For teams that own third-party risk

Vendor due diligence that doesn't stop at onboarding.

Vendor due diligence is how you verify that a supplier's technology, security and practices won't become your risk. Most organisations check once at onboarding and never look again, while the vendor's stack, staff and subprocessors keep changing. StackUp puts vendor due diligence on a standard, repeatable framework, with automation to keep it running.

Independent · no upsell · money-back guarantee

Vendor risk snapshot · Sample Co8 gaps found

Exposure across key vendors

$270,000

  • HighCritical vendor, no breach notification clause$85K
  • HighPayment data with an unassessed supplier$75K
  • MediumNo exit plan for core platform vendor$65K
  • Quick winRe-assess top five vendors on one framework$45K
Third-party risk, priced and prioritised
1
consistent framework across every vendor
8
technology pillars, including vendor management
<1 hr
to baseline your vendor risk posture
$40,000
saved vs a consulting engagement

Trusted by former CTOs of

Toyota logo
HSBC logo
Lendlease logo
Merivale logo
Seek logo
Dubai Holding logo
ASX logo
BOQ logo

The gap

Why vendor due diligence fails after the contract is signed

The onboarding questionnaire captures a vendor at their best moment. Every quarter after that, the answers age, and the risk quietly transfers to you.

Business partners finalising a vendor agreement after due diligence

One framework for every vendor

Ad-hoc reviews produce incomparable answers: one vendor judged on a spreadsheet, another on a phone call. StackUp scores vendor management as one of the eight pillars of your technology function, so third-party risk is assessed on the same evidence-based standard as everything else, and expressed in dollars.

Consistent standardEvidence-basedDollar-sized exposureBoard-ready reporting

Oversight that keeps running

Vendors change, ownership, subprocessors, security posture. On StackUp's Continuously Improve plan, vendor due diligence is automated, so re-assessment happens on cadence rather than after an incident. Where a vendor's security is the concern, go deeper with cybersecurity due diligence; where you are absorbing their systems in a deal, run IT due diligence.

Automated re-assessmentChange-driven reviewsExit-plan visibilityPortfolio view

How it works

Three steps to standing vendor oversight

01

Baseline

Put every key vendor on one standard.

  • Assess your vendor management posture across the stack
  • Identify unassessed suppliers handling sensitive data
  • Under an hour to establish the baseline
02

Prioritise

See which vendor risks are worth money.

  • Each exposure sized in dollars, not severity colours
  • Contract gaps flagged: notification, exit, data ownership
  • Board-ready view of third-party risk
03

Monitor

Keep diligence current as vendors change.

  • Automated vendor due diligence on the platform
  • Re-assessment on cadence, not after incidents
  • Track risk trend across your vendor portfolio

Why StackUp

Beyond the onboarding questionnaire

Questionnaires document intentions. A standing framework measures reality, and keeps measuring it.

Questionnaire-based vendor reviews

  • A 200-question spreadsheet nobody re-reads
  • Point-in-time answers, stale within a quarter
  • A different bar for every vendor
  • No link between vendor risk and dollars

StackUp

  • One standard framework across every vendor
  • Re-assessment as vendors and usage change
  • Exposure expressed in dollars and priorities
  • Automated vendor due diligence built into the platform

Reviews

What leaders say about standardised oversight

Executives on moving third-party and technology risk onto one measurable standard.

Not only saved us significant effort and costs but also ensured we had the insights needed to confidently move forward in our deal process.
Jaron Yuen, Managing Director, MA Financial Group
Jaron Yuen
Managing Director, MA Financial Group
Takes the subjectivity and emotion out of assessing technology capability and drives focus on the right areas for improvement.
Ben Tabell, CIO, Technically Savvy
Ben Tabell
CIO, Technically Savvy
Comprehensive and fast.
Justus Hammer, Co-Founder & CEO, Mad Paws
Justus Hammer
Co-Founder & CEO, Mad Paws

FAQs

Vendor Due Diligence questions, answered

What is vendor due diligence?

Vendor due diligence is the structured evaluation of a third-party supplier's technology, security, financial stability and practices before, and during, a commercial relationship. For technology vendors it covers data handling, security posture, resilience, subprocessors and contract terms such as breach notification and exit provisions.

What should vendor due diligence assess?

Five areas do most of the work: data security and privacy (what the vendor can access and how it's protected), operational resilience (backup, recovery, continuity), contractual protections (notification, audit rights, exit and data return), concentration risk (how hard the vendor is to replace) and compliance posture. Each should carry an owner and a review date.

How often should vendors be re-assessed?

Critical vendors quarterly or on any material change, new ownership, new subprocessors, a security incident, a big usage expansion. Lower-tier vendors annually. The honest answer is: more often than almost any organisation currently manages, which is why StackUp automates vendor due diligence rather than relying on calendar discipline.

How is this different from a security questionnaire?

A questionnaire records what the vendor says about themselves at one moment. A due diligence framework scores the risk the relationship actually creates for you, on evidence, on a consistent standard, with a dollar figure, and repeats the check as things change. The questionnaire is an input; it was never the oversight.

How does StackUp automate vendor due diligence?

Vendor management is one of the eight pillars in every StackUp assessment, and the Continuously Improve plan includes automated vendor due diligence, standing re-assessment with AI agent insights, tracked actions and a portfolio view. You set the standard once and the platform keeps applying it.

Put every vendor on one standard

Book a demo to unlock your free 30-day trial. 30 minutes with the founder. Money-back guarantee.

Book a demo