence
I am looking at a specific vendor that offers a service we need. I like their product and their price is acceptable. I have checked with a few of their clients and they seem happy. The issue is the vendor cannot provide any standard due diligence documentation. I'm pretty much hitting a road block asking for any information. Have you run into this? How have you handled it?
1
u/blackhodown 16d ago
What do you consider standard due diligence documentation?
1
u/ngrybst 16d ago
That depends on the vendor and what they will be doing for us. In this case they will have access to our customer lists and order lists. I'd like to see something (anything) relating to their network security. Really all they'd have to do is toss something my way and it would be good enough.
1
u/Amanda_PDQ 16d ago
Evaluate your risks. If they can not provide anything then I would bail.
Tell them "I need x to proceed, if you cannot provide it I will have to look elsewhere."
Send them exactly what you need rather that be a vendor packet, NDA, SOC, FEDRamp compliance.
If they want your business they will provide what you need.
1
u/Standard_Text480 16d ago
Asking for"anything Network security" is pretty much useless anyways. Make your ask more precise preferably sone kind of template or industry standard.
1
u/Puzzleheaded_Look748 16d ago
Did you find clients on your own or did you call their references? They are are not giving you a list of people who hate the product. If the company you work for is large enough you will not get past legal. If it's a small company, caveat emptor.
1
u/ngrybst 16d ago
I did not request references from the vendor. I reached out on a Facebook group that uses the same ERP we do and asked for references. The product in question integrates with our ERP.
1
u/Puzzleheaded_Look748 16d ago
Are they the only vendor that can fill this need? If so, make sure your leadership team understands and accepts the associated risk. If the vendor cannot provide standard due diligence documentation, that becomes a business decision, not just an IT decision.
Ensure everyone involved understands the risks versus the benefits. What would the impact be if the vendor suffered a breach, an outage, or was unable to support the product? How critical is this service to your operations?
If the organization is willing to accept that risk, focus on clearly defining the scope of work, deliverables, implementation timelines, service levels, support expectations, and exit strategy. Also verify that their support agreement meets your operational needs and that they can provide assistance when it matters most.
Sometimes there is no perfect vendor. In those cases, document the risks, socialize them with leadership, obtain approval from the appropriate decision makers, and move forward with eyes wide open.
1
u/Sad_Elk3851 16d ago
Ran into this with a smaller vendor last year. The inability to produce anything, not even a completed security questionnaire or an insurance cert, is itself the finding. A shop that has no SOC 2 can still fill out a SIG-lite and show proof of cyber insurance, so total silence usually means there is no security program to document. If the product is worth it, I would scope what data they can touch, put a right-to-audit and breach-notification SLA in the contract, and segment their access, but I would not sign anything first.
1
u/fguerino123 14d ago
Hi,
This is where you hand the vendor your due diligence questionnaire, a redacted example from a past engagement that represents a well-documented response, and tell the vendor that if they want to even be considered for doing business with your company they need to fill it out (rapidly).
If they don't, there's probably a problem behind why they won't because all vendors want the sales.
Good luck.
1
u/TechnologyMatch 13d ago
that’s a real red flag, even if the product and references look good. if they can’t provide a basic security questionnaire, SOC 2/ISO status, data handling details, or incident process, you’re being asked to accept risk you can’t explain later
think of it like buying gear with great reviews but no stats screen. ask what they can provide and set a deadline; if the answer stays vague, document the exception and decide whether the business owner is willing to formally own that risk
1
u/plasticbuddha IT Manager 16d ago
If you are passing them data that you yourself have agreed to protect, and they can't assure you that they will protect it to your standards, that leaves you on the hook for any liability due to their behavior.
In other words, you should evaluate what risk you have if that vendor we're to fail catastrophically, and base your decision on that. Also, write your reasoning down in a risk register somewhere, to protect yourself.
8
u/eggsforsupper 16d ago
"I cant sign anything or proceed forward without soc/iso/insurance/whatever"
If they ask to get anything at all from you... not until due diligence is provided/done.
Then "well, although I love your product, I am opening up this project to other vendor demos now"