Platform
Third-Party Risk

Vendor Due Diligence

Assess vendors with questionnaires, evidence and risk-based sign-off

Run structured due diligence on a vendor — issuing assessment questionnaires, collecting and validating evidence, screening the entity and its principals, and reaching a risk-based decision with the right sign-off — so every onboarding and renewal rests on a documented, defensible basis rather than a hurried check. Due diligence is the deep-dive that decides whether a firm should take a vendor on and on what terms. OnyxOne turns it from a chased-by-email scramble into a repeatable assessment where the questions fit the risk, the evidence is captured against the answers, and the decision and its reasoning live on the record.

At a glance

How it works, visually

Onboarding & review flowSchematic
Item receivedOnboarding / eventRiskthreshold?Auto-clearLow risk · loggedEscalate to reviewAnalyst investigatesRecord &auditNoYes — parallel review paths

A representative path for onboarding and re-assessing a third party, with escalation where risk warrants it.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

Questionnaires are chased over email

Assessment questions go out as a spreadsheet attachment, responses trickle back in different formats, and the assessor spends more time chasing and collating than analysing. There is no single place where a vendor's assessment actually lives.

Evidence is claimed but never validated

A vendor ticks a box to say it holds a certification or a control, but the supporting evidence is missing, expired, or never checked against the claim. The assessment records assertions, not verified facts, and no one can tell the difference later.

Every vendor gets the same questionnaire

A generic assessment asks a low-risk supplier hundreds of irrelevant questions and a critical provider too few of the ones that matter. Without risk-based scoping, diligence is simultaneously burdensome and inadequate.

The decision basis isn't recorded

A vendor is approved, but why — what the residual risks were, what conditions were attached, who signed off — lives in an email or a memory. When the relationship later goes wrong, the firm cannot show the decision was reasoned.

Re-diligence starts from scratch every time

At renewal, the previous assessment cannot be found or reused, so the whole exercise is repeated from zero. Effort is duplicated, and there is no clean view of how a vendor's risk profile has changed over time.

The approach

How OnyxOne addresses it

Questionnaires issued and tracked in one place

Assessments are issued to vendors, completed and returned within the platform, so responses arrive in a consistent structure and the whole assessment lives on the vendor's record. Chasing and collating give way to reviewing.

Evidence captured against each answer

Supporting evidence is attached to the specific response it substantiates and checked against the claim, with expiry tracked. The assessment records verified facts, and an assertion without evidence is visible as exactly that.

Risk-based questionnaire scoping

The questions a vendor receives are scoped to its tier, category and the nature of what it provides, so a critical provider is probed deeply on what matters and a low-risk supplier is not buried in irrelevance. Diligence is proportionate by design.

A recorded, risk-based decision

The assessor reaches a decision with the residual risks, any conditions and the sign-off captured on the record. The basis for onboarding or renewing a vendor is documented as it is made — defensible if the relationship is ever questioned.

Reusable assessments across the lifecycle

Prior assessments are retained and reused at renewal, so re-diligence updates the previous picture instead of starting from zero, and the change in a vendor's risk profile over time is visible on one record.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Assessment questionnaires

Issue structured due-diligence questionnaires and collect responses within the platform.

Risk-based scoping

Scope the questions to the vendor's tier, category and service so diligence is proportionate.

Evidence collection & validation

Attach evidence to each response, check it against the claim and track its expiry.

Screening of entity & principals

Screen the vendor and its beneficial owners and principals against sanctions, PEP and adverse-media sources.

Assessment scoring

Score responses and evidence to summarise a vendor's risk position for the decision.

Risk-based sign-off

Record the decision, residual risks and conditions with the appropriate approval.

Conditions & remediation

Attach conditions or remediation actions to an approval and track them to completion.

Reusable assessment history

Retain prior assessments so renewals update the picture rather than restarting it.

Renewal & re-diligence

Trigger and run re-assessments on a risk-based cycle from the vendor's record.

Immutable assessment trail

Every questionnaire, response, evidence item and decision is written to an append-only record.

Dashboards

The views your team works from

Purpose-built dashboards and views, each answering a question a specific role needs to act on.

An executive viewIllustrative
ILLUSTRATIVE EXAMPLEOPEN CASES128SLA ADHERENCE96%SCREENING ALERTS1.2kOVERDUE REVIEWS14Cases by categoryAMLKYCFraudSanctionsConductOtherRisk mixby tierHighMediumLow

A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.

Assessment pipeline

Due-diligence assessments in progress by stage and tier, highlighting overdue questionnaires and pending sign-offs.

Evidence status

Evidence collected, validated, missing or expiring across assessments, so gaps are closed before decision.

Screening results

Screening outcomes for vendors and their principals, with hits routed for review before approval.

Decision log

Recorded decisions with residual risks, conditions and sign-off, giving a defensible view of every vendor approval.

Renewal calendar

Vendors due for re-diligence on their risk-based cycle, so renewals are prompted before evidence goes stale.

Automation

What the platform automates

Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.

Questionnaire issuance

Assessments scoped to the vendor's tier are issued automatically, with reminders driven until responses are complete.

Evidence-expiry tracking

Attached evidence nearing expiry is flagged automatically so the assessment does not silently go stale.

Principal screening

The vendor and its principals are screened automatically as part of the assessment and re-screened on list updates.

Sign-off routing

Completed assessments route to the appropriate approver automatically based on the vendor's tier and residual risk.

Renewal scheduling

Re-diligence is scheduled automatically on each vendor's risk-based cycle and prompted ahead of time.

AI assistance

Where AI helps the analyst

Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.

Response summarisation

Summarises a vendor's questionnaire responses and evidence so the assessor can review them quickly, then verify before deciding.

Evidence-consistency checks

Flags where attached evidence appears inconsistent with, or does not support, a response, for the assessor to examine.

Question suggestion

Suggests follow-up questions where a response is thin or concerning, which the assessor chooses whether to pursue.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01ScopeThe questionnaire is scoped to the vendor's tier, category and service, so it askswhat matters and skips what does not.02Issue & collectThe assessment is issued to the vendor, completed within the platform, and returnedwith responses in a consistent structure.03Validate evidenceSupporting evidence is attached to each response, checked against the claim, and itsexpiry recorded.04Screen & scoreThe vendor and its principals are screened, and responses and evidence are scoredinto a summary risk position.05Decide & sign offThe assessor records a risk-based decision with residual risks and any conditions,and the appropriate approval is applied.06Retain & renewThe assessment is preserved and reused at renewal, so re-diligence updates thepicture and tracks how the profile changes.

Every result, decision and override is captured against the record it belongs to.

01

Scope

The questionnaire is scoped to the vendor's tier, category and service, so it asks what matters and skips what does not.

02

Issue & collect

The assessment is issued to the vendor, completed within the platform, and returned with responses in a consistent structure.

03

Validate evidence

Supporting evidence is attached to each response, checked against the claim, and its expiry recorded.

04

Screen & score

The vendor and its principals are screened, and responses and evidence are scored into a summary risk position.

05

Decide & sign off

The assessor records a risk-based decision with residual risks and any conditions, and the appropriate approval is applied.

06

Retain & renew

The assessment is preserved and reused at renewal, so re-diligence updates the picture and tracks how the profile changes.

The value

What your team gains

One place

Assessment, not admin

Questionnaires issued, completed and evidenced in the platform replace email chasing, so assessors spend their time analysing rather than collating.

Verified

Facts, not assertions

Evidence captured against each answer and checked for expiry means the assessment records verified facts, and unsupported claims are visible as such.

Proportionate

The right depth of diligence

Risk-based scoping probes critical vendors deeply and spares low-risk ones the irrelevant, so diligence is neither burdensome nor inadequate.

Defensible

A documented decision basis

Residual risks, conditions and sign-off recorded on the vendor's record mean an onboarding questioned later is already accounted for.

Renewals build on the past

Retained, reusable assessments let re-diligence update the previous picture instead of restarting, and show how a vendor's risk has changed.

Faster, calmer audits

Because questions, evidence, screening and sign-off all live on the record, showing how a vendor was assessed is retrieval, not reconstruction.

Built for

Industries it serves

BankingFinancial ServicesFintechInsuranceInvestment FirmsHealthcareTechnologyCorporate & Trust Service ProvidersRegulated Enterprises
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Third-party register
  • Runs within the third-party-risk lifecycle, drawing tier and context from the vendor's register record
Screening & data sources
  • Screens the vendor and its principals against the sanctions, PEP and adverse-media sources configured for your deployment
Evidence & document stores
  • Collects and preserves supporting evidence from and to your existing document repositories
Procurement & contract systems
  • Aligns diligence outcomes with your existing procurement and contract-management systems
Collaboration & notification
  • Routes questionnaire issuance, reminders and approvals through your existing email and messaging channels
Assurance

Security, compliance & reporting

Security & data handling

  • Assessments, responses and evidence are encrypted in transit and at rest.
  • Role-based access controls who can scope, issue, assess and approve a due-diligence assessment.
  • Segregation of duties can separate the assessor from the approver, where policy requires it.
  • Sensitive vendor evidence is restricted to authorised roles under need-to-know.
  • Every questionnaire, response, evidence item and decision is written to an append-only audit trail.
  • Data residency and retention for assessment records are configurable to your regulatory obligations.

Compliance support

  • Supports vendor and outsourcing due-diligence expectations under operational-resilience regimes
  • Underpins risk-based assessment and sign-off obligations for third-party onboarding
  • Supports sanctions and financial-crime screening of vendors and their principals
  • Assists periodic re-diligence and evidence-currency requirements
  • Provides documented, timestamped evidence of vendor assessment for audit and examination

Reports & exports

  • Assessment status and completion reports by vendor and tier
  • Evidence-validation and expiry reports
  • Screening-outcome reports for vendors and principals
  • Decision, condition and remediation reports
  • Re-diligence due and overdue reports
  • Due-diligence management information for risk and procurement governance
Best practice

How to get the most from it

Scope to the risk, not the template

Tailor the questionnaire to the vendor's tier and service. A right-sized assessment gets better answers than a generic one that asks a low-risk supplier a hundred irrelevant questions.

Insist on evidence, then check it

Require supporting evidence for material claims and validate it against the answer. An assessment full of unverified assertions is a false comfort.

Record the residual risk, not just the yes

Capture what risks remain after diligence and any conditions attached to approval. That is the reasoning an examiner and your own future self will need.

Reuse at renewal

Build re-diligence on the retained prior assessment. Restarting from zero wastes effort and hides how the vendor's risk profile has moved.

FAQ

Questions, answered

How are questionnaires tailored to each vendor?

The questions are scoped to the vendor's tier, category and the nature of what it provides, so a critical provider is assessed deeply on what matters and a low-risk supplier is not buried in irrelevant questions. Diligence is proportionate rather than one-size-fits-all.

How is evidence handled?

Supporting evidence is attached to the specific response it substantiates, checked against the claim, and its expiry tracked — so the assessment records verified facts, and an answer with no evidence behind it is visible as an unsupported assertion.

Does this screen the vendor as well?

Yes. The vendor entity and its beneficial owners and principals are screened against the sanctions, PEP and adverse-media sources configured for your deployment, with the results captured on the assessment record alongside the questionnaire and evidence.

How does re-diligence at renewal work?

Prior assessments are retained and reused, so a renewal updates the previous picture rather than starting from scratch, and the change in the vendor's risk profile over time is visible on one record. Re-diligence can be scheduled on a risk-based cycle from the vendor's record.

Is OnyxOne deciding whether to approve a vendor?

No. The platform scopes the diligence, collects and validates the evidence, screens the vendor and summarises the risk, but a person makes and signs off the risk-based decision and owns it. OnyxOne is decision-support software, not the approver.

See Vendor Due Diligence in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.