Обновлено

SRV-32 / THIRD-PARTY DUE DILIGENCE

A counterparty enters the risk chain before it enters the contract

BLACKFILE verifies suppliers, agents, intermediaries and other third parties with a depth corresponding to their role, authority, geography and potential influence on the client's company.

The result can be used as a one-off check or as part of a repeatable process. It does not replace internal compliance policy and legal assessment of the relationship.

View tier system

For an initial assessment, the type of third party, its role and the countries involved are sufficient. No documents are transferred at this step.

  • SUPPLIERS
  • AGENTS
  • INTERMEDIARIES
  • TIERING
  • ESCALATION
  1. TIER 1Basic verificationHigh-volume flow of low-risk suppliers
  2. TIER 2Extended checkSignificant suppliers, distributors, payment intermediaries
  3. TIER 3Enhanced verification and escalationAgents with authority, intermediaries in sensitive jurisdictions
Select a third-party type to see how role and authority determine the level of verification
02 / WHY A UNIFORM CHECK DOES NOT WORK

A stationery supplier, an agent with government contacts, and a payment intermediary raise different questions

A single checklist either overloads a high-volume flow or misses material circumstances in a high-risk intermediary. For this reason, the role of the third party is determined first, and only then the set of sources, the depth of verification, and the conditions for re-checking.

Legal and compliance obligations depend on the country, industry, relationship, and authority of the third party. BLACKFILE does not claim that a company is automatically liable for every action of every counterparty: we show which circumstances have been verified and which remain open.

The depth of a check should match the role of the third party, not a uniform template applied to everyone.

03 / WHO AND WHEN

When third-party due diligence becomes a mandatory part of a decision

The analyst works with a map of suppliers and agents
  1. 01

    Compliance and legal teams

    Justification of the verification level and a documented basis for each conclusion are required.

  2. 02

    Procurement services

    A high-volume flow of suppliers needs to be sorted into levels without overloading the process.

  3. 03

    International companies with a network of agents

    Agents in different countries hold different authority and different levels of risk.

  4. 04

    Exporters and distributors

    The distribution chain touches sanctions regimes and requires verification of end recipients.

  5. 05

    Investors checking the target's chain

    The risk of the investment target's counterparties transfers to the transaction.

  6. 06

    Before entering a new country

    A local intermediary may hold authority that an ordinary supplier does not.

  7. 07

    After a change in the counterparty's owner

    A change of ownership is grounds for revisiting the level and scope of verification.

  8. 08

    On a signal of conflict of interest

    An intersection between a counterparty and the client's employees is checked separately.

04 / THIRD-PARTY RISK TIERING SYSTEM

Роль и полномочия третьего лица определяют уровень проверки, а не размер компании

Select a third-party type to see how role and authority determine the level of verification
R-01

Office supplies vendor

Tier 1 - basic
  1. 01
    Type and roleMass-market supplier of standard goods with no access to the client's decisions.
  2. 02
    AuthorityCannot act on the client's behalf, has no access to funds or data.
  3. 03
    GeographyOne country, the same jurisdiction as the client.
  4. 04
    Financial volumeSmall recurring volume, standard payment terms.
  5. 05
    Public connectionsNo public connections with government organizations found.
  6. 06
    Risk levelTier 1 - basic
  7. 07
    Depth of verificationRegistration, status, directors, sanctions screening, indicators of genuine activity.
  8. 08
    Re-verification triggerScheduled review at an agreed interval or upon change of owner.

This is not a universal model for all companies and industries. Criteria are agreed with the client and its legal or compliance team. No single numerical risk score is produced: the tier is assigned based on the totality of factors and is always accompanied by a rationale.

Three levels of verification

TIER 1

Basic verification

High-volume flow of low-risk suppliers

Какие данные нужны
  • name and jurisdiction
  • registration number, if known
  • subject matter of the relationship
Depth of verification
Confirmation of existence and status, directors, sanctions screening, basic indicators of actual business activity.
Sources
  • Corporate registries
  • Sanctions lists
  • Public footprint of activity
Что требует подтверждения
Current registration status and absence of sanctions matches for the company and its directors.
Что переводит на следующий уровень
Emergence of authority to act on behalf of the client, access to a government client, change of owner, or increase in volume.
Repeat verification
Scheduled review at an agreed interval.
TIER 2

Extended check

Significant suppliers, distributors, payment intermediaries

Какие данные нужны
  • structure and volume of the relationship
  • known owners
  • countries of operation
Depth of verification
Ownership structure, beneficial owners to the extent available, related companies, litigation and regulatory episodes, PEP and sanctions exposure.
Sources
  • Registries of several countries
  • Litigation and debt registers
  • Sanctions and PEP sources
  • Verified publications
Что требует подтверждения
Chain of ownership to the extent available, reality of operations, and absence of unresolved contradictions.
Что переводит на следующий уровень
Discovery of a public role held by a participant, a sanctions overlap, a conflict of interest, or indicators of a shell company.
Repeat verification
Review at the set interval and upon a change of jurisdiction, owner, or volume.
TIER 3

Enhanced verification and escalation

Agents with authority, intermediaries in sensitive jurisdictions

Какие данные нужны
  • role and scope of authority
  • remuneration terms
  • counterparties and ultimate recipients
Depth of verification
Full chain of ownership and control, public roles and the period held, conflicts of interest with the client's employees, remuneration terms, secondary verification of material findings.
Sources
  • Registers and disclosures for each country
  • Government contracts to the extent available
  • Litigation and regulatory materials
  • Primary sources of publications
Что требует подтверждения
Every material finding - with a source and a date; contradictions are either resolved or expressly recorded as open.
Что переводит на следующий уровень
Further escalation is a decision for the client to make: termination, additional contractual terms, or refusal of the relationship.
Repeat verification
Immediate reassessment upon the triggering event, not on a calendar basis.

The level is not a legal conclusion and does not characterize the good faith of the counterparty. It defines the scope of work and the terms of subsequent monitoring.

What determines the level

  • 01type and role of the third party
  • 02ability to act on behalf of the client
  • 03access to funds or data
  • 04interaction with government bodies
  • 05country and industry
  • 06amount and structure of remuneration
  • 07owners and controlling persons
  • 08PEP and sanctions exposure
  • 09presence of genuine business activity
  • 10litigation and regulatory matters
  • 11possible conflict of interest with client employees

Factors are assessed together, not summed into a score. A single factor - for example, the ability to act on behalf of the client - can raise the level regardless of the others.

05 / WHAT IS ESTABLISHED

Fourteen areas of third-party verification

The composition is determined by the level: Tier 1 applies the basic set, Tier 3 - the full set. Areas not covered in a given country are recorded as limitations.

01

Company and people

  • registration and current status
  • owners and managers
  • beneficial owners in the available part
  • related companies
  • recurring addresses
02

Exposure and history

  • sanctions and PEP matches
  • litigation and debt episodes
  • regulatory history
  • government contracts
  • public roles
03

Reality and contradictions

  • actual operating activity
  • conflicts of interest
  • contradictions between the questionnaire and external sources
  • events requiring re-verification
Updating the analytical file on the desk
THIRD-PARTY DUE DILIGENCE

A verified counterparty is not a status held forever, but a state as of a date, with a known condition for review

06 / RELATED WORKFLOW

Twelve steps from defining third-party types to recording the review date

  1. 01Defining third-party types.
  2. 02Defining risk criteria.
  3. 03Assigning a tier.
  4. 04Verifying corporate data.
  5. 05Verifying owners and roles.
  6. 06Verifying material connections.
  7. 07Sanctions and PEP screening.
  8. 08Verifying actual activity.
  9. 09Resolution of contradictions.
  10. 10Secondary verification of material conclusions.
  11. 11Building a risk profile.
  12. 12Recording the event or the date of re-verification.

The process is connected: risk criteria are set once and applied to the entire flow, and the result for each object contains the basis for its level and the condition for its review.

ONBOARD / MONITOR / ESCALATE

A check remains valid for as long as the counterparty and the nature of the relationship remain unchanged

  1. 01 / ONBOARD

    Initial assessment

    Verification before the relationship begins: the level is assigned according to role and authority, and the scope of work is agreed in advance.

  2. 02 / MONITOR

    Repeat verification

    Review on an agreed schedule or upon an event. Frequency and triggers are fixed in the outcome of the first check.

  3. 03 / ESCALATE

    Escalation

    A change of owner, jurisdiction, role, sanctions status, or a material incident moves the subject to a higher level.

A check becomes outdated if the counterparty itself or the nature of the relationship changes. For this reason, the date of the source and the trigger for reassessment are part of the outcome. Continuous observation is not implied: monitoring is conducted only if separately agreed as a service.

07 / WHAT THE CLIENT RECEIVES

Risk profile of the counterparty and the rule by which it is reviewed

Каждый вывод сопровождается источником и датой. Подтвержденное отделено от неподтвержденного, условия эскалации названы прямо.

R-01 / RESULT

Third-party profile and risk tier

Counterparty profile, assigned tier, and the basis for its selection - without a universal risk score.

R-02 / RESULT

Ownership and control summary

Owners, managers, and beneficial owners in the available part, with the limits of the check indicated.

R-03 / RESULT

Sanctions and PEP screening record

Screening result with identification of matches and context, not a list of similar names.

R-04 / RESULT

Conflict of interest map and source log

Overlaps with the client's employees and related persons, a log of sources and dates for each conclusion.

R-05 / RESULT

Confirmed and unconfirmed

Separate lists of information and a list of documents to be requested from the counterparty.

R-06 / RESULT

Escalation conditions and decision memo

Event or date for re-verification and a short decision for the client's internal team.

What an anonymized Third-Party File looks like

THIRD-PARTY FILESAMPLE
  1. 01Third-party profile
  2. 02Risk tier and the basis for its selection
  3. 03Ownership and control summary
  4. 04Sanctions and PEP screening record
  5. 05Genuine business activity and operational indicators
  6. 06Confirmed and unconfirmed information
  7. 07Conflict of interest map
  8. 08Litigation, debt, and regulatory episodes
  9. 09Source log
  10. 10List of documents to request
  11. 11Escalation conditions
  12. 12Date or event for re-verification
  13. 13Decision memo for the internal team

A demonstration file structure. It does not describe any specific counterparty or check.

The result is not a legal assessment of compliance and does not replace the company's internal compliance policy.

08 / WHERE THIS APPLIES

For those responsible for the flow of external parties

CL-01 / CLIENT

Compliance functions

Justify the level of verification and retain a documented basis for the internal file.

CL-02 / CLIENT

Legal teams

Obtain a list of questions and contractual conditions before signing an agreement with an intermediary.

CL-03 / CLIENT

Procurement services

Separate the mass flow into tiers and avoid spending in-depth verification on low-risk suppliers.

CL-04 / CLIENT

International companies with a network of agents

Uniform tier criteria for all countries of operation and clear escalation rules.

CL-05 / CLIENT

Exporters and distributors

Verification of the distribution chain and end recipients in sanctions-sensitive directions.

CL-06 / CLIENT

Investors

Verification of the target company's counterparties as part of deal preparation.

09 / COMPOSITE EXAMPLE

How role changes the level of verification

Business meeting: discussing terms of work with an intermediary
TPD-01Third-Party Due DiligenceComposite example

The intermediary looked like an ordinary supplier, but his authority required a different level of verification

Задача. The company planned to engage a local intermediary in a new country. Formally, he provided standard consulting services, but the terms of the contract allowed him to interact with government bodies on the client's behalf.

Результат. BLACKFILE did not draw a conclusion of violation. The role was moved to an elevated tier, the check was expanded to owners, public connections, actual activity, and remuneration terms. The client received a list of questions and control conditions before signing the contract.

New country, one intermediary

The example is composite and does not describe a specific client. Illustrative image: the client's identity is not disclosed.

10 / PROCESS

From third-party types to the review rule

  1. 01

    Types and criteria

    Which third parties are within scope and what determines the tier

  2. 02

    Tier assignment

    Tier based on role, authority, geography and volume

  3. 03

    Check

    Corporate data, owners, connections, screening, actual activity

  4. 04

    Contradictions

    Resolution of discrepancies and secondary review of material conclusions

  5. 05

    Risk profile

    Profile, basis for the tier and list of open questions

  6. 06

    Review

    Event or date for re-verification and escalation conditions

11 / FORMATS

Three engagement formats for third parties

The format depends on the number of subjects, the complexity of roles and the number of jurisdictions

01

Single Third Party Check

Individual quote

Timeframe agreed before work begins

After assessing the number of subjects and risk tiers

One-off check of a single third party with a brief profile and basis for the tier

Included
  • one counterparty
  • one agreed tier
  • brief third-party profile
  • sanctions and PEP screening
  • list of open questions

Brief counterparty profile with tier and review condition

02Main engagement format

Enhanced Third-Party Review

Individual quote

Timeframe agreed before work begins

After assessing the number of subjects and risk tiers

In-depth check of an intermediary or agent with a full file

Included
  • complex role and authority
  • several jurisdictions
  • owners and connections
  • PEP and sanctions screening with identification of matches
  • conflicts of interest
  • full due diligence file

Full third-party file with a conflict map and escalation conditions

03

Third-Party Program Support

Individual quote

Timeframe determined after scope assessment

After assessing the number of subjects and risk tiers

Repeatable procedure for a flow of third parties with tiering and escalation rules

Included
  • group of suppliers or agents
  • risk tiering against client criteria
  • repeatable procedure
  • escalation rules
  • re-check rules

A functioning check workflow with clear revision rules.

12 / LIMITATIONS

What third-party due diligence provides and what remains outside its scope

The scope of data available depends on the country: in some cases participants and beneficial owners are disclosed, in others only the fact of registration. An unavailable area is recorded as a limitation, not replaced by an assumption.

BLACKFILE does not replace a company's internal compliance policy and does not provide a legal qualification of the relationship with a third party - this is a task for the client's own advisor.

  • risk tier is not a legal conclusion
  • a connection to a public figure does not prove a violation
  • a sanctions match requires identification
  • the absence of adverse records does not guarantee good faith
  • the final decision is made by the client
14 / FAQ

Questions about third-party due diligence

Company Due Diligence is an in-depth check of a single company as the object. Third-Party Due Diligence works with a flow of external parties: first the role and risk level of each is determined, then the depth of the check is set to match that level. For one mass-market supplier a basic set is sufficient, for an agent with authority - in-depth work is required.

Based on a set of factors: the role and authority of the third party, access to funds and data, interaction with government bodies, country and industry, remuneration structure, owners and public connections. We do not produce a single numeric score - the level is always accompanied by a basis that can be challenged or revised.

Yes, this is the Third-Party Program Support format: the criteria for each level are set once, the flow is sorted by level, and escalation and revision rules are fixed for each object. In-depth work is applied only to those whose role places them higher.

Only if separately agreed as a service. By default the result reflects the state as of the date of the check, and the file records the date of the source and the trigger for re-assessment - a change of owner, jurisdiction, role, or a material public episode.

A name match is not identification of a person. We verify identity by date of birth, jurisdiction and role, assess the degree of proximity to the listed person and describe the context. The legal qualification under a specific regime is provided by the client's own lawyer.

The counterparty's owners, managers and representatives are compared against the client's employees and related persons within the limits of lawfully accessible information. An overlap is recorded as a circumstance for internal review, not as an accusation.

No. The absence of adverse records does not guarantee good faith, and risk tier is not a legal conclusion. The check reduces uncertainty and provides grounds for contract terms and subsequent monitoring; the final decision is made by the client.

The type of third party, its role and presumed authority, the countries involved and the number of objects. Internal documents and counterparty questionnaires are not required at this stage.

Determine the level of verification before the counterparty enters your risk chain

15 / INITIAL ASSESSMENT

Describe the third party and its role without submitting documents

At the first step, do not attach questionnaires, contracts or internal documents. The type of third party, the purpose and its role are sufficient.

Contact

Information from the form is used only to respond to the enquiry and is not passed to third parties.