Skip to main content
Category: Third-Party Due Diligence

Integrity Due Diligence

Also known as: IDD, Due Diligence for Integrity
Simply put

Integrity due diligence is the process of gathering independent information to understand the integrity and corruption risks tied to a third party, such as a potential business partner, supplier, or acquisition target, before entering into a relationship with them. It is intended to surface concerns, particularly around corruption, that standard financial or legal checks may not reveal. It is one input into risk management decisions and does not by itself guarantee that misconduct will be prevented.

Formal definition

Integrity due diligence (IDD) is the investigative process of collecting and verifying independent information to assess the integrity and corruption risks associated with a third party or counterparty, typically conducted prior to establishing or continuing a business relationship. It is generally positioned to identify risks not normally revealed by financial, legal, or commercial due diligence processes, and in the corruption context draws on responsible business conduct frameworks such as OECD standards to address risks within supply chains and third-party networks. IDD is a discrete component of a broader third-party risk management and compliance program; it does not substitute for ongoing monitoring, contractual controls, training, or other program elements, and its effectiveness depends on scope, data quality, and implementation. This entry is educational and not a substitute for qualified legal counsel, as applicable obligations and standards vary by jurisdiction.

Why it matters

Third-party relationships expose an organization to risks that originate outside its direct control. Standard financial, legal, and commercial due diligence is designed to evaluate a counterparty's financial health, contractual standing, and business viability, but these processes are generally not structured to surface integrity and corruption risks. Integrity due diligence is intended to fill that gap by gathering independent information about a potential business partner, supplier, or acquisition target before a relationship is established, so that decision-makers can weigh corruption and integrity concerns alongside commercial considerations.

Corruption risk is frequently concentrated in supply chains and extended third-party networks, where the acquiring organization may have limited visibility. Responsible business conduct frameworks, such as the OECD standards referenced in the Due Diligence for Integrity workstream, are oriented toward addressing corruption risks in these networks. IDD applies that orientation at the counterparty level, helping organizations understand who they are doing business with before committing to a relationship.

It is important to be clear about what IDD does and does not do. IDD is one input into a risk management decision; it does not by itself guarantee that misconduct will be prevented, and its usefulness depends heavily on the scope of the inquiry, the quality of available data, and how findings are acted upon. Because applicable obligations and standards vary by jurisdiction and can touch on matters requiring legal judgment, IDD findings are typically most valuable when integrated with ongoing monitoring, contractual controls, and qualified legal input rather than treated as a standalone safeguard.

Who it's relevant to

Compliance officers and ethics program managers
IDD is a core element of third-party risk management, and program owners are responsible for defining when it is triggered, what scope it covers, and how its findings feed into onboarding and continuation decisions. They must ensure IDD is positioned as one input among broader program controls, monitoring, contractual provisions, and training, rather than as a standalone safeguard against misconduct.
Legal and deal teams
In the context of acquisitions and new business relationships, legal and transaction teams rely on IDD to surface integrity and corruption risks that financial, legal, and commercial due diligence typically do not reveal. Because applicable obligations vary by jurisdiction, these teams should treat IDD as educational input and engage qualified legal counsel on how findings bear on specific transactions.
Procurement and supplier management staff
Those onboarding suppliers and business partners use IDD to understand the integrity and corruption risks tied to counterparties before committing. Given that corruption risk often sits within supply chains and third-party networks, procurement staff benefit from integrating IDD outcomes with contractual controls and ongoing monitoring.
Learning and development staff
Training designers can use IDD to help relevant personnel understand what the process does and does not accomplish, clarifying that gathering independent information about a third party informs a risk decision but does not by itself guarantee prevention of misconduct, and that outcomes depend on scope, data quality, and implementation.

Inside IDD

Third-Party and Counterparty Screening
The process of gathering and evaluating information about prospective or existing business partners, agents, distributors, suppliers, joint venture partners, and acquisition targets to identify integrity-related risks. This typically covers ownership and control structures, beneficial ownership, and connections to government officials or politically exposed persons. It is one component of a broader compliance program and does not by itself satisfy program obligations.
Reputational and Adverse Information Review
Examination of publicly available and commercially sourced information for indicators of bribery, corruption, fraud, sanctions exposure, litigation history, regulatory actions, and other conduct that may present risk. This is intended to inform a risk judgment rather than to produce a definitive legal conclusion.
Risk-Based Tiering
The practice of calibrating the depth of due diligence to the assessed risk of the relationship, considering factors such as jurisdiction, industry, contact with government officials, and transaction value. Higher-risk relationships generally warrant more extensive inquiry, while lower-risk relationships may warrant a lighter approach.
Documentation and Recordkeeping
The creation and retention of records showing what inquiries were made, what was found, how risks were assessed, and what decisions resulted. This supports the ability to demonstrate that a good-faith, reasonable process was followed, which is generally regarded as relevant to how enforcement authorities evaluate compliance efforts.
Ongoing Monitoring and Refresh
Periodic re-review of relationships and re-screening against updated information, rather than treating due diligence as a one-time event at onboarding. The appropriate cadence depends on risk level and changes in circumstances.
Escalation and Decision Governance
Defined pathways for reviewing red flags, resolving concerns, and approving, conditioning, or declining a relationship. This connects the diligence findings to accountable decision-making and, where appropriate, to legal counsel.

Common questions

Answers to the questions practitioners most commonly ask about IDD.

Is integrity due diligence the same as a general background check?
No. A general background check typically verifies identity, employment history, or credit standing, whereas integrity due diligence is a risk-based review focused on a party's ethics and compliance profile, such as bribery and corruption exposure, sanctions and adverse-media findings, conflicts of interest, and beneficial ownership. The two overlap but are not interchangeable, and the scope of integrity due diligence is generally driven by the specific compliance risks a relationship presents.
Does completing integrity due diligence guarantee that a third party will behave lawfully or shield the company from liability?
No. Integrity due diligence is intended to identify and help manage risk before and during a relationship, but it cannot guarantee future conduct or provide automatic legal protection. Enforcement authorities generally evaluate whether due diligence was reasonable, risk-based, and acted upon, not merely whether it was performed. Outcomes depend on implementation, ongoing monitoring, and how findings are used, and any assessment of legal exposure requires qualified legal counsel.
How do you decide how much due diligence a given third party requires?
A risk-based approach is generally used: the depth of review is calibrated to factors such as the nature of the engagement, the counterparty's role and interactions with government officials, the jurisdictions involved, transaction value, and the type of industry. Lower-risk relationships may warrant streamlined screening, while higher-risk ones may call for enhanced review including deeper ownership analysis and documented interviews. The specific tiering criteria should be defined in policy and confirmed with compliance and legal teams.
When should integrity due diligence be conducted in the lifecycle of a third-party relationship?
It is generally performed before onboarding or contracting, so findings can inform the decision to proceed, and then refreshed periodically or upon trigger events such as changes in ownership, scope, jurisdiction, or adverse media. Treating it as a one-time onboarding step rather than an ongoing process is a common gap; the appropriate refresh cadence depends on the counterparty's risk level and should be set in program policy.
How does integrity due diligence connect to the rest of a compliance program?
It is one component of a broader system rather than a standalone control. It typically feeds into contract terms and audit rights, risk assessment, ongoing monitoring, training for relevant personnel, and escalation or remediation processes when red flags arise. Its value depends on whether findings are documented, reviewed by appropriate decision-makers, and linked to concrete actions rather than filed and forgotten.
What should happen when due diligence surfaces a red flag?
A red flag generally does not automatically disqualify a party; it signals the need for further review and a documented decision. Common steps include seeking clarification, escalating to compliance or legal, imposing enhanced controls or contractual safeguards, or declining the relationship where risk cannot be adequately mitigated. Because some findings touch matters that vary by local law, the appropriate response should be determined with qualified legal counsel, and both the analysis and the resolution should be recorded.

Common misconceptions

Integrity due diligence is a one-time check completed at onboarding.
It is generally understood as a risk-based, ongoing process. Circumstances, ownership, and adverse information can change over time, so many programs incorporate periodic monitoring and re-screening rather than relying on a single point-in-time review.
Completing integrity due diligence protects an organization from liability.
No due diligence process guarantees legal protection or prevents misconduct. A reasonable, documented, risk-based process may support an organization's position on how it managed risk, but outcomes depend on implementation, context, and applicable law, which vary by jurisdiction and require qualified legal counsel.
Integrity due diligence and a full compliance program are the same thing.
Integrity due diligence is one component within a larger compliance and ethics system that also includes elements such as a code of conduct, training, risk assessment, reporting channels, and monitoring and auditing. It addresses counterparty and third-party risk specifically and does not substitute for the other program elements.

Best practices

Adopt a risk-based tiering model so the depth of diligence corresponds to the assessed risk of each relationship rather than applying a uniform level of scrutiny to all counterparties.
Document the inquiries made, the information found, the risk assessment reached, and the resulting decision so the process can be demonstrated later.
Establish clear escalation pathways for red flags, and involve qualified legal counsel where findings touch matters that vary by local law or carry potential legal exposure.
Treat due diligence as ongoing by scheduling periodic re-screening and monitoring, with cadence calibrated to risk and to changes in circumstances.
Identify beneficial ownership and control structures and screen for connections to government officials, as these commonly bear on bribery and corruption risk.
Integrate diligence findings with the broader compliance program rather than treating them in isolation, and confirm any specific regulatory requirements against primary sources for the relevant jurisdiction.