Most organisations work with third parties: suppliers, contractors, software providers, and other partners that keep things running behind the scenes. They’re part of your team, even if they’re not on the payroll. But that connection brings shared responsibility. When a third-party vendor is breached or fails to meet regulatory expectations, it’s your business that may face the fallout. That’s why having a clear, practical approach to third-party due diligence (TPDD) is a smart move, especially as risks evolve and compliance pressures increase.
It’s Not Just About Compliance
Headlines around supplier-related data breaches are now routine. But it’s not just about cyber threats. Third-party risk can impact everything from uptime to customer trust. Some of the key risks we see include:
- Security gaps: A poorly secured vendor can become an easy way into your network.
- Regulatory issues: Non-compliance by a supplier can land you in hot water, especially under laws like GDPR or NIS2.
- Service disruption: A supplier going offline, folding, or failing to deliver can impact your operations.
- Reputation: Working with the wrong partners can damage trust with customers and stakeholders.
When and How to Carry Out Due Diligence
Due diligence should start before a contract is signed, but it can’t stop there. Risk profiles change. Teams grow. Tech stacks evolve. Here’s a useful rhythm to follow:
- At onboarding – Assess financial health, data handling, certifications, incident history.
- Regular reviews – Annually as a minimum, more often for higher-risk suppliers.
- Triggered checks – For example, if a supplier is breached, if the contract changes, or if there are new legal requirements.
You don’t need expensive software to do this well. A structured, repeatable approach, even using simple tools is often enough.
AI Brings New Considerations
If you’re using AI tools or platforms provided by third parties, there are extra questions to ask. Some AI systems use questionable datasets, lack transparency, or present new security challenges. Due diligence here should cover:
- Where the data comes from
- How models are trained and tested
- Whether they comply with regulations
- What security or ethical safeguards are in place
We expect this to become a key focus for regulators over the next year.
It’s Not About Blame – It’s About Resilience
Good supplier relationships are built on trust, but also on accountability. Due diligence isn’t about catching vendors out, it’s about understanding where the risks are and agreeing how they’ll be managed. That protects your organisation, your customers, and your reputation. If you haven’t reviewed your approach recently, it’s worth putting TPDD back on the radar. We’re seeing more organisations tighten this up and for good reason.
Need a hand building a practical supplier risk process?
Evolve North can help. We support organisations with tailored third-party due diligence frameworks, risk reviews, and supplier assurance process. Call us on 01748 905 002 or drop us a line at info@evolvenorth.com to get started.
