Example result
Here's what you get — a real example generated by the tool:
# Vendor Due Diligence Report: BrightCloud Data Solutions
## Executive Summary
Overall risk: **Medium**. BrightCloud will hold read/write access to the production customer database, which makes data security the dominant risk factor. Recommend proceeding only after the vendor answers the security and compliance questions below and provides a signed data processing agreement.
## Risk Scoring Matrix
| Category | Risk Level | Key Concern | Why It Matters Here |
| --- | --- | --- | --- |
| Financial Stability | Medium | Contract value ($50k-$250k) is material but not business-critical | A mid-size vendor failure would disrupt hosting but not halt operations |
| Operational/Delivery | Medium | Single point of failure for hosting | No stated backup/failover vendor mentioned |
| Legal & Compliance | High | Vendor based in Vietnam; no stated data residency terms | Cross-border data transfer may trigger GDPR obligations if EU customer data is involved |
| Data Security & Privacy | High | Direct read/write access to production customer DB | A breach or misconfiguration exposes customer data directly |
| Concentration/Dependency Risk | Low | Hosting can be migrated to another provider if needed | Not a proprietary or hard-to-replace service |
## Overall Risk Rating
**Medium-High** — driven primarily by direct database access combined with cross-border data transfer.
## Industry & Country-Specific Flags
- Vietnam has no EU adequacy decision; transferring EU personal data requires Standard Contractual Clauses (SCCs) or equivalent safeguards
- Confirm BrightCloud's own subcontractors/sub-processors, especially for hosting infrastructure
- Verify local data protection law compliance (Vietnam's Personal Data Protection Decree)
## Due Diligence Questions to Send the Vendor
**Data Security**
1. What encryption is applied to data at rest and in transit?
2. Can you provide your most recent SOC 2 or ISO 27001 report?
3. Who, specifically, has production database access on your team?
**Compliance**
4. What legal mechanism do you use for transferring EU data outside the EU?
5. Do you use any sub-processors, and where are they located?
**Financial**
6. Can you share evidence of financial stability (e.g. years in operation, client references)?
**Operational**
7. What is your documented incident response SLA for a data breach?
8. What is your disaster recovery/failover plan for hosting outages?
## Recommended Next Steps
- Require a signed Data Processing Agreement with SCCs before granting DB access
- Request SOC 2 report and 2 client references
- Insist on a 72-hour breach notification clause in the contract
- Do not grant write access until the above are confirmed
Frequently Asked Questions
What file format do I get?
You get a professionally formatted .docx Word document with a risk-scoring table, industry and country-specific flags, and a vendor-specific list of due diligence questions — ready to forward or attach to your vendor file.
Why is this cheaper than GRC software or a consultant?
Enterprise GRC platforms charge $200+/mo and often require a sales call. A procurement consultant charges $150-250/hour. This tool generates a comparable scored risk report and vendor questions for a one-time €19.99 payment.
How is this different from a free checklist template or ChatGPT?
Free templates are blank — you fill in every risk category yourself. ChatGPT gives you a generic bullet list. This tool scores each risk category based on the vendor's actual industry, country, and contract size, and writes vendor-specific follow-up questions for you.
How fast do I get my report?
Within 30 seconds of payment. You'll see the report on screen and can download the .docx file immediately.
Is this a substitute for legal or compliance review?
No. This report is a structured starting point for your own due diligence process, not a legal opinion. For high-value or regulated contracts, use it alongside your legal or compliance team's review.
Do you store the vendor information I enter?
No. Your vendor details are used only to generate your report and are not stored or shared after your report is created.
Can I get a refund?
Yes. If the report doesn't match your vendor's details, contact us within 24 hours for a full refund, no questions asked.