Integrity Due Diligence
Integrity due diligence is the process of gathering independent information to understand the integrity and corruption risks tied to a third party, such as a potential business partner, supplier, or acquisition target, before entering into a relationship with them. It is intended to surface concerns, particularly around corruption, that standard financial or legal checks may not reveal. It is one input into risk management decisions and does not by itself guarantee that misconduct will be prevented.
Integrity due diligence (IDD) is the investigative process of collecting and verifying independent information to assess the integrity and corruption risks associated with a third party or counterparty, typically conducted prior to establishing or continuing a business relationship. It is generally positioned to identify risks not normally revealed by financial, legal, or commercial due diligence processes, and in the corruption context draws on responsible business conduct frameworks such as OECD standards to address risks within supply chains and third-party networks. IDD is a discrete component of a broader third-party risk management and compliance program; it does not substitute for ongoing monitoring, contractual controls, training, or other program elements, and its effectiveness depends on scope, data quality, and implementation. This entry is educational and not a substitute for qualified legal counsel, as applicable obligations and standards vary by jurisdiction.
Why it matters
Third-party relationships expose an organization to risks that originate outside its direct control. Standard financial, legal, and commercial due diligence is designed to evaluate a counterparty's financial health, contractual standing, and business viability, but these processes are generally not structured to surface integrity and corruption risks. Integrity due diligence is intended to fill that gap by gathering independent information about a potential business partner, supplier, or acquisition target before a relationship is established, so that decision-makers can weigh corruption and integrity concerns alongside commercial considerations.
Corruption risk is frequently concentrated in supply chains and extended third-party networks, where the acquiring organization may have limited visibility. Responsible business conduct frameworks, such as the OECD standards referenced in the Due Diligence for Integrity workstream, are oriented toward addressing corruption risks in these networks. IDD applies that orientation at the counterparty level, helping organizations understand who they are doing business with before committing to a relationship.
It is important to be clear about what IDD does and does not do. IDD is one input into a risk management decision; it does not by itself guarantee that misconduct will be prevented, and its usefulness depends heavily on the scope of the inquiry, the quality of available data, and how findings are acted upon. Because applicable obligations and standards vary by jurisdiction and can touch on matters requiring legal judgment, IDD findings are typically most valuable when integrated with ongoing monitoring, contractual controls, and qualified legal input rather than treated as a standalone safeguard.
Who it's relevant to
Inside IDD
Common questions
Answers to the questions practitioners most commonly ask about IDD.