The Biggest Due Diligence Challenges And How To Overcome Them
Due diligence helps organisations make informed decisions and manage supplier and third-party risk. But fragmented processes, incomplete information, and increasingly complex supply chains can make it difficult to carry out consistently and efficiently.
Due diligence helps organisations make informed decisions and manage supplier and third-party risk. But fragmented processes, incomplete information, and increasingly complex supply chains can make it difficult to carry out consistently and efficiently.
For many organisations, the principles of due diligence are straightforward: gather the right information, verify it, assess the risks, and make an informed decision.
In practice, the process can be far more difficult.
Supplier information may be stored across questionnaires, emails, spreadsheets, and internal systems. Different teams may assess the same supplier independently. Documents can become outdated, regulations continue to evolve, and limited resources must be spread across growing supplier populations.
Recognising these challenges helps organisations understand where their processes need to improve - and where standardisation, collaboration, and technology can reduce the administrative burden.
Why Is Due Diligence So Challenging?
Due diligence often involves multiple suppliers, risk areas, internal teams, and sources of evidence.
Procurement may need to assess operational capability and financial stability. Cybersecurity teams need information about data and systems. Legal and compliance teams consider regulatory obligations, while sustainability teams review environmental and social practices.
Each function brings important expertise, but without a coordinated process, due diligence can become fragmented.
The challenge is not simply collecting more information. It is creating a process that provides the right information to the right teams at the right time.
Common Due Diligence Challenges
1. Incomplete Or Inaccurate Supplier Information
Due diligence depends on the quality of the information provided.
Suppliers may leave questions unanswered, misunderstand what is being requested, submit expired documents, or provide claims that are not supported by evidence.
This can happen because:
-
Questions are unclear or overly technical
-
The supplier does not understand why the information is needed
-
Responsibility is spread across several supplier teams
-
Required policies or evidence are not readily available
-
The same information is requested in different formats
-
Documents and company details have changed
Incomplete information creates delays and makes it difficult to form a reliable view of risk.
How To Overcome It
Use clear, proportionate questionnaires with guidance explaining what is required.
Define evidence standards and check that responses are complete, current, and consistent. Where important information is missing or contradictory, follow up with the supplier rather than making assumptions.
Human validation can also help identify errors, clarify responses, and improve the quality of the evidence available to decision-makers.
2. Time-Consuming Manual Processes
Many organisations still manage due diligence through spreadsheets, emails, shared folders, and manually updated trackers.
These processes may appear manageable for a small number of suppliers but become increasingly difficult to maintain as the supplier population grows.
Teams can spend significant time:
-
Sending questionnaires
-
Chasing responses
-
Checking whether documents have been received
-
Moving information between systems
-
Tracking approvals
-
Monitoring expiry dates
-
Updating risk registers
-
Preparing audit evidence
This reduces the time available for analysing risks and addressing significant concerns.
How To Overcome It
Standardise repeatable tasks and centralise supplier information where possible.
Technology can support questionnaire distribution, document management, expiry tracking, workflow coordination, and reporting. External validation and supplier support can further reduce the amount of administrative work carried out internally.
The aim should be to free specialist teams to focus on interpreting findings and making decisions.
3. Duplicated Questionnaires And Evidence Requests
Suppliers are often asked for similar information by multiple customers - and sometimes by several teams within the same customer organisation.
Procurement, cybersecurity, legal, compliance, TPRM, and sustainability teams may each issue separate questionnaires covering overlapping areas.
This creates:
-
Repeated effort for suppliers
-
Longer response times
-
Inconsistent versions of the same information
-
Frustration across the relationship
-
Additional review work for internal teams
-
Greater risk of outdated or contradictory answers
Duplicated requests add volume without necessarily improving assurance.
How To Overcome It
Bring internal requirements into a coordinated due diligence framework.
A shared evidence base allows each function to apply its own expertise, thresholds, and decisions while working from the same supplier information.
Shared assurance can extend this approach across multiple buying organisations by collecting and validating common information once rather than asking each supplier to repeat the same process.
4. Inconsistent Assessment Criteria
Due diligence decisions can vary when different teams, departments, or business units use their own questionnaires, risk ratings, and approval standards.
One supplier may be considered acceptable by one team but high-risk by another - not because the relationship is different, but because the assessment methods are inconsistent.
This makes it difficult to:
-
Compare suppliers fairly
-
Explain decisions
-
Apply risk appetite consistently
-
Escalate concerns appropriately
-
Demonstrate effective governance
How To Overcome It
Create a common due diligence framework with defined:
-
Risk categories
-
Evidence requirements
-
Assessment criteria
-
Scoring methods
-
Approval thresholds
-
Escalation routes
-
Review frequencies
Specialist teams should retain ownership of decisions within their areas, but their assessments should form part of a consistent overall process.
5. Applying The Same Process To Every Supplier
A standardised process does not mean every supplier should receive the same assessment.
Requiring a small, low-risk supplier to complete the same extensive questionnaire as a critical technology provider can create unnecessary work. At the same time, a basic assessment may not provide enough assurance for a supplier supporting essential operations.
A one-size-fits-all process can:
-
Overburden smaller suppliers
-
Slow down low-risk onboarding
-
Consume internal resources
-
Hide the most significant risks within excessive information
-
Fail to provide enough scrutiny for critical relationships
How To Overcome It
Apply a risk-based approach.
Classify suppliers using factors such as:
-
Service criticality
-
Contract value and duration
-
Access to systems or sensitive information
-
Regulatory exposure
-
Geographic location
-
Use of subcontractors
-
Availability of alternative suppliers
-
Potential impact of failure
The supplier’s classification should determine which questions, evidence, specialist reviews, and monitoring arrangements are required.
6. Keeping Up With Regulatory Change
Due diligence requirements continue to evolve as new regulations, standards, and stakeholder expectations emerge.
Changes may affect areas such as:
-
Data protection
-
Cybersecurity
-
Operational resilience
-
Modern Slavery
-
ESG reporting
-
Anti-bribery and corruption
-
Sanctions
-
Supply chain security
Organisations must understand which changes apply, update their requirements, and obtain additional evidence from relevant suppliers.
This can be particularly difficult when different departments track changes independently or when requirements vary between industries and countries.
How To Overcome It
Assign clear responsibility for monitoring regulatory developments and translating them into due diligence requirements.
Review questionnaires and assessment standards regularly, communicate changes across internal teams, and apply new requirements proportionately.
Working through an industry community can also help organisations align on common challenges and develop shared assurance standards together.
7. Fragmented Ownership Across Internal Teams
Due diligence rarely belongs to one function.
Procurement may coordinate supplier engagement, but finance, legal, compliance, cybersecurity, operations, and sustainability teams may all need to contribute.
Without clear ownership:
-
Suppliers receive conflicting requests
-
Reviews become delayed
-
Actions remain incomplete
-
Risks fall between teams
-
Approval decisions become unclear
-
No one owns ongoing monitoring
How To Overcome It
Define responsibilities across the complete supplier lifecycle.
Clarify:
-
Who coordinates the assessment
-
Who reviews each risk area
-
Who communicates with the supplier
-
Who can approve exceptions
-
Who owns remediation actions
-
Who makes the final decision
-
Who monitors the supplier after approval
A single coordinated process can support different specialist reviews without removing functional accountability.
8. Monitoring Suppliers After Onboarding
Due diligence is often concentrated at the beginning of a relationship.
Once the supplier has been approved and the contract signed, information may not be reviewed again until renewal - or until a problem occurs.
During that time:
-
Financial stability can deteriorate
-
Ownership can change
-
Certifications can expire
-
New cyber vulnerabilities can emerge
-
Subcontractors can be introduced
-
Regulations can change
-
Service performance can decline
A one-off assessment provides only a snapshot of the supplier’s risk.
How To Overcome It
Combine scheduled reviews with event-triggered monitoring.
Review frequency should reflect the supplier’s risk and criticality. Organisations should also reassess a supplier when material changes or warning signs emerge.
Potential triggers include:
-
Financial deterioration
-
Cyber incidents
-
Regulatory enforcement
-
Adverse media
-
Ownership changes
-
Expired certifications
-
Service failures
-
New subcontractors
-
Changes to data or system access
This helps organisations identify changes earlier and respond before they develop into significant problems.
9. Managing Large Supplier Populations
As supplier populations grow, it becomes difficult to apply meaningful due diligence to every relationship using manual processes.
Teams may face:
-
Thousands of supplier records
-
Large volumes of supporting documents
-
Different review schedules
-
Multiple outstanding actions
-
Limited specialist resources
-
Inconsistent information across business units
Trying to apply the same level of scrutiny to every supplier can overwhelm internal teams.
How To Overcome It
Create a complete supplier inventory and segment suppliers by risk and criticality.
Prioritise intensive assessment and monitoring for suppliers whose failure would have the greatest impact. Use lighter, standardised processes for lower-risk relationships.
Centralised information and automated workflow support can help teams manage larger populations without losing visibility.
10. Limited Visibility Of Subcontractors And Fourth Parties
A direct supplier may depend on other organisations to deliver its services.
These fourth parties could include cloud providers, manufacturers, logistics partners, offshore service centres, and specialist subcontractors.
The buying organisation may have no direct contract with these providers, but their failure can still cause disruption, data exposure, or compliance problems.
Limited visibility makes it difficult to understand:
-
Where critical dependencies exist
-
Who can access sensitive information
-
Where products or services are delivered
-
Whether common providers create concentration risk
-
How lower-tier risks are assessed and monitored
How To Overcome It
Require higher-risk suppliers to disclose material subcontractors and explain how they assess and oversee them.
Focus on fourth parties supporting critical services, processing sensitive data, or introducing material operational, regulatory, or reputational risk.
Contracts should also define notification and approval requirements when important subcontracting arrangements change.
11. Supplier Fatigue And Poor Engagement
Lengthy, repeated, or irrelevant questionnaires can make due diligence frustrating for suppliers.
Smaller suppliers may not have dedicated compliance teams or extensive policy libraries. They may struggle to interpret questions designed for much larger organisations.
Poor supplier engagement can result in:
-
Delayed responses
-
Incomplete questionnaires
-
Low-quality evidence
-
Repeated clarification
-
Strained relationships
-
Suppliers choosing not to participate
How To Overcome It
Make requirements clear, relevant, and proportionate.
Explain why information is needed, provide practical guidance, and give suppliers access to human support where possible.
A better supplier experience improves response quality while helping capable organisations demonstrate their controls without unnecessary barriers.
12. Weak Audit Trails And Decision Records
Due diligence evidence is often spread across emails, shared folders, spreadsheets, and individual systems.
Even when appropriate checks have been completed, organisations may struggle to demonstrate:
-
What information was reviewed
-
Whether it was validated
-
Which risks were identified
-
Who approved the supplier
-
Why an exception was accepted
-
Whether remediation was completed
-
When the supplier should be reassessed
This makes internal reviews, audits, and regulatory enquiries more difficult.
How To Overcome It
Maintain a structured record of the assessment, findings, actions, approvals, and review dates.
Decision records should explain the rationale - not simply state that a supplier passed or failed.
A central evidence base makes it easier to trace decisions and demonstrate that a consistent process was followed.
13. Collecting Too Much Information
More information does not always create better assurance.
Extensive questionnaires can generate large volumes of evidence that internal teams do not have the time or expertise to review properly.
This can make significant risks harder to identify while creating the impression that due diligence is complete simply because many questions have been answered.
How To Overcome It
Ensure each question supports a defined risk assessment or decision.
Remove duplicated or unnecessary requests and focus detailed evidence requirements on material risks.
A smaller amount of relevant, validated information is often more useful than a large volume of unreviewed documentation.
14. Failing To Track Remediation
Due diligence frequently identifies gaps that do not prevent immediate approval but still require improvement.
If remediation actions are managed informally, they can remain unresolved long after the supplier has been onboarded.
Common problems include:
-
No clear owner
-
Unclear deadlines
-
Missing evidence requirements
-
Temporary risk acceptance becoming permanent
-
Actions not being reviewed at renewal
How To Overcome It
Record each remediation action with:
-
The issue and associated risk
-
The improvement required
-
The responsible owner
-
A completion date
-
Evidence needed for closure
-
Interim controls
-
An escalation route
Approval conditions should remain visible until the actions have been verified and formally closed.
How To Build A More Effective Due Diligence Programme
Many due diligence challenges are connected.
Incomplete information creates more manual follow-up. Fragmented ownership produces duplicated requests. Inconsistent criteria make large supplier populations harder to manage. Weak monitoring allows information to become outdated.
A more effective programme should combine:
-
A complete supplier and third-party inventory
-
Risk-based segmentation
-
Standardised assessment criteria
-
Proportionate questionnaires
-
Validated supplier information
-
Clear internal ownership
-
Coordinated cross-functional reviews
-
Documented decisions and remediation
-
Ongoing monitoring
-
A common source of supplier evidence
The objective is to reduce administrative friction while improving the quality of the information used to make decisions.
How Technology Can Help
Technology can support more scalable due diligence by helping organisations:
-
Centralise supplier information
-
Standardise questionnaires
-
Adapt questions according to risk
-
Track documents and expiry dates
-
Coordinate reviews and approvals
-
Monitor changes and warning signs
-
Manage remediation actions
-
Maintain audit trails
-
Report across large supplier populations
However, technology alone cannot resolve poor-quality information or unclear processes.
The strongest approach combines appropriate systems with consistent standards, supplier support, expert validation, and clear human decision-making.
How Shared Assurance Addresses Due Diligence Challenges
In a traditional model, every organisation collects and reviews similar information from the same suppliers independently.
Shared assurance replaces much of this duplication with a common evidence base.
Supplier information is collected, validated, and maintained once before being made available to participating buying organisations.
This can help address several common challenges by:
-
Reducing repeated questionnaires
-
Improving information quality
-
Applying consistent assurance requirements
-
Reducing manual follow-up
-
Giving internal teams access to the same evidence
-
Supporting ongoing information updates
-
Improving the supplier experience
-
Helping assurance processes scale
Buying organisations continue to apply their own risk appetite, specialist judgement, and approval decisions. Shared assurance reduces the administrative work required to reach those decisions.
Key Takeaway: Better Due Diligence Is About Quality, Not Volume
The biggest due diligence challenges often come from fragmented processes, duplicated effort, inconsistent standards, and unreliable information.
Solving these problems does not require organisations to ask more questions. It requires a clearer, more proportionate process built around trusted information, defined responsibilities, and ongoing visibility.
By standardising common requirements and focusing resources on material risks, organisations can make due diligence more efficient, scalable, and valuable.
Spending more time chasing information than assessing risk?
Hellios collects, validates, and maintains supplier information on behalf of its communities - reducing duplicated effort and taking a significant portion of the administrative work off your teams.
Spend less time following up on questionnaires and documents, and more time managing the risks that matter.
