Eric Ngu is a Team Leader, Due Diligence at Blue Umbrella. We encourage our team
members to share their insights and expertise by contributing to our content library.
Third-party due diligence has become an integral part of how organizations identify and manage risks associated with customers, suppliers, business partners, and other counterparties. While sanctions screening, politically exposed person (PEP) checks, and adverse media reviews are fundamental components of the due diligence process, they form only part of a broader risk assessment.
One common challenge in due diligence is the assumption that screening results alone are sufficient to determine a third party’s overall risk profile. A report showing no sanctions matches, no PEP exposure, and limited adverse media may appear to indicate low risk. However, from a due diligence perspective, these results often represent the beginning of the assessment rather than its conclusion.
Effective due diligence is not simply about identifying information; it is about providing sufficient context for organizations to make informed, risk-based decisions.
Sanctions lists, regulatory enforcement databases, and PEP screening tools are designed to identify known and measurable risks. They provide valuable information that supports regulatory compliance and helps organizations identify individuals or entities requiring enhanced scrutiny.
However, many reputational concerns do not appear on any watchlist.
For example, a privately owned company may have no regulatory findings or sanctions exposure but could have been the subject of widely reported allegations involving procurement irregularities, governance failures, or unethical business practices. Similarly, a supplier may not appear on any enforcement list but may have been linked to recurring labor rights concerns reported by reputable media outlets or international organizations.
These circumstances do not necessarily indicate that a business relationship should be avoided. Rather, they highlight the importance of understanding the broader context surrounding the third party before making a risk decision.
Organizations increasingly recognize that due diligence should support commercial decision-making, not simply confirm whether a screening result exists.
One of the recurring observations during quality assurance reviews of due diligence reports is that adverse information is sometimes presented without sufficient context for decision-makers to understand its significance.
For example, a report may identify that a company has been linked to corruption allegations or regulatory investigations. While factually accurate, such statements alone often leave important questions unanswered.
Decision-makers are more likely to ask:
Providing answers to these questions transforms information into meaningful analysis.
Similarly, adverse media findings should not be assessed solely on their existence. The credibility of the reporting source, the consistency of reporting across multiple sources, the outcome of any investigation, and the recency of the information should all be considered when evaluating its relevance.
The objective is not to eliminate every uncertainty, but to provide sufficient context for organizations to understand the nature of the identified risks.
Reputational risk is often subjective and can vary depending on an organization’s industry, geographic footprint, regulatory obligations, and risk appetite. Consequently, effective due diligence should focus on presenting objective information while enabling clients to make informed decisions based on their own governance framework.
Several practical considerations can strengthen this assessment.
First, evaluate the reliability of the available information. Reports published by regulatory authorities, courts, and established news organizations generally carry greater evidentiary value than unverified online sources, user-based websites, or opinion-based commentary.
Second, distinguish between allegations and established findings. Not every allegation results in regulatory action or legal proceedings, and due diligence reports should clearly differentiate between ongoing investigations, resolved matters, and unsubstantiated claims.
Third, assess the subject’s role within the reported event. The significance of an adverse finding may differ substantially depending on whether the individual or entity was the primary subject of an investigation, a minority shareholder, a former executive, or merely referenced in related reporting.
Finally, consider whether the identified concerns represent isolated events or recurring patterns. Repeated allegations involving similar misconduct across multiple years or jurisdictions may warrant greater attention than a single historical incident that has since been resolved.
These considerations allow organizations to move beyond binary screening results and adopt a more comprehensive, risk-based approach to third-party due diligence.
Recent regulatory developments also demonstrate that the concept of reputational risk continues to evolve.
In April 2026, the U.S. Office of the Comptroller of the Currency (OCC) announced that it would remove references to reputation risk from its supervisory guidance and examination procedures. The OCC explained that supervisory activities should remain focused on measurable financial and operational risks rather than subjective assessments of reputational concerns.
While this development applies specifically to U.S. national banks and federal savings associations, it reinforces an important principle for due diligence practitioners. The purpose of due diligence is not to make commercial decisions on behalf of an organization. Rather, it is to provide objective, well-supported information that enables organizations to evaluate potential risks in accordance with their business objectives, governance framework, and risk appetite.
As regulatory expectations continue to evolve across jurisdictions, organizations are increasingly expected to demonstrate that their due diligence processes support informed and well-documented decision-making.
Managing reputational risk in third-party due diligence requires more than identifying sanctions matches or compiling adverse media findings. It requires understanding the context surrounding those findings, evaluating their relevance, and presenting information in a manner that supports sound business judgment.
High-quality due diligence should not be measured solely by the volume of information collected. Its value lies in helping organizations distinguish between information that is merely available and information that is meaningful for risk assessment.
As organizations continue to navigate an increasingly complex regulatory and business environment, the ability to provide contextual, objective, and risk-based analysis will remain one of the defining characteristics of an effective third-party due diligence program.