Tools and providers
Part of Choosing marketplace seller software with one fictional fixture for every route
Due diligence on a marketplace software vendor, from identity to the terms of exit
Investigate a marketplace software vendor through separate identity, claim, contract, safety, data, security, accessibility, money and exit evidence.
Marketplace seller software vendor due diligence should separate what is registered, claimed, contracted, independently evidenced and still unknown. This checklist is for one fictional England merchant, authorised seller, marketplace account and exact service edition supporting a product, stock and later order-state exchange.
No vendor was examined. Research closed on 6 September 2026. Complete every field from current evidence and send the dossier to the named reviewers before contracting or enabling production.
Identity and authority
- Record the legal and trading entities, registered details, contracting authority, service, edition, territory and evidence date.
- Obtain evidence that the seller may connect the named marketplace account for the bounded job.
- List marketplace terms, interface permissions and supplier dependencies by version.
Companies House register guidance states that filed information is not verified by Companies House. Keep that narrow fact apart from a vendor's service claim or the buyer's account evidence.
Function and state definitions
- Obtain schemas, identifiers, validations, transformations, sequencing, retries, rejected-event handling and limits.
- Map placed, accepted, authorised, captured, fulfilled, cancelled, returned, partially refunded, disputed and settled states.
- Name the owner of conflicting stock, late data, duplicate events and correction.
Treat documentation as a first-party claim until the fictional fixture shows the behaviour in the exact configuration. Do not infer scale, accuracy or durability from one pass.
Consumer and product evidence
- Trace description, total price, delivery, optional choice, confirmation, cancellation, return and refund fields.
- Map product identity, model or batch, manufacturer or importer, warning, instruction and traceability evidence where relevant.
- Require suppression, correction, withdrawal and incident routes with retained logs.
GOV.UK lists online seller information and journey fields in its online-selling guidance. OPSS product-safety advice distinguishes Great Britain and Northern Ireland and notes that sector rules can apply. Qualified reviewers must apply both to the actual case.
Data and device operations
- Record purposes, fields, sources, people, controller and processor facts, recipients and remote access.
- Obtain subprocessor, transfer, retention, rights-support, incident, export and deletion evidence.
- List cookies, pixels, SDKs and similar storage or access with purpose, duration and activation point.
The ICO's storage and access technology guidance was finalised on 29 April 2026. A privacy and PECR adviser must assess the precise operation; marketplace authority is not consent for unrelated tracking.
Security, accessibility and support
- Inspect authentication, privileged roles, logs, support access, incident contacts, recovery evidence and access removal.
- Record independent assessment scope and date without treating a certificate as approval.
- Define accessible staff and customer tasks, test setup, barriers, alternative route and remediation owner.
NCSC supplier-assurance questions cover governance, data, access, incidents and exit. They guide questions rather than certify answers. Support channels and service fields need exact contract evidence; leave thresholds blank.
Commercial terms and exit
- Capture currency, VAT basis, charging unit, period, term, limits, pass-through charges and renewal from the precise offer.
- Put liability, indemnity, insurance, audit, suspension and change control before the appropriate reviewers.
- Test export fields, isolated restore, deletion, open-order handover and return to the current process.
Record each answer's source, date, owner, limitation and expiry. Any unknown in a non-compensating consumer, safety, tax, privacy, security, accessibility or exit gate produces hold. The checklist documents an investigation; it cannot establish legal compliance or vendor fitness.