
Vendor Due Diligence
Part of AdTech interoperability and technical standards
Maintaining a technical inventory of an advertising stack
Record each advertising-system connection, its versions, field contract, owners and observable events so changes and incidents can be traced.
A technical inventory should show which advertising systems are connected and what an operator needs to maintain or investigate each connection. A vendor list cannot answer that. Record the route, deployed version, field contract, owner and available evidence for every material handoff.
Use the connection as the record
One vendor may provide several interfaces, and one interface may serve different properties or accounts. Give each connection its own record, including its sender, receiver, account, property, format and purpose. Separate production and test routes.
| Field | What to record |
|---|---|
| Route | Sender, receiver, account or network, property and format |
| Interface | Protocol, encoding, endpoint or integration method, standard release and product build |
| Data contract | Required fields, extensions, taxonomies, units, defaults and a sample-message reference |
| IDs | Native placement, account, deal or campaign ID namespaces and approved mappings |
| Timing and events | Deadline or timeout rule, event definitions and available reports or logs |
| Control | Internal owner, partner contact, configuration owner and last verified date |
| Change | Release dependency, applicable support date, prior configuration and review trigger |
Keep a reference to credentials and their owner rather than placing secret values in a broadly shared inventory. Include the access process and escalation contact an authorised operator would need.
Record deployed behaviour
The standard and the deployed connection are different records. OpenRTB defines recommended and optional fields and provides ext objects for exchange-specific data. Record what this route sends, what its receiver uses and where the extension definition is kept. Where sharing is permitted, attach a redacted representative request and response with their collection date and configuration version.
Product documentation can identify dependencies to check. Google Authorized Buyers publishes an OpenRTB protocol reference and separate Google extensions. Prebid.js combines core code with selected adapters and optional modules.
Neither source identifies the fields or modules enabled in an account you have not inspected. An inventory entry saying only 'OpenRTB' or 'Prebid' would miss those operational details.
Treat reporting with the same precision. Record the event counted, source, dimensions, time zone, extraction route and documented retention limit. A bid win and a delivered impression need separate entries even when dashboards show them together.
Update it when the route changes
Refresh the record when a property, format, partner route, field mapping, wrapper build, API version, taxonomy, report or account permission changes. Assign the change owner to update the entry as part of the release. Preserve the prior record and effective date so an incident can be examined against the configuration that was live at the time.
Review external documentation when a dependency changes or its support date approaches. OpenRTB 2.6 receives date-coded updates, while Google publishes API-specific deprecation schedules. Record a support date from the applicable product schedule, not from the OpenRTB version number.
Deprecation and Support Schedules for Key AdTech Standards
- OpenRTB 2.6 Updates
- Date-coded updates published by the Interactive Advertising Bureau (IAB)
- Google Authorized Buyers API
- Deprecation schedules published by Google, separate from OpenRTB versions
Use the record to investigate
For missing bids, find the affected connection and its last confirmed handoff. The entry should lead to the relevant payload example, counters and owner on each side. If a required field is absent, check where it was meant to be populated. If it is present but no bid arrives, inspect receiver and timeout evidence before changing the sender.
Mark an unknown item as unknown, with an owner and review date. The inventory is useful when it shows what is connected, what each side expects and where the next piece of evidence can be found.


