Global Advice Network | Borgergade 111 | DK - 1300 Copenhagen K
E-Mail: info@business-anti-corruption.org | Phone: (+45) 60 88 10 44

Building a Risk-Based Review of Third-Party Agents

Third-party agents can help a company enter new markets, navigate local procedures, obtain permits, represent commercial interests, and manage relationships with public institutions. They can also create serious exposure when their activities involve government officials, state-owned enterprises, customs authorities, licensing bodies, or politically connected intermediaries.

A sound review process does more than collect a passport copy and run a sanctions search. It evaluates why the agent is needed, what the agent will do, how the relationship will operate, and whether the proposed compensation and controls match the corruption risk. The objective is a defensible business decision based on evidence, proportionality, and ongoing oversight.

Risk-based anti-corruption due diligence should also reflect the limits of available information. Country indicators, public records, and commercial databases are useful inputs, but they do not replace company-specific investigation. The methodology disclaimer is a useful reminder that external country and governance information should inform judgment rather than determine it automatically.

Start With The Business Rationale

The first question is whether the proposed intermediary is genuinely necessary. A legitimate agent should perform a defined commercial or technical function that the company cannot reasonably conduct itself. Vague explanations such as “opening doors,” “handling relationships,” or “making things easier” deserve closer examination because they may conceal improper influence or unofficial payments.

The business sponsor should prepare a short rationale before the agent is engaged. It should explain the market opportunity, the services required, the expected duration, the relevant customers or authorities, and why the proposed individual or firm has the appropriate capabilities. This document establishes a baseline against which later claims can be tested.

The rationale should also identify the agent’s contact with public officials. An intermediary who sells ordinary private-sector products presents a different profile from one who secures government contracts, obtains construction approvals, clears goods through customs, or manages tax disputes. The more direct and consequential the government interaction, the deeper the review should become.

Map The Agent’s Exposure

Due diligence begins with a clear description of the relationship. Identify the legal entity or individual being retained, its owners, directors, employees, subcontractors, affiliates, and intended payment recipients. Determine whether the agent will act in its own name, represent the company, use a local partner, or pass work to another intermediary.

The risk assessment should examine several dimensions at the same time:

  • Geographic exposure: country, region, city, and locations where services will occur.
  • Government contact: frequency, purpose, decision-making authority, and access to sensitive processes.
  • Transaction value: contract size, expected commissions, reimbursed expenses, and payment structure.
  • Service type: licensing, customs, public procurement, tender support, inspections, tax work, or ordinary sales.
  • Ownership and connections: government ownership, political exposure, family relationships, or links to customers.
  • Operational complexity: subcontractors, cash handling, offshore accounts, unusual invoicing, or multiple jurisdictions.

A low-risk agent may provide routine technical support to private customers, receive a fixed fee into a local corporate account, and have transparent ownership. A higher-risk agent may be introduced by a public official, demand a success fee, lack relevant experience, and request payment through an unrelated company. The second profile requires enhanced checks and potentially a decision not to proceed.

Compare Risk Signals Before Deciding

A practical assessment combines inherent risk with the strength of available controls. Inherent risk reflects the circumstances before safeguards are applied. Control strength reflects the company’s ability to reduce, detect, and respond to misconduct. A strong contract does not eliminate a high-risk relationship if the company cannot verify the agent’s work or monitor its payments.

Risk factor Lower-risk indicator Higher-risk indicator Proportionate response
Ownership Clear corporate records and identifiable beneficial owners Opaque ownership, nominees, or unexplained entities Obtain ownership documents and independent verification
Government interaction Limited, routine contact with public bodies Direct influence over permits, tenders, customs, or inspections Conduct enhanced background checks and approval
Experience Relevant references and documented market expertise No credible experience or recently formed business Validate qualifications, references, and work history
Compensation Fixed, reasonable fee tied to documented services Large success fee, cash request, or payment to a third party Benchmark fees and require transparent invoices
Geography Stable regulatory environment and familiar operating model High corruption exposure or complex local rules Use country research and stronger monitoring
Transparency Complete responses and prompt document sharing Evasive answers, inconsistencies, or refusal to certify Escalate, pause onboarding, or reject the relationship
Subcontracting Prior approval and named service providers Unapproved intermediaries or unexplained pass-throughs Require disclosure and audit rights

Country-level information can help prioritize questions, but it should not be used as a shortcut for judging every person or company in a jurisdiction. For example, the India country profile may help a review team understand broad governance and business-environment issues relevant to an Indian engagement. The team should then test those general indicators against the agent’s actual role, customer base, payment proposal, and public-sector contacts.

A useful scoring model can assign ratings such as low, medium, high, and critical to each factor. However, numerical scores should support professional judgment rather than replace it. One critical concern, such as a request to conceal the agent’s identity from a government customer, may outweigh several low-risk characteristics.

Verify Identity, Capability, And Connections

The company should obtain and verify core information directly from reliable sources. This normally includes the agent’s legal name, registration details, registered address, tax identification, ownership structure, directors, banking information, professional qualifications, and relevant employment history. Documents should be current and consistent across records.

Independent checks are important because documents supplied by the agent may be incomplete or misleading. Search corporate registries, court records, procurement databases, regulatory registers, sanctions and watchlist sources, reputable news archives, and specialist databases where appropriate. Check variations of names, translations, former entities, and related companies. Record the date, source, search terms, and results so another reviewer can reproduce the work.

Capability verification should focus on whether the agent can actually perform the proposed services. Speak with references who can describe specific assignments, deliverables, timelines, and payment arrangements. Review previous contracts, marketing materials, staff biographies, licenses, and evidence of sector knowledge. A well-connected person who cannot explain the work may be a conduit for influence rather than a legitimate service provider.

Connections to officials require careful handling. A government employee, political candidate, close relative of a public official, or former official is not automatically disqualified, but the relationship may create conflicts of interest or heightened bribery risk. Establish the nature, timing, and relevance of the connection, apply any required legal restrictions, and obtain approval from compliance and legal functions before proceeding.

Test Compensation And Conduct Controls

Payment design often reveals whether the arrangement is commercially credible. Fees should reflect the work, market conditions, qualifications, time required, and measurable results. A commission that is disproportionate to the contract value, a request for cash, or a demand for payment to a personal or offshore account should trigger escalation.

The agreement should describe the services in concrete terms and prohibit bribery, facilitation payments, improper gifts, undisclosed subcontracting, and false records. It should require compliance with applicable anti-corruption laws, permit termination for misconduct, and provide audit and information rights. The agent should certify ownership, conflicts of interest, government relationships, and the accuracy of invoices.

Controls should operate in practice rather than remain standard wording in a template. Business sponsors need to know what work was performed, which expenses were incurred, who attended meetings, and what deliverables were produced. Finance teams should match invoices to contract terms and supporting evidence. Compliance should review exceptions and investigate warning signs promptly.

Use the following controls when the risk assessment identifies meaningful exposure:

  • Require written pre-approval for gifts, hospitality, travel, charitable contributions, and political engagement connected with the work.
  • Pay only to an account held in the agent’s verified legal name, in a country connected to the engagement, unless a documented exception is approved.
  • Prohibit cash payments, vague expense claims, split invoices, and payments routed through unrelated companies.
  • Schedule periodic certifications, refreshed screening, and targeted training for the agent and relevant employees.
  • Escalate red flags to legal or compliance personnel before work continues or funds are released.

Training should be tailored to the agent’s actual activities. An intermediary dealing with customs officials needs practical guidance on facilitation-payment requests and documentation. An agent supporting public tenders needs rules on interactions with procurement officials, competitors, consultants, and politically exposed persons. Generic annual training may be insufficient for these situations.

Make Decisions And Keep Reviewing

The final approval should explain the evidence considered, the risk rating, unresolved issues, required controls, and the person accountable for oversight. Approval authority should match the level of risk. A routine engagement may be approved by a business manager and compliance reviewer, while a high-risk agent may require senior legal, compliance, or executive approval.

Some findings call for remediation before approval. The company might request missing ownership information, clarify a conflict, revise the payment structure, remove an unapproved subcontractor, or obtain stronger references. Other findings should lead to rejection, including credible evidence of bribery, falsified records, unexplained government influence, refusal to provide basic information, or demands that cannot be reconciled with company policy.

Due diligence is a continuing process. Re-screen the agent at intervals based on risk and when a significant event occurs, such as a change in ownership, new government contract, unusual payment request, regulatory investigation, adverse media, expansion into another country, or appointment of a new subcontractor. The review schedule should be documented rather than left to individual memory.

Monitoring should connect compliance information with commercial activity. Compare commissions with actual revenue, review expense patterns, examine unusual discounts, test deliverables, and look for sudden changes in bank accounts or invoicing entities. Employees who manage agents should have a clear reporting channel and should understand that commercial urgency does not suspend approval requirements.

Build An Evidence-Based Approval File

A complete file allows the company to demonstrate that it acted reasonably when appointing and supervising the intermediary. It should contain the business rationale, risk assessment, identity and ownership documents, screening results, reference checks, conflict declarations, compensation analysis, approvals, contract, training records, certifications, monitoring notes, and decisions about unresolved concerns.

The record should distinguish facts from assumptions. If a registry confirms ownership, cite the registry and date. If a reference gives a favorable opinion, identify the reference’s role and the substance of the conversation. If information cannot be verified, state that clearly and explain how the uncertainty affected the decision.

A useful file also records rejected candidates and terminated relationships. This helps identify recurring patterns, such as the same introducer proposing several opaque agents or repeated requests for payment outside approved channels. Trend analysis can reveal weaknesses in business-unit controls and guide future training or third-party screening.

Companies can make the process efficient by using tiered questionnaires and review paths. Low-risk relationships should not face unnecessary bureaucracy, while high-risk engagements should receive deeper investigation and senior scrutiny. The key is consistency: similar risk profiles should produce similar questions, approvals, and monitoring expectations.

Begin with the next proposed agent rather than waiting for an incident. Define the commercial need, map the agent’s exposure, verify the people and entities involved, challenge the payment model, and document the decision. When these steps become part of ordinary procurement and onboarding, third-party oversight becomes a practical business control rather than a last-minute compliance obstacle.

copyright © Global Advice Network