Vendor Due Diligence: Evaluating Web3 Partners
The Executive Verdict
Introduction: The "Counterparty" Crisis
In Web2, vendor risk is Data. In Web3, it is Solvency. The failures of FTX and Celsius were not technology failures; they were Vendor failures. As a business leader, you must scrutinize Web3 vendors more than your bank.
1. The Core Filter: The "Trustless Test"
Ask: "Can you move my money without my permission?"
A traffic light system. Green = Non-Custodial (SaaS). Yellow = Qualified Custodian (Trust Co). Red = Commingled/Black Box (Yield Platform).
Strategic Directive: If a vendor falls into Zone 3, do not hire them.
2. Technical Diligence: Audit or Die
3. Operational & Legal Diligence
4. The "Black Box" Red Flags
Disqualifiers: "Proprietary Trading Bot" (Gambling), "Guaranteed Yield" (Ponzi), "Quiet Mode" (Regulatory Evasion), "DAO Managed" (No Liability).
5. The Exit Strategy: Vendor Lock-In
Can you fire them? Check for Data Portability (CSV exports) and Key Portability (Reconstruct key shards). If you cannot export your keys, you do own your money.
6. The RFP Checklist
Conclusion: Paranoia is a Virtue
Optimism is for the roadmap; paranoia is for the contract. Your job is to find the vendor that will still be there in 5 years. Boring is safe.
F.A.Q // Logical Clarification
Can I use a hardware wallet (Ledger) for business?
"For sole proprietorships, yes. For companies, No. It's single-user. Use an Enterprise MPC wallet."
What is Smart Contract Risk vs Vendor Risk?
"Smart Contract Risk is code failure. Vendor Risk is bankruptcy. Non-custodial minimizes Vendor Risk."
Are decentralized protocols vendors?
"Technically no, but treat them with equal diligence. Who audited the code? Who holds admin keys?"
Should I pay in crypto?
"Acceptable (USDC), but ensure you get a proper tax invoice."
Module ActionsCW-MA-2026
Institutional Context
"This module has been cross-referenced with Executive Strategy / Procurement standards for maximum operational reliability."