No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Featured

3 Important Points to Remember About Third-Party Risks

by Michael Volkov
February 28, 2018
in Featured, Risk
concept of due diligence stopping domino effect

How Much Due Diligence is Enough?

It’s easy to get in over one’s head when conducting third-party due diligence. How deep is it necessary to dive to ensure your vendors and suppliers are doing business above board? Michael Volkov provides some expert insight into what “due diligence” means – and what it doesn’t.

If you want to learn and read about managing third-party risks, you will have no trouble finding articles, white papers, webinars and more available to you on the internet.  And for good reason.

Third parties create significant risks, and these risks are not just limited to bribery; they extend into sanctions, money laundering, privacy and cybersecurity, human trafficking, child labor and reputational damage.  The compliance marketplace offers lots of solutions, including automation, due diligence, risk ranking and a host of alternative solutions.

Before you leap into the due diligence world, however, it is important to understand exactly what you are trying to accomplish and why you need to tailor your solutions to your specific needs.

When assessing the issue, there are three important points to understand about due diligence:

What is the Legal Standard?

The term “due diligence” is defined to mean “reasonable inquiries.”  I know that sounds like mumbo jumbo, but it is important to recognize what “reasonable inquiries” does not mean.  As an attorney and a former prosecutor, I know the importance of focusing on burdens of proof — “reasonable inquiries” does not mean “beyond a reasonable doubt,” nor does it mean by a “preponderance of evidence.”  In fact, the standard of “reasonable inquiries” means reasonable questions and follow-up.  It does not mean boil the ocean.

Life always depends on context, and so does due diligence.  A reasonable inquiry in one circumstance may not be reasonable in another.  Everything has to be assessed through the eyes of relevant risks.  Adjusting your due diligence review of a third party to the specific risk profile is imperative.

Agents/Distributors v. Vendors/Suppliers

The FCPA expressly prohibits corrupt payments made through third parties or intermediaries. Specifically, it covers payments made to “any person, while knowing that all or a portion of such money or thing of value will be offered, given or promised, directly or indirectly,” to a foreign official.  The “knowing” requirement includes a representational component, meaning that a person who receives payment (i.e., a third-party) must be acting on behalf of the payor of the money.  If I make a payment to someone who is representing me and I know that the person will be paying a foreign official on my behalf, I am liable for that bribe.

On the other hand, if I pay a vendor who is not representing me or acting on my behalf for a good or service, and that vendor pays a bribe to further its business (not necessarily just mine, but for his overall business operations), then I am not liable for the bribe paid by the vendor.

As an example, if my company buys potato chips from a vendor (along with thousands of other companies in a specific country) and the vendor ends up paying a bribe to customs officials in that country to favor its shipments, as a customer of the vendor, I am not liable for the vendor’s bribery payments, because the vendor is not acting on my behalf.

That does not mean you can ignore the risks created by your vendors and suppliers.  On the contrary; vendors and suppliers pose many risks and are often involved in bribery or fraud schemes.  My point is that vendors and suppliers, in the absence of a specific representational function, do not create classic bribery risks, and they should be screened in accordance with this risk profile.

Third-Party Professionals

The third-party universe includes professionals.  As we have seen in the anti-corruption world, bribes can be paid by lawyers, tax professionals, lobbyists and consultants.  These representatives act on behalf of their client companies and therefore create potential corruption risks.

A foreign law firm should be screened like any other third-party candidate based on the specific risks involved. Moreover, law firms should be subject to the same controls, invoicing requirements, description of services and fees that are commensurate with the specific project and the market.

History is replete with instances where lobbyists have been used (and continue to be used) to funnel illegal payments to government officials (e.g., Abscam and Abramoff, just to name a few). For that reason, lobbyists in foreign countries may create significant corruption risks and should be subjected to a commensurate level of controls.

This article was republished with permission from Michael Volkov’s blog, Corruption, Crime & Compliance.

Tags: Third Party Risk Management
Previous Post

Don’t Put All Your Compliance Eggs in the MiFID II Basket

Next Post

TRACE: White House Ethics Czar

Michael Volkov

Michael Volkov

Michael-Volkov-leclairryan Michael Volkov is the CEO of The Volkov Law Group LLC, where he provides compliance, internal investigation and white collar defense services.  He can be reached at mvolkov@volkovlaw.com. Michael has extensive experience representing clients on matters involving the Foreign Corrupt Practices Act, the UK Bribery Act, money laundering, Office of Foreign Asset Control (OFAC), export controls, sanctions and International Traffic in Arms, False Claims Act, Congressional investigations, online gambling and regulatory enforcement issues. Michael served for more than 17 years as a federal prosecutor in the U.S. Attorney’s Office in the District of Columbia; for five years as the Chief Crime and Terrorism Counsel for the Senate Judiciary Committee, and Chief Crime, Terrorism and Homeland Security Counsel for the Senate and House Judiciary Committees; and as a Trial Attorney in the Antitrust Division of the U.S. Department of Justice. Michael also maintains a well-known blog: Corruption Crime & Compliance, which is frequently cited by anti-corruption professionals and professionals in the compliance industry.

Related Posts

Ethixbase360 TPRM Volatility

Third-Party Risk in an Age of Engineered Volatility & Fragmentation

by Corporate Compliance Insights
June 2, 2026

How to stay resilient as regulatory, geopolitical and tech pressures rise eBook Third-Party Risk in an Age of Engineered Volatility...

forced labor

The EU Is Making Forced Labor a Trade Compliance Problem, Not Just an ESG Issue

by Allison Raley and Nikita Kulkarni
May 20, 2026

Most forced labor compliance frameworks ask companies to publish statements and describe their policies. The EU's new forced labor regulation...

Ethixbase360 Third Party Cyber Risk

A Practical Guide to Third-Party Cyber Risk Management

by Corporate Compliance Insights
May 8, 2026

A practical, business-focused look at third-party cyber risk as the natural next step in TPRM eBook A Practical Guide to...

Ethixbase360 2026 Pharma Guidebook

2026 Outlook: Navigating Third-Party Risk in the Pharmaceutical & Life Sciences Sector

by Corporate Compliance Insights
May 8, 2026

Stay ahead of regulatory change and position TPRM as competitive advantage 2026 outlook Navigating Third-Party Risk in the Pharmaceutical and...

Next Post
TRACE: White House Ethics Czar

TRACE: White House Ethics Czar

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights