Global Advice Network | Borgergade 111 | DK - 1300 Copenhagen K
E-Mail: info@business-anti-corruption.org | Phone: (+45) 60 88 10 44

Auditing third-party agents: practical compliance controls

Third-party agents can open doors to new customers, government tenders, licences and local relationships. They can also expose a company to bribery, fraud, conflicts of interest, sanctions breaches, money laundering and reputational damage. A consultant who appears to be a routine intermediary may, in practice, be dealing with public officials, controlling payments or influencing procurement decisions on the company’s behalf.

Best practices for conducting a compliance audit of a third-party agent begin before an auditor requests a single document. The company should understand why the agent is needed, where the agent operates, what services are being provided and which decisions the agent can influence. A structured review then tests whether the relationship was properly approved, whether payments are justified and whether controls work in daily business.

Define the relationship and audit scope

The first step is to document the agent’s role in plain language. An agent may introduce customers, secure permits, manage customs clearance, represent the company in a tender or provide market intelligence. Each activity carries a different risk profile. An intermediary who communicates with a ministry in Canberra, a state-owned utility in Perth or a municipal authority in Southeast Asia requires closer scrutiny than a supplier providing routine administrative support.

The audit scope should cover the full life of the relationship, including onboarding, contract approval, payment, travel, gifts, expenses, subcontracting and renewal. It should identify the relevant business units and decision-makers, rather than treating the agent as a standalone procurement file. The company’s own compliance policy, applicable local laws and the agent’s operating environment should all be considered. General information sources can help set boundaries, but their limitations should be recognised, as explained in the site’s disclaimer.

A written scope also prevents an audit from becoming an unfocused search for irregularities. It should state the review period, transactions to be sampled, records to be examined, personnel to be interviewed and risk questions to be answered. For a high-risk relationship, the scope may include related entities, beneficial owners and downstream representatives.

Apply a risk-based screening process

A risk assessment should consider the country, sector, transaction and individual agent. Risk increases where the agent operates in a jurisdiction with weak enforcement, works in construction or infrastructure, interacts with public officials, handles licences or customs matters, or receives success fees linked to a government contract. Complex ownership, unexplained offshore accounts and pressure to avoid written agreements are additional warning signs.

Australian companies should distinguish between domestic and international exposure without assuming that domestic work is automatically low risk. A project in Sydney, Melbourne or Brisbane can involve state-owned bodies, planning approvals and public procurement. The Criminal Code Act 1995 (Cth) contains foreign bribery offences, while state integrity agencies and procurement rules may apply to conduct involving Australian public officials. A relationship that appears commercially ordinary may still create serious legal consequences if payments are used to influence a decision.

Risk scoring should produce a reasoned outcome, not just a colour on a spreadsheet. The file should explain why the agent is classified as low, medium or high risk, what evidence supports that rating and which controls follow from it. High-risk agents may require enhanced due diligence, senior approval, more frequent transaction testing and a shorter contract term.

Verify identity, ownership and qualifications

A compliance audit should confirm who the agent is, who owns or controls the business and who will actually perform the work. Obtain registration records, tax information, business addresses, licences, professional qualifications, résumés and relevant litigation or regulatory history. Compare the information across corporate databases, bank records, websites and the agent’s own representations. Differences in names, addresses or ownership percentages should be resolved rather than filed away.

Beneficial ownership checks are essential where an agent is connected to a customer, government official, political figure or employee of the company. Screening should cover sanctions, politically exposed persons, enforcement actions, adverse media and conflicts of interest. A local reputation check can be valuable, but it should be conducted lawfully and documented carefully. References should come from identifiable sources and should address the agent’s actual work, not merely confirm that the agent is well known.

The audit should test whether the agent’s qualifications match the services invoiced. A consultant claiming specialist engineering or regulatory expertise should be able to demonstrate relevant capability. An agent with no staff, office or sector experience may be a pass-through for another party. Subcontractors and “local partners” should be identified because hidden intermediaries often create the greatest difficulty in tracing responsibility.

Test contracts, compensation and payments

The written agreement should describe the services, territory, reporting obligations and payment terms with enough precision to support testing. It should prohibit bribery, improper facilitation payments, undisclosed subcontracting, conflicts of interest and false records. Audit rights, access to supporting documents, termination rights and cooperation with investigations should be included. Contract language should be consistent with actual practice; an extensive compliance schedule cannot compensate for vague commercial obligations.

Compensation should reflect legitimate market value and be paid through an account held in the agent’s own name in the country where services are performed, unless there is a documented reason for another arrangement. Large upfront payments, round-number invoices, cash requests, payments to relatives and transfers to unrelated jurisdictions require enhanced review. Commission structures linked to winning a public contract deserve particular attention, especially where there is no clear evidence of the work performed.

The audit should reconcile contracts, purchase orders, invoices, bank confirmations, expense claims, emails and accounting entries. Look for split invoices below approval thresholds, duplicate descriptions, vague phrases such as “special handling”, and payments recorded as marketing or facilitation costs without supporting detail. In Australia, records should also be assessed against the company’s tax and accounting obligations. If the business is an entity regulated under Australia’s anti-money laundering framework, relevant customer identification and transaction monitoring duties may also apply under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006.

Review interactions with officials and commercial partners

Interviews should cover what the agent actually does, who gives instructions and how meetings or introductions take place. Ask the agent to describe a recent transaction from first contact to payment, then compare the account with internal records. Questions should address gifts, hospitality, travel, political or charitable contributions, permits, inspections, customs, tender information and requests from officials. A credible agent should be able to explain the business purpose and supporting evidence without relying on vague claims about personal influence.

Testing should include samples from higher-risk transactions and periods around tender decisions, licence approvals or contract renewals. Review calendars, correspondence, meeting notes and expense records where lawful and proportionate. Any hospitality in connection with an official should be tested against policy limits and approval records. Everyday business customs, such as sharing meals after meetings or attending sporting events, may be legitimate, but the timing, value and participants matter.

In sectors such as construction and infrastructure, risk can accumulate across multiple contractors, consultants and government touchpoints. A company assessing a major project should build a corruption risk map that connects agents to permits, land, procurement, subcontractors and payment milestones. A corruption risk map can help auditors identify concentration points that a contract-by-contract review might miss.

Evaluate the control environment and audit evidence

An agent’s compliance programme should be assessed in proportion to its size and risk. A small Australian consultancy may not have a dedicated compliance officer, but it should still be able to explain its approval process, record expenses, train relevant personnel and escalate concerns. The audit should examine whether policies are communicated, whether staff understand them and whether management acts consistently when commercial pressure arises.

Evidence should be tested for reliability. A policy stored on a shared drive does not show that it was followed. Training attendance should be supported by content, dates and participant records. A due diligence form should be compared with source documents and approval emails. Where records are incomplete, auditors should establish whether the gap is isolated or reflects a wider weakness in recordkeeping.

Data analysis can reveal patterns that manual review misses. Search for repeated payments just below approval thresholds, round amounts, weekend transactions, unusual descriptions and invoices submitted shortly before a tender award. Compare the agent’s commission with comparable arrangements and expected workload. Preserve relevant evidence securely, restrict access to sensitive material and maintain a clear chain of custody if misconduct may need to be reported or investigated.

Report findings and manage remediation

Audit findings should distinguish confirmed misconduct, control failures, documentation gaps and unresolved concerns. Each finding should state the evidence, the relevant requirement, the risk to the business and the responsible owner. A missing invoice is not equivalent to a bribe, but repeated missing invoices may indicate a deliberate effort to conceal payments. Clear classification helps senior management respond proportionately.

Remediation may include obtaining missing records, repaying unsupported expenses, changing approval thresholds, retraining staff, suspending payments, replacing an intermediary or terminating the relationship. High-risk findings should have deadlines and executive oversight. The agent should be given a controlled opportunity to respond, but its explanation should be tested against independent evidence rather than accepted automatically.

Where potential bribery, fraud, money laundering or false accounting is identified, the company should preserve records and involve appropriately qualified legal and compliance professionals. Self-reporting, regulator engagement and disciplinary action require a careful assessment of the facts and applicable law. Retaliation against whistleblowers should be prohibited, and reporting channels should be available to employees, agents and subcontractors.

Build ongoing monitoring into the relationship

A compliance audit is most effective when it forms part of a continuing third-party management process. Risk ratings should be refreshed when the agent changes ownership, expands into a new country, seeks a higher commission, begins dealing with public bodies or uses subcontractors. Screening should be repeated at intervals suited to the risk, rather than only when a contract is renewed.

Monitoring can include annual certifications, targeted transaction reviews, refreshed beneficial ownership checks, training, sample site visits and management reports. Contract renewals should require evidence that the agent performed the agreed services and that previous findings were resolved. An agent working across Melbourne and regional project sites, for example, may require different monitoring from an intermediary working on an international tender involving customs officials and state-owned enterprises.

Boards and senior executives should receive information that allows them to see patterns across the portfolio. Several low-value exceptions involving the same agent, business unit or country may represent a material risk when considered together. Procurement, finance, legal, internal audit and operational teams should share relevant information while respecting privacy, confidentiality and employment requirements.

A sound audit leaves the company with more than a completed checklist. It creates a defensible record of why the agent was appointed, what controls were applied, what evidence was reviewed and how concerns were addressed. It also helps demonstrate that the company took reasonable steps to prevent improper conduct by people acting on its behalf.

The practical takeaway is to link every third-party payment to a verified person, a documented service, a legitimate business purpose and an approval trail that can withstand independent review. For higher-risk agents, add enhanced due diligence, transaction testing and regular reapproval before commercial urgency turns a manageable relationship into a compliance incident.

copyright © Global Advice Network