Software

Gain a 360-degree view of third-party risk by using our SaaS software to centralize, track, automate, assess and report on your vendors. 

Managed Services

Let us handle the manual labor of third-party risk management by collaborating with our experts to reduce the workload and mature your program. 

Overview
Document Collection
Policy/Program Template/Consulting
Virtual Vendor Management Office
Vendor Site Audit

Ongoing Monitoring

Let us handle the manual labor of third-party risk management by collaborating with our experts.

VX LP Sequence USE FOR CORPORATE SITE-thumb
Venminder Exchange

As Venminder completes assessments for clients on new vendors, they are then made available inside the Venminder Exchange for you to preview scores and purchase as you need.

CREATE FREE ACCOUNT

Use Cases

Learn more on how customers are using Venminder to transform their third-party risk management programs. 

Industries

Venminder is used by organizations of all sizes in all industries to mitigate vendor risk and streamline processes

Why Venminder

We focus on the needs of our customers by working closely and creating a collaborative partnership

1.7.2020-what-is-a-third-party-risk-assessment-FEATURED
Sample Vendor Risk Assessments

Venminder experts complete 30,000 vendor risk assessments annually. Download samples to see how outsourcing to Venminder can reduce your workload.

DOWNLOAD SAMPLES

Resources

Trends, best practices and insights to keep you current in your knowledge of third-party risk.

Webinars

Earn CPE credit and stay current on the latest best practices and trends in third-party risk management.  

See Upcoming Webinars

On-Demand Webinars

 

Community

Join a free community dedicated to third-party risk professionals where you can network with your peers. 

Weekly Newsletter

Receive the popular Third Party Thursday newsletter into your inbox every Thursday with the latest and greatest updates.

Subscribe

 

Venminder Samples

Download samples of Venminder's vendor risk assessments and see how we can help reduce the workload. 

resources-whitepaper-state-of-third-party-risk-management-2023
State of Third-Party Risk Management 2023!

Venminder's seventh annual whitepaper provides insight from a variety of surveyed individuals into how organizations manage third-party risk today.

DOWNLOAD NOW

video

Basic Checklist to Streamline Vendor Due Diligence

CPE Credit Eligible

Streamline your vendor due diligence, make it easier on yourself.

While you might tailor your vendor due diligence based on the type of product, service or level of risk, creating a basic checklist is the key to streamlining your third party due diligence process. 

You may also be interested in:

 

Video Transcript

Welcome to this week’s Third Party Thursday! My name is Wendy Davis and I’m the Operations Manager here at Venminder.

Today we are going to talk about the due diligence guide or checklist. And first a note of caution, the word ‘checklist’ is a bit of a misnomer. While you might check items off the list, you do need to make sure that each item is adequately reviewed to ensure it meets the purpose for which you are gathering.

There are some basic items that you want to make sure you are always collecting, and while you might tailor this based on the type of product or service or even a risk based type of approach, there are certain things that you would normally gather for each and every new third party. These are certain foundational documents that should always be obtained.

There are 6, here we go:

  1. The articles of incorporation - so that you can understand what type of company it is and if it can do the job. For example, you wouldn’t expect your core processor to be a sole proprietorship or even an LLC.

  2. Business license and any other professional license required - This is particularly true of those in the payment card industry to make sure they are PCI compliant, and any attorneys you are doing business with to make sure they are a member of the bar association or have expertise in the particular type of activity in which you have them engaged.

  3. Their tax id number - again, so that you can understand some of the basic foundational items about them, what type of business is it and who is the ownership. You probably want to do an OFAC check or determine if the owners are a politically exposed person in a case of overseas activity.

  4. A reputation risk check - this is becoming increasingly important since the days of the CFPB complaint database. You can easily search the CFPB complaint database or do a Better Business Bureau check on them and when you find problems there you probably want to understand what their complaint management activities are.

  5. A secretary of state check - make sure they are good bill paying citizens in the state they are incorporated.

  6. A site tour or a picture of the facility - to make sure you are comfortable that they are who they say they are and they aren’t simply a store front for some other activity. 

Now depending on the nature or product or service, you may want to gather some additional items:

  • Policy and procedures - such as for call centers, you probably want to look at some of their underlying policies and procedures. This would be a good idea as well for any marketing or processing companies you are dealing with as well.

  • A copy of their recent audit report - whether internal or external can often help you identify problems before they present a risk to your organization.

  • The SSAE18 Report - the new SSAE18 standards that went into effect in May of 2017 are particularly helpful because they will help you understand who are their critical subservice providers.

  • Network diagram and any penetration testing - depending on the type of processing data they are doing for you, you may want to look at their network diagram and any penetration testing that has been done to make sure that your data is always protected.

  • Insurance certificates or business continuity plans - some other items you may want to consider in certain circumstances such as insurance certificates or business continuity plans or scripting in the case of call centers and IVR activity.

And that’s it, that a pretty good comprehensive list of some of the basic checklist of items you should be covering in vendor due diligence. Again, I’m Wendy and thanks for tuning in to this week’s third party Thursday; if you haven’t already done so, please subscribe to our series.

38116-newsletter

Subscribe to our Third Party Thursday Newsletter

Receive weekly third-party risk management news, resources, and more to your inbox.

 

New Call-to-action

Ready to Get Started?

Schedule a personalized solution demonstration to see how Venminder can transform your vendor risk management processes.

Request a Demo