KYB AND COMPLIANCE
Vendor due diligence questionnaire: map answers to evidence before approval
A practical way to turn supplier questionnaire answers into verified company evidence, exception states and approval-ready records without duplicating a broad checklist.
The decision: treat the questionnaire as a claim register
A vendor due diligence questionnaire should be treated as a claim register, not as a completed control. Each answer says something about a legal entity, a control, a person, a location, a financial period or a subcontractor. Before a supplier is approved, the workflow should decide which answers can be accepted as self-attestation, which require documentary support and which must be checked against an independent source.
This matters because current third-party risk material is moving in a risk-based direction rather than a one-size-fits-all template direction. Recent US proposals for banking organisations emphasise aligning third-party risk management with the risk level of each relationship, while a recent European framework extends third-party risk governance across non-ICT services that support critical or important functions. The operational lesson for product, compliance, credit and procurement teams is narrow: collect fewer unsupported answers and preserve stronger evidence for the answers that can change the approval decision.
This article uses vendor due diligence in the procurement and supplier-review sense: the review of a third party you may buy from, rely on or connect to your systems. It is not seller-side due diligence in an acquisition. The existing broad supplier checklist question is already well served elsewhere; the distinct implementation question here is how to convert a completed questionnaire into evidence states that a reviewer, auditor or system can understand later.
What the current vendor due diligence questionnaire results leave unanswered
Current results for this intent are useful but mostly stop at templates, category lists and high-level process advice. They commonly tell teams to ask about corporate standing, ownership, sanctions, financial health, security, privacy, insurance, subcontractors, resilience and contract terms. That is a reasonable starting point, but it leaves the enterprise reader with a harder question: when the supplier answers, which values are actually verified, which are merely asserted and which should block or escalate approval?
The gap becomes visible when a supplier returns a neat set of answers. A registered entity answer may be independently checkable; a statement about ultimate ownership may be partial; a statement about financial stability may refer to a parent rather than the contracting subsidiary; a security answer may be covered by a report that excludes the system being bought; and a subcontractor answer may be accurate on the response date but incomplete after a service change. These are not the same evidence problem.
The answer is to separate four layers. First, resolve the legal entity that will sign the contract. Secondly, classify each questionnaire answer as a claim about identity, control, finance, security, privacy, resilience or contract scope. Thirdly, attach the best available support and record its limits. Finally, give the reviewer a state such as supported, corrected, contradicted, self-attested, missing, unavailable or stale. That state is more useful than a green tick because it tells the next person what was actually established.
Build the answer-to-evidence matrix before sending the form
The best time to design a questionnaire is before a business owner sends it to the supplier. Start with inherent risk: what the vendor would hold, reach, process or interrupt if the relationship failed. A low-risk stationery supplier should not receive the same depth of review as a payroll provider, cloud processor, payment partner or outsourced compliance tool. Recent official material supports this principle by focusing oversight on risk, criticality, operational resilience and proportionality rather than on identical paperwork for every relationship.
For each question, define the expected evidence type. Some answers can be accepted as self-attestation because the impact is low or the matter is contractual. Others should be tied to a registry record, filed account, certificate, policy, report, insurance document, sanctions result, ownership document, processor list or contract clause. Where CompanyProof is used for company facts, the practical value is preserving the entity, fact and source context so a questionnaire answer does not float away from the record that supports it.
The matrix should also define who owns the exception. Procurement may own missing contact information; compliance may own sanctions, beneficial ownership and integrity questions; security may own control evidence; finance or credit may own filed-financial comparability; legal may own authority, contract and subcontracting clauses. A single questionnaire can collect all of these, but a single reviewer should not silently resolve all unresolved evidence states.
- Record the original supplier answer before normalising it.
- Name the legal entity, jurisdiction and registration number for every identity-dependent answer.
- Separate source retrieval from verification against the supplier’s claim.
- Preserve source dates, retrieval dates and document periods rather than only the upload date.
- Assign one owner and one next action for every exception.
Worked example: a hypothetical software supplier
Consider a hypothetical case. A US financial-services firm is considering Northbridge Risk Analytics Ltd, a fictional private company incorporated in England and Wales, as a supplier of operational-risk analytics. The supplier states that it is active, privately owned, has no material subcontractors, stores customer data only in the UK, holds a current security report and has sufficient financial resilience to support a three-year contract. The retrieval date for this example is 23 September 2026; the entity is fictional, so the example illustrates workflow design rather than a real company assessment.
The first question is not whether the vendor looks reputable. It is whether the supplier named in the questionnaire is the same legal entity that will sign the contract and invoice the customer. The reviewer records the claimed registered name, company number, jurisdiction and address, then checks the relevant public record. If the number matches but the registered name has changed, the identity answer is corrected, not ignored. If the name is ambiguous and several entities could match, the state is unresolved until the contracting entity is confirmed.
The ownership answer needs a different treatment. A register entry for control persons, a shareholder document and a supplier self-declaration may support different claims. If the supplier says “no ultimate beneficial owner over the policy threshold”, the reviewer should store the threshold, source and chain boundary. Missing public ownership data is not proof that there is no owner; it is a missing evidence state that may be acceptable for a low-risk supplier and unacceptable for a critical one.
The financial answer also needs context. If the questionnaire cites group revenue but the contract is with a smaller subsidiary, the figure does not support the supplier’s resilience claim without further explanation. The matrix should capture reporting entity, period, currency, consolidation scope and filing date. For a material contract, a stale or parent-only figure may trigger credit review rather than automatic rejection. For a small non-critical service, it may simply be recorded as an accepted limitation.
A practical vendor due diligence checklist for answer testing
A vendor due diligence checklist is useful when it tells the reviewer what to do with each answer. The checklist below is deliberately narrower than a full supplier policy. It focuses on the evidence transition from questionnaire response to approval record.
Use three tests for every material answer. The identity test asks whether the answer belongs to the contracting entity. The support test asks whether the answer is backed by a source appropriate to the risk. The decision test asks whether the remaining uncertainty is acceptable, needs a condition, or should block approval. This method keeps the review proportionate without letting unsupported answers become hidden approvals.
- Identity and authority: verify the contracting entity, jurisdiction, registration number, status and signing route before relying on wider answers.
- Ownership and control: record whether the answer is self-attested, registry-supported, document-supported, incomplete or contradictory.
- Financial evidence: compare reporting entity, period, currency, filing date and consolidation scope before using figures in credit or resilience decisions.
- Security and privacy: check that reports, certificates and policies cover the product, environment, data types and period relevant to the proposed relationship.
- Subcontracting and location: distinguish a current subprocessors list from a contractual right to change it later, and record the notification or approval rule.
Decision table: convert answers into review states
A questionnaire workflow should not have only pass and fail outcomes. Pass and fail are decisions; the matrix needs evidence states that explain the route to those decisions. The same state can lead to different decisions depending on the supplier tier, contract value, data access and operational dependency.
For example, unavailable registry data on the day of review should not be treated as misconduct. It may require retry, an approved fallback source or manual escalation. A contradictory registration number is more serious because the system may be reviewing the wrong legal entity. A self-attested control may be acceptable for a low-impact tool but insufficient for a critical service supporting regulated operations.
- Supported: the observed evidence matches the supplier answer and is current enough for the policy.
- Corrected: the evidence supports the relationship only after the stored answer is amended and the original claim is preserved.
- Contradicted: the evidence conflicts with a material answer and should stop reliance on that claim until resolved.
- Self-attested: the supplier answer is recorded, but no independent evidence has been obtained or required for that tier.
- Missing or unavailable: the required evidence was not supplied or could not be retrieved; the record should show which condition applies.
Implementation pattern for product and compliance teams
A product team building a supplier intake flow should start with the data model, not the form layout. Store the supplier response, the selected legal entity, the evidence object, the verification state, the reviewer, the decision and the next review trigger as separate fields. If those elements are collapsed into a single status, later monitoring and audit will be weak even if the original questionnaire was long.
The workflow should also distinguish missing from contradictory evidence. Missing means the information was not obtained or not available in the expected source. Contradictory means the source returned a value that conflicts with the supplier’s statement. Unavailable means the source or document could not be accessed at the time of review. Stale means the evidence may have been valid but is too old for the current policy. These distinctions prevent teams from treating absence of evidence as a clean result.
Finally, decide which answers can reopen the relationship after approval. A change in legal status, a new contracting entity, a material ownership change, a filed-financial ageing threshold, a critical subcontractor change or an expired assurance report may all require review. The trigger should point back to the answer and evidence it affects. That is what turns a questionnaire from a static procurement attachment into a reusable evidence record.
Timeline: recent signals pushing questionnaires towards evidence-led review
A selectable sequence of public milestones that support risk-based, evidence-aware supplier review rather than generic form collection.
Supplier due diligence guide finalised
A public cybersecurity supply-chain guide describes due diligence as research into available pertinent information and frames supplier assessment around ownership, provenance, resilience, foundational practices and supply-chain tiers.
Select a node to inspect its meaning. Nodes represent categories or stages, not measured quantities.
Comparison: answer states in a supplier questionnaire workflow
A practical classification for turning supplier answers into reviewable evidence records before approval.
Claim captured
The response is stored exactly as provided so later corrections and disputes can be traced back to the original statement.
Select a node to inspect its meaning. Nodes represent categories or stages, not measured quantities.
FREQUENTLY ASKED QUESTIONS
vendor due diligence questionnaire FAQs
What is a vendor due diligence questionnaire?
A vendor due diligence questionnaire is a structured set of questions used to collect supplier claims before or during a business relationship. It should identify the legal entity, service scope, ownership, financial position, security posture, privacy obligations, subcontractors and exceptions, then connect material answers to evidence.
Is vendor due diligence the same as supplier due diligence?
In procurement usage, vendor due diligence and supplier due diligence often mean the same review of a third party you may buy from or rely on. The phrase can also mean seller-side due diligence in an acquisition, so policies and forms should make the procurement context explicit.
What should a vendor due diligence checklist include?
A practical checklist should include legal identity, registration, ownership or control, financial evidence, sanctions or integrity checks, security, privacy, resilience, subcontractors, contract rights and exception handling. For each item, it should say what evidence is expected and who owns unresolved answers.
How do you verify questionnaire answers about a supplier’s legal identity?
Start with the contracting entity named in the questionnaire and compare its registered name, registration number, jurisdiction, status and address against the relevant public or approved source. Keep the original answer, observed value, source, retrieval time and any mismatch instead of overwriting the supplier’s claim.
How should a team handle missing ownership information?
Missing ownership information should be recorded as missing, not treated as proof that no owner exists. The next action depends on risk tier: accept a limitation, request documents, use another approved source, escalate to compliance or pause approval until the ownership question is resolved.
Can a supplier self-attestation be enough evidence?
Yes, but only for questions where policy permits self-attestation at that supplier tier. Low-impact answers may not justify independent verification. Material answers about identity, control, financial resilience, regulated services, sensitive data or critical operations usually need stronger evidence or explicit exception approval.
How often should questionnaire evidence be refreshed?
Refresh frequency should follow risk, source type and trigger events rather than a single annual rule. A low-risk supplier may be reviewed at renewal, while a critical supplier may need event-based review when legal identity, ownership, financial period, subcontractors or security evidence changes.
What is the difference between retrieval and verification?
Retrieval records what a source or document returned at a point in time. Verification compares that observed value with the supplier’s answer and decides whether it supports, corrects, contradicts or leaves the claim unresolved. Keeping the distinction prevents a downloaded document from being mistaken for approval.
How should a KYB API support vendor due diligence?
A KYB API used in this workflow should help resolve the legal entity, return relevant company facts and preserve source context. The business system should still apply the organisation’s policy, because a verified registration fact is not the same as a complete supplier approval decision.
What is the next step after improving the questionnaire?
Build an answer-to-evidence matrix for one high-risk supplier tier first. Define the claim, required support, evidence state, owner, blocker rule and review trigger for each material question. Then extend the pattern to lower-risk tiers with fewer required evidence checks.
