Vendor Onboarding Checklist
A vendor onboarding checklist tool builds the list from two answers: what kind of vendor this is and what data they will touch. A SaaS handling health data gets a Business Associate Agreement line; a hardware supplier gets firmware and decommissioning steps. Progress is saved locally so a review can continue later.
Last reviewed by the Radiatus Cloud team
Want this done for your business?
Radiatus delivers cloud, security & automation for growing teams.
How the list is assembled
Every checklist starts with the items that apply to any vendor: a named business owner, a signed NDA before access, an entry in the third-party register with a risk tier, contract terms covering security obligations and breach notification, and an offboarding plan. On top of that, type-specific and data-specific items are added.
Type-specific items
- SaaS: a current SOC 2 or ISO 27001 certificate, single sign-on and SCIM deprovisioning, a sub-processor list, an uptime SLA and a data-export path.
- Development agency: scoped repository access, secure-development attestation, IP assignment, and synthetic or masked staging data.
- Consultant or contractor: a background check, a managed-device or VDI policy, time-boxed named access with MFA.
- Hardware: firmware lifecycle, changed default credentials, supply-chain provenance, network segmentation, and wiped or destroyed data-bearing components at decommissioning.
Data-specific items
The data classification drives the legal preconditions. PII adds a GDPR Article 28 Data Processing Agreement, a lawful basis, a transfer mechanism if data leaves the EU or UK, and a retention schedule. Financial data adds a PCI Attestation of Compliance and bank-detail change verification. Health data (PHI) adds a HIPAA Business Associate Agreement, which the tool marks as a hard precondition: access is not granted before it is signed.
Tracking
Tick items as evidence is gathered; the count and completion state are stored in your browser per vendor type and data class, so closing the tab does not lose progress. The list is a starting framework, not a substitute for your own procurement and legal review.
Related tools
- Third-Party Risk Assessor — Assess vendor risk based on data access and type.
- SaaS Risk Heatmap — Pick the SaaS apps your company runs, add your own, and get a heatmap ranking each by data criticality times access scope, with the risk each carries.
- Compliance Calendar — Enter your frameworks and a start date to lay out a year of recurring compliance obligations (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, NIST CSF) with dates and an .ics download.
- GDPR DPIA Generator — Build a GDPR Article 35 Data Protection Impact Assessment: necessity, proportionality, risk scoring and mitigations. Structured DPIA template, free.
Frequently Asked Questions
Why does the checklist change with the data type?
Because the legal preconditions do. Personal data requires a Data Processing Agreement under GDPR, payment data brings PCI scope, and health data requires a HIPAA Business Associate Agreement before any access. The tool adds those lines only when they apply.
Is my progress saved?
Yes, in your browser's local storage, keyed by vendor type and data class. It stays on this device and is not synced anywhere. Record it in your procurement system for the audit trail.
What is a BAA and when is it required?
A Business Associate Agreement is the HIPAA contract that must be signed before a vendor handles protected health information. The tool marks it as a precondition: PHI access should not be granted until it is executed.
Does this replace a vendor risk assessment?
No. It produces the onboarding checklist. A full assessment evaluates the vendor's own controls, certifications and financial stability; this ensures you complete the contractual and access steps for the vendor and data in front of you.
Can I use it for a vendor that touches no sensitive data?
Yes. Selecting no sensitive data still produces the base contract, register and offboarding items, which apply to every vendor regardless of what data they hold.
Privacy & Security
Generated locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Third-Party Risk Assessor
BusinessAssess vendor risk based on data access and type.
SaaS Risk Heatmap
BusinessPick the SaaS apps your company runs, add your own, and get a heatmap ranking each by data criticality times access scope, with the risk each carries.
Compliance Calendar
ComplianceEnter your frameworks and a start date to lay out a year of recurring compliance obligations (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, NIST CSF) with dates and an .ics download.