Skip to main content
Category: Anti-Bribery and Corruption

Anti-Corruption Due Diligence

Also known as: Anti-Bribery and Corruption Due Diligence, ABC Due Diligence
Simply put

Anti-corruption due diligence is the process a company uses to check the background of third parties such as agents, distributors, and suppliers before or during a business relationship, to spot and reduce the risk of bribery or corruption. It typically involves background checks and investigations scaled to how risky a particular relationship appears. It is generally part of a broader anti-bribery and corruption compliance program rather than a one-time exercise.

Formal definition

Anti-corruption due diligence is the systematic process of evaluating third parties, transactions, and business relationships to identify, assess, and mitigate corruption and bribery risks. In practice it centers on risk-based background checks and investigations of intermediaries (for example agents, distributors, and suppliers), with the depth of inquiry calibrated to each third party's risk profile; a satisfactory review generally seeks evidence that the third party maintains an anti-bribery program appropriate to that profile. It is commonly informed by responsible business conduct standards addressing corruption risks in supply chains and forms one component of an organization's wider anti-bribery and corruption compliance framework. The specific legal obligations, required scope, and documentation vary by jurisdiction, sector, and entity type; this entry is educational and not legal or compliance advice.

Why it matters

Third parties such as agents, distributors, and suppliers are a persistent source of corruption exposure, because a company can be held accountable for improper payments made on its behalf by an intermediary. Anti-corruption due diligence gives an organization a structured way to understand who it is doing business with before and during a relationship, and to calibrate the depth of its scrutiny to the risk a particular counterparty presents. Without it, a company may lack visibility into red flags that, if left unexamined, could translate into legal, financial, and reputational consequences.

Because corruption risk often sits deep in supply chains, due diligence is increasingly framed as part of broader responsible business conduct expectations rather than a standalone box-ticking task. Standards developed by bodies such as the OECD have addressed how companies can apply due diligence to tackle corruption risks in their supply chains, reflecting a shift toward treating third-party integrity as an ongoing management responsibility.

The specific legal obligations, required scope, and documentation vary considerably by jurisdiction, sector, and entity type, and this entry is educational rather than legal or compliance advice. What constitutes adequate due diligence in one regime or industry may fall short in another, so organizations generally need to interpret these expectations against the particular laws and enforcement environment that apply to them.

Who it's relevant to

Chief Compliance Officers
Compliance leaders typically own the design and operation of the anti-bribery and corruption program, including how third-party due diligence is risk-tiered, triggered, documented, and refreshed. They are generally responsible for ensuring the process produces evidence appropriate to each third party's risk profile and for coordinating it with the wider compliance framework.
General Counsel and Legal Teams
Legal functions generally advise on how anti-corruption obligations apply across the relevant jurisdictions, sectors, and entity types, and on how due diligence findings translate into contractual protections and onboarding decisions. Because required scope and documentation vary by regime, legal input is often central to interpreting what adequate due diligence means in a given context.
Procurement and Business Development Managers
Those who engage agents, distributors, and suppliers are typically the front-line owners of the relationships subject to due diligence. They generally need to understand when and how the process applies so that risk-based checks are completed before or during a relationship and red flags are escalated rather than overlooked.
Internal Auditors and Assurance Functions
Assurance functions generally provide independent review of whether the due diligence process is designed appropriately and operating effectively, including whether inquiry depth is genuinely calibrated to risk and whether supporting evidence is retained. Their role is oversight and testing rather than ownership of the operational process itself.
Boards and Audit or Risk Committees
Boards and their relevant committees typically hold oversight responsibility for the effectiveness of the anti-bribery and corruption program as a whole, including third-party due diligence, without performing the operational work. They generally seek assurance that management has implemented a risk-based approach proportionate to the organization's corruption exposure.

Inside Anti-Corruption Due Diligence

Risk-Based Scoping
The practice of calibrating the depth of due diligence to the assessed corruption risk of a relationship, typically weighing factors such as the counterparty's jurisdiction, industry sector, interaction with government officials, use of intermediaries, and transaction value. Higher-risk relationships generally warrant enhanced diligence, while lower-risk ones may justify a streamlined review.
Third-Party and Intermediary Screening
The evaluation of agents, distributors, consultants, joint venture partners, and other intermediaries who may act on the entity's behalf. Because liability can arise from the conduct of third parties, screening typically examines ownership, beneficial ownership where identifiable, reputation, and any connections to government officials or politically exposed persons.
Red Flag Identification
The systematic detection of warning indicators such as unusual payment arrangements, requests for offshore payments, refusal to provide anti-corruption certifications, lack of relevant qualifications, or a reputation for improper conduct. Red flags generally prompt escalation and further inquiry rather than an automatic decision to proceed or decline.
Documentation and Recordkeeping
The retention of evidence showing that diligence was performed, findings were assessed, and decisions were reasoned. Contemporaneous records typically support the demonstration of a reasonable, good-faith process, which is often relevant to how enforcement authorities view a program under certain regimes.
Ongoing Monitoring
The recognition that due diligence is generally not a one-time event; relationships are typically re-assessed periodically or when triggering events occur, such as a change in ownership, role, or risk profile. This distinguishes point-of-onboarding review from the continuing lifecycle of a relationship.
Contractual Protections
The use of anti-corruption representations, warranties, audit rights, and termination clauses in agreements with third parties. These provisions typically reinforce due diligence by establishing enforceable obligations and remedies, though they do not substitute for substantive assessment of the counterparty.

Common questions

Answers to the questions practitioners most commonly ask about Anti-Corruption Due Diligence.

Is anti-corruption due diligence just a background check performed once before onboarding a third party?
No. A one-time background check is only one input. Anti-corruption due diligence is generally understood as a risk-based, ongoing process that assesses corruption risk before engaging a third party and continues to monitor that relationship over its life. Point-in-time screening does not capture changes in ownership, conduct, or risk exposure that arise after onboarding, which is why many programs pair initial diligence with periodic refresh cycles and event-driven reviews. The appropriate depth and frequency typically depend on the risk profile of the counterparty, jurisdiction, and transaction. This entry is educational and not legal or compliance advice; program design should reflect your own facts and applicable law.
Does completing due diligence guarantee that a company is protected from liability if the third party later pays a bribe?
No. Due diligence generally supports, but does not guarantee, a defense. Under many anti-corruption regimes, the existence and quality of due diligence may be relevant to assessing whether an organization had adequate or reasonable procedures, but outcomes vary by jurisdiction, by the specific legal standard applied, and by the facts. Diligence that is thorough on paper but ignored in practice, or that fails to act on identified red flags, offers limited protection. The value of due diligence lies in identifying and responding to risk, not in the mere completion of a form. Whether any particular process affects liability is a legal question that depends on the applicable framework and professional judgment.
How should the depth of due diligence be matched to the level of risk?
A risk-based approach typically tiers the intensity of diligence to the assessed corruption risk of the relationship. Lower-risk counterparties may warrant streamlined screening, while higher-risk situations, for example those involving interaction with government officials, higher-risk jurisdictions, opaque ownership, or intermediaries acting on the company's behalf, generally call for enhanced diligence such as deeper ownership analysis, references, or on-site inquiry. Common risk factors weighed include the counterparty's role, geography, sector, and the nature and value of the engagement. The specific thresholds and tiers are matters of program design and judgment, and should be documented so decisions are defensible and consistent.
Who within the organization owns anti-corruption due diligence, and what is the board's role?
Responsibility is generally distributed rather than held by a single function. The compliance function typically designs the due diligence methodology, sets risk criteria, and reviews escalated or higher-risk cases, while the business or procurement function that sponsors a relationship usually performs or initiates the diligence and owns the underlying commercial risk. Internal audit or another assurance function may independently test whether the process operates as designed. The board or a designated committee generally holds oversight responsibility, satisfying itself that a program exists and functions, rather than performing operational diligence itself. Exact allocation varies by organizational structure, size, and applicable expectations.
What are common red flags that anti-corruption due diligence is designed to surface?
Diligence is typically structured to identify indicators warranting further inquiry rather than to reach conclusions on their own. Frequently cited red flags include requests for unusual payment arrangements or offshore accounts, a counterparty recommended or required by a government official, close ties between the counterparty and officials, a lack of relevant qualifications or capacity for the services purportedly provided, reluctance to certify anti-corruption commitments, and unclear or concealed beneficial ownership. A red flag is a prompt for escalation and resolution, not automatically a disqualifying finding; how each is investigated and documented is a matter of program design and judgment. The examples here are illustrative and not exhaustive.
How should due diligence findings be documented and escalated?
Programs generally record what was reviewed, what was found, how red flags were resolved, and who approved the engagement, so that decisions are traceable and defensible. Higher-risk findings are typically escalated according to a defined pathway, often to compliance or a review committee, before the relationship proceeds, and unresolved concerns may result in additional conditions, contractual protections, or declining the engagement. Many programs also provide for periodic refresh and event-driven re-review, and retain records consistent with applicable retention expectations. The specific escalation thresholds, approval authorities, and retention periods depend on the organization's structure and applicable requirements, and should be set with appropriate professional input.

Common misconceptions

Anti-corruption due diligence is a compliance formality that ends once a counterparty is onboarded.
Due diligence is generally an ongoing process rather than a single gate. Risk profiles change, and many programs re-assess relationships periodically or upon triggering events. A one-time check at onboarding typically leaves subsequent conduct unmonitored.
Contractual anti-corruption clauses on their own protect the entity from liability.
Representations, warranties, and audit rights are useful reinforcements but do not replace substantive assessment of a counterparty. Under many regimes, an entity can face exposure for the conduct of third parties despite having such clauses if the underlying diligence was inadequate or ignored red flags.
Identifying a red flag means the relationship must be terminated or declined.
A red flag generally signals the need for further inquiry and escalation, not an automatic outcome. The appropriate response depends on the facts, whether the concern can be resolved, and the entity's own judgment and risk appetite; some red flags are satisfactorily addressed while others are not.

Best practices

Calibrate the depth of diligence to assessed risk, reserving enhanced review for higher-risk jurisdictions, sectors, intermediaries, and relationships involving government interaction, rather than applying a uniform level to all counterparties.
Establish clear escalation pathways so that identified red flags are routed for further inquiry and documented resolution before a relationship proceeds, and define who holds authority to approve or decline.
Maintain contemporaneous records of the diligence performed, findings, and the reasoning behind decisions, so the process can be demonstrated as reasonable and good-faith if later reviewed.
Re-assess counterparties on a periodic basis and upon triggering events such as changes in ownership, role, or risk profile, treating due diligence as an ongoing lifecycle rather than a one-time onboarding step.
Use anti-corruption representations, warranties, audit rights, and termination provisions to reinforce diligence, while ensuring these contractual protections supplement rather than replace substantive assessment.
Clarify ownership of the process, with management and the relevant compliance function typically responsible for conducting and maintaining diligence, and assurance or oversight functions positioned to test the program's design and operating effectiveness. Confirm requirements against the specific applicable regime and seek qualified advice for fact-specific situations.