Global Advice Network
| Borgergade 111 | DK - 1300 Copenhagen K
|
|
|
|
Designing a Third-Party Due Diligence Questionnaire for SMEsSmall and medium enterprises often depend on agents, distributors, consultants, suppliers, logistics providers, and joint-venture partners to reach customers and operate across borders. These relationships can create valuable commercial opportunities, but they may also expose a business to bribery, conflicts of interest, fraud, sanctions violations, money laundering, and reputational damage. A well-designed third-party due diligence questionnaire helps an SME gather relevant information before entering or renewing a business relationship. It should reveal who owns the intermediary, how the company operates, what services it will provide, and whether its proposed compensation and government contacts create elevated compliance risks. The most effective questionnaire is proportionate, clear, and connected to an actual review process. A long form that nobody assesses is less useful than a focused set of questions supported by documents, risk-based approval, and periodic monitoring. Why a focused questionnaire mattersThird parties may act on behalf of a company without being employees, which can make improper conduct harder to detect. An agent who pays an unofficial fee to secure a permit, for example, may expose the hiring company to enforcement action even if senior management did not authorize the payment. The risk is especially significant when the intermediary interacts with public officials, controls access to licenses, or receives success-based fees. A questionnaire creates a consistent record of the company’s initial assessment. It gives procurement, sales, legal, and compliance teams a shared basis for deciding whether a relationship should proceed, require enhanced review, or be rejected. It also helps demonstrate that the business took reasonable steps to understand its partners and prevent misconduct. The form should support, rather than replace, independent verification. A third party’s answers may be incomplete, inaccurate, or deliberately designed to conceal an ownership connection. Screening, reference checks, document reviews, interviews, and approval controls are needed when responses indicate higher risk. Set a proportionate scopeAn SME should begin by classifying the relationship. A local office supplier with no public-sector contact usually does not require the same level of review as a customs broker, sales representative, or consultant hired to win a government contract. Applying one intensive process to every vendor can overwhelm a small compliance team and encourage superficial answers. The questionnaire should therefore reflect factors such as the third party’s role, country, industry, payment structure, access to confidential information, interaction with public officials, and use of subcontractors. A basic questionnaire may be suitable for low-risk suppliers, while higher-risk relationships should trigger enhanced due diligence and senior approval. Country and sector context also matter. A business assessing a waste contractor should examine licensing, disposal records, tipping-fee arrangements, subcontractors, and connections to municipal authorities. The risks described in this analysis of waste sector corruption illustrate why a generic supplier form may miss conduct specific to an industry. A tiered approach keeps the process manageable:
Build questions around the real riskThe first section should establish the third party’s identity. Ask for its full legal name, trading names, registration number, registered address, operating locations, website, date of incorporation, and main business activities. Request the names and ownership percentages of directors, ultimate beneficial owners, and controlling persons rather than accepting only the name of a local contact. Ownership questions should cover both direct and indirect interests. The form can ask whether any owner, director, employee, or close relative is a current or former public official, politically exposed person, or representative of a state-owned enterprise. It should also ask whether anyone connected to the third party has a personal or business relationship with the customer’s employees or government decision-makers involved in the proposed engagement. The next section should examine capability. Ask the third party to explain its relevant experience, qualifications, licenses, staffing, geographic coverage, and proposed responsibilities. A company claiming to provide specialized services should be able to show credible experience and resources. An intermediary with no apparent expertise, employees, or operating history may be a nominee or a channel for improper payments. Questions about compensation deserve careful wording. Request the proposed fee, commission, bonus, reimbursement terms, payment currency, bank account location, and basis for calculating the amount. Ask whether payments will be made to a different entity, an individual, a cash account, or an offshore account without a clear commercial reason. The questionnaire should require disclosure of gifts, hospitality, charitable contributions, political donations, or other benefits connected to the engagement. Ask for evidence and score the answersQuestions become useful when the respondent knows what evidence is expected. Depending on risk, supporting documents may include a certificate of incorporation, ownership chart, business license, tax registration, professional credentials, audited accounts, bank confirmation, compliance policies, and references from comparable customers. Documents should be current and consistent with information found through public records and screening databases. The form should include clear declarations. The third party can confirm that its answers are complete and accurate, disclose changes in ownership or government relationships, comply with anti-bribery and sanctions laws, keep accurate records, and permit reasonable audit or information rights. It should also identify any subcontractors expected to perform material work. A scoring model can help prioritize attention, but it should not produce an automatic decision without human judgment. A high score may result from several moderate indicators, while one serious red flag—such as a hidden beneficial owner or a request for payment to an unrelated account—may justify escalation even if the overall score appears low.
Account for regional and local conditionsA questionnaire should include a country-risk section without assuming that every business in a particular country presents the same threat. Ask where the third party operates, where it will provide services, and which public bodies or state-owned companies it will contact. The answers can then be assessed against country profiles, enforcement developments, sanctions requirements, and local corruption indicators. Local practices may also affect the form. In some markets, a third party may commonly use family-owned subcontractors, informal brokers, or cash-based logistics providers. These practices do not automatically prove misconduct, but they require transparency and supporting evidence. The form should ask who will actually perform the work and whether any part of the fee will be passed to another intermediary. For companies operating in South Asia, country-specific research can sharpen the review. An SME assessing an Indian distributor, consultant, or public-sector intermediary can consult the India country profile alongside its questionnaire. That information should inform follow-up questions, not replace an assessment of the individual third party and transaction. Sector-specific prompts are equally important. Construction, extractive industries, healthcare, defense, customs brokerage, waste management, and public procurement often involve permits, inspections, licensing, or discretionary government decisions. The questionnaire should ask about these touchpoints directly and record which party is responsible for each interaction. Turn responses into a controlled decisionThe questionnaire should be completed before contract signature, appointment, or payment. A business owner may sponsor the relationship, but an independent reviewer should examine the answers and evidence. For higher-risk cases, approval may need to come from a compliance officer, legal adviser, finance leader, or senior management committee. Every decision should have a documented outcome. The file can record approval, approval with conditions, a request for further information, temporary suspension, or rejection. Conditions might include a narrower scope of work, payment only against invoices and verified deliverables, anti-corruption training, restrictions on subcontracting, or a requirement for periodic certifications. The contract should reflect the findings. Useful provisions include compliance with anti-bribery and sanctions laws, accurate books and records, no unauthorized subcontracting, cooperation with investigations, audit rights, reporting of potential misconduct, and termination rights for serious violations. Contract language is more effective when it matches the controls the business can actually operate. Records should be retained in a central location with access limited to appropriate personnel. The file should include the completed questionnaire, evidence, screening results, approvals, contract, monitoring notes, and follow-up correspondence. A consistent record helps the company identify repeat issues across suppliers and respond efficiently to audits or regulatory inquiries. Keep the process practical for small teamsA small enterprise does not need a complex technology platform to create a credible due diligence process. A controlled digital form, shared register, document naming convention, and calendar reminder can provide a useful foundation. The form should use plain language, explain why information is requested, and identify a contact for questions. The questionnaire should be reviewed when there is a significant change in the relationship. Trigger events may include a new country, government contract, ownership change, unusual payment request, new subcontractor, regulatory inquiry, adverse media report, or expansion into a higher-risk service. Routine renewals can be less intensive when the risk profile remains stable, but the business should still confirm that core information is current. Training should cover the people most likely to identify warning signs. Procurement staff need to understand ownership and payment red flags; finance teams should know when to hold a payment; sales teams should recognize problematic requests from agents; and managers should understand that commercial urgency does not remove approval requirements. Practical recommendations for lean compliance teams
Put the questionnaire to workA third-party questionnaire is valuable when it changes decisions and behavior. Before launching it, map the business’s most important intermediaries, identify the roles that involve public officials or sensitive payments, and define who reviews each risk level. This makes the process easier to administer and prevents forms from becoming a paper exercise. The final document should be tested with a few real relationships. Remove questions that generate information no one uses, clarify terms that respondents misunderstand, and add prompts where reviewers repeatedly need follow-up. The goal is a defensible, risk-based process that produces reliable information without placing an unrealistic burden on an SME. Implement the questionnaire alongside screening, written contracts, payment controls, training, and periodic monitoring. With those elements working together, a small business can make better-informed partner selections, identify warning signs earlier, and demonstrate that integrity is part of its commercial decision-making. Start by reviewing the highest-risk third parties already in your network and apply the questionnaire before the next appointment, renewal, or material payment. |