Outsourcing due diligence is the process of evaluating a third-party service provider’s operational resilience, financial stability, and control environment before signing a contract. Under global standards like the US Office of the Comptroller of the Currency (OCC) Bulletin 2013-29 and the European Banking Authority (EBA) Guidelines on Outsourcing Arrangements, organizations must apply a risk-based approach to assessments. This means the intensity of the due diligence process scales directly with the criticality of the outsourced business service.
[Determine Service Criticality] ---> [Issue Custom Due Diligence Questionnaire] ---> [Verify Control Certifications]

Before engaging a new vendor, the business unit must execute an inherent risk assessment to determine if the activity is a Critical Outsourcing Arrangement. If a failure or disruption of the service could threaten the organization’s financial stability, systemic operations, or regulatory compliance status, it is flagged as Critical.
For these high-exposure partnerships, the organization must verify independent control certifications, such as SOC 2 Type II reports or ISO 27001 registrations. This documentation confirms that the vendor’s internal control configurations have been audited for design and operating effectiveness over a sustained period.

Â