---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Types of due diligence

# Types of due diligence {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Types of Due Diligence

The due diligence process involves various types of assessments to evaluate third-party engagements based on their nature, criticality, and associated risks.
Understanding these types is essential for ensuring informed decision-making and risk management.
Show full answer Show less  

## Key Features

* **Information Security Due Diligence:** Assesses data protection practices, cybersecurity measures, and incident response capabilities to safeguard sensitive information.
* **Financial Due Diligence:** Evaluates the financial health of the third party, including profitability and liquidity, to ensure their capability to meet obligations.
* **Legal Due Diligence:** Reviews compliance with legal and regulatory requirements to identify potential risks and liabilities.
* **Operational Due Diligence:** Assesses the operational capabilities and processes of the third party to ensure they can deliver required products or services.
* **Compliance Due Diligence:** Verifies adherence to laws and industry standards, identifying compliance gaps that could lead to legal issues.
* **Reputation Due Diligence:** Evaluates the third party's reputation and past performance to ensure alignment with organizational values.

## Key Outcomes

Utilizing the Third-party Risk Management features, customers can streamline the due diligence process through:

* Questionnaire templates for financial assessments.
* Due Diligence Request (DDR) workflows for orchestrating reviews and approvals.
* Comprehensive reports and dashboards for tracking requests and timelines.

To access these features, navigate to the Vendor Management Workspace within ServiceNow and activate the Third-party Risk Due Diligence plugin to utilize preconfigured workflows and tools for effective risk management.  
In the due diligence process, you typically conduct several types of due diligence to gather relevant information and assess various aspects of the third party. The particular types of due diligence that you conduct vary
depending on the nature and criticality of the engagement and the risks involved.

Information Security due diligence

:   Information security due diligence is critical. It involves evaluating the third party's data protection practices, cybersecurity measures, and information handling processes. This includes assessing their data security policies,
    incident response capabilities, encryption practices, and employee training on data protection. The objective is to safeguard sensitive information and mitigate the risk of data breaches or unauthorized access.

Financial due diligence

:   Financial due diligence involves assessing the financial health and stability of the third party. It includes reviewing financial statements, analyzing profitability, liquidity, debt levels, cash flow, and other financial indicators. The
    goal is to understand the financial viability of the third party and help ensure that they have the capacity to fulfill their obligations.

Legal due diligence

:   Legal due diligence involves examining the legal and regulatory compliance of the third party. It includes reviewing contracts, agreements, licenses, permits, and legal documents. The purpose is to identify any legal risks,
    liabilities, ongoing litigation, or regulatory non-compliance that could impact your organization's interests.

Operational due diligence

:   Operational due diligence focuses on assessing the operational capabilities and processes of the third party. It involves evaluating their infrastructure, facilities, supply chain, production processes, quality controls, and capacity to
    meet your organization's requirements. The goal is to help ensure that the third party can effectively deliver the desired products or services.

Compliance due diligence

:   Compliance due diligence involves verifying the third party's adherence to applicable laws, regulations, and industry standards. It includes assessing their compliance programs, policies, and procedures related to areas such as
    anti-corruption, data privacy, information security, environmental practices, and labor standards. The objective is to identify any compliance gaps or risks that could result in legal or reputational issues for your organization.

Reputation due diligence

:   Reputation due diligence focuses on evaluating the third party's reputation, integrity, and past performance. It involves conducting background checks, reviewing references, searching for news or media coverage, and assessing any past
    controversies or ethical issues. The purpose is to help ensure that the third party has a positive reputation and aligns with your organization's values and expectations.

## Financial due diligence example {#tprm-due-diligence-types__section_bgy_3dh_phc}

Financial due diligence evaluates a third party or engagement's financial health and stability. Third-party Risk Management supports this process by providing:

* Questionnaire templates with financial questions and document requests that you can send to the third party or engagement using an assessment through the third‑party portal.For more information see, [Sample questionnaires](https://servicenow-prod.fluidtopics.net/4XNa_43gXEjib4J5SvD5sQ "The questionnaire that you use can depend on your industry, geographic area, jurisdiction, or the particular nature of your operations. These questionnaires are provided as part of the base system and are samples that shouldn’t be implemented into your risk management program without first being reviewed and approved by your legal team.") and [Create an external assessment](https://servicenow-prod.fluidtopics.net/OsRUS7II7EVkcaW_YAOWrw "Create an assessment and initiate the third-party risk assessment life cycle using Third-party Risk Management. An external assessment specifies the details for the third party or engagement and defines the plan for completing the assessment.").

* Due Diligence Request (DDR) workflows that orchestrate internal review, external assessment, approvals, and contract risk checks.For more information see, [Due diligence workflow](https://servicenow-prod.fluidtopics.net/qzVUTDoX2tjNy4ZNBARynw "The Third-party risk management (TPRM) processes provide a consistent framework for your third-party risk management program. You can customize the workflow processes to meet your organization's needs.").

* Reports and dashboards to track active requests, aging items, and completion timelines.For more information see, [Monitoring the due diligence request process](https://servicenow-prod.fluidtopics.net/VQBUvN0VMWYog1dR86_7Pw "TPR managers and TPR admins can perform a wide variety of tasks from the due diligence management dashboard. They can work on all processes in the workflow for a due diligence request: IRQs, external due diligence, approval, contract risk, and closed requests.").

{#tprm-due-diligence-types__ul_cgy_3dh_phc}

Access these features by navigating to the Vendor Management Workspace:

1. Go to WorkspacesVendor Management Workspace. On the Risk tab, select the due diligence management icon ![]().
2. On the Due diligence management page, select a stage (IRQ, Due diligence, Approvals, Contract risk, Final review, Closed) to view actionable lists.
3. Open a Due diligence request record to manage the workflow.
4. To send financial questionnaires or document requests from a DDR or an Assessment record, create an assessment.
5. Use the Due Diligence Management page to monitor status and aging.

{#tprm-due-diligence-types__ol_dgy_3dh_phc}

For more information see, [Monitoring the due diligence request process](https://servicenow-prod.fluidtopics.net/VQBUvN0VMWYog1dR86_7Pw "TPR managers and TPR admins can perform a wide variety of tasks from the due diligence management dashboard. They can work on all processes in the workflow for a due diligence request: IRQs, external due diligence, approval, contract risk, and closed requests.") and [Create an external assessment](https://servicenow-prod.fluidtopics.net/OsRUS7II7EVkcaW_YAOWrw "Create an assessment and initiate the third-party risk assessment life cycle using Third-party Risk Management. An external assessment specifies the details for the third party or engagement and defines the plan for completing the assessment.").  
Note:  
Activate the Third‑party Risk Due Diligence plugin (com.sn_tprm_dd) to enable preconfigured workflows and the Risk Concentration Map. For more information, see [Configuring Third-party Risk Management](https://servicenow-prod.fluidtopics.net/fSbrfETvXhzOC1Ihw7li7Q "You can activate or upgrade TPRM, by downloading the applications from the ServiceNow Store and then configuring the settings to meet your needs.") and [Enable the TPRM Risk concentration map](https://servicenow-prod.fluidtopics.net/8dKp~cABB86VqBH8Jhs2ew "After you install the Risk concentration map feature, you must install a Google license to enable the feature.").

*[\>]: and then


