Skip to main content
Category: Third-Party and Supply Chain

Third-Party Intermediary

Also known as: TPI, Intermediary, Broker
Simply put

A third-party intermediary is an outside person or organization that sits between two parties, such as a customer and a supplier, and helps facilitate transactions, negotiations, or interactions between them. In many settings this includes brokers who find, negotiate, and arrange contracts on a customer's behalf. The specific activities and any regulatory obligations attached to intermediaries generally depend on the jurisdiction and sector in which they operate.

Formal definition

A third-party intermediary (TPI) is an external entity that offers intermediation services between two contracting parties, facilitating transactions, negotiations, or interactions and helping one party navigate a marketplace to secure contracts. In some sectors, such as UK energy, the term denotes any organization positioned between a customer and a supplier, including brokers who source and negotiate arrangements; in law or diplomacy it more broadly describes a third party providing intermediation between two parties. Whether a given intermediary is subject to formal regulation varies by jurisdiction, sector, and entity type, and the evidence here reflects specific contexts (notably UK energy) rather than a universal regulatory standard. This entry is educational and not legal, audit, or compliance advice.

Why it matters

Third-party intermediaries occupy a position of trust and influence between contracting parties, which makes them a significant focus for compliance functions. Because an intermediary acts on behalf of, or between, principals to facilitate transactions and negotiations, its conduct can expose the parties it serves to reputational, contractual, and, depending on the sector and jurisdiction, regulatory consequences. The evidence here draws on specific contexts, notably the UK energy market, where a TPI is described as any organization that sits between a customer and a supplier, including brokers who find and negotiate arrangements, rather than a single universal standard.

The compliance relevance of intermediaries generally turns on the fact that their activities may not be directly visible to the parties relying on them. Where an intermediary sources, negotiates, or arranges contracts on a customer's behalf, the customer depends on the intermediary's representations and conduct to navigate a marketplace and secure appropriate terms. This dependency is one reason intermediary arrangements attract governance attention and, in some sectors, evolving regulatory interest; in the UK energy context the digest references consideration of regulating TPIs, though the specific scope and status of any such regime depend on the responsible authorities and are outside what can be confirmed here.

Whether and how an intermediary is regulated varies by jurisdiction, sector, and entity type. In law or diplomacy the term describes broadly a third party offering intermediation between two parties, while in a market context it may denote a broker or agent facilitating trade. Organizations should treat the presence of an intermediary as a factor to assess on its own facts rather than assume a fixed set of obligations applies. This entry is educational and not legal, audit, or compliance advice.

Who it's relevant to

Chief Compliance Officers
Compliance leaders generally assess intermediary relationships because an outside party facilitating transactions on the organization's behalf can create exposure that is not directly visible internally. Where a sector is moving toward regulating intermediaries, as the digest suggests in the UK energy context, compliance functions typically monitor whether and how such requirements apply to their entity and jurisdiction.
General Counsel and Legal Teams
Because an intermediary offers intermediation services between two contracting parties, legal teams are typically concerned with how the intermediary's authority, representations, and conduct are defined and constrained in contractual arrangements. The applicable obligations depend on jurisdiction and sector, so legal review is generally fact-specific rather than governed by a single standard.
Procurement and Contracting Functions
Teams that engage brokers or intermediaries to source, negotiate, and arrange contracts, such as energy customers using TPIs, rely on the intermediary to help navigate a marketplace and secure terms. These functions are generally attentive to how the intermediary is selected, what it is authorized to do, and how its role is documented.
Sector-Specific Market Participants
In markets where the intermediary concept is defined broadly and may be subject to evolving regulation, such as UK energy, where a TPI is any organization sitting between a customer and a supplier, suppliers, customers, and the intermediaries themselves have an interest in understanding how the term is applied and what obligations may attach in their specific sector.

Inside TPI

Definition and Scope
A third-party intermediary is generally an external party engaged to act on an organization's behalf in dealings with customers, government officials, or other counterparties. Common examples include agents, sales representatives, distributors, consultants, brokers, customs and freight forwarders, and lobbyists. The precise categories treated as intermediaries depend on the organization's risk profile, sector, and the jurisdictions in which it operates.
Risk Rationale
Intermediaries frequently feature in anti-bribery and corruption exposure because payments or influence can flow through them to third parties, potentially creating liability for the engaging organization under anti-corruption regimes in various jurisdictions. Sanctions, money laundering, data protection, and reputational risks may also arise depending on the intermediary's role and geography.
Risk-Based Due Diligence
A tiered process typically used to assess intermediaries before and during engagement, calibrated to the risk presented by the country, sector, transaction value, and the nature of the intermediary's interactions with government officials. Higher-risk relationships generally warrant enhanced scrutiny; lower-risk ones may warrant streamlined review.
Contractual Controls
Provisions commonly built into intermediary agreements, such as anti-corruption representations and warranties, audit and information rights, compliance certifications, and termination rights for breach. These are control mechanisms whose effectiveness depends on both design and consistent enforcement.
Ongoing Monitoring
Post-engagement activities such as periodic re-screening, review of payment patterns, refreshed certifications, and reassessment triggered by changes in risk. Monitoring is distinct from onboarding due diligence and addresses risks that emerge over the life of the relationship.
Accountability and Ownership
Responsibility for intermediary risk is typically shared: the business or relationship owner generally owns the commercial relationship and first-line controls, the compliance function commonly designs and oversees the program and monitors adherence, and the board or a designated committee generally provides oversight of the overall program rather than managing individual relationships.

Common questions

Answers to the questions practitioners most commonly ask about TPI.

Does engaging a third-party intermediary transfer the organization's compliance liability to that intermediary?
No. Engaging an intermediary generally does not transfer the engaging organization's own legal or regulatory exposure. Under many anti-bribery and sanctions regimes, an organization can be held accountable for acts undertaken on its behalf by agents, distributors, consultants, or other intermediaries. Contractual indemnities and representations may allocate certain risks between the parties, but they typically do not extinguish the organization's direct exposure to regulators. Whether and how liability attaches depends on the applicable law, the facts, and the nature of the relationship, so this should be assessed with qualified counsel.
Is due diligence on a third-party intermediary a one-time step completed at onboarding?
Generally, no. Many frameworks and enforcement expectations treat intermediary oversight as an ongoing process rather than a single onboarding check. Risk profiles can change over time as ownership, jurisdictions, services, or transaction patterns shift. Organizations commonly supplement initial due diligence with periodic refreshes, event-driven reviews triggered by red flags, and monitoring appropriate to the assessed risk level. The appropriate cadence and depth depend on the risk rating, sector, jurisdiction, and the organization's own policies and judgment.
Who within the organization typically owns responsibility for third-party intermediary oversight?
Accountability is usually distributed across the lines of defense rather than resting with a single function. The business or relationship owner (first line) typically owns the day-to-day relationship and the operational controls. The compliance function (second line) commonly sets policy, defines due diligence standards, and monitors adherence. Internal audit (third line) generally provides independent assurance over the design and operating effectiveness of the program. The board or a relevant committee typically exercises oversight of the overall framework rather than managing individual relationships. The precise allocation depends on the organization's structure and documented responsibilities.
How might an organization determine the appropriate level of due diligence for a given intermediary?
Many organizations apply a risk-based approach, calibrating the depth of due diligence to the assessed risk of the relationship rather than applying uniform procedures to all intermediaries. Factors commonly considered include the jurisdictions involved, the intermediary's interaction with government officials, the nature and value of services, ownership and control structures, and any red flags identified. Higher-risk relationships typically warrant enhanced due diligence, while lower-risk relationships may warrant a proportionately lighter process. The specific tiering criteria and thresholds are a matter of the organization's own policy and judgment.
What contractual provisions do organizations commonly consider when engaging intermediaries?
Organizations frequently consider provisions such as compliance representations and warranties, audit and information rights, anti-bribery and sanctions clauses, obligations to cooperate with investigations, and termination rights linked to compliance breaches. Such clauses can support oversight and provide a basis for action, but as noted they generally do not eliminate the organization's own regulatory exposure. The enforceability and appropriateness of specific terms depend on governing law and should be reviewed with counsel; this entry is educational and not legal advice.
How can red flags identified during due diligence be handled once the relationship is active?
Red flags are typically escalated and resolved through a documented process before onboarding proceeds, and ongoing monitoring may surface new red flags during the relationship. Common practices include escalating findings to the compliance function or a designated committee, requiring remediation or additional information, imposing enhanced controls, or declining or terminating the relationship where risks cannot be mitigated. Maintaining a clear audit trail of how red flags were assessed and resolved supports both internal assurance and any subsequent regulatory review. The appropriate response depends on the specific facts and the organization's risk appetite.

Common misconceptions

Using a third-party intermediary transfers or insulates the organization from liability for the intermediary's conduct.
In many jurisdictions, anti-corruption and related regimes can hold an engaging organization accountable for improper acts carried out through intermediaries, particularly where the organization knew of, was willfully blind to, or failed to guard against the risk. Whether liability attaches depends on the applicable law and facts; this is not legal advice.
Completing onboarding due diligence once is sufficient to manage intermediary risk.
Onboarding due diligence and ongoing monitoring are distinct activities. Risk profiles can change over the life of a relationship, so due diligence is generally treated as a lifecycle process with periodic reassessment rather than a one-time gate.
Strong contractual anti-corruption clauses by themselves ensure compliance.
Contractual controls represent control design; their protective value depends on operating effectiveness, whether audit rights are exercised, certifications are verified, and breaches are acted upon. Clauses that are never enforced provide limited assurance.

Best practices

Adopt a risk-based, tiered approach that calibrates the depth of due diligence to country, sector, transaction, and role-based risk factors rather than applying uniform screening to all intermediaries.
Treat due diligence as a lifecycle process, combining pre-engagement screening with periodic re-screening and event-driven reassessment when risk indicators change.
Embed enforceable contractual controls, anti-corruption representations, audit and information rights, compliance certifications, and termination rights, and actually exercise those rights so that control design is matched by operating effectiveness.
Clarify accountability by defining first-line ownership for business relationship owners, program design and monitoring for the compliance function, and program-level oversight for the board or relevant committee.
Monitor payment patterns, refresh certifications, and document the rationale for engagement and risk decisions to create an auditable record.
Tailor the program to applicable jurisdictional requirements and the organization's own risk profile, and seek qualified legal or compliance advice for specific situations, since this entry is educational and not legal, audit, or compliance advice.