Third Party Intermediary Due Diligence: Risk Management

Introduction

Most organizations spend real time vetting a new customer or supplier. Far fewer apply the same scrutiny to the agent, broker, consultant, or subcontractor acting on their behalf. That gap matters.

An intermediary with authority to negotiate, pay officials, or access sensitive systems can create liability a standard vendor never could.

Third-party intermediary due diligence is the risk-based process of answering four questions: who is this party, what do they actually do, who controls them, and does the relationship create legal, financial, sanctions, corruption, or reputational exposure?

This article walks through a practical approach: define the relationship, assess risk, verify the evidence, apply proportionate controls, and keep monitoring after approval. The aim is practical: catch the problems that surface only after the contract is signed.

Key Takeaways

  • Risk tracks function and authority, not the label on the contract.
  • Questionnaires and sanctions screens are a starting point; corroborate material findings independently.
  • Approval isn't the finish line; monitor, escalate, and reassess for the full relationship life.
  • Document every conclusion with sources, capture dates, and stated research limits.

Essential Definitions for Third-Party Intermediary Due Diligence

What is a third-party intermediary?

A third-party intermediary is an outside person or organization that represents, introduces, negotiates for, sells for, or otherwise acts on an organization's behalf. A party that only ships parts or stocks shelves, with no representative authority, is not one.

Several roles commonly function as intermediaries, depending on what they actually do:

  • Sales agents and brokers
  • Consultants and lobbyists
  • Distributors and resellers
  • Joint-venture partners
  • Customs brokers
  • Subcontractors and certain vendors with delegated authority

How is third-party due diligence different from general vendor onboarding?

Basic vendor onboarding checks identity, pricing, insurance, and operational capability. Intermediary due diligence goes further — it examines authority, beneficial ownership, government touchpoints, compensation structure, conflicts of interest, and conduct history.

A party's title isn't the test. The real question: can this party influence decisions, access officials or customers, handle funds, or make commitments in the organization's name? A "consultant" who introduces your company to a government procurement officer carries far more risk than a consultant who formats reports.

What are the four main types of due diligence?

Industry guidance commonly groups third-party reviews into four lenses that combine according to risk:

Lens What it examines
Commercial/financial Financial standing and the business rationale for the arrangement
Legal/compliance Anti-bribery, sanctions, AML exposure, and regulatory connections
Operational Capacity to actually perform the contracted service
Reputational/integrity Adverse news, track record, and political associations

Intermediary reviews typically draw on all four rather than treating them as separate checklists.

Why Third-Party Intermediaries Create Risk

Regulatory, sanctions, and anti-corruption exposure

Under the Foreign Corrupt Practices Act, a bribe paid indirectly through an intermediary can trigger the same liability as a bribe paid directly. Deliberate ignorance of what an agent is doing can satisfy the knowledge requirement.

The DOJ and SEC's FCPA Resource Guide treats personnel at qualifying state-owned enterprises as potential foreign officials. Customs brokers, licensing consultants, and agents dealing with regulators all deserve a closer look.

Warning signs worth investigating, per that same guidance:

  • Excessive commissions relative to market norms
  • Vague or undocumented consulting work
  • An agent with no apparent relevant business
  • A connection introduced at an official's insistence
  • Requests for payment through offshore accounts

These red flags don't prove wrongdoing — they signal where to dig deeper.

The scale of the exposure isn't theoretical. DOJ's investigation into commodity-trading bribery schemes produced six corporate resolutions, 20 individual convictions, and more than $1.7 billion in combined penalties. Eight corrupt intermediaries were among the 19 individuals tied to those corporate resolutions.

FCPA intermediary bribery investigation penalties and conviction statistics

Sanctions risk follows a similar logic: name-matching alone misses structural exposure. Under OFAC's 50 Percent Rule, an entity is blocked if one or more sanctioned parties own 50% or more of it in aggregate, even indirectly through layered ownership. A clean name screen on the intermediary itself tells you nothing about who sits two ownership tiers up.

Financial, fraud, and operational risk

Not every intermediary problem involves a government official. Watch for:

  • Inflated commissions or unexplained success fees
  • Pass-through payments with no clear service behind them
  • Undisclosed subcontracting
  • Payment instructions that don't match the intermediary's stated role

Weak oversight also creates purely operational exposure, including service disruption, data exposure, licensing lapses, or supply-chain interruption, even when no law is broken. A subcontractor whose insurance lapses mid-project, or whose bond gap goes unnoticed, can leave your organization holding the liability, which is the kind of lapse Muster is built to flag.

Reputational and ownership risk

Adverse media, undisclosed related parties, and opaque ownership structures can erode stakeholder trust long before any regulator gets involved.

A low-profile intermediary can still carry hidden risk: a shared address with a company whose operating authority was revoked, a recently formed entity linked to a predecessor through matching officers and equipment financing, or a director with an undisclosed political connection. None of these facts show up on a standard sanctions screen. They surface only through independent record review.

A Risk-Based Third-Party Intermediary Due Diligence Process

A proportionate four-phase process keeps intermediary due diligence thorough without treating every relationship the same.

Phase 1: Identify and classify the relationship

Build a complete inventory from procurement records, contracts, accounts-payable data, and local operating teams. These sources often reveal intermediaries that never appear on a master vendor list. For each one, record:

  • Legal name, trading names, and locations
  • Services performed and compensation structure
  • Owners, key personnel, and government interactions
  • Subcontracting arrangements

Classify by what the party actually does, not by the label in the purchase order.

Phase 2: Set the risk tier and review scope

Build a documented risk model using factors such as:

  • Government touchpoints and jurisdiction
  • Ownership complexity
  • Payment structure
  • Prior red flags

Define what low-, medium-, and high-risk reviews require, including enhanced due diligence, legal review, site verification, or senior approval. Risk tiering should be proportionate. Not every intermediary needs the same depth of scrutiny.

Phase 3: Collect and verify information

Request incorporation records, ownership details, licenses, references, and bank information. Screen the intermediary and its owners against current sanctions, debarment, and adverse-media sources.

Then corroborate self-reported information independently. Public filings, court records, procurement databases, and professional histories confirm or contradict what the questionnaire says.

Separate verified facts from unresolved discrepancies, and preserve the source and capture date for every material finding.

Phase 4: Decide, document, and remediate

Present findings in a decision-ready summary: the risk, the evidence, your confidence level, and unresolved questions. Possible outcomes include:

  1. Approve
  2. Approve with conditions
  3. Defer pending information
  4. Escalate for enhanced review
  5. Remediate
  6. Decline

Document who approved the decision, what evidence supported it, and when the relationship comes up for review again.

Four-phase risk-based third-party intermediary due diligence process

Turning Due Diligence Findings Into Ongoing Risk Management

Contractual and financial controls

Have counsel tailor agreements to address permitted services, territory, subcontracting limits, compensation, audit rights, and termination triggers. Compensation terms should meet three tests:

  • Commercially reasonable for the market
  • Tied to documented services
  • Paid only through approved channels

If a distributor's discount or an agent's commission looks disconnected from the work performed, resolve it before signing.

Ongoing monitoring and review triggers

Monitoring combines periodic review with event-driven reassessment, not a one-time rescreen at onboarding. Triggers that should prompt a fresh look:

  • Ownership or control changes
  • New countries or government contracts
  • Payment-method changes or sanctions-list alerts
  • Adverse media, complaints, or litigation

When a trigger fires: pause payments where appropriate, investigate, refresh ownership and sanctions checks, and document the conclusion.

Four-step event-driven intermediary risk reassessment workflow

Governance, training, and escalation

Assign responsibility across the business sponsor, procurement, legal, compliance, and finance, and preserve independence for high-risk decisions. Intermediaries operating in higher-risk categories should receive relevant policies, anti-corruption training, and clear consequences for non-compliance. Escalate immediately for falsified documents, unexplained payments, undisclosed ownership, or refusal to provide required information.

Evidence quality and workflow efficiency

A centralized record (intermediary, risk tier, evidence, decision, controls, and next review date) keeps the program defensible under later scrutiny. Reviews move faster when evidence standards stay explicit:

  • Every claim carries its source and capture date
  • Computed findings stay separate from unsupported assertions
  • Research boundaries are stated plainly, not implied

Salvara supports that workflow. It organizes public records, license and bond filings, and open-web research into source-dated findings, and keeps any internal data you add private.

In one illustrative counterparty review, a freight broker's file showed a current $75,000 bond, a 19-day surety gap, and a shared address with four logistics entities (one with revoked operating authority). A questionnaire alone will not surface that detail.

A Practical Implementation Framework for US Organizations

Start with the highest-risk relationships first: parties acting on your behalf, touching government or regulated customers, earning significant commissions, or operating through opaque ownership.

Build a minimum review packet containing:

  • Identity, ownership, and role
  • Compensation and screening results
  • Source records and decision rationale
  • Controls and next monitoring date

Test the program periodically. Sample completed files, check whether controls actually operate, and research whether new information would change a prior decision.

Smaller organizations don't need a massive compliance apparatus. A documented risk model, an approved questionnaire, independent verification, contract controls, and a scheduled review cycle cover most of the ground. For the independent-verification step, organizations turning scattered public records and open-web information into source-verified findings can explore an evidence-based workflow through Salvara.

Frequently Asked Questions

What are the five phases of the third-party risk management (TPRM) lifecycle?

Most frameworks cover planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination. Terminology varies by organization and industry; banking guidance, for instance, names these stages slightly differently.

What is third-party due diligence?

Third-party due diligence is the risk-based process of identifying, verifying, assessing, approving, and monitoring an external party before and during the relationship. It is not a one-time check performed only at onboarding.

What is a third-party intermediary?

An external person or organization that represents, introduces, negotiates for, sells for, or otherwise acts on a company's behalf. That role is distinct from a supplier that simply provides goods without representative authority.

What are the four main types of due diligence?

Commercial/financial, legal/compliance, operational, and reputational/integrity due diligence. The exact grouping and names can differ depending on the organization applying them.