Global Advice Network
| Borgergade 111 | DK - 1300 Copenhagen K
|
|
|
|
Creating a Risk-Based Monitoring Schedule for High-Risk Business PartnersA high-risk business partner can expose a company to bribery, fraud, sanctions violations, money laundering, conflicts of interest, and serious reputational damage. Initial due diligence is essential, but a questionnaire and screening report only describe the relationship at one point in time. Ownership structures change, intermediaries take on new roles, and political or regulatory conditions can shift quickly. A risk-based monitoring schedule gives compliance teams a practical way to keep partner information current. Instead of reviewing every supplier, distributor, agent, consultant, and joint-venture partner at the same interval, the company allocates attention according to the level and nature of risk. This makes monitoring more proportionate, defensible, and easier to connect to business decisions. The strongest programs combine scheduled reviews with event-driven checks. A partner may require annual certification, quarterly sanctions screening, or a new investigation after a change in ownership. The schedule should therefore function as a living control system rather than a calendar of repetitive administrative tasks. Why Monitoring Must Follow RiskPartner risk is rarely determined by a single factor. A small local consultant may present significant exposure if the consultant interacts with public officials, receives success-based commissions, or operates in a country where corruption enforcement is weak. A large multinational supplier may have stronger controls but still require attention because of complex subcontracting chains or government-linked customers. A useful risk assessment considers the partner’s services, location, ownership, public-sector contact, payment structure, use of subcontractors, and history of allegations or enforcement actions. The company should also assess the importance of the relationship. A partner responsible for market access, customs clearance, licensing, procurement, or government contracts generally warrants closer oversight than a low-value office supplier. Monitoring should test whether the original risk assumptions remain accurate. It should also examine whether controls are operating in practice. A partner may have adopted a written anti-bribery policy, for example, while continuing to use unexplained cash payments or poorly documented commissions. The gap between stated policy and actual conduct is often where the greatest warning signs emerge. Define the Partner Risk ProfileBefore setting review intervals, create a consistent risk profile for each business partner. The profile should explain why the relationship is considered low, moderate, high, or critical risk. A simple score can support consistency, but the written rationale matters more than the numerical result. Decision-makers need to understand the facts behind the rating and the controls required in response. Relevant indicators may include country corruption risk, exposure to politically exposed persons, beneficial ownership opacity, unusual compensation, adverse media, government touchpoints, high-risk industries, and reliance on third parties. The assessment should distinguish inherent risk from residual risk. Inherent risk describes the exposure created by the relationship itself, while residual risk reflects the exposure remaining after due diligence, contractual safeguards, training, approval procedures, and oversight are applied. Risk ratings should be reassessed when the relationship changes. A distributor that begins handling public tenders, a consultant requesting a new payment destination, or a supplier adding an undisclosed subcontractor should not wait for the next routine review. Clear rating criteria help business and compliance teams recognize when a monitoring schedule needs to be accelerated. Set Review Frequency and Trigger EventsThe schedule should combine periodic reviews with defined trigger events. Periodic reviews provide a predictable minimum level of oversight, while trigger events allow the company to respond to new information. High-risk partners may require a formal review every six or twelve months, with continuous sanctions screening and targeted checks between reviews. Critical relationships may need quarterly certifications, transaction testing, and senior compliance approval. A trigger event should lead to a documented action, not simply an entry in a watchlist. Common triggers include a merger, acquisition, ownership change, leadership change, expansion into a new country, new government contract, significant increase in fees, payment through an unrelated account, credible allegation of misconduct, or refusal to provide updated information. A partner’s failure to cooperate can itself justify escalation or suspension. The review calendar should state who owns each task, what evidence must be collected, and what happens when a deadline is missed. Automated reminders are helpful, but automation should not replace judgment. A case owner may need to bring forward a review because a country has entered a period of political instability or because a new enforcement action reveals a previously unknown industry pattern. Match Controls to ExposureMonitoring activities should be tailored to the risks identified in the partner profile. Repeating the same annual questionnaire for every third party often produces large volumes of low-value data. A better approach combines general controls with targeted procedures. For example, a partner with government-facing responsibilities may require evidence of public-official interactions, commission approvals, and tender-related training, while a logistics provider may require transaction testing and review of customs payments. The schedule should also define evidence standards. Acceptable evidence might include current corporate registry extracts, beneficial ownership records, licenses, training logs, payment samples, invoices, subcontractor lists, conflict-of-interest declarations, and certification from an authorized executive. Documents should be checked for consistency, translated where necessary, and compared with information from independent sources.
A review should end with a clear outcome: continue, continue with remediation, restrict activity, suspend payments, or terminate the relationship. The outcome and reasons should be recorded in the compliance system. This creates an audit trail showing that monitoring influenced actual risk decisions rather than serving as a purely documentary exercise. Use Intelligence and Regional ContextOpen-source intelligence can strengthen ongoing monitoring when it is used systematically. Compliance teams may review corporate registries, court records, procurement databases, sanctions lists, regulatory notices, credible news sources, and professional networks. Guidance on open-source screening can help teams design a proportionate process before and during a partner relationship. Searches should use alternative spellings, local-language terms, former company names, executive names, and related entities. Analysts should distinguish verified facts from allegations and document the source, date, relevance, and disposition of each finding. A negative result does not prove that risk is absent, particularly where public records are incomplete or difficult to access. Regional context also matters. Business practices involving gifts, hospitality, facilitation, charitable contributions, and informal introductions may vary across markets, but cultural expectations do not override company policy or anti-corruption law. Resources on gift-giving and compliance can help reviewers interpret local practices without treating cultural custom as automatic justification for an improper benefit. Country risk profiles and local legal guidance should inform monitoring intensity, yet they should not determine the rating by themselves. A lower-risk jurisdiction can still contain a problematic partner, just as a reputable international company can operate responsibly in a challenging environment. The partner, transaction, and specific activity remain the central focus. Turn Monitoring Into a Governed ProcessA monitoring schedule works when responsibilities are divided clearly. Procurement may own business information, the relationship manager may coordinate certifications, finance may test payments, legal may maintain contract protections, and compliance may determine risk ratings and escalation. Internal audit can independently assess whether the process is operating as designed. The schedule should connect to the partner lifecycle. No new work should begin until required onboarding steps are complete, and material changes should initiate a risk reassessment. Contracts should include audit rights, accurate-records obligations, anti-bribery commitments, training expectations, restrictions on subcontracting, and termination rights. These provisions give the company a basis for obtaining information and responding when controls fail. Practical Controls for Every Review
Metrics can reveal whether the process is effective. Useful measures include the percentage of high-risk partners reviewed on time, average remediation age, number of overdue certifications, screening alerts by disposition, payment exceptions, and partners suspended because of unresolved concerns. These indicators should be reviewed periodically by compliance leadership and relevant business executives. Keep the Schedule CurrentA risk-based monitoring schedule should be recalibrated as the business, regulatory environment, and partner population evolve. At least annually, the company should test whether its risk factors remain relevant, whether review frequencies are producing useful information, and whether teams are escalating issues consistently. Significant enforcement actions, new legislation, acquisitions, or expansion into unfamiliar markets may justify an earlier program review. The organization can use a structured compliance resource such as the Business Anti-Corruption Portal to support country research, legislation checks, training, due diligence, and anti-corruption terminology. External resources are most valuable when they complement internal records, interviews, transaction data, and knowledge of the commercial relationship. A well-designed schedule makes oversight proportional without making it passive. It directs deeper scrutiny toward partners whose activities, locations, influence, or conduct create the greatest exposure, while preserving efficient controls for lower-risk relationships. Put the schedule into the third-party management system, assign accountable owners, and begin the next review with the partners whose risk profile demands immediate attention. |