What is Enhanced Due Diligence (EDD)?
What is enhanced due diligence In third-party risk management?
Enhanced due diligence in TPRM is a deeper level of investigation applied to third parties assessed as presenting elevated risk. It goes beyond verifying that a vendor exists and passes a basic screening check. It examines who is behind the entity, what their connections are, where the money flows, and whether the relationship creates exposure your organisation cannot adequately mitigate.
Standard due diligence establishes the basics: legal identity, ownership at the surface level, sanctions and adverse media screening, and a risk tier. EDD applies when that baseline reveals factors that require deeper scrutiny before you can make a defensible decision to proceed.
The scale of what is at stake is not theoretical. Approximately 90% of US Foreign Corrupt Practices Act (FCPA) enforcement cases since 1978 have involved third-party intermediaries, and over 80% of FCPA cases in the past five years alone are still linked to third-party conduct.
Source: Ankura, citing Stanford Law School FCPA ClearinghouseThe liability does not require you to have known about the misconduct. It requires only that you failed to exercise adequate oversight.
How does EDD differ from standard due diligence?
Standard due diligence screens. EDD investigates.
Standard checks confirm identity, run sanctions and PEP lists, review adverse media at a surface level, and assign a risk tier. For the majority of third parties, that is proportionate. EDD applies when the risk profile demands more: a deeper trace of ownership structures, verification of business rationale, investigation of individuals connected to the entity, analysis of the third party's government and political connections, and a higher standard of independent corroboration throughout.
The other key difference is documentation. Standard due diligence records what was found. EDD must record the reasoning behind the decision to proceed, the sources used, what they revealed, and who approved the relationship on what basis. That file is what you produce if you are ever questioned by a regulator, a prosecutor, or an auditor.
When does a third party require EDD?
EDD is triggered by risk factors in the relationship, not by a fixed category of vendor. The most common triggers in a third-party context are:
High-risk geographies.
Third parties operating in, or routing transactions through, jurisdictions with high levels of corruption, weak rule of law, or active conflict. Transparency International's Corruption Perceptions Index and the FATF grey and black lists are the standard reference points for geographic risk calibration.
Government-adjacent roles.
Third parties that interact with government officials on your behalf, influence regulatory decisions, or operate in markets dominated by state-owned entities. This includes agents, distributors, consultants, and local representatives in sectors such as defence, energy, infrastructure, and telecoms. Under the FCPA, willful blindness or awareness of a high probability that improper payments are being made by a third party may be interpreted as knowledge of a corrupt payment, providing the basis for liability. (White & Case, citing DOJ/SEC, KYC Hub)
PEP-connected or politically linked ownership.
Where the third party is owned or controlled by a politically exposed person, a close associate, or an entity with documented ties to a government or political party.
Complex or opaque ownership structures.
Layered holding companies, nominee arrangements, trusts, or structures that make it difficult to identify the natural person who ultimately benefits from the relationship.
Adverse media or prior enforcement history.
Prior regulatory findings, litigation, allegations of corruption, human rights violations, sanctions breaches, or modern slavery associations identified during initial screening.
High-value or high-risk contracts.
Relationships involving significant financial flows, commission-based compensation structures, sole-source contracts, or unusual payment terms that warrant closer scrutiny of the business rationale.
What does third-party EDD involve?
Beneficial ownership tracing.
Every layer of the corporate structure is traced to the natural persons who ultimately own or control it, verified through independent sources rather than self-declaration.
Individual-level background investigation.
Key individuals connected to the entity, including owners, directors, and senior management, are investigated for adverse history: enforcement actions, sanctions, litigation, reputational concerns, and political connections.
Business rationale verification.
Understanding why this specific third party is being used, what services they are genuinely performing, and whether their compensation is commensurate with the work. The DOJ and SEC explicitly expect companies to document that contract terms describe specific services performed and that payment is proportionate to work delivered.
Adverse media and open-source investigation.
Structured research beyond automated database screening, including regulatory filings, court records, investigative journalism, and local-language media in relevant jurisdictions.
Reference and field enquiries.
For higher-risk or higher-value relationships, direct enquiries with references, in-country verification, or specialist local intelligence may be warranted.
Contractual and compliance obligations.
EDD findings should directly inform contract terms: anti-bribery representations, audit rights, compliance training requirements, and termination provisions for non-compliance. While 91% of companies include some anti-corruption clauses in third-party agreements, 39% do not include compliance audit clauses, and 32% do not include provisions allowing termination in the event of non-compliance. (White & Case global compliance survey, KYC Hub)
What drives third-party EDD requirements?
No single regulation mandates EDD universally across all third-party relationships. What drives it is a combination of legal liability frameworks, enforcement expectations, and your own risk appetite.
UK Bribery Act 2010.
The only statutory defence against a charge of failing to prevent bribery is demonstrating that adequate procedures were in place. EDD on high-risk third parties is central to that defence. The Act applies to commercial organisations operating in the UK regardless of where the conduct occurs.
US Foreign Corrupt Practices Act.
The DOJ and SEC evaluate third-party due diligence quality when assessing corporate liability and making charging decisions. Enforcement agencies look not only at whether due diligence occurred but at how the third-party contract was structured, whether the third party was managed effectively, and whether payment requests were properly scrutinised. (Global Legal Insights, citing DOJ/SEC, International Monetary Fund)
EU and national supply chain laws.
The German Supply Chain Due Diligence Act (LkSG), the French Duty of Vigilance Law, and the EU Corporate Sustainability Due Diligence Directive (CS3D) impose obligations on organisations to identify and address human rights and environmental risks in their supply chains. EDD is the mechanism for high-risk supplier relationships.
FATF standards.
For organisations subject to AML obligations, FATF Recommendations require enhanced scrutiny for relationships involving high-risk jurisdictions, PEP-connected entities, and complex ownership structures.
How do you build a defensible third-party EDD programme?
Embed EDD into your tiering model.
EDD should activate automatically when defined risk thresholds are met, not be applied inconsistently based on individual judgment. Document which risk factors trigger EDD and apply that consistently across every business unit and geography.
Calibrate depth to actual risk.
EDD is proportionate, not uniform. An agent in a FATF-greylisted country on a high-value government-adjacent contract requires deeper investigation than a consultant in a stable jurisdiction on a modest retainer. Define what EDD means at each risk level and apply it accordingly.
Use independent corroboration throughout.
Self-declared information from a third party is a starting point, not a conclusion. Every material claim about ownership, business history, and compliance record should be verified through independent sources: corporate registries, court records, regulatory filings, and where necessary, specialist intelligence.
Document the decision, not just the outcome.
A defensible EDD file shows what risk was identified, what investigation was conducted, what it found, who reviewed it, and why the decision to proceed was made. It should be legible to a regulator without additional narration.
Translate findings into contract terms.
EDD findings should directly shape the contractual relationship. Higher-risk third parties warrant stronger anti-bribery representations, explicit audit rights, and clear termination provisions. A thorough EDD file that results in a standard contract does not amount to adequate procedures.
Maintain ongoing oversight.
Third parties remain the dominant source of FCPA exposure, with agents, distributors, consultants, and local intermediaries continuing to generate the majority of enforcement cases. (Volkov Law, citing DOJ enforcement patterns) EDD at onboarding does not protect you from what happens afterwards. Periodic re-screening, transaction monitoring, and audit rights exercised in practice are all part of a programme that holds up to scrutiny.
Source: LSEGFrequently asked questions
What is the difference between due diligence and enhanced due diligence in TPRM?
Standard due diligence screens for known risk factors and establishes a baseline profile. EDD applies when that baseline identifies elevated risk. It involves deeper investigation of individuals, ownership, business rationale, and connections, with independent corroboration and documented decision-making at senior level.
Which third parties typically require EDD?
Those operating in high-risk jurisdictions, playing a government-adjacent role, owned or controlled by PEPs, presenting complex or opaque ownership structures, or flagged by adverse media during initial screening. High-value or commission-based relationships in sensitive sectors are also common triggers.
Can a company be liable for a third party's conduct even without knowing about it?
Yes, under both the UK Bribery Act and the FCPA. Willful blindness, meaning the failure to investigate when red flags were present, can be treated as constructive knowledge. The defence in both frameworks relies on demonstrating that adequate procedures were in place, not on proving the company was unaware.
How often should EDD be repeated?
Whenever material risk factors change. Ownership changes, new adverse media, changes in the geographic or political context of the relationship, and the start of new contract phases or payment structures are all triggers for re-screening. High-risk relationships should also be reviewed on a defined periodic cycle regardless of whether specific triggers arise.
What makes an EDD programme defensible?
Consistent application of defined risk criteria, independent corroboration of material claims, documented senior-level decision-making, and contract terms that reflect EDD findings. A programme that is thorough on paper but inconsistently applied, or that produces findings that never influence contract terms, will not satisfy a regulator.