Third-Party Due Diligence
Third-party due diligence is the process an organization uses to evaluate outside parties it works with, such as suppliers, vendors, and intermediaries, to identify risks that could harm the organization. It typically looks at a third party's integrity, reliability, compliance history, and financial condition before and during the business relationship. The depth of the review generally varies with the risk each third party presents.
Third-party due diligence is a structured process for assessing and verifying the integrity, reliability, compliance posture, financial standing, and overall risk exposure of external entities such as vendors, suppliers, and intermediaries. It commonly spans multiple risk domains, including compliance, financial, operational, reputational, and security risk, and is generally applied on a risk-based basis so that the scope and intensity of review reflect the assessed risk of each relationship. Operationally, due diligence activities are typically owned and executed by management (for example, procurement, compliance, or vendor risk functions) as part of a broader third-party risk management program, while the board and relevant committees generally retain oversight rather than execution responsibility. Specific requirements, triggers, and standards vary by jurisdiction, sector, and entity type, and this entry does not address any single legal regime.
Why it matters
Organizations increasingly rely on external suppliers, vendors, and intermediaries to deliver products, services, and business functions, and the conduct of those third parties can create risk that flows back to the organization. Third-party due diligence matters because it helps an organization identify integrity, compliance, financial, operational, reputational, and security risks before entering or continuing a relationship, rather than discovering problems only after harm has occurred. Without adequate due diligence, an organization may unknowingly engage a party that lacks financial stability, has a troubled compliance history, or otherwise exposes the organization to loss.
Because risk is not uniform across relationships, due diligence is generally applied on a risk-based basis, so that higher-risk third parties receive deeper scrutiny and lower-risk relationships receive proportionate review. This allows an organization to focus limited resources where the exposure is greatest. The depth and cadence of review typically continue through the life of the relationship, not just at onboarding, because a third party's circumstances and risk profile can change over time.
The specific triggers, standards, and expectations for third-party due diligence vary by jurisdiction, sector, and entity type, and this entry does not address any single legal regime. It is educational and not legal, audit, or compliance advice; whether and how a particular organization must conduct due diligence depends on its own facts, applicable requirements, and professional judgment.
Who it's relevant to
Inside TPDD
Common questions
Answers to the questions practitioners most commonly ask about TPDD.