Prompt
What should be part of a vendor onboarding compliance workflow?
Latest observation
A solid vendor onboarding compliance workflow should cover risk, legal, security, financial, and operational checks before a vendor is approved. Here’s a practical checklist of what to include:
1. Vendor intake and classification
- Collect basic vendor information:
- Legal name, tax ID, address, country of incorporation
- Primary contacts
- Services/products provided
- Ownership structure
- Classify the vendor by:
- Risk level
- Data access level
- Criticality to operations
- Geography/jurisdiction
- Whether they are subcontractors or third parties
2. Due diligence screening
- Sanctions and watchlist screening
- Anti-bribery/anti-corruption checks
- Politically exposed person (PEP) screening where relevant
- Adverse media review
- Beneficial ownership verification
- Litigation, bankruptcy, and regulatory action checks
- Conflict of interest disclosure
3. Legal and contract review
- Standard terms and conditions
- Data processing agreements, if personal data is involved
- Confidentiality/NDA requirements
- Service level agreements and performance terms
- Audit rights
- Termination and exit clauses
- Liability, indemnity, insurance requirements
- Jurisdiction and governing law review
4. Security and privacy assessment
If the vendor will handle systems, data, or facilities:
- Security questionnaire
- Information security controls review
- Access control and identity management checks
- Encryption requirements
- Incident response and breach notification process
- Business continuity and disaster recovery evidence
- Secure development practices, if applicable
- Privacy impact assessment
- Data retention and deletion requirements
- Subprocessor/subcontractor review
5. Financial and operational review
- Financial stability assessment
- Credit checks, if appropriate
- Business continuity of supply
- Capacity and delivery capability
- Reference checks
- Insurance coverage verification
- Certifications/licenses required to provide the service
6. Compliance and regulatory checks
Depending on industry and geography:
- AML/KYC requirements
- Export controls and trade restrictions
- Industry-specific regulatory obligations
- Labor and human rights compliance
- Environmental, social, and governance requirements
- Modern slavery/supply chain due diligence
- Records retention requirements
7. Approval workflow
- Assign approvers based on risk tier
- Require sign-off from:
- Procurement
- Legal
- Compliance
- Security/IT
- Privacy
- Finance
- Business owner
- Define thresholds for escalations and exceptions
- Document any risk acceptances
8. Onboarding controls
- Create vendor master record
- Validate bank account details using secure verification
- Set payment terms and tax status
- Restrict system access until approvals complete
- Issue required policies/code of conduct
- Capture acknowledgments and certifications
9. Ongoing monitoring
- Periodic re-screening and re-assessment
- Renewal review based on risk level
- Track incidents, audit findings, and SLA performance
- Monitor sanctions, financial, and reputational changes
- Review subcontractor changes and service scope changes
10. Offboarding / termination readiness
- Data return or deletion confirmation
- Access revocation
- Final invoice and payment review
- Retention of records
- Lessons learned / post-engagement review
Good practice controls
- Risk-based tiering so low-risk vendors have a lighter process
- Standardized questionnaires and evidence requirements
- Centralized approval and audit trail
- Clear exception management
- Automated screening where possible
- Defined review frequency by vendor risk
If you want, I can turn this into a workflow diagram, a RACI matrix, or a vendor onboarding checklist template.
Observation history
Unlock observation history
Create a free Obsurfable account to unlock historical responses, model comparisons, and deeper brand intelligence.
How did Obsurfable measure this prompt?
Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.
Which AI systems does Obsurfable collect answers from?
OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, and Meta AI.