This will depend on the type of vendor and the services you're consuming from them, so this answer will be somewhat general. I'll assume in the context of this question that by "on-premise" you're asking about a vendor who's service you're hosting within your own environment versus a cloud service provider or at the vendor. If you're asking about a vendor hosting a service within a vendor owned data center versus a cloud service provider, let me know and I or a community member will address that.
For services you're hosting within your environment, on prem, many of the due diligence checks are now your own internal controls, but some remain. Much of the information security, resiliency, and continuity due diligence will be internally focused instead. What's left are controls around the software/service itself and what support the vendor provides.
Information Security Policy
Software Change Management Policy
Software Development Security Policy
Background Checks on support and development
Security and Privacy Training for support and development
Business continuity for support and updates
Financials for continuity
How are others handling on-premise vendor due diligence? Have these vendors been more difficult to obtain the due diligence materials you're asking for?