FREE TOOL 04 / Assessment

Vendor due diligence

Review a provider's safeguards, evidence and exceptions, then record a decision and follow-up actions. For RIA operations, compliance and technology teams.

Spreadsheet · Text · PDF · Editable copyRead the guide ↗
Inputs stay in this browser tab

No automatic saving. Download a copy or choose Save to free account to keep your work. Avoid client details, credentials and confidential evidence.

A CLEAR RECORD, FROM SCOPE TO NEXT STEPS

Vendor due diligence

Define your scope, work through focused questions and keep a decision record with evidence references and follow-up actions.

  1. Define the firm, period and information in scope.
  2. Record judgments with evidence and rationale.
  3. Export a complete draft and continue from your saved copy.

No account required. Download your work or explicitly save it to a free account. Use categories and fictional labels; avoid sensitive records.

Sources, assumptions & limits

Template 1.1.0 · Sources checked October 2, 2026. A planning aid, not legal advice, a system assessment or a compliance determination. User-recorded statuses are not independently verified.

SEC-SP-2024: Regulation S-P amendments, release 34-100155 and correction 34-100155A ↗ — Applies according to the rule's institution and information scope; this initial worksheet does not determine applicability, calculate incident deadlines or provide an exhaustive legal assessment. Qualified regulatory content review remains pending.

NIST-1305: CSF 2.0: Quick-Start Guide for Cybersecurity Supply Chain Risk Management ↗ — Voluntary guidance; review depth, evidence and reassessment timing depend on the service and firm's exposure.

Read our methodology