TRUST CENTER
The paperwork your finance team asks for, in one place.
Vendor onboarding shouldn’t slow down the engagement. Every document below is available on request, and most go out the same business day.
VENDOR DUE DILIGENCE
Documents available for your review
Vendor onboarding often requires more than a certificate of insurance and a tax form. Finance, legal, compliance, and information security teams may each need different information before approving a service provider.
I maintain a set of business, security, and governance documents to support that review. Some materials are available immediately. Others are provided upon request or under NDA because they contain information about internal security practices.
Business and onboarding documents
Certificate of Insurance
A current certificate confirming N.O. IT Strategy LLC’s applicable business and professional liability coverage. If your organization needs to be named as the certificate holder, include the legal name and address with your request.
Form W-9
A current signed Form W-9 for accounts payable, tax reporting, and vendor onboarding.
Nondisclosure Agreement
I can provide my standard mutual NDA or review your organization’s agreement. Confidentiality requirements are confirmed before access to sensitive systems or information begins.
Security and governance documents
SOC 2 Alignment Statement
A public explanation of how I map my internal practices to the SOC 2 Trust Services Criteria, including the limits of that alignment and the fact that N.O. IT Strategy has not undergone an independent SOC 2 examination.
Security and Data Handling Summary
An overview of access controls, authentication, endpoint protection, data storage, retention, backup practices, and information disposal.
Written AI Use Policy
The standards governing when AI tools may be used, what information is prohibited from being entered, how outputs are reviewed, and how client-specific restrictions are handled.
Incident Response Plan Summary
An overview of how I address detection, containment, evidence preservation, investigation, client communication, recovery, and post-incident review.
Vendor Independence and Conflict Disclosure
A written statement describing how I maintain vendor neutrality, avoid commissions and referral incentives, and disclose the use of specialists or subcontractors when an engagement requires outside expertise.
Additional due-diligence information
Depending on the proposed engagement, I can also provide:
- Professional references
- A description of relevant insurance coverage
- Data-retention and disposal information
- A list of approved service providers that may support my business operations
- Additional control information requested through your vendor questionnaire
- Clarification of access, data handling, and engagement closeout procedures
- Documentation supporting a risk-based vendor exception when appropriate
Detailed technical information may require a signed NDA. Full internal security procedures, credentials, system configurations, and information that could weaken security are not distributed as general sales materials.
REQUEST PROCESS
Tell me what your review requires
Every organization handles vendor onboarding differently. You do not need to request the entire document set if your process only requires a few items.
Send the name of your organization, the documents needed, and any vendor questionnaire or special instructions. I will confirm the request and provide the appropriate materials within two business days whenever possible.
NEXT STEP
If the paperwork checks out, let's talk about the work
Vendor onboarding is the easy part. Let’s identify what IT pain points your currently dealing with and let’s figure out a way to get you past them.