What does the due diligence process look like?
There is no universal standard for exactly how due diligence should be carried out. But organisations that have made it work tend to follow the same six steps, with each step building on the previous one.
1. Mapping and verification
First, you need to know which suppliers you have – and make sure the basic information about them is correct. This step is often underestimated. Open almost any supplier register and you are likely to find duplicates, dormant relationships and companies where no one quite remembers who owns the relationship anymore.
Supplier information is verified against official registers, including ownership structure, financial status and whether the business is actually active. If you have long or complex supply chains, this verification may also need to extend to subcontractors where relevant.
We cover this step in detail in How to map your global supply chain.
2. Risk-based prioritisation
Once your suppliers have been mapped, you categorise them according to risk. Factors may include country, industry, contract value, how critical the supplier is and what data they have access to.
This classification determines how far you need to go in the following steps. A supplier in a conflict-affected region should not be assessed in the same way as a supplier of office paper. Likewise, an ICT third-party provider with access to key systems should not be treated like a cleaning company.
Without prioritisation, due diligence either becomes too superficial or prohibitively expensive.
3. Screening
Screening involves automated checks against sanctions lists, watchlists and PEP lists (politically exposed persons), often supplemented by adverse media monitoring.
It is an ongoing activity, not a one-off check. Lists change and ownership structures change. A supplier that showed no warning signs last year may be flagged today.
4. In-depth assessment
Suppliers classified as high risk require closer assessment. This is where self-assessment questionnaires (SAQs) come in, together with policies, certificates, interviews and, in some cases, site visits or third-party audits.
From a sustainability perspective, the questions cover areas such as human rights, working conditions, environmental impact and business ethics. From a cyber perspective, they focus on information security, data protection and continuity.
Under DORA, organisations must also maintain a formal register of their contractual arrangements with ICT third-party service providers.
5. Remediation and issue management
This is where information gathering turns into action.
A gap – whether it is a supplier failing to meet requirements, a risk that has materialised or an SAQ response that reveals a weakness – requires dialogue, a remediation plan, escalation and, ultimately, termination of the relationship if necessary.
Actions need to be documented, time-bound and followed up.
This is where many organisations get stuck. The information has been collected, but no one takes the next step on the issues identified. That transition determines whether due diligence creates real impact or simply loses momentum.
6. Monitoring and reporting
The final step never really ends.
Self-assessments need to be renewed on time, corrective actions need to have an effect, the current status must be reportable to management and the documentation must be ready when auditors come knocking.
This is also where the work becomes visible externally – to the board, to customers with their own requirements and to supervisory authorities under CSDDD, NIS2 and similar regulations.
A mature due diligence process can show the full chain at any time – from risk to SAQ to action to follow-up – without someone having to piece everything together manually.
These six steps are not a linear journey. They run in cycles as supplier relationships evolve, while different suppliers move through different stages at the same time. It is this parallel nature of the work that makes Excel increasingly difficult to rely on once you have more than a handful of active supplier relationships.
Where does due diligence fit into the procurement process?
Due diligence is not a separate project alongside procurement. Its activities should be embedded into the procurement process you already have.
When it works well, procurement teams do not experience it as additional work. It becomes part of their everyday work – with better information to support decisions.
Before contract: qualification
This is where verification, screening and an initial assessment take place.
For low-risk suppliers, this may be enough. For high-risk suppliers, a more in-depth SAQ process starts before the contract is signed.
This is also where due diligence can have the greatest impact, because a known risk is always harder to manage once the supplier is already under contract.
In the contract
Requirements are formally embedded in the agreement: the supplier code of conduct, audit rights, requirements for subcontractors, information security and ICT appendices – the latter particularly relevant under DORA – incident reporting obligations, and the right to escalate or terminate the agreement if compliance falls short.
These clauses are not just a matter for legal.
If procurement does not understand which clauses address which risks, the contract can easily become a paper exercise rather than an effective risk management tool.
During the relationship: ongoing monitoring
Once the supplier relationship is established, an ongoing monitoring cycle begins: renewed self-assessments, new screenings, potential site visits and status updates.
The level of risk determines the frequency. A critical supplier might be reviewed every quarter, while a low-risk supplier may require significantly less frequent follow-up.
This is where system support saves the most time. Reminders are sent automatically, status updates are kept where they belong and no one has to keep track of every cycle in their head.
When an issue occurs
Something happens: there is an incident at a supplier, a screening generates a flag or an SAQ response does not add up.
Procurement then needs to know exactly what happens next: escalation path, remediation plan, deadline and follow-up.
This is where the difference between a documented process and a process that actually works becomes clear.
During renegotiation and renewal
When a contract comes up for renewal, the supplier's history becomes part of the decision-making process.
How well did the supplier handle follow-ups? What issues were identified, and how were they addressed? Has the risk increased or decreased?
For many organisations, this is the point where due diligence data starts to actively inform procurement decisions rather than simply documenting them.
The common denominator across all phases is procurement. Sustainability and security contribute specialist knowledge and help define priorities, but procurement owns the supplier relationship, the contract and the escalation process.
Four common challenges in due diligence
Most organisations already carry out some form of supplier assessment. The question is how.
Across the organisations we speak to – regardless of sector or level of maturity – we repeatedly see four common patterns.
Volume without prioritisation
Hundreds or thousands of suppliers are treated in the same way. The same code of conduct, the same questionnaire, the same monitoring frequency.
It looks structured, but it does not reflect the actual risk.
A high-risk supplier in a conflict-affected region ends up in the same process as an office supplier in Sweden, while a critical subcontractor further upstream may not be visible at all.
Collecting information instead of managing risk
Sending out self-assessments, collecting policies and updating CSR reports is exactly that: information gathering.
It creates documentation, which is valuable during an audit. But documentation alone does not reduce risk.
Risk is reduced only when the information you collect leads to actions being prioritised, implemented and followed up. Many organisations stop at the information-gathering stage and call it due diligence.
Unclear ownership between procurement, sustainability and security
ESG questions tend to land with sustainability. Cyber questions go to IT or information security. The relationship itself – the contract, the dialogue and the escalation process – sits with procurement.
When responsibility is spread across three functions, no one owns the full picture. Critical issues fall between the cracks or are addressed too late.
Read our article on collaboration between procurement and sustainability for a deeper look at how responsibilities can be shared.
Reactive, regulation-driven work
When a new regulation takes effect – CSRD, then CSDDD, EUDR, CBAM, NIS2 or DORA – organisations often start again from scratch.
Resources are spent understanding the latest regulation and rebuilding the tools around it, rather than incorporating the new requirements into an existing way of working.
The organisation keeps rebuilding the structure instead of using it. The cost of inaction explores this pattern in more detail.
This is not a problem that can be solved with more templates or more people. It is a structural problem. And as long as the structure is missing, supply chain complexity will continue to grow faster than your ability to control it.
Risk-based prioritisation: the logic that connects due diligence
Risk is not just another perspective alongside compliance, sustainability and security. It is the logic that connects them.
Why? Because risk is what forces you to prioritise.
At its worst, compliance can become an endless checklist of requirements. Sustainability can be reduced to a supplier code of conduct. Cybersecurity can become a collection of controls.
But when you start with risk – which suppliers are most critical, what risks they expose you to, how likely those risks are and how serious the impact could be – every activity becomes connected to the organisation's actual situation.
For a deeper look at what risk maturity means in practice, read our article on supply chain risks.
In practice, this means:
- A self-assessment only becomes meaningful when it is connected to a risk. What are you trying to protect against with this particular supplier? Once you have answered that question, data collection becomes a tool for reducing risk rather than an end in itself.
- In-depth reviews are prioritised based on criticality and risk, not on what happens to be easiest to assess. Ten thorough reviews are more valuable than a hundred superficial ones.
- Issue management becomes a way to verify that the most significant risks are under control, rather than a separate administrative process alongside the supplier relationship.
- ESG and cyber risks are prioritised together when they relate to the same supplier. A critical supplier is critical regardless of the type of risk it exposes you to.
With risk at the centre, you also gain a common frame of reference – a language that the Head of Procurement, Head of Sustainability, CISO, Legal and the CEO can all understand.
The conversation shifts from “Which regulations do we need to comply with?” to “Which risks are we willing to accept in our value chain – and which are we not?”
Collecting information is not enough – action is what protects your organisation
This is where most initiatives lose momentum, and it is worth looking at more closely.
The pattern is almost always the same. An organisation invests in good questionnaires, collects policies from hundreds of suppliers, categorises the responses and stores everything in an archive.
And that is where the work stops.
Issues are recorded but not followed up. High-risk suppliers are flagged but not escalated. Controls are scheduled but never completed.
The problem is not a lack of knowledge – most organisations know exactly what they should be doing. The problem is execution.
And that is where the difference becomes clear between due diligence that actually protects the organisation and due diligence that merely shows an attempt was made.
Due diligence creates real value when:
- The Head of Procurement can see the status of all supplier assessments without having to call the Head of Sustainability or the CISO.
- The responsible category manager knows which risks are associated with their suppliers and can take action where the relationship is managed.
- Issues are escalated automatically when thresholds are exceeded, rather than when someone happens to spot them in a spreadsheet.
- Management gets a consolidated view of risk across the value chain – covering both ESG and cyber – without someone manually combining three separate reports.
- An auditor can trace the full chain from risk to SAQ to action to follow-up without exporting data from five different systems.
These are not minor tool features. They are the difference between a due diligence process that lives with one specialist and one that has become part of how the value chain is managed.
System support is part of the solution. Equally important is giving procurement, sustainability and security a shared place to work, where everyone uses the same assessments and the same follow-up process.
Here we explore what that can look like in practice when you scale supplier assessments.
Three levels of due diligence maturity – where are you?
Maturity in due diligence is more about the type of work you do than the amount of work you do.
Most organisations move through three levels. The first step towards progressing is understanding where you are today.
Level 1: Reactive
Work happens when someone raises a flag. A stakeholder gets in touch, an incident occurs or a regulation requires a response.
Between these events, the work largely sits still.
Documentation lives in Excel spreadsheets and Word templates, usually managed by one or two people who “know how it works”. Individual questions can be answered, but there is no consolidated overview.
The supplier code of conduct exists and is sent out – but it may be unclear who has signed it and when.
This is where most organisations start.
It is also the level where replacing a key person, or introducing a single new requirement, quickly exposes how fragile the underlying structure is.
Level 2: Structured
There is now a defined process that is documented and embedded in the organisation.
SAQs are sent out systematically, screening runs continuously and the supplier code of conduct is included in every contract.
But the process usually covers only one side of the equation: ESG or cyber, rarely both within the same flow.
System support is in place, but information gathering and action remain separate activities, and the volume of documentation often grows faster than the actual reduction in risk.
This is the most common stage for organisations that have moved beyond the beginner phase.
It is also where fatigue can start to set in: “We are doing all of this, but I’m not sure it is actually protecting us.”
Level 3: Integrated
Risk determines what is done, when it is done and how far the assessment needs to go.
ESG and cyber are managed in the same flow for the same supplier. Issues are escalated automatically and are not closed until the action taken has been documented.
Procurement, sustainability and security work in the same system using the same data.
When the board asks for the current risk picture across the value chain, the answer is already on the screen. No one needs to spend the weekend manually combining three reports.
Historical data is also used to inform procurement decisions – during renegotiations, when selecting a new supplier or when reviewing a category.
At this level, due diligence is no longer simply a cost of compliance. It becomes a foundation for better business decisions.
Indicators at each level
Six indicators show how due diligence develops from Level 1 (Reactive), through Level 2 (Structured), to Level 3 (Integrated):
- Tools: From Excel, Word and email, through system support that is often separate for each perspective, to one shared way of working across ESG and cyber.
- Prioritisation: From no formal prioritisation beyond what gets flagged, through categorisation that exists but does not drive resource allocation, to risk-based prioritisation that guides every activity.
- Information gathering: From ad hoc collection, through a systematic SAQ cycle, to SAQ cycles linked to risk level and contract stage.
- Action: From reactive and often undocumented, through manual processes that depend on individual ownership, to automated escalation with documented follow-up.
- Reporting: From manual compilation when needed, through periodic reports that are often separate for ESG and cyber, to a consolidated real-time view across all risk types.
- Ownership: From unclear ownership, through clear responsibility within each perspective but unclear handovers between functions, to procurement at the centre with other functions providing specialist support.
Most organisations are somewhere between Levels 1 and 2.
Moving to Level 3 rarely requires one major transformation. It is more often the result of a series of deliberate choices: letting risk drive prioritisation, managing ESG and cyber in the same flow, and shifting the focus from collecting information to taking action.
From a specialist responsibility to part of everyday procurement
The biggest difference between organisations that experience due diligence as a burden and those that have made it an effective part of their operations is not how much they do.
It is where the work happens.
In one organisation, due diligence is a specialist responsibility. The Head of Sustainability manages the ESG perspective, the CISO manages cyber and procurement operates separately with its contracts.
Each function produces its own documents and reports, but the full picture never exists in one place. When management asks for it, someone has to compile it manually for that specific occasion.
In another organisation, due diligence is embedded directly into the procurement process.
The specialists define the questions, thresholds and risk classifications. But the work itself happens where the supplier relationship is managed.
Ownership is distributed – and that is precisely why the process holds up over time.
This is the way of working the Stratsys Due Diligence suite is built to support. Not as a tool for the specialist alone, but as a shared place where procurement, sustainability and security work together.
Explore the Due Diligence suite
Definitions and key concepts
Value chain due diligence – The structured process of identifying, assessing, addressing and following up on risks among suppliers, partners and subcontractors. It brings sustainability and cyber perspectives together in one way of working and may extend across multiple tiers of the supply chain. It is driven by regulations such as CSDDD, the Norwegian Transparency Act, EUDR, CBAM, the EU Forced Labour Regulation, NIS2 and DORA. It should be distinguished from information security and data protection, which refer to an organisation's own internal security work.
Verification – Checking that a supplier exists, is active and that basic information such as ownership structure, financial status and business description is correct. This is the first step in the due diligence process.
Screening – Automated checks against sanctions lists, watchlists and PEP lists (politically exposed persons), often supplemented by adverse media monitoring. Screening is carried out continuously, rather than as a one-off exercise.
Risk-based prioritisation – Categorising suppliers according to risk level based on factors such as country, industry, contract value, criticality and access to sensitive assets. This determines the depth of the subsequent assessment.
SAQ (Self-Assessment Questionnaire) – A questionnaire completed by the supplier and adapted to the relevant risk level and perspective – ESG, cyber or both. It provides the basis for a more in-depth assessment.
Third-party risk – An umbrella term for risks arising from an organisation's dependence on external parties. It includes both ESG and cyber risks and has become increasingly common as supply chains have grown more complex.
High-risk supplier – A supplier that, following the prioritisation stage, is assessed as exceeding a defined threshold that warrants more in-depth evaluation. Each organisation defines this threshold based on its own business context, typically using factors such as country, industry, contract value and criticality.
Issue – An identified gap between what is required of a supplier and what is actually delivered, identified through an SAQ response, screening, an audit or the ongoing supplier relationship. An issue triggers a remediation plan.
Remediation plan – A documented and time-bound plan describing how an issue will be addressed, the steps the supplier needs to take and how follow-up will be carried out. A remediation plan without a deadline is a request, not an action.
Supplier code of conduct – The requirements you place on suppliers regarding behaviour, ethics and business practices. To have real impact, it should be embedded in the contract and linked to a clear follow-up mechanism.
ICT third-party service provider – A DORA term for providers of information and communication technology services on which financial entities depend. These providers are subject to specific requirements for contractual arrangements and ongoing monitoring.
DORA Register of Information / DORA-100 – The formal register of contractual arrangements with ICT third-party service providers that financial entities are required to maintain under DORA.
Webinars on the topic
Over the past few years, we have brought together experts in sustainability, procurement, legislation and information security for a series of webinars on due diligence in the value chain.
Below you will find the recorded sessions, arranged in an order that reflects how many organisations progress through the topic themselves – from the fundamentals and practical implementation to strategy and more in-depth perspectives.
Strategy and in-depth perspectives
- Due Diligence Insights 2.0 (in English) — Strategic insights and practical examples from some of Europe's most experienced experts in sustainability, procurement and legislation.
- Sustainable Supply Chains in a Regulatory Jungle (in English) — How to navigate a rapidly expanding regulatory landscape in which CSRD, CS3D, EUDR and REACH need to be managed simultaneously, while the rules themselves continue to evolve.
- Due Diligence – From a Product Assessment Perspective (in English) — Due diligence from a product assessment perspective, with Anna Lindstedt. Particularly useful for industries heavily affected by EUDR and CBAM, where traceability needs to extend to product level.