Due diligence is the proportionate investigation of a proposed supplier, transaction, or relationship before an authorized decision. The review may cover identity, ownership, financial condition, sanctions, security, privacy, quality, capability, insurance, legal, sustainability, or operational risk, depending on context. Required evidence, reviewers, refresh intervals, and escalation paths should be defined rather than assumed.
In plain English
It is the evidence-based check performed before accepting a supplier or relationship risk.
Illustrative example
At Northstar Industrial Systems, a critical software supplier is reviewed for security, privacy, financial, legal, and service-continuity evidence before onboarding approval.
- Related terms
- Supplier qualification; Supplier risk assessment; Compliance tracking; Critical supplier
- Lifecycle stages
- Source; Approve; Govern
- Stakeholders
- Procurement; IT and Security; Compliance and Legal; Finance