Due diligence
Also known as: Third-party due diligence · Vendor due diligence · Third-party risk management
An investigation carried out before a significant decision — onboarding a vendor, signing a partner, acquiring a company — to uncover risks the other party would not disclose.
Legal basis
U.S. DOJ Criminal Division — Evaluation of Corporate Compliance Programs (Sept. 2024)
Due diligence starts from a simple premise: the other party has every incentive to show its best side. So the company investigates on its own — legal and financial standing, ownership, litigation, sanctions, ties to government officials — before committing.
In the US its weight comes largely from enforcement. Under the Foreign Corrupt Practices Act, a company can answer for bribes paid by agents and intermediaries acting on its behalf, and DOJ's Evaluation of Corporate Compliance Programs asks whether third-party management is risk-based, whether there is a business rationale for each third party, and whether the relationship is monitored after onboarding — not just checked once.
That last point is where traditional due diligence fails: it becomes a snapshot, done at contracting and filed away. Owners change, officers become defendants, vendors pick up sanctions. What protects you is rerunning the check when the signal changes.
Frequently asked questions
What is third-party due diligence?
It is the investigation a company runs on vendors, agents, distributors and partners before and during the relationship, covering ownership, reputation, litigation, sanctions and ties to government officials, scaled to the risk each third party presents.