No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

To Drive Due Diligence and Compliance, Don’t Overburden Your Suppliers

Robust due diligence can make life easier for vendors

by Dean Alms
July 10, 2023
in Compliance, Risk
supplier burden

Satisfying third-party due diligence and compliance requirements can be time-consuming, especially for your suppliers — and global regulations around supply chain due diligence are only growing. Aravo’s Dean Alms offers his advice: Make things easier on your suppliers, not harder.

Bribery and corruption, cybersecurity attacks and data spills, ESG concerns, geopolitical shifts and manmade or natural disasters pose complex and enduring risks to a company’s extended enterprise. Governing bodies at the state, national and international level have passed supply-chain and third-party due-diligence laws and regulations to mitigate these risks, with more on the horizon.

You, your suppliers and their suppliers may operate in multiple markets that have new or changing regulations and compliance expectations. Thus, it’s critical to remain vigilant and align with evolving anti-bribery and corruption (ABAC), financial reporting, cybersecurity and data privacy, ESG and trade laws, regulations and standards across global jurisdictions. 

Teams that manage risk and drive compliance should build and foster collaborative relationships with their supplier base and digitally enable each other to be reciprocal, transparent and efficient. As a result, these relationships will not only help fulfill their statutory obligations but also help their business needs and support enduring partnerships.

semitrucks
Compliance

Tracking Down Emissions When They’re Buried in Your Supply Chain

by Sarah Carpenter
February 22, 2023

Manufacturers are pressed from all sides to prove their environmental bona fides, but given the nature of manufacturing-related emissions, that means making sure their global supply chains are environmentally conscious. Assent’s

Read moreDetails

As supply chain risks and cyber threats rise, so do regulations

It’s our responsibility as corporate and global citizens to do what we can to drive positive change where we can to combat corruption, cyber risks, environmental exploitation and social injustice from within our extended supply chains. Complying in good faith with laws and regulations is part of this responsibility.

Examples of ESG due diligence laws include the U.S. Uyghur Forced Labor Prevention Act (UFLPA), the German Supply Chain Due Diligence Act (LkSG), the EU’s Corporate Sustainability Reporting Directive (CSRD) and recently enacted Canadian forced labor and child labor law. Add to that the pending disclosure rule changes from the SEC and International Sustainability Standards Board, which are expected to require more publicly traded companies to report their Scope-3 emissions. 

While ESG risks have risen, so have cybersecurity threats. Today, more than 80% of chief information officers say their software supply chains are vulnerable to cyber attacks. In this area, too, government agencies have acted, including a series of presidential executive orders and new electrical system standards — and proposed SEC regulations in the financial services sector.

And this is to say nothing of the continuing geopolitical tensions that ramp up the strain on supply chains, including Russia’s war in Ukraine, Chinese economic espionage and human rights abuses and malign Iranian actions in the Middle East, all of which have earned those countries economic and political sanctions along with trade embargoes and restrictions.

To drive compliance, carrots work better

How can companies comply with more supply chain laws and regulations to mitigate risks and drive continuous improvement throughout their value chains? How should they address their suppliers’ and vendors’ compliance obligations to fulfill their own legal or regulatory requirements?

To be sure, the answer isn’t simply to dump all the work off to your suppliers. Here are some best practices to drive due diligence and compliance without driving either you or your suppliers to your breaking points.

Nail initial supplier due diligence: Conduct a comprehensive initial assessment and obtain industry and third-party certifications, audits, supplier surveys and past performance evaluations. This approach establishes a strong foundation for both you and the supplier, benefiting future periodic reassessments and compliance with relevant laws and regulations.

Incorporate compliance KPIs into supplier performance management: Integrate regulatory compliance into ongoing performance management with suppliers. Establish, manage and assess adherence to relevant laws and regulations (e.g., FCPA, UFLPA, LkSG) by incorporating them into measurable KPIs for supplier accountability and maintaining legal standing.

Supplement initial due diligence reports with risk intelligence data: Ensure that the solution being used to manage supplier risks incorporates real-time insights to streamline onboarding and enrich risk reviews. This helps the organization prioritize third parties that represent the highest risk to the business.

Continuously monitor third parties to stay informed and vigilant: Continuous monitoring offers early warnings for potential risks to the business, facilitating prompt corrective actions with suppliers and accelerating supply chain resiliency.

The responsible path for most companies building a TPRM program for their extended enterprise is to think big, start small and grow fast. Think big and design a program accordingly, so you don’t end up with multiple fragmented solutions that lack visibility, data integrity, and clarity over your overall risk. Start small, as ESG, cybersecurity, and other risk areas will heighten, and applicable regulations will change. Grow fast by incrementally expanding your risk domains as needed. Finally, plan to build agile and resilient capabilities as you move through various maturity levels with your TPRM program, tracking success, delivering performance metrics and impacting the business. 

Tags: Due DiligenceSupply Chain
Previous Post

2023 Risk & Compliance Benchmark Report

Next Post

Why a Structured Program Is the Only Way to Reach Your Data Privacy Potential

Dean Alms

Dean Alms

Dean Alms is the chief product officer for Aravo overseeing product strategy, management, marketing and product design. He recently joined Aravo to build an organization that would expand the product portfolio and market reach of industry-leading apps in third-party risk management.

Related Posts

shipping containers port of los angeles

What Antitrust’s Indirect-Purchaser Doctrine Can Teach Tariff Refund Litigants

by Steve Safranski and Alexander Rosselli
July 17, 2026

Establishing Article III standing and showing the cost of the damages may prove tough for consumers

hand checking off checklist

10 Questions Every Organization Should Ask a Potential AI Vendor

by Angela Juneau
July 15, 2026

Adopting AI without understanding how it was built and how it handles data can expose an organization to risks that...

shipping containers in port aerial view

Redesigning the Trade Compliance Operating Model for an Era of Structural Disruption

by Alyson Potenza, Emal Ehsan & Sydney Hurst
June 22, 2026

The combination of global volatility and overwhelming data presents a challenge multinationals must contend with

merger and acquisition concept two hands

Deal Scrutiny is Changing the Role of GRC Leaders

by Matt Hillary
June 12, 2026

The expectations placed on cybersecurity and risk change quickly once diligence begins

Next Post
data privacy cameras watching

Why a Structured Program Is the Only Way to Reach Your Data Privacy Potential

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights