Skip to main content
Category: Third-Party Due Diligence

Tiered Due Diligence

Also known as: Levels of Due Diligence, Risk-Based Due Diligence Tiers
Simply put

Tiered due diligence is an approach to checking who a company does business with by sorting third parties into different levels of scrutiny based on how risky they are. Lower-risk relationships receive a lighter review, while higher-risk ones get deeper investigation. The goal is to focus effort and resources where the potential for problems is greatest, rather than applying the same checks to everyone.

Formal definition

Tiered due diligence is a risk-based methodology for investigating and verifying third parties, such as suppliers, donors, or business partners, by assigning them to defined risk tiers (commonly low, medium, and high) that determine the depth and rigor of the review conducted. Lower tiers may involve a matching or screening exercise supported by automation and human analysis to identify sanctions, adverse media, or watchlist matches, while higher tiers escalate to enhanced verification, documentary review, and investigative research. It is one component of a broader third-party risk management or compliance program and does not by itself constitute a complete program; its allocation of scrutiny across risk levels is intended to support proportionate resource deployment, though effectiveness depends on how risk criteria are calibrated and how consistently the tiers are applied. Some regulatory regimes require risk-based due diligence across an entire supply chain, but specific obligations are jurisdiction-dependent and should be confirmed against primary sources and qualified legal counsel. This entry is educational and not a substitute for professional advice.

Why it matters

Applying uniform due diligence to every third party is inefficient and, in practice, unsustainable. Organizations routinely engage large numbers of suppliers, partners, donors, and intermediaries, and the risk each presents varies widely. Tiered due diligence matters because it allows compliance and risk teams to concentrate investigative effort and budget where the potential for legal, financial, or reputational harm is greatest, rather than diluting resources by treating a low-risk vendor the same as a high-risk foreign intermediary.

The approach also supports the risk-based expectations embedded in many third-party risk management frameworks. Some regulatory regimes require organizations to conduct risk-based due diligence across an entire supply chain, meaning scrutiny should extend beyond the first tier of direct relationships. However, the specific obligations that apply are jurisdiction-dependent and should be confirmed against primary sources and qualified legal counsel. Tiered due diligence is a methodology that can help operationalize a risk-based posture, but it does not by itself satisfy any particular legal requirement.

It is important to be realistic about limitations. Tiering is only as sound as the criteria used to assign risk levels and the consistency with which those tiers are applied. Miscalibrated criteria, placing genuinely high-risk relationships in a lighter tier, for example, can create blind spots. Tiered due diligence is one component of a broader compliance program and does not guarantee that misconduct will be detected or prevented; its value depends heavily on implementation and ongoing review.

Who it's relevant to

Compliance officers and third-party risk managers
These practitioners design the tiering framework, define the risk criteria that assign counterparties to low, medium, or high tiers, and set the review requirements for each level. They are responsible for ensuring tiers are applied consistently and that the model remains one calibrated part of a broader third-party risk management program rather than a standalone control.
Procurement and supplier management teams
Teams that onboard and manage suppliers rely on tiered due diligence to determine how deeply a given vendor must be vetted. Where obligations extend to conducting risk-based due diligence across an entire supply chain, these teams may need to look beyond first-tier relationships, though the specific scope depends on jurisdiction and should be confirmed with qualified legal counsel.
Nonprofit and grant-making organizations
Organizations that accept donations or fund partner entities can apply the same tiered logic to donors and grantees, sorting them into low, medium, and high risk categories to provide a proportionate level of assurance that a counterparty is legitimate before proceeding.
Legal and audit teams
These functions assess whether the tiering methodology is defensible and whether it is applied consistently in practice. They evaluate how risk criteria are calibrated, test whether higher-risk relationships receive the intended enhanced scrutiny, and advise on where jurisdiction-specific legal requirements bear on the program.

Inside Tiered Due Diligence

Risk-Based Tiering
A structured approach that sorts third parties, counterparties, or transactions into categories (commonly low, medium, and high risk) so that the depth of due diligence applied is proportionate to the assessed risk level rather than uniform across all relationships.
Risk Criteria and Scoring
The defined factors used to assign a tier, which may include geography and jurisdictional corruption exposure, industry sector, nature of the interaction with government officials, transaction value, and the counterparty's ownership structure. The specific weighting and thresholds should be documented and confirmed against the organization's own risk assessment.
Baseline (Lower-Tier) Diligence
The minimum level of screening applied to relationships assessed as lower risk, typically consisting of standard identity verification and sanctions or watchlist screening. This is intended to be lighter-touch and should not be treated as sufficient for higher-risk relationships.
Enhanced (Higher-Tier) Diligence
Deeper investigation reserved for relationships assessed as higher risk, which may include beneficial ownership analysis, adverse media review, source-of-wealth or source-of-funds inquiry, and site visits or third-party investigative reports. The applicable measures vary by jurisdiction and program design.
Documentation and Audit Trail
The recorded rationale for the tier assigned and the diligence performed, supporting the ability to demonstrate a reasoned, risk-based process. This is a monitoring and record-keeping element and is distinct from training staff to apply it.
Ongoing Monitoring and Re-Tiering
Periodic review and event-triggered reassessment that can move a relationship to a different tier when risk factors change, recognizing that a tier assignment is not a permanent classification.

Common questions

Answers to the questions practitioners most commonly ask about Tiered Due Diligence.

Does tiered due diligence mean lower-risk third parties can be skipped entirely?
No. Tiered due diligence calibrates the depth and intensity of review to assessed risk; it does not eliminate review for lower-risk relationships. Lower tiers typically still involve a baseline level of screening or documentation, just proportionately less than higher-risk tiers. Treating any tier as a complete exemption from scrutiny misapplies the concept. The specific baseline for each tier should be defined in your program's risk-based procedures and, where legal obligations apply, confirmed with qualified counsel.
Is completing tiered due diligence a guarantee that a third party will not engage in misconduct?
No. Tiered due diligence is intended to support informed risk decisions and demonstrate a reasonable, risk-based approach; it does not guarantee prevention of misconduct or confer legal protection. Its value depends on implementation, the quality of information gathered, and ongoing monitoring rather than a one-time review. Outcomes vary by context, and no due diligence process by itself assures a particular legal result.
How do organizations decide which tier a given third party falls into?
Tiering is generally driven by a risk assessment that weighs factors such as the nature of the engagement, geographic and sector risk, the counterparty's role, and the degree of interaction with government officials or regulated activities. Organizations typically define criteria and thresholds in advance so that assignment is consistent and documented. The precise factors and weightings depend on the program's risk profile and should be tailored rather than adopted from a generic template.
What distinguishes the review activities performed at higher tiers versus lower tiers?
Higher tiers generally involve more extensive activities, such as deeper background research, verification of ownership and control, adverse media and sanctions screening, questionnaires, and in some cases enhanced review or interviews, while lower tiers may rely on more limited screening and documentation. The distinction is one of depth, breadth, and frequency of review proportionate to assessed risk. Exact activities should be specified in your procedures and reflect applicable legal and policy requirements.
How often should tiering assignments and due diligence be refreshed?
Because risk is not static, tiered due diligence is typically paired with periodic refresh cycles and event-driven reviews triggered by changes such as new ownership, expanded scope, or adverse findings. Higher-risk tiers are generally reviewed more frequently than lower-risk ones. Refresh intervals should be defined in program procedures; this glossary does not prescribe specific timeframes, which depend on risk and any applicable requirements.
How does tiered due diligence relate to the rest of a compliance program?
Tiered due diligence is one component of third-party risk management and does not by itself constitute a complete compliance program. It works alongside other elements such as risk assessment, contractual controls, training, monitoring and auditing, and escalation channels. Effective use depends on integrating due diligence findings into onboarding decisions and ongoing oversight rather than treating it as a standalone or one-time checkpoint. This entry is educational and not a substitute for professional legal advice.

Common misconceptions

Tiered due diligence is a legal requirement mandated identically across all jurisdictions.
It is a risk-based methodology, and expectations for it arise from various sources that differ by jurisdiction and are not uniform. Frameworks such as the DOJ Evaluation of Corporate Compliance Programs and guidance associated with anti-bribery laws generally regard a proportionate, risk-based approach favorably, but the specific obligations vary by applicable law. Whether and how it is required should be confirmed with qualified legal counsel for the relevant jurisdiction.
Assigning a low-risk tier means no further attention is needed for that relationship.
A lower tier reduces the depth of initial diligence but does not eliminate the need for ongoing monitoring or re-assessment. Risk profiles change over time, and a low-risk classification is a point-in-time judgment, not a permanent exemption from scrutiny.
Completing tiered due diligence guarantees the organization is protected from liability or that misconduct will be prevented.
No due diligence process guarantees prevention of misconduct or legal protection. Tiered due diligence is intended to support a defensible, proportionate risk-management process, but outcomes depend on implementation quality, accurate risk assessment, and consistent execution. It is one component of a broader compliance program, not a standalone safeguard.

Best practices

Anchor tier definitions and scoring criteria to your organization's documented risk assessment, and state the thresholds explicitly so tier assignments are consistent and reproducible.
Match the depth of diligence to the assigned tier, reserving enhanced measures such as beneficial ownership analysis and adverse media review for higher-risk relationships while maintaining a defensible baseline for all.
Document the rationale for each tier assignment and the diligence performed, creating an audit trail that supports demonstrating a reasoned, risk-based process.
Establish both periodic review cycles and event-triggered re-tiering so that changes in risk factors prompt reassessment rather than leaving classifications static.
Confirm jurisdiction-specific requirements with qualified legal counsel, since expectations for due diligence vary by applicable law and this framework is educational rather than a substitute for professional advice.
Treat tiered due diligence as one part of a larger compliance program integrated with monitoring, screening, and other controls, and avoid relying on it as a standalone assurance of prevention or legal protection.