EPIC Insurance Brokers & Consultants
Vendor Due Diligence Steps for Organizations
Pages
2
Time to read
5 mins
Publication
Language
English
Pages
2
Time to read
5 mins
Publication
Language
English
This guide outlines essential steps for conducting vendor due diligence, which is critical for organizations outsourcing business functions. It highlights the increasing risk of data breaches associated with third-party vendors, citing that 62 percent of breaches occur through these channels. The document emphasizes the importance of prioritizing vendors based on their access to critical data and the level of risk they present. It suggests a tiering approach to categorize vendors and establishes general categories for due diligence, including financial stability, corporate reputation, and governance practices. Additionally, it addresses the need to consider fourth-party risks, which involve the risks posed by a vendor's subcontractors. The guide aims to provide a foundational framework for organizations to enhance their vendor risk management processes.