Due Diligence
Due diligence is the process of investigating and verifying information about a person, company, or transaction before entering into a business relationship or agreement. In practical terms, it is the reasonable care an organization takes to understand who it is dealing with and what risks that relationship may carry before committing to it. It is a decision-support activity, not a guarantee that a relationship will be free of problems.
In a third-party risk context, due diligence is the structured investigation and evaluation of a prospective or existing third party, such as a supplier, service provider, or business partner, to assess relevant risks before or during a business relationship. It reflects the standard of care a reasonable business is normally expected to exercise before entering into an agreement, and typically involves collecting and verifying information across areas that may include legal, financial, operational, security, and reputational dimensions, though the scope varies by risk tier and program design. Due diligence is often concentrated at onboarding and is inherently point-in-time; unless paired with ongoing monitoring, its findings can become stale, and reliance on self-reported information without independent verification limits the assurance it provides. Depth of investigation is generally proportionate to the assessed inherent risk of the relationship rather than uniform across all third parties.
Why it matters
Due diligence is the point at which an organization decides, on the basis of evidence rather than assumption, whether and how to enter a relationship with a third party. Because it reflects the reasonable care a business is normally expected to exercise before committing to an agreement, it functions both as a risk-reduction activity and as a demonstrable record of that care. When performed well, it surfaces legal, financial, operational, security, and reputational concerns while they can still shape the decision, whether to proceed, to proceed with conditions, or to decline. It is decision support, however, not a guarantee: a completed due diligence process does not ensure a relationship will be free of problems.
The practical stakes come from due diligence's inherent limitations. It is typically concentrated at onboarding and is point-in-time by nature, so its findings describe a third party as it was at the moment of assessment, not as it evolves. A supplier's financial position, ownership, control environment, or geopolitical exposure can change materially after onboarding, and without ongoing monitoring the original findings become stale. Reliance on self-reported information without independent verification further constrains the assurance due diligence provides, an attestation that a control exists is not the same as independent confirmation that it operates effectively.
For these reasons, due diligence is best understood as the entry stage of a broader lifecycle rather than a standalone safeguard. Programs that treat a passed onboarding review as durable assurance risk carrying unexamined exposure for the life of the relationship. Depth proportionate to inherent risk, verification where the stakes warrant it, and pairing with continued monitoring are what allow due diligence to remain meaningful over time.
Who it's relevant to
Inside DD
Common questions
Answers to the questions practitioners most commonly ask about DD.