What does Deloitte’s approach to vendor management actually emphasize?
Core themes in Deloitte’s framework
Deloitte’s vendor management and third-party governance publications consistently emphasize a risk-based, evidence-driven approach to oversight — one that aligns supplier governance with enterprise risk management and regulatory compliance objectives rather than treating vendor management as a standalone procurement discipline. Their frameworks connect third-party risk directly to the organization’s broader operational risk structure, with particular emphasis on documentation quality, due diligence standards, and the traceability of governance decisions to specific risk findings.
Deloitte’s guidance on third-party due diligence — published in collaboration with the Wall Street Journal — outlines a three-step approach to evaluating bribery and corruption risk in third-party relationships: understanding the third party’s business model and client base, assessing historical compliance issues, and verifying that internal controls are adequate for the relationship’s risk level (https://deloitte.wsj.com/cfo/third-party-due-diligence-3-steps-to-evaluate-bribery-corruption-risk-78194f3c). This framework, while developed in the context of anti-corruption compliance, applies with equal relevance to the broader vendor due diligence discipline that modern procurement programs need to execute consistently.
Risk-tiered oversight
One of the most practically useful principles in Deloitte’s vendor management framework is the insistence on risk-tiered oversight: not all vendors deserve the same governance intensity, and applying enterprise-level due diligence to commodity suppliers creates overhead without proportional risk reduction. Tier-based governance — intensive oversight for high-risk, high-criticality relationships; standard oversight for mid-tier; lightweight monitoring for commodity — is a principle Deloitte articulates for regulated financial and professional services contexts but which applies universally to any procurement organization managing a diverse supplier base.
Documentation as governance evidence
Deloitte’s compliance-oriented publications consistently emphasize that governance value lies not just in the process but in its documentation: the evidence that due diligence was performed, that findings were reviewed, and that decisions were made based on the risk picture rather than assumption. This emphasis on documentation as governance evidence reflects a regulatory reality — in an examination or audit, an undocumented due diligence process is indistinguishable from no process at all. For procurement teams building vendor risk programs, this principle argues for building documentation rigor in from the start, not treating it as an administrative afterthought.
Which governance principles from big-firm thinking apply at any company size?
Universal principles
The governance principles that emerge from enterprise-scale frameworks like Deloitte’s are often more universally applicable than the scale of their original context suggests. The specific tools and reporting structures may require adaptation for smaller organizations, but the underlying principles apply regardless of company size:
- Risk-based prioritization: Allocate governance effort in proportion to risk exposure — not uniformly across all vendors regardless of their business impact.
- Evidence-based decisions: Base sourcing, renewal, and escalation decisions on documented evidence rather than relationship history or impression. The bigger the decision, the stronger the evidentiary foundation should be.
- Ownership accountability: Every vendor relationship should have a named owner who is accountable for its governance outcomes. Unnamed ownership is accountability diffusion.
- Audit trail discipline: Document decisions and their rationale at the time they’re made, not reconstructed later. Contemporaneous records are the governance artifact that auditors and regulators accept; reconstructed records create both accuracy risk and credibility risk.
- Continuous improvement: Governance programs that are assessed periodically and updated based on findings — not maintained as static policies — improve over time rather than degrading.
Adaptation for lean teams
The adaptation required to apply enterprise governance principles in lean procurement teams is primarily one of tool simplicity, not principle modification. The risk-tiered oversight principle applies whether the governance tool is a sophisticated platform or a well-designed spreadsheet. The evidence-based decision principle applies whether the evidence is a 50-page due diligence report or a completed questionnaire and three reference checks. The ownership accountability principle applies whether it’s enforced through a GRC system or a simple assignment in a shared document. The principle is the constant; the tool is the variable.
How should third-party due diligence be structured for different risk levels?
Due diligence by tier
Deloitte’s three-step due diligence framework — understanding the business model, assessing compliance history, and verifying internal controls — provides a structure that can be calibrated to risk level without losing its fundamental logic. The questions asked are the same at every tier; the depth of verification varies with the risk.
| Due diligence element | High-tier (intensive) | Mid-tier (standard) | Low-tier (baseline) |
|---|---|---|---|
| Business model review | Full documentation + in-person or video interview | Questionnaire + document review | Basic registration and qualification check |
| Compliance history | Third-party database check + reference checks | Questionnaire self-attestation + verification of key certifications | Compliance certification collection only |
| Internal controls | Security audit, financial review, BCP assessment | Standard questionnaire on key controls | Spot check on required certifications |
| Review frequency | Annual full reassessment | Annual standard review | Biennial or event-triggered |
Documentation standards
Documentation standards for each tier should be specified in the vendor risk policy before assessments begin. High-tier documentation includes: completed questionnaire, supporting evidence inventory, assessor notes, risk rating with scoring rationale, and approval record. Mid-tier documentation includes: completed questionnaire, compliance certification copies, and risk rating. Low-tier documentation includes: registration record and certification collection confirmation. These standards define what “due diligence completed” means at each tier — preventing the ambiguity that allows governance gaps to accumulate unnoticed.
What does Deloitte mean by due diligence in a practical procurement context?
Practical application
In Deloitte’s published frameworks, due diligence refers specifically to the structured process of understanding a third party’s business model, risk profile, compliance history, and internal controls before entering or renewing a relationship — and documenting that understanding in a way that’s auditable and defensible. In a practical procurement context, this translates to: asking structured questions before awarding contracts, collecting and verifying compliance documentation, and recording the findings and the decisions they informed in an accessible format.
The “structured” element is what separates due diligence from informal pre-qualification. A conversation with a supplier contact about their business is not due diligence. A completed questionnaire with supporting documentation, reviewed by an assessor against defined criteria, with a documented risk rating and approval record, is due diligence. The structure is what makes the process auditable and reproducible — the qualities that give it governance value.
Bribery and corruption risk context
Deloitte’s WSJ-published guidance specifically addresses bribery and corruption risk in the context of third-party relationships — a governance area that is particularly important for organizations operating internationally or engaging distributors, agents, and intermediaries on their behalf. The three evaluation steps — business model assessment, compliance history, and internal control verification — provide a structure that is directly applicable to anti-corruption due diligence and is equally useful as a general framework for vendor risk assessment. For procurement teams that need to satisfy both general vendor governance and anti-corruption compliance requirements, the same structured questionnaire and evidence collection process can serve both purposes when designed with both in mind.
Practical procurement translation
The practical procurement translation of Deloitte’s due diligence framework produces a vendor onboarding questionnaire that covers: the supplier’s organizational structure and ownership, relevant compliance certifications, regulatory history, key client references, financial stability indicators, data and security practices, and business continuity planning. This questionnaire, calibrated by risk tier, forms the core due diligence instrument that procurement teams can apply consistently across their vendor base — producing the evidentiary documentation that governance frameworks require without creating a burden disproportionate to the risk level of the relationship.
What are the limits of big-firm vendor management frameworks for mid-market buyers?
Scale mismatch
The most significant limitation of enterprise vendor management frameworks — including Deloitte’s — for mid-market buyers is scale mismatch: frameworks designed for organizations with dedicated vendor governance teams, sophisticated GRC platforms, and extensive internal resources require adaptation before they’re applicable to organizations with lean procurement teams and limited technology investment.
A framework that assumes a dedicated third-party risk manager for each business domain, annual comprehensive reassessments for all vendors above a threshold, and board-level reporting on third-party risk exposure is not implementable by a two-person procurement team managing 200 suppliers while also handling daily procurement operations. The governance principles are sound; the implementation design needs to be right-sized to the organization’s actual capacity.
Prioritization gaps
Enterprise frameworks also tend to underemphasize prioritization — because organizations with sufficient resources can apply comprehensive governance to most of their supplier base. Mid-market buyers must make harder choices: which vendors receive intensive due diligence and which receive minimal baseline qualification, which categories get formal sourcing events and which get Spotbuy-style managed sourcing, which governance investments produce the most risk reduction per dollar of effort. Big-firm frameworks don’t address these tradeoffs well because they were designed for contexts where the tradeoffs are less acute.
Right-sizing guidance
The right-sizing principles for applying enterprise governance frameworks in mid-market contexts are consistent: keep tier definitions simple (three tiers, with clear criteria), start with the governance elements that prevent the highest-probability, highest-impact failures (concentration risk mapping, contract expiration tracking, compliance documentation for Tier 1 vendors), and build toward more comprehensive governance as the organizational capacity to sustain it develops. Enterprise-grade governance built incrementally and sustainably produces better outcomes than enterprise-grade governance deployed comprehensively and abandoned within a year when the maintenance burden exceeds the team’s capacity.
What should the conclusion include before applying enterprise vendor management principles to a lean program?
Adaptation and rollout summary table
| Enterprise principle | Right-sized lean application | Owner |
|---|---|---|
| Risk-tiered oversight | Three tiers, criteria document, calibrated review frequency | Procurement Lead |
| Evidence-based decisions | Standard questionnaire by tier, evidence checklist | Risk / Procurement |
| Ownership accountability | Named owner for every active contract above threshold | Category Managers |
| Audit trail discipline | Consistent documentation in shared folder or system — contemporaneous | Procurement |
| Due diligence by tier | Tiered questionnaire with minimum evidence standard by tier | Procurement |
| Continuous improvement | Annual policy review + findings incorporated from exceptions | Procurement Lead |
Expert recommendations
- Take the principles, right-size the tools. Enterprise governance principles — risk-tiered oversight, evidence-based decisions, audit trail discipline — apply at any company size. The implementation tools should match the team’s capacity to sustain them, not the sophistication of their enterprise counterparts.
- Start with the highest-consequence gaps. Concentration risk, missing contracts, and compliance documentation gaps are the areas where governance failures most reliably produce material business consequences. Address these before building more comprehensive governance layers.
- Document decisions contemporaneously. The governance principle that has the most disproportionate value relative to its implementation cost is contemporaneous documentation: recording decisions and their rationale at the time they’re made. This habit is the difference between a governance process that an audit confirms and one that an audit finds incomplete.
Sources
- Deloitte / WSJ — Third-party due diligence: https://deloitte.wsj.com/cfo/third-party-due-diligence-3-steps-to-evaluate-bribery-corruption-risk-78194f3c
- NIST SP 800-161r1: https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final
- CIPS Sourcing Strategy: https://www.cips.org/intelligence-hub/sourcing/strategy
Application rollout checklist
- Identify the two to three enterprise governance principles most directly applicable to current program gaps
- Right-size the implementation tool for each principle to match current team capacity
- Build documentation habits before building governance processes — documentation is the governance artifact
- Assess whether the right-sized application is actually being followed 90 days after implementation — if not, simplify further
- Add governance layers incrementally as the team’s capacity to sustain them develops





