Vendor due diligence Run due diligence on your vendors

Classify each vendor on your own criteria, ask for the answers and documents you need, and keep it all on one record. Do the check before you sign, and prove you did.

Unlimited users  •  Free onboarding and support  •  No commitment

A vendor due diligence questionnaire in .legal, with a question about the vendor's organisational security measures
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell
Illustration of the due diligence loop: a questionnaire goes out to a vendor, documents come back, and the results land on a dashboard

Vendor due diligence Meridian screens a new data processor in days, not weeks, and keeps the paper trail

Peter Lund is legal counsel at Meridian Nordic. With around 1,200 active suppliers and processors, onboarding a new cloud vendor used to mean a scatter of emails, a risk assessment in a spreadsheet, and a data processing agreement that someone had to chase for weeks. Now Peter classifies the vendor on Meridian's own criteria, sends one questionnaire that asks for both answers and documents, and the vendor uploads everything through a link. When it's approved, the contract moves straight into Contract Management with its renewal date and obligations in view.

  • A risk score built from Meridian's own parameters, not a black box.
  • The DPA and security documentation land straight on the vendor record.
  • The vendor responds from their inbox, so there's nothing to install.
  • Approved vendors carry a contract with obligations and a renewal reminder.

  • Classify on your terms

    Score a vendor's risk from parameters you define, not a black box.

  • Ask once, gather everything

    One questionnaire pulls answers and documents straight onto the vendor.

  • No login for vendors

    The vendor responds from their own inbox, with nothing to install.

  • From check to contract

    Approved vendors flow into a contract with obligations and renewals tracked.

Why .legal?

The vendor list in .legal, showing each vendor's country, business area, compliance area, certifications and linked assets

Vendor due diligence Start with the vendor, or sync it in

Everything hangs off the vendor record, so that's where you begin. Create it with the basic details, or sync your vendors in from another system and work them in .legal.

  • Register a new vendor with its basic information in a few fields.
  • Or set up an integration so vendors flow in from another system.
  • Everything you gather later lands back on this one record.
The Classifications tab on a vendor record, showing a completed Data Processor Classification with a High risk level

Vendor due diligence Classify the risk on your terms

Not every vendor needs the same scrutiny. You set up an internal assessment with the parameters that matter to you, and answering a few questions gives the vendor a risk classification.

  • Define your own parameters, like whether they handle personal data or how large the deal is.
  • Decide how critical each parameter is, so the score reflects your risk appetite.
  • Nothing is scored automatically, the classification comes from your inputs.
A due diligence questionnaire question on organisational security measures, with IT security policy, ISMS and access governance ticked

Vendor due diligence Ask the vendor directly

Once you know the risk, you ask for what you need. You design the questionnaire, both the questions and the documents, and send it to the vendor as an audit.

  • Pull information like their IT security measures with questions you write.
  • Request specific documents, the DPA, a code of conduct, a certificate.
  • The vendor uploads and submits, and it files itself on the vendor record.
The vendor's upload step, asking them to drag and drop an audit statement or choose a file, with no documents added yet

Vendor due diligence No login, no friction for the vendor

The vendor is an outside party, so we don't make them join your platform. You register a contact, and they get a link in their own inbox.

  • The vendor opens a link, no account and nothing to install.
  • They can work with their own colleagues to answer and gather documents.
  • Everything they submit lands back on the vendor, gathered in one place.
The annual task overview in .legal, with a planned task to review a data processor agreement and its due date

Vendor due diligence One process for new and existing vendors

A new vendor and one you've worked with for years need slightly different questions, but it's the same engine underneath. So you set it up once and reuse it.

  • Build one questionnaire for onboarding and a second for existing relationships.
  • Put a periodic review in your annual wheel, say once a year per critical vendor.
  • Get a reminder in the system when it's time to send the updated questionnaire.
A contract record in Contract Management, showing the contract type, status and the signed agreement filed under Documents

Vendor due diligence From approved vendor to live contract

Saying yes is the start, not the end. Once a vendor is approved, the contract goes into Contract Management and you manage it for as long as it runs.

  • Upload the contract with its metadata about the deal and the vendor.
  • Keep running audits with the vendor across the life of the contract.
  • Let AI help upload and tag the contract, and scan it against your best practice.
Illustration of .legal as the rails: a questionnaire travels out to a vendor and returns as an approved stack of documents

Vendor due diligence Rails, not a ready-made assessment

We give you the technical part, distributing a questionnaire and pulling documentation back from an outside party. We don't hand you a plug-and-play template set, because the right design depends on how you're organised.

  • You design the classification and the questionnaire, we distribute and collect.
  • A few templates exist to start from, like a data processor audit.
  • The risk decision stays yours, .legal runs the process, it doesn't vet the vendor for you.
.legal in practice

Features for vendor due diligence

Vendor register, or synced in

Create a vendor with its basic details, or sync vendors from another system, then work them all in one place.

Your own risk classification

Define the parameters that matter, like whether they handle personal data or how large the deal is, weight them, and get a risk score from your answers.

Due diligence questionnaires

Design the questions yourself and send them to the vendor as an audit, from IT security measures to a code of conduct.

Document requests without a login

Ask for the DPA or other documentation, the vendor uploads it through a link, and it lands on the right vendor record.

Annual review wheel

Set a periodic re-check on a vendor and get a reminder in the system when it's time to send the updated questionnaire.

Contract handover, with AI

Move an approved vendor into Contract Management, where AI helps upload the contract, fill the metadata, and scan it against your best practice.

Vendor due diligence Frameworks this covers

One due diligence process, several regimes that expect it.

  • icon-framework-NIS2

    NIS2

    Show that you assess and monitor the vendors in your value chain, part of the supply-chain security an essential entity must run.

    Learn about NIS2
  • icon-framework-GDPR

    GDPR

    Do due diligence on a processor and collect the data processing agreement before any data flows, in line with Article 28.

    Learn about GDPR
  • icon-framework-ISO

    ISO 27001

    Evidence that you evaluate and monitor supplier security, the supplier-relationship controls in Annex A.

    Learn about ISO 27001
  • icon-framework-DORA

    DORA

    For financial entities, keep due diligence and contracts on ICT third-party providers in order across the value chain.

    Learn about DORA
.legal compliance platform

Run vendor due diligence with...

Do you need to run due diligence on your vendors? We recommend the following modules and addons for that task.

Our Customers

+400

companies

+10.000

users

+79.000

contracts

+14.000

processing activities

Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.

Frequently Asked Questions about vendor due diligence

What does vendor due diligence in .legal actually cover?

The whole process before and during a vendor relationship. You register the vendor, classify its risk, send a questionnaire, collect the documentation you need, and keep it all on one record so you can show you did the check.

Does the platform score vendor risk automatically?

No. Nothing is scored automatically. You set up the parameters and how critical each one is, answer a few questions on the vendor, and the risk score comes from your own inputs.

Do vendors need a login to respond?

No. You register a contact on the vendor, and they get a link in their own inbox. They can gather the answers with colleagues outside the platform, and everything they submit lands back on the vendor.

Can we treat a data processor differently from an ordinary vendor?

Yes. You can build different classifications and questionnaires per vendor type. A data processor might get more than one, say the general vendor check plus a separate data processor audit.

Are there ready-made questionnaire templates?

Some, for example a data processor audit. Beyond that we give you the rails to distribute and collect, not a plug-and-play set. We recommend you design your own classification and questionnaire, because the right ones depend on your organisation.

What happens after we approve a vendor?

You upload the contract to Contract Management with its metadata, keep obligations and renewals in view, and keep running audits with the vendor across the life of the contract. AI can help upload and tag the contract and scan it against your best practice.

How do we keep existing vendors up to date?

Use the same engine with a version of the questionnaire aimed at existing relationships, and set a periodic review in your annual wheel. The system reminds you when a vendor is due for a fresh check.

Can we run due diligence across a group of companies?

Yes, with the Group Companies add-on. The same vendor can be shared across the group and used differently by each company, so you assess once and still reflect how each entity uses it.

Which regulations does this help with?

The supply-chain expectations in NIS2, processor due diligence under GDPR Article 28, supplier controls in ISO 27001, and ICT third-party risk under DORA for financial entities.

Still unsure?

Ask Johannes directly, he runs most demos personally

Book him here
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell