Prompt

What should be part of a vendor onboarding compliance workflow?

Latest observation

Jul 15, 2026 · OpenAI APIWeb search: off

A solid vendor onboarding compliance workflow should cover risk, legal, security, financial, and operational checks before a vendor is approved. Here’s a practical checklist of what to include:

1. Vendor intake and classification

  • Collect basic vendor information:
    • Legal name, tax ID, address, country of incorporation
    • Primary contacts
    • Services/products provided
    • Ownership structure
  • Classify the vendor by:
    • Risk level
    • Data access level
    • Criticality to operations
    • Geography/jurisdiction
    • Whether they are subcontractors or third parties

2. Due diligence screening

  • Sanctions and watchlist screening
  • Anti-bribery/anti-corruption checks
  • Politically exposed person (PEP) screening where relevant
  • Adverse media review
  • Beneficial ownership verification
  • Litigation, bankruptcy, and regulatory action checks
  • Conflict of interest disclosure

3. Legal and contract review

  • Standard terms and conditions
  • Data processing agreements, if personal data is involved
  • Confidentiality/NDA requirements
  • Service level agreements and performance terms
  • Audit rights
  • Termination and exit clauses
  • Liability, indemnity, insurance requirements
  • Jurisdiction and governing law review

4. Security and privacy assessment

If the vendor will handle systems, data, or facilities:

  • Security questionnaire
  • Information security controls review
  • Access control and identity management checks
  • Encryption requirements
  • Incident response and breach notification process
  • Business continuity and disaster recovery evidence
  • Secure development practices, if applicable
  • Privacy impact assessment
  • Data retention and deletion requirements
  • Subprocessor/subcontractor review

5. Financial and operational review

  • Financial stability assessment
  • Credit checks, if appropriate
  • Business continuity of supply
  • Capacity and delivery capability
  • Reference checks
  • Insurance coverage verification
  • Certifications/licenses required to provide the service

6. Compliance and regulatory checks

Depending on industry and geography:

  • AML/KYC requirements
  • Export controls and trade restrictions
  • Industry-specific regulatory obligations
  • Labor and human rights compliance
  • Environmental, social, and governance requirements
  • Modern slavery/supply chain due diligence
  • Records retention requirements

7. Approval workflow

  • Assign approvers based on risk tier
  • Require sign-off from:
    • Procurement
    • Legal
    • Compliance
    • Security/IT
    • Privacy
    • Finance
    • Business owner
  • Define thresholds for escalations and exceptions
  • Document any risk acceptances

8. Onboarding controls

  • Create vendor master record
  • Validate bank account details using secure verification
  • Set payment terms and tax status
  • Restrict system access until approvals complete
  • Issue required policies/code of conduct
  • Capture acknowledgments and certifications

9. Ongoing monitoring

  • Periodic re-screening and re-assessment
  • Renewal review based on risk level
  • Track incidents, audit findings, and SLA performance
  • Monitor sanctions, financial, and reputational changes
  • Review subcontractor changes and service scope changes

10. Offboarding / termination readiness

  • Data return or deletion confirmation
  • Access revocation
  • Final invoice and payment review
  • Retention of records
  • Lessons learned / post-engagement review

Good practice controls

  • Risk-based tiering so low-risk vendors have a lighter process
  • Standardized questionnaires and evidence requirements
  • Centralized approval and audit trail
  • Clear exception management
  • Automated screening where possible
  • Defined review frequency by vendor risk

If you want, I can turn this into a workflow diagram, a RACI matrix, or a vendor onboarding checklist template.

Observation history

Unlock observation history

Create a free Obsurfable account to unlock historical responses, model comparisons, and deeper brand intelligence.

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, and Meta AI.