Tiered Due Diligence
Tiered due diligence is an approach to checking who a company does business with by sorting third parties into different levels of scrutiny based on how risky they are. Lower-risk relationships receive a lighter review, while higher-risk ones get deeper investigation. The goal is to focus effort and resources where the potential for problems is greatest, rather than applying the same checks to everyone.
Tiered due diligence is a risk-based methodology for investigating and verifying third parties, such as suppliers, donors, or business partners, by assigning them to defined risk tiers (commonly low, medium, and high) that determine the depth and rigor of the review conducted. Lower tiers may involve a matching or screening exercise supported by automation and human analysis to identify sanctions, adverse media, or watchlist matches, while higher tiers escalate to enhanced verification, documentary review, and investigative research. It is one component of a broader third-party risk management or compliance program and does not by itself constitute a complete program; its allocation of scrutiny across risk levels is intended to support proportionate resource deployment, though effectiveness depends on how risk criteria are calibrated and how consistently the tiers are applied. Some regulatory regimes require risk-based due diligence across an entire supply chain, but specific obligations are jurisdiction-dependent and should be confirmed against primary sources and qualified legal counsel. This entry is educational and not a substitute for professional advice.
Why it matters
Applying uniform due diligence to every third party is inefficient and, in practice, unsustainable. Organizations routinely engage large numbers of suppliers, partners, donors, and intermediaries, and the risk each presents varies widely. Tiered due diligence matters because it allows compliance and risk teams to concentrate investigative effort and budget where the potential for legal, financial, or reputational harm is greatest, rather than diluting resources by treating a low-risk vendor the same as a high-risk foreign intermediary.
The approach also supports the risk-based expectations embedded in many third-party risk management frameworks. Some regulatory regimes require organizations to conduct risk-based due diligence across an entire supply chain, meaning scrutiny should extend beyond the first tier of direct relationships. However, the specific obligations that apply are jurisdiction-dependent and should be confirmed against primary sources and qualified legal counsel. Tiered due diligence is a methodology that can help operationalize a risk-based posture, but it does not by itself satisfy any particular legal requirement.
It is important to be realistic about limitations. Tiering is only as sound as the criteria used to assign risk levels and the consistency with which those tiers are applied. Miscalibrated criteria, placing genuinely high-risk relationships in a lighter tier, for example, can create blind spots. Tiered due diligence is one component of a broader compliance program and does not guarantee that misconduct will be detected or prevented; its value depends heavily on implementation and ongoing review.
Who it's relevant to
Inside Tiered Due Diligence
Common questions
Answers to the questions practitioners most commonly ask about Tiered Due Diligence.