Global Advice Network
| Borgergade 111 | DK - 1300 Copenhagen K
|
|
|
|
Building a Risk-Based Review of Third-Party AgentsThird-party agents can help a company enter new markets, navigate local procedures, obtain permits, represent commercial interests, and manage relationships with public institutions. They can also create serious exposure when their activities involve government officials, state-owned enterprises, customs authorities, licensing bodies, or politically connected intermediaries. A sound review process does more than collect a passport copy and run a sanctions search. It evaluates why the agent is needed, what the agent will do, how the relationship will operate, and whether the proposed compensation and controls match the corruption risk. The objective is a defensible business decision based on evidence, proportionality, and ongoing oversight. Risk-based anti-corruption due diligence should also reflect the limits of available information. Country indicators, public records, and commercial databases are useful inputs, but they do not replace company-specific investigation. The methodology disclaimer is a useful reminder that external country and governance information should inform judgment rather than determine it automatically. Start With The Business RationaleThe first question is whether the proposed intermediary is genuinely necessary. A legitimate agent should perform a defined commercial or technical function that the company cannot reasonably conduct itself. Vague explanations such as “opening doors,” “handling relationships,” or “making things easier” deserve closer examination because they may conceal improper influence or unofficial payments. The business sponsor should prepare a short rationale before the agent is engaged. It should explain the market opportunity, the services required, the expected duration, the relevant customers or authorities, and why the proposed individual or firm has the appropriate capabilities. This document establishes a baseline against which later claims can be tested. The rationale should also identify the agent’s contact with public officials. An intermediary who sells ordinary private-sector products presents a different profile from one who secures government contracts, obtains construction approvals, clears goods through customs, or manages tax disputes. The more direct and consequential the government interaction, the deeper the review should become. Map The Agent’s ExposureDue diligence begins with a clear description of the relationship. Identify the legal entity or individual being retained, its owners, directors, employees, subcontractors, affiliates, and intended payment recipients. Determine whether the agent will act in its own name, represent the company, use a local partner, or pass work to another intermediary. The risk assessment should examine several dimensions at the same time:
A low-risk agent may provide routine technical support to private customers, receive a fixed fee into a local corporate account, and have transparent ownership. A higher-risk agent may be introduced by a public official, demand a success fee, lack relevant experience, and request payment through an unrelated company. The second profile requires enhanced checks and potentially a decision not to proceed. Compare Risk Signals Before DecidingA practical assessment combines inherent risk with the strength of available controls. Inherent risk reflects the circumstances before safeguards are applied. Control strength reflects the company’s ability to reduce, detect, and respond to misconduct. A strong contract does not eliminate a high-risk relationship if the company cannot verify the agent’s work or monitor its payments.
Country-level information can help prioritize questions, but it should not be used as a shortcut for judging every person or company in a jurisdiction. For example, the India country profile may help a review team understand broad governance and business-environment issues relevant to an Indian engagement. The team should then test those general indicators against the agent’s actual role, customer base, payment proposal, and public-sector contacts. A useful scoring model can assign ratings such as low, medium, high, and critical to each factor. However, numerical scores should support professional judgment rather than replace it. One critical concern, such as a request to conceal the agent’s identity from a government customer, may outweigh several low-risk characteristics. Verify Identity, Capability, And ConnectionsThe company should obtain and verify core information directly from reliable sources. This normally includes the agent’s legal name, registration details, registered address, tax identification, ownership structure, directors, banking information, professional qualifications, and relevant employment history. Documents should be current and consistent across records. Independent checks are important because documents supplied by the agent may be incomplete or misleading. Search corporate registries, court records, procurement databases, regulatory registers, sanctions and watchlist sources, reputable news archives, and specialist databases where appropriate. Check variations of names, translations, former entities, and related companies. Record the date, source, search terms, and results so another reviewer can reproduce the work. Capability verification should focus on whether the agent can actually perform the proposed services. Speak with references who can describe specific assignments, deliverables, timelines, and payment arrangements. Review previous contracts, marketing materials, staff biographies, licenses, and evidence of sector knowledge. A well-connected person who cannot explain the work may be a conduit for influence rather than a legitimate service provider. Connections to officials require careful handling. A government employee, political candidate, close relative of a public official, or former official is not automatically disqualified, but the relationship may create conflicts of interest or heightened bribery risk. Establish the nature, timing, and relevance of the connection, apply any required legal restrictions, and obtain approval from compliance and legal functions before proceeding. Test Compensation And Conduct ControlsPayment design often reveals whether the arrangement is commercially credible. Fees should reflect the work, market conditions, qualifications, time required, and measurable results. A commission that is disproportionate to the contract value, a request for cash, or a demand for payment to a personal or offshore account should trigger escalation. The agreement should describe the services in concrete terms and prohibit bribery, facilitation payments, improper gifts, undisclosed subcontracting, and false records. It should require compliance with applicable anti-corruption laws, permit termination for misconduct, and provide audit and information rights. The agent should certify ownership, conflicts of interest, government relationships, and the accuracy of invoices. Controls should operate in practice rather than remain standard wording in a template. Business sponsors need to know what work was performed, which expenses were incurred, who attended meetings, and what deliverables were produced. Finance teams should match invoices to contract terms and supporting evidence. Compliance should review exceptions and investigate warning signs promptly. Use the following controls when the risk assessment identifies meaningful exposure:
Training should be tailored to the agent’s actual activities. An intermediary dealing with customs officials needs practical guidance on facilitation-payment requests and documentation. An agent supporting public tenders needs rules on interactions with procurement officials, competitors, consultants, and politically exposed persons. Generic annual training may be insufficient for these situations. Make Decisions And Keep ReviewingThe final approval should explain the evidence considered, the risk rating, unresolved issues, required controls, and the person accountable for oversight. Approval authority should match the level of risk. A routine engagement may be approved by a business manager and compliance reviewer, while a high-risk agent may require senior legal, compliance, or executive approval. Some findings call for remediation before approval. The company might request missing ownership information, clarify a conflict, revise the payment structure, remove an unapproved subcontractor, or obtain stronger references. Other findings should lead to rejection, including credible evidence of bribery, falsified records, unexplained government influence, refusal to provide basic information, or demands that cannot be reconciled with company policy. Due diligence is a continuing process. Re-screen the agent at intervals based on risk and when a significant event occurs, such as a change in ownership, new government contract, unusual payment request, regulatory investigation, adverse media, expansion into another country, or appointment of a new subcontractor. The review schedule should be documented rather than left to individual memory. Monitoring should connect compliance information with commercial activity. Compare commissions with actual revenue, review expense patterns, examine unusual discounts, test deliverables, and look for sudden changes in bank accounts or invoicing entities. Employees who manage agents should have a clear reporting channel and should understand that commercial urgency does not suspend approval requirements. Build An Evidence-Based Approval FileA complete file allows the company to demonstrate that it acted reasonably when appointing and supervising the intermediary. It should contain the business rationale, risk assessment, identity and ownership documents, screening results, reference checks, conflict declarations, compensation analysis, approvals, contract, training records, certifications, monitoring notes, and decisions about unresolved concerns. The record should distinguish facts from assumptions. If a registry confirms ownership, cite the registry and date. If a reference gives a favorable opinion, identify the reference’s role and the substance of the conversation. If information cannot be verified, state that clearly and explain how the uncertainty affected the decision. A useful file also records rejected candidates and terminated relationships. This helps identify recurring patterns, such as the same introducer proposing several opaque agents or repeated requests for payment outside approved channels. Trend analysis can reveal weaknesses in business-unit controls and guide future training or third-party screening. Companies can make the process efficient by using tiered questionnaires and review paths. Low-risk relationships should not face unnecessary bureaucracy, while high-risk engagements should receive deeper investigation and senior scrutiny. The key is consistency: similar risk profiles should produce similar questions, approvals, and monitoring expectations. Begin with the next proposed agent rather than waiting for an incident. Define the commercial need, map the agent’s exposure, verify the people and entities involved, challenge the payment model, and document the decision. When these steps become part of ordinary procurement and onboarding, third-party oversight becomes a practical business control rather than a last-minute compliance obstacle. |