Skip to main content
Category: Third-Party Due Diligence

Third-Party Intermediaries

Also known as: TPI, TPIs, Third-Party Intermediary, Intermediaries
Simply put

A third-party intermediary is an outside organization or individual that acts between a company and another party, such as a customer, supplier, or government body, often to represent the company or arrange transactions on its behalf. Common examples include agents, brokers, sales and marketing representatives, and comparison services. Because these parties act in the company's name or on its behalf, they can create compliance risks that the company may be held responsible for.

Formal definition

Third-party intermediaries (TPIs) are external entities engaged to represent, act on behalf of, or transact between an organization and a counterparty. In a corporate compliance context, TPIs commonly include agents authorized to represent the company, sales and marketing representatives, brokers, distributors, and similar business partners; the specific categories depend on the classification framework an organization applies during third-party due diligence. TPIs are a focus of compliance programs because conduct by an intermediary acting on a company's behalf can expose the company to liability, making TPI identification, classification, and risk-based due diligence a distinct component of a broader third-party risk management process. Note that in some sector-specific and jurisdiction-specific contexts, such as the UK retail energy market, 'Third-Party Intermediary' is a defined regulatory term referring to entities (for example, energy brokers and price comparison websites) that sit between customers and suppliers; whether and how TPIs are formally regulated varies by jurisdiction and sector and requires confirmation against the applicable regulatory regime. This entry is educational and not a substitute for qualified legal advice.

Why it matters

Third-party intermediaries occupy a position of elevated compliance risk precisely because they act in a company's name or on its behalf. When an agent, broker, or sales representative interacts with a customer, supplier, or government body, the conduct of that intermediary can be attributed to the engaging organization, meaning the company may bear responsibility for actions it did not directly carry out. This attribution of liability is why TPI identification, classification, and risk-based due diligence are treated as a distinct focus within third-party risk management rather than a routine procurement matter.

The risk is not uniform across all intermediaries. An entity authorized to represent the company, such as a sales and marketing representative empowered to negotiate on the company's behalf, generally presents different exposure than a party with a more limited or transactional role. For this reason, organizations classify third parties during due diligence and calibrate the depth of scrutiny to the risk each relationship presents. Due diligence on intermediaries is one component of a broader compliance program and does not by itself constitute a complete program.

The term also carries a jurisdiction- and sector-specific meaning that readers should not conflate with the general compliance usage. In the UK retail energy market, 'Third-Party Intermediary' is a defined regulatory term referring to businesses such as energy brokers and price comparison websites that sit between customers and suppliers to help consumers navigate the market and arrange contracts. Whether and how TPIs are formally regulated varies by jurisdiction and sector; the applicability of any particular regulatory regime should be confirmed against primary sources and, where consequences turn on it, with qualified legal counsel.

Who it's relevant to

Compliance officers and third-party risk managers
Those responsible for third-party risk management need to identify and classify intermediaries and apply risk-based due diligence, because conduct by a party acting on the company's behalf can expose the organization to liability. This work is one component of a broader compliance program, not a substitute for it.
Legal and audit teams
Legal and audit functions assess where liability may attach through intermediary conduct and confirm whether sector- or jurisdiction-specific regimes, such as the UK retail energy TPI framework, apply. Because these matters vary by local law, they may require qualified legal counsel; glossary entries are educational and not a substitute for professional advice.
Ethics and training program managers
Those designing training and program materials should help internal stakeholders distinguish among intermediary categories (agents, brokers, distributors, and similar) and understand why intermediary relationships warrant due diligence. Training on this topic supports, but does not by itself guarantee, sound handling of third-party risk.
Business owners engaging intermediaries
Sales, procurement, and commercial teams that engage agents, brokers, or representatives are often the first to identify a new intermediary relationship. Their accurate reporting of an intermediary's role and authority supports the classification and due diligence process on which risk assessment depends.

Inside TPI

Definition and Scope
Third-party intermediaries are external parties, such as agents, distributors, resellers, consultants, brokers, customs agents, and joint venture partners, that act on behalf of or in connection with an organization, often interacting with customers, government officials, or other stakeholders. They are a distinct category of business relationship because their conduct can create legal and reputational exposure for the engaging organization.
Risk Basis
Intermediaries are a focus of anti-corruption regimes because organizations can face liability for improper payments or conduct undertaken by these parties on their behalf. Frameworks such as the FCPA (U.S. jurisdiction) and the UK Bribery Act (UK jurisdiction) address liability arising through third parties; the specific reach and standards differ by jurisdiction and should be confirmed against primary sources and qualified counsel.
Due Diligence
A risk-based screening and background review process applied before engagement and periodically thereafter. Due diligence is intended to identify red flags such as unclear ownership, government affiliations, unusual payment terms, or reputational concerns. It is one control within a broader third-party management process, not a standalone guarantee of integrity.
Contractual Controls
Provisions such as anti-corruption representations, audit rights, termination clauses, and compliance certifications that define expectations and remedies. These are distinct from training and monitoring and depend on enforcement to be meaningful.
Ongoing Monitoring and Auditing
The continued oversight of intermediary conduct after engagement, which may include transaction review, periodic recertification, and exercise of audit rights. This is a monitoring and auditing function distinct from initial onboarding and from training activities.
Training Component
Targeted communication and instruction directed at internal staff who manage intermediaries and, where appropriate, at the intermediaries themselves regarding compliance expectations. Training is only one element of managing third-party risk and does not by itself satisfy an organization's compliance obligations.

Common questions

Answers to the questions practitioners most commonly ask about TPI.

Does conducting due diligence on a third-party intermediary at onboarding satisfy our obligations for that relationship?
No. Onboarding due diligence is one point in the relationship, not the whole of it. Third-party risk is generally regarded as ongoing, and the intermediary's conduct, ownership, and risk profile can change after engagement. Due diligence is typically paired with contractual controls, periodic re-screening, monitoring, and audit or termination rights so that oversight continues throughout the relationship. Treating a single onboarding check as complete leaves the intervening period unmonitored. The scope and frequency of ongoing oversight depend on the risk the intermediary presents and should be calibrated accordingly; specific requirements may vary by jurisdiction and should be confirmed with qualified counsel.
Does engaging a third party to act on our behalf transfer the associated legal and compliance risk to that third party?
Not in the way this question assumes. Using an intermediary does not insulate an organization from responsibility for conduct carried out on its behalf; a third party is a component of the organization's risk exposure rather than a mechanism for shifting it away. Frameworks addressing corporate misconduct commonly consider whether an organization exercised appropriate oversight of the third parties it engaged. Contractual indemnities and representations may allocate certain liabilities between parties, but they do not necessarily eliminate the organization's own exposure. Whether and how liability attaches is a legal question that varies by jurisdiction and requires qualified legal advice.
How should we decide the level of due diligence to apply to a given intermediary?
A risk-based approach is generally applied, meaning the depth of due diligence is scaled to the risk the intermediary presents rather than applied uniformly. Factors commonly weighed include the nature of the services, the geography and sector involved, the degree of government or public-official interaction, ownership and control, and the compensation structure. Higher-risk relationships typically warrant enhanced measures, while lower-risk ones may justify a lighter approach. Documenting the rationale for the level chosen is important so the assessment can be explained later. This is one input into a broader program and not a standalone control.
What contractual provisions are commonly used to support oversight of intermediaries?
Contracts with intermediaries often include representations and warranties regarding lawful conduct, compliance obligations tied to relevant policies, audit and information rights, cooperation requirements, and termination rights triggered by compliance concerns. Such provisions are intended to preserve the organization's ability to monitor and act, and they are frequently paired with training or certification expectations for the third party. These terms support oversight but do not by themselves ensure compliant conduct, and their enforceability and appropriate wording vary by jurisdiction. Contract drafting in this area should involve qualified legal counsel.
How does intermediary oversight connect to the rest of the compliance program?
Third-party oversight is one component of a compliance program and depends on other components to function. Risk assessment identifies which intermediaries and which activities warrant attention; policies and a code of conduct set the expectations extended to third parties; training may be directed at both internal owners and, where appropriate, the intermediaries themselves; and monitoring, auditing, and reporting channels help detect issues. Treating intermediary management in isolation from these elements limits its effectiveness. It is intended to operate within, not in place of, the broader system.
What ongoing activities help keep intermediary oversight current after onboarding?
Ongoing activities commonly include periodic re-screening and refreshed due diligence at a cadence set by the intermediary's risk level, monitoring for changes in ownership, sanctions status, or adverse information, tracking that contractual compliance obligations continue to be met, and exercising audit or information rights where warranted. Maintaining accurate records of these activities supports the ability to demonstrate oversight later. The specific measures and their frequency depend on implementation and context, and legally sensitive steps such as investigations or terminations may require qualified legal input.

Common misconceptions

Using a third party to conduct business insulates the organization from liability for that party's misconduct.
Under anti-corruption frameworks such as the FCPA and UK Bribery Act, organizations may face liability for improper conduct undertaken on their behalf by intermediaries. The precise standards vary by jurisdiction and should be confirmed with qualified legal counsel; delegating an activity does not automatically delegate the associated legal risk.
Completing due diligence at onboarding is sufficient to manage third-party risk.
Due diligence is a point-in-time control and one part of a larger system. Managing intermediary risk is generally regarded as requiring ongoing monitoring, contractual enforcement, and periodic recertification, because risk profiles can change after engagement.
Training intermediaries or their handlers demonstrates that third-party risk has been addressed.
Training is a distinct component and does not substitute for due diligence, contractual controls, or monitoring. No training method guarantees prevention of misconduct; its value depends on implementation and its integration with other controls.

Best practices

Apply a risk-based due diligence process that scales scrutiny to the intermediary's risk profile, including factors such as ownership transparency, government affiliations, and payment arrangements, and revisit it periodically rather than only at onboarding.
Include anti-corruption representations, audit rights, compliance certifications, and termination provisions in contracts, and establish the internal capacity to actually exercise and enforce them.
Maintain ongoing monitoring and auditing of intermediary activity, including transaction review and periodic recertification, treating oversight as continuous rather than a single event.
Provide targeted training to internal staff who manage intermediaries and, where appropriate, to the intermediaries themselves, while treating training as one element among several rather than a complete solution.
Confirm jurisdiction-specific obligations under applicable frameworks such as the FCPA or UK Bribery Act with qualified legal counsel, since standards for third-party liability differ across jurisdictions.
Document due diligence findings, decisions, and monitoring activities so the process is defensible and traceable, recognizing that this glossary guidance is educational and not a substitute for professional legal advice.