Vendor due diligence
Review a provider's safeguards, evidence and exceptions, then record a decision and follow-up actions. For RIA operations, compliance and technology teams.
No automatic saving. Download a copy or choose Save to free account to keep your work. Avoid client details, credentials and confidential evidence.
Vendor due diligence
Define your scope, work through focused questions and keep a decision record with evidence references and follow-up actions.
- Define the firm, period and information in scope.
- Record judgments with evidence and rationale.
- Export a complete draft and continue from your saved copy.
No account required. Download your work or explicitly save it to a free account. Use categories and fictional labels; avoid sensitive records.
Sources, assumptions & limits
Template 1.1.0 · Sources checked October 2, 2026. A planning aid, not legal advice, a system assessment or a compliance determination. User-recorded statuses are not independently verified.
SEC-SP-2024: Regulation S-P amendments, release 34-100155 and correction 34-100155A ↗ — Applies according to the rule's institution and information scope; this initial worksheet does not determine applicability, calculate incident deadlines or provide an exhaustive legal assessment. Qualified regulatory content review remains pending.
NIST-1305: CSF 2.0: Quick-Start Guide for Cybersecurity Supply Chain Risk Management ↗ — Voluntary guidance; review depth, evidence and reassessment timing depend on the service and firm's exposure.
Read our methodology