Global Advice Network | Borgergade 111 | DK - 1300 Copenhagen K
E-Mail: info@business-anti-corruption.org | Phone: (+45) 60 88 10 44

Using Open Source Intelligence for Pre-Transaction Corruption Screening

A merger, acquisition, joint venture, distributor appointment, or major procurement agreement can expose a company to corruption risks that are difficult to identify through questionnaires alone. A prospective partner may appear financially sound while concealing government connections, sanctions concerns, conflicted intermediaries, or a history of regulatory scrutiny.

Open source intelligence (OSINT) helps compliance teams examine these risks before a transaction becomes difficult to unwind. It involves collecting and evaluating information that is publicly available, including corporate records, court documents, regulatory announcements, credible journalism, procurement data, and professional biographies.

The value of OSINT is not the volume of information discovered. It is the disciplined process used to establish identity, identify warning signs, test explanations, and record why a risk-based decision was made. Used properly, open source research strengthens formal due diligence rather than replacing it.

Why Public Information Matters Before a Deal

Pre-transaction corruption screening is designed to identify risk before a company commits capital, grants access to markets, or enters a relationship that may be interpreted as an agency arrangement. A target or business partner can create exposure through its owners, directors, consultants, agents, subsidiaries, or close relationships with public officials.

Public information often provides the first indication that enhanced due diligence is necessary. A local news report may reveal an investigation involving a proposed intermediary. A government database may show that the counterparty repeatedly wins contracts from one public entity. A corporate registry may disclose a shareholder that was absent from the company’s questionnaire. None of these findings automatically proves misconduct, but each can change the level of scrutiny required.

OSINT is especially useful where records are fragmented across jurisdictions. Companies operating internationally may need to compare corporate registries, court systems, tender portals, parliamentary records, regulator websites, and local-language media. Country context also matters because the availability, reliability, and legal significance of public records differ significantly between markets.

Define The Research Scope First

A successful investigation begins with a clear research question. The team should identify the transaction, the entities involved, relevant individuals, countries, industries, and the specific corruption risks that matter. Searching without a defined scope encourages inconsistent results and makes it difficult to demonstrate that the review was proportionate.

The initial data set should include the counterparty’s legal name, trading names, former names, registration numbers, addresses, websites, subsidiaries, parent companies, directors, beneficial owners, and known representatives. Researchers should also collect alternate spellings and transliterations, particularly when names move between Latin and non-Latin alphabets.

The research period should be documented. A company may need to examine current information, historical ownership, prior contracts, and earlier investigations. Search terms should cover bribery, kickbacks, fraud, procurement, conflict of interest, facilitation payments, political donations, money laundering, debarment, and relevant local-language equivalents.

The team should define escalation thresholds before reviewing results. For example, an unresolved allegation in a low-quality source may require confirmation, while a final court judgment, official enforcement action, or unexplained government affiliation may justify enhanced due diligence immediately.

Use Diverse Sources And Search Techniques

Reliable OSINT combines several source categories rather than relying on a single search engine result. Corporate registries can help verify incorporation, directors, ownership changes, and registered addresses. Government procurement portals may reveal contract patterns, tender awards, and relationships with state-owned enterprises. Court and regulator databases can provide information about enforcement actions, settlements, licensing decisions, and disqualifications.

Reputable media is useful for discovering allegations, investigations, and local context, particularly when official records are difficult to access. However, media reports should be assessed for editorial standards, named sources, publication date, corrections, and whether the report distinguishes allegations from established facts. Professional networking pages and company websites can assist with identity resolution, but they should not be treated as authoritative proof of ownership or qualifications.

Search techniques should be systematic. Researchers can combine a person’s name with the company, country, public body, or terms such as “investigation,” “contract,” or “bribery.” Searches using former company names and old addresses can uncover historical events that current branding obscures. Reverse checks of telephone numbers, email domains, and physical addresses may reveal undisclosed links between supposedly independent entities.

Country-level resources help put findings into context. The Business Anti-Corruption Portal provides country risk profiles, legislation guidance, compliance resources, and practical material that can support a broader risk assessment. Such information should inform the research plan without being used as a substitute for entity-specific verification.

Source category Useful indications Key limitations
Corporate registries Directors, shareholders, registration history, addresses Beneficial ownership may be incomplete or outdated
Procurement portals Public contracts, repeat awards, tender concentration Data quality and publication practices vary
Courts and regulators Judgments, investigations, penalties, licensing action Records may be difficult to search or available only locally
Reputable media Allegations, investigations, political and commercial context Reports may contain unproven claims or errors
Company and professional profiles Business activities, biographies, offices, relationships Information may be promotional, self-reported, or manipulated
Sanctions and debarment lists Formal restrictions and exclusions Absence from a list does not prove low corruption risk

Separate Red Flags From Verified Facts

A red flag is a reason to ask further questions, not a final finding. For example, a director who previously held a senior government role may create a politically exposed person risk, but the legal and compliance implications depend on the role, timing, jurisdiction, transaction, and applicable law. Similarly, a public contract awarded to a counterparty may be routine or may indicate an undisclosed government relationship.

Every relevant result should be classified by source quality and evidentiary status. A useful record distinguishes between confirmed facts, credible allegations, unresolved inconsistencies, contextual indicators, and information that could not be verified. This prevents researchers from presenting speculation as misconduct and helps decision-makers understand the actual basis for escalation.

Identity resolution is a central control. Common names, similar company names, copied biographies, and inconsistent translations can lead to false matches. Researchers should compare dates of birth where lawfully available, employment history, locations, registration numbers, corporate affiliations, and other identifiers. A potential match should remain unconfirmed until enough independent details align.

The review should preserve the original source, access date, relevant quotation or excerpt, search terms, translation method, and researcher’s assessment. Screenshots or downloaded copies may be necessary when pages are likely to change. Records should be stored securely because OSINT files can contain personal data, sensitive allegations, and commercially confidential transaction information.

Interpret Corruption Risk In Context

The meaning of a finding depends on the transaction and the market. An intermediary seeking a success fee for a government-facing project presents a different risk profile from a supplier selling standard goods through a private distributor. Risk increases where a third party has vague services, unusual compensation, offshore payment instructions, weak qualifications, close public-sector connections, or a history of winning government work without transparent competition.

Researchers should examine relationships, not just names on watchlists. A counterparty may be connected to a public official through a family member, former employer, business associate, charity, political organization, or shared company address. These connections require careful verification and should be documented neutrally. The existence of a relationship is not proof that an improper payment occurred.

Local context can reveal why a structure deserves attention. In some markets, nominee directors, informal ownership arrangements, or politically connected conglomerates are common features of the business environment. Their presence may still require controls, but an effective assessment distinguishes ordinary local practice from arrangements that conceal control, influence, or payment flows.

The decision should be proportionate to the combined risk. A credible enforcement action, concealed beneficial owner, and proposed government-facing role may justify pausing the transaction. Several minor inconsistencies may call for clarification and additional documents. A clean search should be recorded as a limited result, since public sources cannot establish that no misconduct exists.

Connect Findings To Governance And Due Diligence

OSINT should feed into a formal workflow with clear ownership. Compliance, legal, procurement, finance, security, and the transaction team may each hold relevant information. One person should be responsible for coordinating the review, resolving contradictions, approving escalations, and ensuring that the final decision is documented.

The responsibilities of the compliance function become especially important in mid-sized multinational enterprises, where resources may be limited and business teams may manage relationships directly. Guidance on the compliance officer’s role can help organizations clarify oversight, reporting lines, training responsibilities, and escalation arrangements before a transaction reaches approval.

A negative or inconclusive result should not automatically end the review. The company may request ownership charts, government-contact disclosures, litigation records, licenses, references, invoices, proposed scopes of work, and explanations for adverse media. It may interview the counterparty and require representations, audit rights, payment restrictions, anti-corruption commitments, and termination rights in the agreement.

If material concerns remain unresolved, the transaction should be escalated to an appropriately senior decision-maker. The record should explain the issue, the evidence, the counterparty’s response, the residual risk, and the reason for proceeding, delaying, redesigning, or rejecting the relationship. This creates an auditable connection between intelligence and business action.

Build A Repeatable Screening Practice

A repeatable process makes open source research more reliable and less dependent on individual judgment. It should define who searches, which sources are acceptable, how local-language research is handled, how adverse information is rated, and when enhanced due diligence is mandatory. Procedures should also address privacy, data retention, lawful processing, and restrictions on intrusive investigation methods.

Training matters because researchers can unintentionally create risk by copying unverified accusations, accessing personal information without a legitimate purpose, or ignoring information that does not fit an initial assumption. Staff should understand confirmation bias, source reliability, translation limitations, and the difference between a politically exposed person indicator and evidence of corruption.

Practical controls can include:

  • Use a standard identity and ownership profile for every counterparty and connected individual.
  • Search current and historical names across corporate, regulatory, court, procurement, and media sources.
  • Record source quality, publication dates, access dates, search terms, and unresolved contradictions.
  • Obtain a documented response to material adverse information before approving the relationship.
  • Set review dates so that high-risk partners are screened again during the relationship.

The process should continue after signing. Ownership can change, a consultant can take a public appointment, or a distributor can begin pursuing government contracts. Periodic rescreening, transaction monitoring, contract certifications, targeted audits, and employee reporting channels help detect new risks that were not visible during the original review.

A disciplined OSINT program gives decision-makers a clearer view of who stands behind a prospective partner and how that partner operates. It supports informed negotiation, stronger contractual protections, and earlier escalation when warning signs appear. It also demonstrates that the company applied a reasoned, risk-based process rather than treating a completed questionnaire as proof of integrity.

Make open source research a defined stage of every material transaction. Assign responsibility, preserve evidence, verify identities, investigate meaningful red flags, and connect the result to an approval decision. Use credible public information as the starting point for deeper due diligence and as an ongoing compliance control throughout the business relationship.

copyright © Global Advice Network