Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before awarding a contract, verify that the supplier is legally identifiable, financially and operationally able to deliver, credible in relevant past performance, and clear about the price and obligations it has proposed. Match the depth of each check to the procurement’s value, complexity, and risk; corroborate important claims, document how findings affect the decision, and keep material risks under review after award.

This checklist is a practical framework, not a universal legal standard. Procurement rules, exclusion grounds, sanctions obligations, and human-rights requirements vary by jurisdiction and supplier category. New Zealand government procurement guidance calls for due diligence proportionate to value, complexity, and risk throughout the procurement lifecycle. UK guidance on supplier financial standing has a narrower stated scope: central government departments, executive agencies, and non-departmental public bodies.

1. Define the scope and risk before requesting evidence

Start with the contract you are actually buying. A supplier may be suitable for one engagement and unsuitable for another, so set the checks against the requirement rather than sending every bidder an undifferentiated document list.

  • Describe the goods or services, contract term, delivery locations, expected volumes, and service-critical dependencies.
  • Identify subcontractors and lower-tier suppliers that could materially affect delivery, security, or continuity.
  • Assess criticality, ease of substitution, geographic exposure, access to sensitive data or systems, and the consequences of interruption.
  • Choose checks according to value, complexity, and risk; record which checks apply and why.
  • Where a formal tender process applies, state requested evidence and the evaluation approach in the tender documents, and decide when checks will occur.

For ICT suppliers, NIST’s final SP 1326 guide, published in July 2026, offers additional due-diligence dimensions: foreign ownership, control or influence; provenance; resilience; foundational cybersecurity practices; and supply-chain tiers. It is an ICT-focused assessment guide, not a universal statutory checklist.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Confirm legal identity, ownership, and eligibility

Establish which legal entity would sign and perform the contract. Check information against authoritative company or charity registers where available, rather than relying only on a proposal or sales contact.

  • Verify the legal name, registration details, legal structure, and operating locations.
  • Identify beneficial owners and relevant control relationships, including entities that may affect the supplier’s independence or risk profile.
  • Check applicable procurement exclusion or debarment grounds under the rules for your jurisdiction, and record what you checked and the result.
  • For international suppliers, goods, or transactions, determine whether sanctions screening or export-control diligence applies. Relevant obligations depend on the parties, goods, transaction, and governing law.

The European Commission’s February 19, 2024 guidance addresses due diligence and circumvention red flags for export-related sanctions. It does not replace jurisdiction-specific legal advice or other sanctions obligations.

3. Assess whether the supplier can financially perform

Review financial information in proportion to the contract’s exposure and the consequences of supplier failure. A large or business-critical commitment may warrant stronger evidence and monitoring than a low-value, readily replaceable purchase.

Rank #2
Sale
Better Office Products To Do List Notepad, 8.5" x 11", Planning Note Pad, 50 Sheets, Double Wire Spiral, Daily Agenda Productivity Checklist Organizer,(1 Pack)
  • SIMPLE, ATTRACTIVE DESIGN - The notepad flaunts a design that's both stylish and fun, making it the perfect backdrop for your daily tasks.
  • 8.5" X 11": LETTER SIZE - With ample space for jotting down your to-dos, appointments, and reminders, this notepad ensures you never miss a beat. The larger size offers room to breathe and encourages creative planning.
  • DOUBLE-WIRE SPIRAL BINDING - Tear off sheets as needed or keep them intact to be able to look back on your prior tasks. Whether you're at your desk, in a meeting, or on the go, your notepad is ready for you to use as you see fit.
  • 50 SHEETS - Created so you can pack all your tasks onto one sheet in order to set and achieve goals, plan and complete projects, and stay organized no matter how you use your notepad.
  • VERSATILE FOR TRACKING ALL YOUR TASKS - Whether you're a busy professional, a student managing coursework, or a parent juggling household chores, this notepad can help you organize. It's perfect for daily/weekly planning, making lists, setting priorities, and tracking progress.
  • Review appropriate financial history and audited accounts, credit information, and other relevant evidence.
  • Consider whether the supplier can support this specific contract, not just whether it appears viable in general.
  • Where information is available, assess reliance on key subcontractors or concentrated revenue that could threaten delivery.
  • Decide whether financial risk calls for monitoring, contingency arrangements, or other mitigation during the contract.

Do not use a single ratio or credit score as a universal pass/fail threshold unless the threshold has a defensible basis and was disclosed appropriately. The cited guidance does not establish a universal financial threshold. UK central-government guidance covers economic and financial standing assessment both before award and during contract delivery within its stated public-sector scope.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Examine integrity, conduct, and relevant performance

Check for credible indicators of bribery, corruption, or other adverse conduct relevant to the contract. Past conduct should be assessed objectively against the disclosed criteria, not used as a proxy for personal preference.

  • Review delivery performance, health and safety, employment practices, ethics, and management practices where they bear on the requirement.
  • Request current or recent customer references and interview referees where useful.
  • Compare supplier claims with performance reports, published material, case studies, or other independent records.
  • Record the evidence and its relevance rather than relying on informal impressions or unsupported allegations.

5. Test delivery capability, systems, and price assumptions

Verify that the supplier has the people, expertise, capacity, systems, and processes needed for the whole contract term. Ask whether the proposal’s assumptions are realistic and whether the quoted price can deliver the required outcomes.

  • Request relevant staff CVs, service or contract performance reports, compliance certificates, and accreditation or audit reports.
  • Confirm the supplier understands deliverables, service levels, reporting duties, and other contract obligations.
  • Test key proposal assumptions, dependencies, exclusions, resourcing, and price components against the requirement.
  • Use interviews, presentations, site visits, or client references when appropriate and included in the procurement process.

6. Add checks for particular risk areas

ICT and cybersecurity suppliers

For an ICT supplier, use NIST SP 1326’s five dimensions as relevant: foreign ownership, control or influence; provenance; resilience; foundational cyber practices; and supply-chain tiers. Tailor the questions to the service, data, and access involved; do not present this ICT guide as a legal checklist for every supplier.

Human rights and supply-chain visibility

Map suppliers, subcontractors, locations, and sourcing relationships where they affect the goods or services. Identify and prioritize potential forced-labour, human-trafficking, and child-labour risks, then plan mitigation and remediation suited to the issue. Public Services and Procurement Canada notes that smaller organizations can take targeted steps such as adopting policies, researching prospective suppliers, and seeking responsible-business commitments.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Export-related sanctions

Where the transaction makes it relevant, assess business partners, goods, and transactions for applicable sanctions risk and possible circumvention red flags. Apply the law relevant to the parties and transaction; the European Commission guidance cited here is specifically about export-related sanctions.

7. Collect evidence that answers a decision question

New Zealand Government Procurement advises checking more than one source. Evidence may include supplier documents, the buyer’s own research, referees, and third-party confirmation. Choose each item because it answers a risk or evaluation question; collecting documents without a decision purpose adds effort without improving the decision.

  • Audited accounts, credit checks, and financial information for financial capacity.
  • Company-register records and other authoritative records for identity and ownership.
  • References, client interviews, and current performance reports for delivery record.
  • Insurance and compliance certificates, staff CVs, and audit or accreditation reports for relevant capability and controls.
  • Site visits or other direct observation where the nature of the requirement makes them useful.

For each check, maintain a record with the criterion, risk addressed, evidence requested, independent source used, date checked, finding, unresolved issue, decision owner, mitigation or follow-up, and rationale for acceptance, escalation, or rejection. This creates a traceable link between evidence and the decision.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

8. Apply findings consistently to the award decision

Use a verification matrix to map evidence against fit for purpose, ability to deliver, and value for money. New Zealand’s example matrix includes proposal documents, clarifications, references, interviews, presentations, site visits, audited accounts, credit checks, register checks, contract terms, and security checks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Apply the same disclosed criteria to comparable bidders while tailoring the depth of diligence to each procurement’s risk. Compare evidence-backed results across legal identity and ownership, financial capacity, integrity, relevant performance, capability and resilience, compliance and risk exposure, price assumptions, subcontractor visibility, and the strength of supporting evidence.

  • If new information could affect the evaluation, bring it to the evaluation panel.
  • For a serious issue, consider exclusion or non-award under the applicable procurement rules.
  • For a less serious or remediable issue, decide whether additional evidence or a mitigation is needed before proceeding.
  • Record the reason for the outcome so the decision can be understood and reviewed later.

9. Continue oversight after award

Due diligence is not just a one-time pre-award form. Keep material risks under review during contract performance, with the response proportionate to the effect a change could have on delivery.

  • Monitor financial standing where deterioration could threaten delivery.
  • Reassess significant changes in ownership, subcontracting, delivery locations, cybersecurity posture, performance, or exposure when they matter to the contract.
  • Use the contract’s reporting, review, and escalation mechanisms to address new evidence or changing risk.
  • Maintain a practical continuity or mitigation response for risks that could disrupt a critical service.

Preserving public-facing evidence

If a supplier’s public website or service pages form part of your review, a screenshot can help preserve what was visible during an assessment. Treat it as supporting context, not proof of legal identity, financial health, compliance, or actual service performance. For material procurement records, retain the original evidence and record where and when it was collected using your organization’s normal records process.

For capturing a publicly accessible page, ScreenshotNeo is a website screenshot API and MCP server for developers. One GET request can return a PNG, JPEG, WebP, or PDF; its clean-shot options accept cookie banners and remove known consent platforms, newsletter popups, and chat widgets before capture. Because those steps can change what appears in the image, use an unaltered record when the interface itself is material evidence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Example cURL request; replace the sample page with the public page you are authorized to capture. See the ScreenshotNeo API documentation for request options.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed by ScreenshotNeo; responses include X-Page-Verdict and X-Billed headers. It also offers an MCP server with take_screenshot, get_page_info, and capture_pdf tools for AI agents. Free includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Sign up for 1,000 free screenshots a month, with no card required.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.