BBNO Partners Speak with an advisor
Counterparty Risk

Third-Party and Supplier Due Diligence: Building a Defensible Programme

Where something goes wrong in a supply chain, the question is whether the organisation had a process capable of preventing it — and whether that process was actually followed.

Regulators, courts, and counterparties increasingly expect an organisation to know who it does business with. Where something goes wrong — a supplier implicated in bribery, a distributor breaching sanctions, a contractor using forced labour — the question asked is not whether the organisation intended the outcome but whether it had a process capable of preventing it, and whether that process was actually followed.

Why the Standard Has Risen

Several bodies of law converge on the same expectation from different directions.

Anti-bribery legislation in a number of jurisdictions makes an organisation liable for bribery committed on its behalf by associated persons — including agents, distributors, and intermediaries. Where a defence exists, it typically turns on whether adequate or reasonable procedures were in place, of which risk-based third-party due diligence is a central component.

Sanctions regimes impose strict liability in many cases. Intent is frequently irrelevant, and dealing indirectly with a restricted party through an intermediary does not cure the breach.

Supply chain due diligence obligations have moved from voluntary standards toward binding law in several jurisdictions, requiring identification and mitigation of human rights and environmental risks in a company's value chain, with reporting requirements attached.

Anti-money laundering frameworks require regulated firms to identify beneficial owners and understand the nature of business relationships.

Risk-Based Means Differentiated

Every framework requires a risk-based approach, and the term is routinely misapplied to mean either a single procedure applied to everyone or an unstructured exercise of judgement. It means neither.

It means a defined methodology that assigns counterparties to risk tiers using consistent criteria, applies proportionate diligence to each tier, and documents both the assignment and the reasoning. Criteria typically include:

  • Jurisdiction — corruption indices, sanctions exposure, rule of law, the presence of relevant conflicts
  • Sector — extractives, construction, defence, and healthcare carry elevated baseline risk
  • Relationship type — an agent acting on the organisation's behalf presents materially different exposure from a supplier of commodity goods
  • Government interaction — whether the counterparty deals with public officials or obtains licences and permits on the organisation's behalf
  • Value and duration — a long-term high-value relationship warrants deeper diligence than a one-off low-value purchase
  • Ownership opacity — complex structures, nominee arrangements, or jurisdictions where beneficial ownership is not ascertainable

Applying identical diligence to every counterparty is not conservative. It consumes capacity on low-risk relationships that would otherwise go to the small number of counterparties that actually warrant scrutiny, and it produces an alert volume no team can meaningfully review.

What Each Tier Involves

TierTypical scopeRefresh
StandardIdentity and registration verification, sanctions and watchlist screening, basic adverse mediaPeriodic, event-driven
EnhancedBeneficial ownership to natural persons, expanded adverse media, PEP assessment, financial standing, questionnaireAnnual or on trigger
ElevatedIndependent investigative research, local-language searches, litigation and regulatory history, site visit where warrantedAnnual with interim monitoring

Beneficial Ownership Is the Hard Part

Screening a company name against a sanctions list is the easy step and the least informative. The substantive question is who ultimately owns and controls the counterparty, because restrictions commonly extend to entities owned or controlled by designated persons even where the entity itself is not listed.

This requires tracing ownership through intermediate holding layers to natural persons, aggregating indirect holdings where ownership is split across several designated parties, and identifying control exercised through means other than shareholding — board appointment rights, voting agreements, or contractual arrangements. The detail is developed further in our note on sanctions screening in international supply chains.

Point-in-Time Diligence Is Not Enough

Onboarding checks establish a position on one date. Ownership changes, designations are added, and adverse media appears afterwards. A programme that screens only at onboarding will, over a relationship of any length, be wrong.

Ongoing monitoring means continuous or periodic rescreening against updated lists, alerting on ownership changes, adverse media monitoring proportionate to tier, and defined triggers for re-diligence — a change of control, entry into a new market, a material contract change, or any credible allegation.

Making the Programme Defensible

A programme that exists but cannot be evidenced provides limited protection. Records should demonstrate:

  • What the methodology was at the relevant time, including subsequent versions
  • Why a given counterparty was assigned to a given tier
  • What was checked, against which sources, on what date, and by whom
  • What was found, and where a concern was identified, how it was resolved and who approved proceeding
  • That monitoring actually operated, rather than merely being specified

The last point is where programmes most often fail on examination. A documented procedure that was not followed is worse than no procedure, because it establishes that the organisation understood the risk and did not act on its own controls.

Common questions

How far into a supply chain do obligations extend?

It depends on the regime. Some obligations attach to direct contractual counterparties; others extend to the wider value chain where risks are known or ought reasonably to be known. Where an organisation has actual knowledge of a risk further down the chain, limiting review to direct suppliers is unlikely to be defensible.

Is a screening tool sufficient?

No. Automated screening handles list matching at scale but cannot resolve ownership structures, assess the credibility of adverse media, or exercise judgement on whether to proceed. It is one component of a programme, not the programme.

What triggers re-diligence outside the normal cycle?

A change of ownership or control, expansion into a higher-risk market, a material change in contract scope or value, an adverse media report, a new designation affecting a related party, or any internal concern raised about the relationship.


The information on this page is for general reference only and does not constitute legal, tax, or accounting advice. Regulatory requirements and implementation timetables change frequently — verify the current position with qualified advisers in the relevant jurisdiction. Contact BNO Partners.