Global Advice Network
| Borgergade 111 | DK - 1300 Copenhagen K
|
|
|
|
Best Practices for Documenting Due Diligence for Regulatory InspectionsRegulatory inspections rarely focus on whether a company has a policy sitting in a shared drive. Inspectors want to see how the organization identified risk, made decisions, verified information, handled exceptions, and monitored relationships over time. A well-organized due diligence file turns those activities into clear, reviewable evidence. Documentation is therefore a control in its own right. It supports anti-corruption compliance, third-party risk management, sanctions screening, beneficial ownership checks, and decisions involving agents, distributors, suppliers, consultants, and public-sector contacts. A strong record should allow an independent reviewer to understand what happened without relying on the memory of the employee who managed the relationship. The most reliable approach combines a consistent process with proportionate judgment. Files should be complete enough to withstand scrutiny, but practical enough that employees can maintain them throughout the life of a relationship. The anti-corruption resources available from the Business Anti-Corruption Portal can help organizations align their records with broader country, legal, and compliance considerations. Define The Purpose And ScopeBefore collecting documents, establish why due diligence is required and what questions the review must answer. The file should identify the third party, proposed services, countries involved, ownership structure, payment arrangements, government touchpoints, and the business reason for engagement. This initial profile provides a reference point for evaluating whether the depth of review is appropriate. A risk-based scope is more defensible than a one-size-fits-all checklist. A local supplier with no public-sector interaction may require basic identity and ownership verification. An intermediary working in a high-risk market, paid by commission, and interacting with government officials requires deeper checks, documented interviews, enhanced screening, and senior approval. The rationale for the selected level of review should be recorded in plain language. If the company decides not to obtain a particular document, the file should state why the item was unnecessary, unavailable, or replaced by another reliable source. Inspectors generally respond better to a documented, reasoned decision than to an incomplete checklist with no explanation. Build A Complete Evidence FileA due diligence file should tell a chronological story. Start with the request to onboard or renew the third party, then preserve the risk assessment, questionnaires, certifications, screening results, research notes, approvals, contract, training records, and monitoring activity. Dates, responsible employees, and version information should appear consistently across the record. Source quality matters as much as document volume. Corporate registry extracts, regulatory databases, court records, sanctions lists, official websites, audited financial information, and reputable media usually carry more weight than unexplained internet searches. Each research item should include the source, access date, search terms where relevant, reviewer, result, and any limitations. Where information is provided directly by the third party, retain the original submission and supporting evidence. A signed questionnaire alone may not establish that ownership, qualifications, licenses, or government connections were independently verified. The file should distinguish between information supplied by the counterparty and information confirmed through external sources. Preserve Decisions And EscalationsInspection risk often arises from undocumented judgment rather than from an obvious policy breach. If a reviewer identifies a politically exposed person, adverse media, unusual payment request, ownership opacity, or inconsistent answers, the file should show how the issue was assessed and resolved. Capture the facts, the risk rating, the people consulted, the decision-maker, and any conditions imposed. Escalations should have a visible audit trail. Emails, memoranda, compliance tickets, meeting minutes, and approval forms can all be useful when they clearly connect to the due diligence file. Avoid relying on informal conversations or undocumented verbal approvals, especially when the decision involves a high-risk jurisdiction, public official, success fee, charitable contribution, or exception to standard controls. A decision record does not need to be lengthy. It should answer four practical questions: What was found? Why did it matter? What action was taken? Who authorized the outcome? If the relationship was approved with enhanced controls, list those controls and assign an owner and review date.
Control Versions, Access, And RetentionAn inspection-ready file must be reliable after it has been created. Use a controlled repository with defined naming conventions, restricted editing rights, audit logs where available, and a clear distinction between draft and final records. A reviewer should be able to identify the approved version without comparing multiple contradictory copies. Access should follow legitimate business need. Sensitive information may include identification documents, personal addresses, banking details, investigation material, and confidential reports. Limit access to authorized personnel, record significant changes, and protect the file from deletion or alteration. Security controls also support credibility by demonstrating that records were preserved with integrity. Retention schedules should reflect legal requirements, contractual obligations, litigation holds, investigation needs, and the company’s compliance policy. The end of a business relationship does not always mark the end of the retention period. Document the retention rule and disposal process, while ensuring that relevant records are suspended from destruction when an inquiry or investigation is pending. Use Technology Without Losing JudgmentTechnology can improve consistency by connecting questionnaires, screening tools, approval workflows, document storage, and renewal reminders. Automated systems may flag sanctions hits, country-risk changes, expired certifications, or missing approvals. They can also produce an activity log showing when a check was completed and by whom. Automation does not replace professional review. A screening alert may involve a false positive, a translated name, an incomplete database, or a person with the same name as the subject. The file should preserve the analyst’s reasoning and supporting evidence, including why an alert was cleared or escalated. A status marked “complete” is not enough if the underlying decision cannot be reconstructed. Training helps employees create usable records rather than simply upload documents. Remote and distributed teams need clear instructions on naming files, recording sources, escalating concerns, and protecting personal data. Guidance on remote employee training can inform the design of short learning modules that explain these expectations in practical scenarios. Test Files Before An InspectionPeriodic file reviews reveal weaknesses while there is still time to correct them. Select samples across countries, business units, risk levels, and third-party categories. Test whether the record supports the original risk rating, contains required evidence, reflects approval authority, and shows timely renewal or monitoring. A quality assurance review should distinguish between missing evidence and poor reasoning. A file may contain every required form yet fail to explain why the relationship was considered high risk. Conversely, a reviewer may identify a reasonable alternative source that was not listed on the standard checklist. Record both findings and use them to improve procedures, templates, and training. Country context should be part of the testing process. Local ownership records, language issues, licensing systems, media availability, and public-sector structures can affect how verification is performed. For example, an India country profile can help compliance teams place local due diligence findings within a broader country-risk assessment rather than treating individual documents in isolation. Practical Controls For Consistent RecordsThe following controls make documentation easier to maintain and easier to defend during an inspection:
These controls work best when built into ordinary workflows. A procurement request, vendor onboarding form, contract approval, invoice review, and annual certification should each connect to the same third-party record. Fragmented evidence creates avoidable gaps, particularly when employees change roles or a regulator requests information quickly. The compliance function should also define response procedures for an inspection. Identify who gathers records, who communicates with inspectors, who checks privilege and privacy restrictions, and who maintains a disclosure log. A controlled response is faster and reduces the risk that employees provide inconsistent, incomplete, or unnecessarily broad material. Strong documentation should make a company’s conduct understandable. Reviewers should be able to see that the organization recognized relevant risks, applied a consistent methodology, investigated concerns, obtained the right approvals, and continued monitoring after onboarding. That standard supports more than regulatory readiness; it strengthens accountability across the entire third-party lifecycle. Begin by selecting a sample of current due diligence files and testing whether an independent reviewer could reconstruct each decision from the records alone. Close the gaps, assign responsibility for ongoing maintenance, and embed the resulting practices into onboarding, renewal, training, and oversight processes. When the next inspection arrives, readiness will be demonstrated through evidence rather than explanations. |