Free Template · XLSX · 8 sheets · 12 formulas

    Supplier Due Diligence Checklist: Excel template for third-party onboarding (2026)

    The documentary verification file for a supplier, before you approve it. Mark which requirements apply, record the evidence for each one, document the findings and sign off the decision in the same workbook. The status — approvable, conditional or not approvable — is computed by the file.

    By Oscar Gamboa, CEO of EGIXIA · Updated August 11, 2026

    100% free · We send the link to your corporate email

    The workbook is in Spanish. Its formulas and dropdown lists behave identically in Excel and Google Sheets.

    Supplier Due Diligence Checklist Excel template — Egixia 2026

    What is supplier due diligence?

    Supplier due diligence is the verification you run before approving a third party: confirming it legally exists, that its tax standing is what it claims, that it does not appear on restricted lists and that it handed over every document your policy requires. It is an entry control, not ongoing monitoring: it happens once per supplier and it ends in a decision.

    That work is split across Procurement, Legal, Finance, Compliance and IT, and it usually lives in an email thread. When someone asks six months later why that supplier was approved, there is no file: there are attachments. This template turns the email thread into one file per supplier, with the requirement, the evidence, who validated it, when it expires and what was decided.

    The workbook ships with eight pre-loaded requirements as a starting point and room for up to 100 per supplier. It is built for the procurement analyst who assembles the folder and for the committee that approves it: the file does not opine on the supplier's risk, it only says whether the file is complete and who decided what.

    The 8 sheets, one by one

    Each sheet covers a stretch of the onboarding: what is requested, what arrived, what fails, what is decided. Twelve formulas wire the sheets together, so the status of the file comes out of what you mark in the checklist, with nobody keeping count by hand.

    Dashboard

    Five live counters over the checklist: items assessed, met, pending, not met and the compliance percentage. Below, the legend of the three onboarding statuses with their guiding criterion and the next step for each.

    Checklist Maestro — master checklist

    The working sheet: eleven columns per requirement — ID, category, requirement, whether it is mandatory, whether it applies, required evidence, the area that reviews it, status, verification date, expiry date and comments — with room for 100 rows and eight requirements already written.

    Documentos y Evidencias — documents and evidence

    The inventory of what actually arrived: document ID, which requirement it answers, where it was filed, whether it was received, document date, expiry date, who validated it and its status (pending, validated, expired or rejected). Ten columns, up to 100 documents.

    Evaluación de Cumplimiento — compliance assessment

    Six computed figures that look only at requirements flagged as applicable: how many apply, how many were met, how many remain pending, how many are not met, the percentage and — the one that matters — the onboarding status that follows from all of it.

    Hallazgos y Acciones — findings and actions

    One row per deviation: requirement affected, description of the finding, severity (low, medium, high or critical), required action, owner, committed date, status (pending, in progress, closed or accepted), closing evidence and notes. This is where an exception gets documented instead of forgotten.

    Aprobación de Onboarding — onboarding approval

    The formal decision, in seven fields: supplier, the compliance result pulled automatically from the previous sheet, the decision (pending, approved, conditionally approved or rejected), who approved it, the date, the conditions or exceptions agreed and the next review.

    Catálogos — category catalogue

    The eight verification categories with their purpose: corporate, tax, financial, legal, compliance, labour, ESG and information security. They are suggested and editable: the file expects you to bend them to your risk model, not the other way round.

    Instrucciones — instructions

    Five usage steps plus the note every tool of this kind should carry in print: it does not replace legal advice, list screening, third-party investigation or the controls required by regulation or by your own policies.

    The eight pre-loaded requirements

    They are neither a standard nor a closed list: they are the starting point you edit. Six ship flagged as mandatory; the labour and ESG ones as optional. Each comes with its category, the evidence you would ask for and the area that normally reviews it, so the discussion in your organisation is about what to remove and what to add, not about where to start. The rows below are translated; in the workbook they read in Spanish.

    IDCategoryRequirementRequired evidenceReviewing area
    DD-001CorporateCertificate of existence / corporate registrationValid documentProcurement
    DD-002TaxTax registration and fiscal standingValid documentFinance
    DD-003FinancialFinancial statements or financial assessmentEvidence defined by policyRisk
    DD-004LegalConflict of interest declarationSigned formLegal
    DD-005ComplianceRestricted-list screeningScreening result and dateCompliance
    DD-006LabourProof of applicable labour obligationsCertification / evidenceProcurement
    DD-007ESGApplicable environmental / social questionnaireQuestionnaire or policySustainability
    DD-008Information securitySecurity / privacy assessmentQuestionnaire / technical evidenceIT

    How the onboarding status is calculated

    The rule is a single nested formula, visible in the compliance assessment sheet. You can open it, argue about it in committee and change it if your onboarding policy differs.

    Any "not met" → Not approvable · any "pending" left → Conditional · 100% compliance → Approvable · anything else → Review
    • The count only takes requirements flagged "Applies = Yes". A requirement your organisation does not demand from that supplier will not drag the result down.
    • Watch the two denominators: the Dashboard counts across every item written in the checklist; the compliance assessment counts only the applicable ones. That is intentional — one measures progress on the folder, the other supports the decision — but it is worth knowing before quoting a percentage in committee.
    • "Approved exception" does not add to the met items: a file with exceptions never reaches "Approvable", it lands on "Review". That is the correct behaviour — an exception is somebody's decision, not a requirement met — and it forces you to write it down in the findings sheet with an owner.

    The four statuses and what to do with each

    The dashboard prints the legend for the first three. The fourth, "Review", is the formula's default exit when the file does not fit any of the other three.

    StatusWhen the formula returns itNext step
    No aprobable — not approvableAt least one applicable requirement is marked "not met"Escalate to Compliance / Legal before continuing
    Condicionado — conditionalNo failures, but applicable requirements remain "pending"Request the evidence and approve conditionally if policy allows it
    Aprobable — approvable100% of the applicable requirements are marked "met"Record the approval and the review date
    Revisar — reviewNone of the three above: the checklist is empty or there are approved exceptionsReview the scope of the checklist before taking it to a decision

    What is inside

    12 formulas

    The five dashboard counters, the six assessment figures and the result carried over to the approval sheet all calculate themselves. You mark statuses; the file concludes.

    7 dropdown lists

    Checklist status, document status, severity, finding status and the final decision all come from closed lists. A file where every analyst invents their own vocabulary stops being comparable across suppliers.

    Colour coding in two places

    Six conditional formatting rules: three colour the checklist status column — met, pending and not met — and three more colour the onboarding status in the assessment sheet.

    Validity, not just receipt

    Both the checklist and the document inventory carry an expiry date column: a certificate received but already expired is not a requirement met, and the file makes that visible.

    What this file does and what it does not

    The file organises the record and calculates whether it is complete. It verifies nothing on your behalf: it does not screen restricted lists, it does not validate a certificate against the public registry that issued it, it does not read a third party's tax standing and it does not replace a background investigation. That note is printed on the instructions sheet and it is worth repeating here.

    Internal money-laundering and terrorist-financing risk management programmes — SAGRILAFT in Colombia and its regional equivalents — require counterparty onboarding to be documented: what was requested, what was received, who validated it and what was decided. This workbook produces that trail and supports the programme your organisation already runs: it does not design it, approve it or replace it. Egixia does not certify or guarantee compliance with any regulation. Restricted-list screening and final approval remain with your compliance officer and your legal advisors.

    Frequently asked questions about supplier due diligence

    What is supplier due diligence and how does it differ from supplier evaluation?

    Due diligence is the verification that happens before approval: confirming the third party legally exists, that its tax and labour standing is what it declared, that it does not appear on restricted lists and that it handed over the documents your policy requires. It happens once, before the first purchase order, and it ends in a decision to approve or not. Supplier evaluation measures something else at another moment: the performance of a supplier already working with you — quality, delivery, total cost — repeated on a recurring basis.

    Which documents are requested in a supplier due diligence?

    It depends on each organisation's policy and on the country. This template ships eight pre-loaded requirements as a starting point, grouped into eight categories: corporate (certificate of existence or registration), tax (registration and fiscal standing), financial (financial statements or financial assessment), legal (conflict of interest declaration), compliance (restricted-list screening), labour (proof of applicable obligations), ESG (environmental and social questionnaire) and information security (security and privacy assessment). Every row is editable, can be flagged as applicable or not, and the sheet takes up to 100 requirements per supplier.

    How does the file decide whether a supplier is approvable?

    With a single formula, applied only to the requirements flagged as applicable. If at least one is marked "not met", the status is Not approvable. If there are no failures but items remain pending, it is Conditional. If 100% is marked "met", it is Approvable. Any other combination — an empty checklist or a requirement with an approved exception — returns Review. It is a guiding result: the formal decision is recorded by hand in the onboarding approval sheet, with the name of the approver, the date, the conditions agreed and the next review.

    Is it useful for SAGRILAFT or an AML/CFT due diligence programme?

    It works as a record, not as a control. It supplies the documentary trail these programmes require — what was requested, which evidence arrived, who validated it, what findings there were and what was decided — and it keeps exceptions written down. It does not screen restricted lists or validate documents against their source: your team or a specialist tool does that, and the result is recorded in the checklist. Egixia does not certify or guarantee regulatory compliance.

    Is it free, and what format does it arrive in?

    Yes, it is free. We ask for your name, company and corporate email so we can send you the download link — no spam chains. It arrives as an .xlsx file in Spanish, compatible with Excel and Google Sheets, with eight pre-loaded requirements and a few rows marked "Ejemplo" (sample) that you can delete before starting.

    What if I do not want one spreadsheet per supplier?

    That is the honest limit of the template: the record covers one supplier, not a base; for the second third party you duplicate the file. When volume justifies it, Egixia's Onboarding module does the same inside the procurement flow: the supplier uploads its own documents, the system tracks expiry dates and onboarding does not advance if a mandatory requirement is missing. Document retention for the client is a capability enabled per project, according to the client's policies.

    Download the supplier due diligence checklist — free

    Leave your corporate email and we will send the link instantly. Eight sheets, 12 formulas, seven dropdown lists, eight pre-loaded requirements and room for 100 per supplier, with the onboarding decision recorded in the same file.

    The download link is sent to your corporate email.

    The workbook is in Spanish. Its formulas and dropdown lists behave identically in Excel and Google Sheets.

    🙏 Found it useful? Help us reach more procurement professionals by following us on LinkedIn.

    Follow Egixia on LinkedIn

    What if the supplier assembled its own file?

    A spreadsheet organises the onboarding of one supplier; it does not scale to a hundred a year. Egixia's Onboarding module gives the third party a portal where it uploads its documents, tracks expiry dates and blocks onboarding while a mandatory requirement is missing. Book a 30-minute demo.

    Schedule strategic demo