Blue Umbrella Resources

Managing Reputational Risk in Third-Party Due Diligence

Written by Eric Ngu | Jul 23, 2026 12:00:01 PM

 

Eric Ngu is a Team Leader, Due Diligence at Blue Umbrella. We encourage our team

members to share their insights and expertise by contributing to our content library.

Third-party due diligence has become an integral part of how organizations identify and manage risks associated with customers, suppliers, business partners, and other counterparties. While sanctions screening, politically exposed person (PEP) checks, and adverse media reviews are fundamental components of the due diligence process, they form only part of a broader risk assessment.

One common challenge in due diligence is the assumption that screening results alone are sufficient to determine a third partys overall risk profile. A report showing no sanctions matches, no PEP exposure, and limited adverse media may appear to indicate low risk. However, from a due diligence perspective, these results often represent the beginning of the assessment rather than its conclusion.

Effective due diligence is not simply about identifying information; it is about providing sufficient context for organizations to make informed, risk-based decisions.

Screening Results Are Only the Starting Point

Sanctions lists, regulatory enforcement databases, and PEP screening tools are designed to identify known and measurable risks. They provide valuable information that supports regulatory compliance and helps organizations identify individuals or entities requiring enhanced scrutiny.

However, many reputational concerns do not appear on any watchlist.

For example, a privately owned company may have no regulatory findings or sanctions exposure but could have been the subject of widely reported allegations involving procurement irregularities, governance failures, or unethical business practices. Similarly, a supplier may not appear on any enforcement list but may have been linked to recurring labor rights concerns reported by reputable media outlets or international organizations.

These circumstances do not necessarily indicate that a business relationship should be avoided. Rather, they highlight the importance of understanding the broader context surrounding the third party before making a risk decision.

Organizations increasingly recognize that due diligence should support commercial decision-making, not simply confirm whether a screening result exists.

Information Alone Does Not Support Risk Decisions

One of the recurring observations during quality assurance reviews of due diligence reports is that adverse information is sometimes presented without sufficient context for decision-makers to understand its significance.

For example, a report may identify that a company has been linked to corruption allegations or regulatory investigations. While factually accurate, such statements alone often leave important questions unanswered.

Decision-makers are more likely to ask:

    • What exactly happened?
    • Was the subject directly involved or only associated with the matter?
    • Was the allegation investigated or independently substantiated?
    • What is the outcome of the investigation?
    • What are the legal or regulatory implications, as well as financial or reputational consequences?

Providing answers to these questions transforms information into meaningful analysis.

Similarly, adverse media findings should not be assessed solely on their existence. The credibility of the reporting source, the consistency of reporting across multiple sources, the outcome of any investigation, and the recency of the information should all be considered when evaluating its relevance.

The objective is not to eliminate every uncertainty, but to provide sufficient context for organizations to understand the nature of the identified risks.

A Risk-Based Approach to Reputational Risk

Reputational risk is often subjective and can vary depending on an organizations industry, geographic footprint, regulatory obligations, and risk appetite. Consequently, effective due diligence should focus on presenting objective information while enabling clients to make informed decisions based on their own governance framework.

Several practical considerations can strengthen this assessment.

First, evaluate the reliability of the available information. Reports published by regulatory authorities, courts, and established news organizations generally carry greater evidentiary value than unverified online sources, user-based websites, or opinion-based commentary.

Second, distinguish between allegations and established findings. Not every allegation results in regulatory action or legal proceedings, and due diligence reports should clearly differentiate between ongoing investigations, resolved matters, and unsubstantiated claims.

Third, assess the subjects role within the reported event. The significance of an adverse finding may differ substantially depending on whether the individual or entity was the primary subject of an investigation, a minority shareholder, a former executive, or merely referenced in related reporting.

Finally, consider whether the identified concerns represent isolated events or recurring patterns. Repeated allegations involving similar misconduct across multiple years or jurisdictions may warrant greater attention than a single historical incident that has since been resolved.

These considerations allow organizations to move beyond binary screening results and adopt a more comprehensive, risk-based approach to third-party due diligence.

Regulatory Developments Continue to Shape Expectations

Recent regulatory developments also demonstrate that the concept of reputational risk continues to evolve.

In April 2026, the U.S. Office of the Comptroller of the Currency (OCC) announced that it would remove references to reputation risk from its supervisory guidance and examination procedures. The OCC explained that supervisory activities should remain focused on measurable financial and operational risks rather than subjective assessments of reputational concerns.

While this development applies specifically to U.S. national banks and federal savings associations, it reinforces an important principle for due diligence practitioners. The purpose of due diligence is not to make commercial decisions on behalf of an organization. Rather, it is to provide objective, well-supported information that enables organizations to evaluate potential risks in accordance with their business objectives, governance framework, and risk appetite.

As regulatory expectations continue to evolve across jurisdictions, organizations are increasingly expected to demonstrate that their due diligence processes support informed and well-documented decision-making.

Conclusion

Managing reputational risk in third-party due diligence requires more than identifying sanctions matches or compiling adverse media findings. It requires understanding the context surrounding those findings, evaluating their relevance, and presenting information in a manner that supports sound business judgment.

High-quality due diligence should not be measured solely by the volume of information collected. Its value lies in helping organizations distinguish between information that is merely available and information that is meaningful for risk assessment.

As organizations continue to navigate an increasingly complex regulatory and business environment, the ability to provide contextual, objective, and risk-based analysis will remain one of the defining characteristics of an effective third-party due diligence program.