Back to resources
RisksArticle

What to check on a vendor before you sign

A questionnaire sent once is not due diligence. Here is how to tier vendors, write the contract and review the files that actually matter.

8 min readSeptember 2026

When a vendor hosts your personal information or connects to your systems, their incident becomes yours. Law 25 leaves the enterprise accountable to the people concerned. ISO 27001:2022, in controls A.5.19 to A.5.23, asks for a written agreement and follow-up over time. Most teams have the vendor fill in a form at onboarding, then file it.

Three tiers, not one questionnaire

Sending 80 questions to the coffee supplier wastes time on both sides. The tier follows what the vendor actually touches.

Standard

No personal information, no access to your systems. A light check at onboarding is enough, as long as the service does not change.

Important

They process some of your personal information, or they have an account in an application that is not critical. Ask where the data sits, who their subcontractors are, and how they notify you of an incident.

Critical

They hold sensitive personal information, an administration access, or a service you cannot operate without. Add a right to verify, an exit plan, and a review at least once a year.

What the written contract has to say

To entrust personal information to a service provider, Law 25 expects a written contract. Someone who is not a lawyer should be able to read it.

  • The measures the vendor takes to protect confidentiality.

  • Use limited to performing the mandate. No resale, and no training of a model on your data, unless a clause says so.

  • Retention ends with the mandate, with return or destruction.

  • Notice without delay of any breach or attempted breach of the confidentiality obligations.

  • The list of subcontractors, and a duty to tell you before adding one that touches the same information.

Review the file, do not only create it

An ISO or SOC 2 certificate from three years ago says nothing about the service you use today. Tie the review to the risk.

Critical

At least once a year, after an incident, and when the vendor changes a subcontractor or a hosting region.

Important

At contract renewal, and if the nature of the service changes.

Standard

At onboarding only, unless the vendor starts touching personal information or a system.

Exit is part of due diligence

When the contract ends, take the information back or have it destroyed, revoke accounts and remote access, and require the same from subcontractors. A dated, signed destruction certificate is worth more than an email that says it is done.

A vendor register that actually gets reviewed

CapTRISK tracks the inventory, questionnaires, score and review dates, instead of a file forgotten in a mailbox.