
Vendor Due Diligence
Part of AdTech vendor due diligence
Planning an exit from a critical advertising vendor
Map critical advertising dependencies, prepare a handover, stage a changeover and close data and access obligations.
Plan an exit while the vendor’s service still works. Identify which advertising functions depend on it, what must continue during a changeover and who can authorise each step. Prepare both an orderly contract end and a shorter contingency response if the service becomes unavailable.
Plan an exit before the vendor fails
- Identify dependent advertising functionsAd selection, buying, creative delivery, audience activation, measurement, billing or reporting.
- Define what must continue during changeoverAffected campaigns, systems and the interruption the business can tolerate.
- Assign who can authorise each stepInternal owners for operational, security, privacy and commercial approvals.
Map the dependencies
List activities that would stop or become unreliable: ad selection, buying, creative delivery, audience activation, measurement, billing or reporting. For each, record affected campaigns and systems, an internal owner, any available alternative and the interruption the business can tolerate. An alternative named on paper is not an operationally ready replacement.
Dependency / Exit question
- Configuration
- Who can read and reproduce essential settings?
- Tags and connections
- Which sites, apps or partners need a switch or shutdown?
- Assets and audiences
- What may be reused under the agreement?
- Reports and invoices
- Which final period needs capture and reconciliation?
- Support
- Who approves the change and investigates a failed handoff?
Dependency mapping checklist
- ConfigurationWho can read and reproduce essential settings?
- Tags and connectionsWhich sites, apps or partners need a switch or shutdown?
- Assets and audiencesWhat may be reused under the agreement?
- Reports and invoicesWhich final period needs capture and reconciliation?
- SupportWho approves the change and investigates a failed handoff?
Prepare the handover
Inventory vendor-controlled accounts, integrations, credentials, tags, files and downstream recipients. Identify records a successor needs, then request a representative export while access is active. Confirm the recipient’s right to use it and whether the format and identifiers suit the intended move.
Capture records within the source’s actual retention window. Confirm retention and export timing directly with the vendor before relying on their availability.
Set transition assistance, notice, export deadlines and relevant charges in the agreement. Assign an owner for final invoice reconciliation and disputes.
Handover preparation sequence
- Inventory vendor-controlled assetsAccounts, integrations, credentials, tags, files and downstream recipients.
- Request a representative export while access is activeIdentify records a successor needs.
- Confirm rights, format and identifiersVerify the recipient’s right to use it and whether it suits the intended move.
- Confirm retention and export timingCapture records within the source’s actual retention window.
- Set agreement termsTransition assistance, notice, export deadlines and relevant charges.
- Assign final invoice ownerReconciliation and disputes.
Stage and close the change
For an orderly move, record the old configuration, prepare the replacement with authorised test data and compare required outputs at equivalent stages. Move an agreed function or share of traffic, monitor it and keep a recovery action. Matching dashboard totals alone do not prove identical underlying events.
If a sudden interruption or security problem forces a faster response, operations, security and privacy owners should choose the safe sequence for the actual systems. The immediate objective may be to stop an affected transfer, preserve necessary records or move essential campaigns through an available route. None of those actions should be assumed appropriate for every incident.
After handover, review users, service accounts, keys and partner permissions for revocation or rotation. Check that transfers and tags intended to stop are inactive. Preserve records the organisation is authorised or required to retain.
For an APP entity’s personal information no longer needed for a permitted purpose, the OAIC describes reasonable steps to destroy or de-identify it, subject to exceptions. Have the privacy owner assess each dataset, including copies and downstream recipients. Close the exit record with exports, gaps, invoices, access changes and any applicable deletion evidence.
Orderly move vs contingency response
- TriggerOrderly: planned contract end. Contingency: sudden interruption or security problem.
- ApproachOrderly: record old configuration, prepare replacement with authorised test data, compare outputs, move an agreed function or share of traffic, monitor and keep a recovery action. Contingency: operations, security and privacy owners choose the safe sequence for the actual systems.
- Immediate objectiveOrderly: compare required outputs at equivalent stages. Contingency: stop an affected transfer, preserve necessary records or move essential campaigns through an available route.
- Validation limitationMatching dashboard totals alone do not prove identical underlying events.
- Post-change actionsReview users, service accounts, keys and partner permissions for revocation or rotation; check transfers and tags intended to stop are inactive; preserve records the organisation is authorised or required to retain.


