Vendor Due Diligence
Assess vendors with questionnaires, evidence and risk-based sign-off
Run structured due diligence on a vendor — issuing assessment questionnaires, collecting and validating evidence, screening the entity and its principals, and reaching a risk-based decision with the right sign-off — so every onboarding and renewal rests on a documented, defensible basis rather than a hurried check. Due diligence is the deep-dive that decides whether a firm should take a vendor on and on what terms. OnyxOne turns it from a chased-by-email scramble into a repeatable assessment where the questions fit the risk, the evidence is captured against the answers, and the decision and its reasoning live on the record.
How it works, visually
A representative path for onboarding and re-assessing a third party, with escalation where risk warrants it.
The problems this module solves
The operational realities that make this hard for compliance and risk teams today.
Questionnaires are chased over email
Assessment questions go out as a spreadsheet attachment, responses trickle back in different formats, and the assessor spends more time chasing and collating than analysing. There is no single place where a vendor's assessment actually lives.
Evidence is claimed but never validated
A vendor ticks a box to say it holds a certification or a control, but the supporting evidence is missing, expired, or never checked against the claim. The assessment records assertions, not verified facts, and no one can tell the difference later.
Every vendor gets the same questionnaire
A generic assessment asks a low-risk supplier hundreds of irrelevant questions and a critical provider too few of the ones that matter. Without risk-based scoping, diligence is simultaneously burdensome and inadequate.
The decision basis isn't recorded
A vendor is approved, but why — what the residual risks were, what conditions were attached, who signed off — lives in an email or a memory. When the relationship later goes wrong, the firm cannot show the decision was reasoned.
Re-diligence starts from scratch every time
At renewal, the previous assessment cannot be found or reused, so the whole exercise is repeated from zero. Effort is duplicated, and there is no clean view of how a vendor's risk profile has changed over time.
How OnyxOne addresses it
Questionnaires issued and tracked in one place
Assessments are issued to vendors, completed and returned within the platform, so responses arrive in a consistent structure and the whole assessment lives on the vendor's record. Chasing and collating give way to reviewing.
Evidence captured against each answer
Supporting evidence is attached to the specific response it substantiates and checked against the claim, with expiry tracked. The assessment records verified facts, and an assertion without evidence is visible as exactly that.
Risk-based questionnaire scoping
The questions a vendor receives are scoped to its tier, category and the nature of what it provides, so a critical provider is probed deeply on what matters and a low-risk supplier is not buried in irrelevance. Diligence is proportionate by design.
A recorded, risk-based decision
The assessor reaches a decision with the residual risks, any conditions and the sign-off captured on the record. The basis for onboarding or renewing a vendor is documented as it is made — defensible if the relationship is ever questioned.
Reusable assessments across the lifecycle
Prior assessments are retained and reused at renewal, so re-diligence updates the previous picture instead of starting from zero, and the change in a vendor's risk profile over time is visible on one record.
What's in the module
Turn on what you need and add more as your programme scales.
Assessment questionnaires
Issue structured due-diligence questionnaires and collect responses within the platform.
Risk-based scoping
Scope the questions to the vendor's tier, category and service so diligence is proportionate.
Evidence collection & validation
Attach evidence to each response, check it against the claim and track its expiry.
Screening of entity & principals
Screen the vendor and its beneficial owners and principals against sanctions, PEP and adverse-media sources.
Assessment scoring
Score responses and evidence to summarise a vendor's risk position for the decision.
Risk-based sign-off
Record the decision, residual risks and conditions with the appropriate approval.
Conditions & remediation
Attach conditions or remediation actions to an approval and track them to completion.
Reusable assessment history
Retain prior assessments so renewals update the picture rather than restarting it.
Renewal & re-diligence
Trigger and run re-assessments on a risk-based cycle from the vendor's record.
Immutable assessment trail
Every questionnaire, response, evidence item and decision is written to an append-only record.
The views your team works from
Purpose-built dashboards and views, each answering a question a specific role needs to act on.
A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.
Assessment pipeline
Due-diligence assessments in progress by stage and tier, highlighting overdue questionnaires and pending sign-offs.
Evidence status
Evidence collected, validated, missing or expiring across assessments, so gaps are closed before decision.
Screening results
Screening outcomes for vendors and their principals, with hits routed for review before approval.
Decision log
Recorded decisions with residual risks, conditions and sign-off, giving a defensible view of every vendor approval.
Renewal calendar
Vendors due for re-diligence on their risk-based cycle, so renewals are prompted before evidence goes stale.
What the platform automates
Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.
Questionnaire issuance
Assessments scoped to the vendor's tier are issued automatically, with reminders driven until responses are complete.
Evidence-expiry tracking
Attached evidence nearing expiry is flagged automatically so the assessment does not silently go stale.
Principal screening
The vendor and its principals are screened automatically as part of the assessment and re-screened on list updates.
Sign-off routing
Completed assessments route to the appropriate approver automatically based on the vendor's tier and residual risk.
Renewal scheduling
Re-diligence is scheduled automatically on each vendor's risk-based cycle and prompted ahead of time.
Where AI helps the analyst
Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.
Response summarisation
Summarises a vendor's questionnaire responses and evidence so the assessor can review them quickly, then verify before deciding.
Evidence-consistency checks
Flags where attached evidence appears inconsistent with, or does not support, a response, for the assessor to examine.
Question suggestion
Suggests follow-up questions where a response is thin or concerning, which the assessor chooses whether to pursue.
The enterprise workflow
A defined, end-to-end process with clear ownership at every stage.
Every result, decision and override is captured against the record it belongs to.
Scope
The questionnaire is scoped to the vendor's tier, category and service, so it asks what matters and skips what does not.
Issue & collect
The assessment is issued to the vendor, completed within the platform, and returned with responses in a consistent structure.
Validate evidence
Supporting evidence is attached to each response, checked against the claim, and its expiry recorded.
Screen & score
The vendor and its principals are screened, and responses and evidence are scored into a summary risk position.
Decide & sign off
The assessor records a risk-based decision with residual risks and any conditions, and the appropriate approval is applied.
Retain & renew
The assessment is preserved and reused at renewal, so re-diligence updates the picture and tracks how the profile changes.
What your team gains
Assessment, not admin
Questionnaires issued, completed and evidenced in the platform replace email chasing, so assessors spend their time analysing rather than collating.
Facts, not assertions
Evidence captured against each answer and checked for expiry means the assessment records verified facts, and unsupported claims are visible as such.
The right depth of diligence
Risk-based scoping probes critical vendors deeply and spares low-risk ones the irrelevant, so diligence is neither burdensome nor inadequate.
A documented decision basis
Residual risks, conditions and sign-off recorded on the vendor's record mean an onboarding questioned later is already accounted for.
Renewals build on the past
Retained, reusable assessments let re-diligence update the previous picture instead of restarting, and show how a vendor's risk has changed.
Faster, calmer audits
Because questions, evidence, screening and sign-off all live on the record, showing how a vendor was assessed is retrieval, not reconstruction.
Industries it serves
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.
- Runs within the third-party-risk lifecycle, drawing tier and context from the vendor's register record
- Screens the vendor and its principals against the sanctions, PEP and adverse-media sources configured for your deployment
- Collects and preserves supporting evidence from and to your existing document repositories
- Aligns diligence outcomes with your existing procurement and contract-management systems
- Routes questionnaire issuance, reminders and approvals through your existing email and messaging channels
Security, compliance & reporting
Security & data handling
- Assessments, responses and evidence are encrypted in transit and at rest.
- Role-based access controls who can scope, issue, assess and approve a due-diligence assessment.
- Segregation of duties can separate the assessor from the approver, where policy requires it.
- Sensitive vendor evidence is restricted to authorised roles under need-to-know.
- Every questionnaire, response, evidence item and decision is written to an append-only audit trail.
- Data residency and retention for assessment records are configurable to your regulatory obligations.
Compliance support
- Supports vendor and outsourcing due-diligence expectations under operational-resilience regimes
- Underpins risk-based assessment and sign-off obligations for third-party onboarding
- Supports sanctions and financial-crime screening of vendors and their principals
- Assists periodic re-diligence and evidence-currency requirements
- Provides documented, timestamped evidence of vendor assessment for audit and examination
Reports & exports
- Assessment status and completion reports by vendor and tier
- Evidence-validation and expiry reports
- Screening-outcome reports for vendors and principals
- Decision, condition and remediation reports
- Re-diligence due and overdue reports
- Due-diligence management information for risk and procurement governance
How to get the most from it
Scope to the risk, not the template
Tailor the questionnaire to the vendor's tier and service. A right-sized assessment gets better answers than a generic one that asks a low-risk supplier a hundred irrelevant questions.
Insist on evidence, then check it
Require supporting evidence for material claims and validate it against the answer. An assessment full of unverified assertions is a false comfort.
Record the residual risk, not just the yes
Capture what risks remain after diligence and any conditions attached to approval. That is the reasoning an examiner and your own future self will need.
Reuse at renewal
Build re-diligence on the retained prior assessment. Restarting from zero wastes effort and hides how the vendor's risk profile has moved.
Questions, answered
How are questionnaires tailored to each vendor?
The questions are scoped to the vendor's tier, category and the nature of what it provides, so a critical provider is assessed deeply on what matters and a low-risk supplier is not buried in irrelevant questions. Diligence is proportionate rather than one-size-fits-all.
How is evidence handled?
Supporting evidence is attached to the specific response it substantiates, checked against the claim, and its expiry tracked — so the assessment records verified facts, and an answer with no evidence behind it is visible as an unsupported assertion.
Does this screen the vendor as well?
Yes. The vendor entity and its beneficial owners and principals are screened against the sanctions, PEP and adverse-media sources configured for your deployment, with the results captured on the assessment record alongside the questionnaire and evidence.
How does re-diligence at renewal work?
Prior assessments are retained and reused, so a renewal updates the previous picture rather than starting from scratch, and the change in the vendor's risk profile over time is visible on one record. Re-diligence can be scheduled on a risk-based cycle from the vendor's record.
Is OnyxOne deciding whether to approve a vendor?
No. The platform scopes the diligence, collects and validates the evidence, screens the vendor and summarises the risk, but a person makes and signs off the risk-based decision and owns it. OnyxOne is decision-support software, not the approver.
Related modules
See Vendor Due Diligence in your programme
Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.