Skip to main content
Category: Third-Party and Supply Chain

Third-Party Due Diligence

Also known as: TPDD, Third-Party Risk Due Diligence, Vendor Due Diligence, Supplier Due Diligence
Simply put

Third-party due diligence is the process an organization uses to evaluate outside parties it works with, such as suppliers, vendors, and intermediaries, to identify risks that could harm the organization. It typically looks at a third party's integrity, reliability, compliance history, and financial condition before and during the business relationship. The depth of the review generally varies with the risk each third party presents.

Formal definition

Third-party due diligence is a structured process for assessing and verifying the integrity, reliability, compliance posture, financial standing, and overall risk exposure of external entities such as vendors, suppliers, and intermediaries. It commonly spans multiple risk domains, including compliance, financial, operational, reputational, and security risk, and is generally applied on a risk-based basis so that the scope and intensity of review reflect the assessed risk of each relationship. Operationally, due diligence activities are typically owned and executed by management (for example, procurement, compliance, or vendor risk functions) as part of a broader third-party risk management program, while the board and relevant committees generally retain oversight rather than execution responsibility. Specific requirements, triggers, and standards vary by jurisdiction, sector, and entity type, and this entry does not address any single legal regime.

Why it matters

Organizations increasingly rely on external suppliers, vendors, and intermediaries to deliver products, services, and business functions, and the conduct of those third parties can create risk that flows back to the organization. Third-party due diligence matters because it helps an organization identify integrity, compliance, financial, operational, reputational, and security risks before entering or continuing a relationship, rather than discovering problems only after harm has occurred. Without adequate due diligence, an organization may unknowingly engage a party that lacks financial stability, has a troubled compliance history, or otherwise exposes the organization to loss.

Because risk is not uniform across relationships, due diligence is generally applied on a risk-based basis, so that higher-risk third parties receive deeper scrutiny and lower-risk relationships receive proportionate review. This allows an organization to focus limited resources where the exposure is greatest. The depth and cadence of review typically continue through the life of the relationship, not just at onboarding, because a third party's circumstances and risk profile can change over time.

The specific triggers, standards, and expectations for third-party due diligence vary by jurisdiction, sector, and entity type, and this entry does not address any single legal regime. It is educational and not legal, audit, or compliance advice; whether and how a particular organization must conduct due diligence depends on its own facts, applicable requirements, and professional judgment.

Who it's relevant to

Chief Compliance Officers and Compliance Functions
Compliance leaders are often responsible for designing and running due diligence processes that evaluate a third party's integrity and compliance history, and for ensuring the review is proportionate to the assessed risk. They typically help set the standards and triggers for when deeper review is warranted.
Vendor Risk and Procurement Teams
Procurement and vendor risk functions frequently own and execute due diligence as part of onboarding and ongoing management of suppliers and vendors. They generally coordinate the assessment of financial, operational, security, and reputational risk across the relationship lifecycle.
Chief Risk Officers and Risk Management
Risk officers are typically concerned with how third-party exposure fits within the organization's broader risk posture and third-party risk management program, including how risk-based scoping is applied so that scrutiny reflects the risk each relationship presents.
Boards and Relevant Committees
The board and its committees generally retain oversight of the third-party risk management program rather than executing individual due diligence reviews. Their focus is typically on whether management has an adequate, risk-based process in place, not on operational performance of specific assessments.
Internal Auditors and Assurance Functions
Assurance functions may evaluate whether due diligence processes are designed appropriately and operating as intended. They typically provide independent perspective on the program rather than owning the underlying due diligence activities.

Inside TPDD

Risk-Based Screening
The initial process of identifying and categorizing third parties by risk level, typically based on factors such as the nature of the engagement, geography, sector, transaction value, and exposure to bribery, sanctions, or reputational concerns. Higher-risk relationships generally warrant more intensive review, while lower-risk ones may receive a lighter touch.
Information Collection and Verification
Gathering and corroborating information about the third party, which may include ownership and beneficial ownership details, corporate registration, financial standing, references, and relevant background. The depth of verification typically scales with the assessed risk tier.
Screening Against Watchlists and Adverse Media
Checking third parties against sanctions lists, politically exposed person (PEP) databases, debarment lists, and negative news sources. The applicable lists and legal obligations vary by jurisdiction and sector.
Red Flag Assessment and Escalation
Evaluating identified concerns (such as opaque ownership, unusual payment terms, or reputational issues) and routing them through a defined escalation path for review and decision, often involving compliance and, for significant matters, senior management.
Documentation and Recordkeeping
Maintaining an auditable record of the diligence performed, findings, decisions, and approvals, which supports demonstrating that reasonable steps were taken and helps satisfy expectations under certain anti-bribery and anti-corruption regimes.
Ongoing Monitoring and Refresh
Periodic or trigger-based re-review of third parties after onboarding, recognizing that diligence is generally not a one-time event; risk profiles can change over the life of a relationship.
Roles and Accountability
Clarity on who owns the activity: business units or procurement typically initiate and own the relationship (first line), compliance sets standards and provides challenge (second line), and internal audit may provide independent assurance over the program's design and operation (third line). The board or a committee generally oversees the program rather than performing diligence itself.

Common questions

Answers to the questions practitioners most commonly ask about TPDD.

Does completing third-party due diligence transfer or eliminate the organization's liability if the third party engages in misconduct?
No. Due diligence is a risk-management and prevention activity, not a liability shield. In many jurisdictions, an organization can remain accountable for the conduct of agents, intermediaries, and business partners acting on its behalf, particularly under anti-bribery and sanctions regimes. Due diligence typically helps demonstrate that reasonable steps were taken and may be a factor regulators or enforcement authorities consider, but it does not automatically absolve the organization. The weight given to it depends on the facts, the jurisdiction, the applicable law or framework, and whether the diligence was adequate and acted upon. This entry is educational and not legal or compliance advice.
Is third-party due diligence a one-time check performed only at onboarding?
Not typically. Onboarding screening is usually a starting point rather than the whole program. Third-party risk generally changes over the life of a relationship as ownership, geography, regulatory status, and behavior evolve. Many programs apply risk-based refresh cycles and event-driven triggers, so higher-risk relationships are reviewed more frequently than lower-risk ones. Treating diligence as a single gate at onboarding leaves a program exposed to changes that occur afterward. The appropriate cadence depends on the organization's risk appetite, sector, jurisdiction, and the nature of the relationship.
How should an organization decide the depth of diligence to apply to a given third party?
A risk-based approach is common: the intensity of diligence is generally calibrated to the assessed risk of the relationship rather than applied uniformly. Factors organizations often weigh include the third party's role (for example, whether it interacts with government officials on the organization's behalf), geography and associated corruption or sanctions exposure, industry, ownership and control, transaction value, and access to sensitive data or systems. Lower-risk relationships may warrant screening and basic verification, while higher-risk relationships may warrant enhanced review, including beneficial ownership analysis and, in some cases, on-site or independent verification. The specific tiers and thresholds are matters of management judgment and should be documented.
Which function owns third-party due diligence, and what is the board's role?
Operational execution of due diligence is generally a management responsibility, often carried out by procurement, compliance, or a dedicated third-party risk function within the first and second lines, depending on how the organization structures its three-lines model. Assurance functions such as internal audit may independently evaluate whether the program is designed and operating effectively, but they do not typically own the process they assess. The board or a relevant committee generally exercises oversight, for example, satisfying itself that a program exists, is resourced, and addresses material risks, rather than performing individual diligence reviews. Attributing operational diligence to the board or oversight duties to management would blur these distinct roles.
What should happen when due diligence surfaces a red flag?
A red flag generally signals the need for further inquiry rather than an automatic decision to proceed or reject. Common practice is to have a defined escalation and resolution process: documenting the finding, seeking additional information or clarification, assessing whether the concern can be mitigated (for example, through contractual controls, enhanced monitoring, or restricting scope), and involving compliance or legal for higher-risk matters. Decisions to onboard despite unresolved concerns are often subject to a documented approval at an appropriate level. The key discipline is that red flags are addressed and the rationale recorded, so the organization can show how issues were considered. What constitutes an adequate response depends on the facts and applicable requirements.
How can due diligence connect to ongoing monitoring rather than sitting in isolation?
Diligence and ongoing monitoring are typically designed as parts of a continuous lifecycle rather than separate activities. Information gathered at onboarding can establish a baseline against which later changes are measured, and the assigned risk tier can drive the frequency and scope of subsequent monitoring, such as periodic re-screening, adverse-media and sanctions-list checks, and event-driven reviews triggered by changes in ownership, regulatory status, or performance. Embedding results in contract terms, like audit and termination rights, can also link diligence findings to enforceable controls. Effectiveness generally depends on clear ownership of monitoring, defined triggers, and a feedback loop that feeds new findings back into the risk assessment.

Common misconceptions

Third-party due diligence is a one-time onboarding checkbox that is complete once a relationship is approved.
Diligence is generally treated as an ongoing discipline. Third-party risk profiles can change over time, so many programs incorporate periodic refresh cycles and event-driven re-reviews rather than relying solely on point-in-time screening at onboarding.
Every third party should receive the same depth of investigation.
Effective programs are typically risk-based, applying proportionate scrutiny. Higher-risk relationships generally warrant enhanced diligence, while lower-risk ones may justify a lighter approach. Treating all relationships identically can waste resources and dilute focus on genuine risk.
Completing due diligence guarantees the organization is protected from liability.
Due diligence supports, but does not guarantee, a defensible compliance posture. Depending on the jurisdiction and applicable regime, demonstrating reasonable, documented, risk-proportionate steps may help, but it does not eliminate risk or substitute for legal advice; obligations and expectations vary by jurisdiction, sector, and entity type.

Best practices

Adopt a documented, risk-based tiering methodology so that the intensity of diligence is proportionate to the assessed risk of each third party.
Define clear escalation paths and decision rights for red flags, specifying when compliance review or senior management approval is required before a relationship proceeds.
Maintain an auditable record of the information collected, findings, decisions, and approvals to demonstrate that reasonable steps were taken.
Build in ongoing monitoring through periodic refresh cycles and trigger-based reviews rather than treating diligence as a one-time onboarding step.
Clarify roles across the lines of defense so business owners, compliance, and internal audit understand their respective responsibilities and the board's or committee's oversight role.
Confirm which screening obligations and lists apply given the organization's jurisdictions and sectors, and seek qualified legal or compliance advice where requirements are uncertain.