Skip to main content

Sample: vendor due diligence report

Canada Cyber-Safe — independent cyber and AI governance for Canadian organisations

The report you hand to a customer

Vendor due diligence is work most organisations dread and few do consistently. What you are buying is not the questionnaire — it is a document you can put in front of a customer, an insurer or a regulator that shows the review actually happened. This is a complete example.

This is an illustrative example. Both companies named below are fictional and every finding is invented to demonstrate the format. It is not a real review, redacted or otherwise — we do not publish client work, and we would not publish a named supplier’s weaknesses in any case.

Third-party review prepared for Northbridge Logistics Inc.

Meridian Payroll Services — vendor due diligence

Tier: 1 — criticalReviewed: July 2026Next review: July 2027Prepared by: Canada Cyber-Safe

Recommendation

Proceed, with two conditions written into the contract before signature. Meridian’s security posture is sound and independently evidenced. The risk is not technical: the contract as drafted gives Northbridge 72 hours’ notice of an incident, which is longer than Northbridge’s own regulatory clock allows.

What they hold, and where

Meridian processes payroll for 340 Northbridge employees: names, addresses, dates of birth, SIN, banking details and salary. Data is stored in Toronto and Montreal, backed up to Montreal, and accessed by Meridian support staff in Ontario. One subcontractor — a Quebec-based print bureau for year-end slips — receives name and address only.

No personal information leaves Canada. This was confirmed against Meridian’s data flow documentation, not only their questionnaire response.

Findings

AreaFindingRating
Independent assuranceCurrent SOC 2 Type II (period ending 31 March 2026), no qualified opinions. Statement of applicability reviewed; scope covers the payroll platform and its hosting.Satisfactory
Breach notificationContract requires notice “within 72 hours”. Northbridge must report to the OPC as soon as feasible after determining a breach occurred; 72 hours of supplier silence consumes that window.Must fix
SubcontractorsThe print bureau was not disclosed in the questionnaire and was found in the master agreement’s schedule. Contract does not require notice before a new subcontractor is added.Must fix
Access controlMFA enforced on all Meridian staff accounts and on the Northbridge administrator accounts. Joiner-mover-leaver process evidenced with a sample of six.Satisfactory
AI and secondary useMeridian confirmed in writing that customer data is not used to train any model and is not passed to any AI service. This is now a standing question in our reviews.Satisfactory
ExitData returned in CSV within 30 days of termination; deletion certified within 90. Tested by request during the review — Meridian produced the process document but has never executed it.Monitor
ConcentrationMeridian also provides Northbridge’s benefits administration. Two critical services rest on one supplier; this was not previously visible on the vendor register.Monitor

The two contract changes

  • Notification within 24 hours of Meridian becoming aware of any incident affecting Northbridge data, with sufficient detail for Northbridge to run its own risk assessment. Meridian indicated during the review that 24 hours is acceptable.
  • Prior written notice before any new subcontractor receives Northbridge personal information, with a right to object.

What we did not do

We did not test Meridian’s systems, and this review is not a penetration test or a certification of Meridian. It is an assessment of whether the evidence Meridian provides is adequate for Northbridge to rely on, and of whether the contract carries the obligations Northbridge’s own regulators will hold it to.

Canada Cyber-Safe has no commercial relationship with Meridian Payroll Services and receives no fee, commission or referral from any supplier we review. Where we assess an organisation, we do not also remediate it.

Why this one matters

The finding that mattered was in the contract, not the technology.

Meridian is a well-run supplier. The review still changed something, because a 72-hour notification clause quietly hands your regulatory deadline to somebody else. That is the kind of thing a questionnaire never surfaces and a security scan cannot see.

Run it yourself, or have us do it

Our vendor review policy template is free and sets out how to tier suppliers and what evidence to demand. If you would rather hand over a supplier and get this back, that is the vendor due diligence service on our services page.

Ask about a vendor reviewSee the board report

Standards we assess against

ISO/IEC 27001:2022 · ISO/IEC 27701:2025 · ISO 9001:2015 · ISO/IEC 42001:2023 · ISO/IEC 23894:2023 (guidance) · ISO/IEC 42005:2025 (guidance)

Français : La première heure — rédigé en français, pas une traduction automatique.

Canada Cyber-Safe is an independent assessment practice. We are not a certification body and we do not issue certificates.