The Different Types Of Due Diligence Explained
Due diligence is not a one-size-fits-all process. Organisations must examine different areas of risk depending on the decision being made, the nature of the relationship, and the potential impact if something goes wrong.
Due diligence is not a one-size-fits-all process. Organisations must examine different areas of risk depending on the decision being made, the nature of the relationship, and the potential impact if something goes wrong.
A critical technology provider requires different checks from a low-risk office supplier, overseas agent, or potential acquisition.
Understanding the different types of due diligence helps organisations determine:
-
Who or what needs to be assessed
-
Which areas of risk should be examined
-
How much evidence and scrutiny the decision requires
The different types can therefore be grouped in two ways: due diligence by relationship and due diligence by risk area.
These categories frequently overlap. A single supplier assessment, for example, may include financial, legal, operational, cybersecurity, ESG, and reputational due diligence.
Why Are There Different Types Of Due Diligence?
Every business relationship creates a different combination of risks.
The appropriate checks will depend on factors such as:
-
The nature and value of the relationship
-
The criticality of the product or service
-
Access to systems, sites, or sensitive information
-
Applicable laws and industry regulations
-
Reliance on subcontractors and fourth parties
-
The countries in which the organisation operates
-
The potential impact of failure
Defining these factors at the beginning helps organisations apply proportionate checks and focus specialist resources where they are needed most.
Due Diligence By Relationship
Due diligence by relationship considers the type of external organisation being assessed and the role it will perform.
The two most common categories are supplier due diligence and third-party due diligence. Supplier due diligence focuses specifically on procurement relationships, while third-party due diligence applies across the organisation’s wider external network.
Supplier Due Diligence
Supplier due diligence focuses specifically on organisations supplying goods or services through a procurement relationship. It assesses whether a supplier has the capability, controls, and stability required to meet the buyer’s requirements.
Supplier due diligence sits within the broader category of third-party due diligence. It usually begins before a supplier is appointed and continues throughout the commercial relationship.
Assessments may examine:
-
Company ownership and trading history
-
Financial stability
-
Insurance and certifications
-
Quality management
-
Regulatory compliance
-
Cybersecurity and data protection
-
Business continuity arrangements
-
ESG and ethical practices
The scope should reflect the supplier’s criticality and the potential impact of failure. Critical or higher-risk suppliers may require independent checks, site visits, additional evidence, and more frequent monitoring.
This helps procurement and risk teams make informed sourcing decisions while reducing the likelihood of disruption, compliance failure, or poor performance.
Third-Party Due Diligence
Third-party due diligence is the broader category. It covers suppliers as well as contractors, consultants, agents, distributors, outsourcing providers, commercial partners, and other external parties.
It helps organisations understand the risks introduced whenever another party supplies to, acts for, represents, or provides services to the business.
Depending on the relationship, checks may examine:
-
Ownership and corporate structure
-
Financial health
-
Conflicts of interest
-
Sanctions and adverse media
-
Anti-bribery and corruption controls
-
Data protection arrangements
-
Regulatory history
-
Use of subcontractors
The assessment should reflect what the third party will do, where it will operate, and the access, authority, or responsibility it will receive.
In short, all suppliers are third parties, but not all third parties are suppliers. Third-party due diligence provides oversight across the organisation’s entire network of external relationships.
Due Diligence By Risk Area
Once the relationship has been defined, the organisation can determine which areas of risk need to be investigated.
Several types may be used within the same assessment.
Financial Due Diligence
Financial due diligence evaluates the financial position and stability of another organisation.
It is commonly used during supplier selection, investments, mergers and acquisitions, lending decisions, and strategic partnerships.
Information reviewed may include:
-
Financial statements
-
Revenue and profitability
-
Cash flow
-
Assets and liabilities
-
Credit ratings
-
Tax obligations
-
Financial forecasts
-
Insurance coverage
In supplier relationships, financial due diligence helps determine whether the supplier is likely to remain viable and continue delivering throughout the contract.
It may also reveal warning signs such as falling revenue, excessive debt, cash-flow pressure, or dependence on a small number of customers.
Legal Due Diligence
Legal due diligence identifies legal obligations, liabilities, ownership issues, and contractual risks.
It helps organisations confirm that the proposed arrangement is lawful, appropriately documented, and aligned with their responsibilities.
Legal due diligence may review:
-
Corporate ownership and authority
-
Existing and proposed contracts
-
Licences and permissions
-
Intellectual property rights
-
Current or previous litigation
-
Employment obligations
-
Regulatory enforcement
-
Data protection responsibilities
-
Termination and liability provisions
The findings can influence contract terms, warranties, indemnities, approval conditions, or the decision to proceed.
Legal due diligence is particularly important when relationships cross jurisdictions, involve regulated services, or create access to valuable data or intellectual property.
Operational Due Diligence
Operational due diligence assesses whether an organisation can deliver its commitments consistently and withstand disruption.
A supplier may appear financially sound while still lacking the people, processes, technology, or capacity required to provide the service effectively.
Operational checks may cover:
-
Staffing levels and expertise
-
Delivery capacity
-
Quality management processes
-
Technology and infrastructure
-
Performance history
-
Dependency on key individuals
-
Reliance on sites, regions, or subcontractors
-
Business continuity and disaster recovery
-
Incident and crisis management
This form of due diligence is especially important for suppliers supporting business-critical operations. It helps organisations understand how services are delivered, where potential points of failure exist, and whether appropriate contingency plans are in place.
ESG Due Diligence
Environmental, social, and governance due diligence evaluates whether a business operates responsibly and aligns with relevant ethical, sustainability, and governance standards.
Organisations increasingly need reliable ESG information to meet regulatory requirements, support reporting, respond to stakeholder expectations, and deliver their own sustainability commitments.
ESG due diligence may examine:
-
Environmental policies and performance
-
Carbon emissions and reduction plans
-
Waste and resource management
-
Labour standards and working conditions
-
Human rights and Modern Slavery controls
-
Equality, diversity, and inclusion
-
Anti-bribery and ethical conduct
-
Governance and accountability
The depth of assessment may vary according to a supplier’s size, sector, location, and environmental or social impact.
A proportionate approach helps businesses gather meaningful evidence without placing unreasonable requirements on smaller or lower-risk suppliers.
Cybersecurity Due Diligence
Cybersecurity due diligence examines how a supplier or third party protects systems, networks, and information.
It is particularly important where an external organisation will process sensitive data, connect to internal systems, provide critical technology, or rely on cloud infrastructure.
Cybersecurity checks may include:
-
Security policies and governance
-
Recognised certifications
-
Access controls and authentication
-
Data encryption and storage
-
Vulnerability and patch management
-
Security testing
-
Previous cyber incidents
-
Incident response arrangements
-
Employee training
-
Controls applied to subcontractors
Cyber due diligence helps organisations identify weaknesses before access is granted and determine whether remediation, contractual controls, or ongoing monitoring are required.
Because cyber risks change quickly, these assessments should continue beyond onboarding.
Reputational Due Diligence
Reputational due diligence examines whether an organisation’s history, conduct, ownership, or associations could damage trust in the business engaging it.
A third party may meet technical requirements but still present a significant reputational risk because of previous misconduct, controversial practices, or links to unsuitable individuals or organisations.
Reviews may consider:
-
Adverse media coverage
-
Regulatory investigations
-
Legal disputes
-
Ethical controversies
-
Customer complaints
-
Ownership and leadership history
-
Political exposure
-
Conduct in local communities
Reputational due diligence is particularly relevant for high-profile partnerships, overseas relationships, acquisitions, sponsorships, and organisations operating in higher-risk markets.
Commercial Due Diligence
Commercial due diligence assesses the strength and viability of a commercial opportunity.
It is often associated with investments and acquisitions, but it can also help organisations evaluate strategic suppliers and business partners.
This may involve examining:
-
Market position and reputation
-
Customer base
-
Competitors
-
Demand for products or services
-
Pricing and commercial model
-
Growth prospects
-
Dependence on key clients
-
Strategic alignment
Commercial due diligence helps decision-makers determine whether the proposed relationship or transaction makes business sense - not simply whether the organisation meets compliance requirements.
Human Rights And Ethical Due Diligence
Human rights and ethical due diligence examines how an organisation identifies and manages the risk of harm to workers, communities, and other affected groups.
It may be included within ESG due diligence but can require a dedicated assessment where supply chains extend into higher-risk sectors or locations.
Checks may cover:
-
Modern Slavery and forced labour
-
Child labour
-
Working hours and pay
-
Freedom of association
-
Workplace health and safety
-
Recruitment practices
-
Grievance and remediation processes
-
Conditions within subcontracted supply chains
This enables organisations to look beyond the policies a supplier holds and consider how effectively responsible practices are implemented throughout its operations.
How Do The Different Types Work Together?
The different types of due diligence should not operate as isolated exercises.
A critical supplier may be financially stable but have weak cyber controls. Another may demonstrate strong operational capability but lack adequate business continuity arrangements. An organisation that satisfies technical requirements may still create legal, ethical, or reputational concerns.
Combining relevant assessments gives decision-makers a more complete understanding of the relationship.
For example, onboarding a technology supplier could require:
-
Supplier due diligence to confirm its capability and credentials
-
Financial due diligence to assess its stability
-
Legal due diligence to review contracts and data responsibilities
-
Operational due diligence to understand service delivery and continuity
-
Cybersecurity due diligence to assess information security controls
-
ESG due diligence to examine responsible business practices
The results can then be considered together rather than reviewed separately by different teams using disconnected information.
Choosing The Right Types Of Due Diligence
Not every business relationship requires every type of due diligence.
Organisations should use an initial risk assessment to determine which checks are relevant and how much evidence is needed. Factors such as criticality, spend, data access, location, and regulatory exposure can help establish the appropriate level of scrutiny.
A risk-based approach enables organisations to:
-
Avoid unnecessary checks for lower-risk relationships
-
Apply greater scrutiny to critical or high-risk third parties
-
Direct specialist resources towards the most significant risks
-
Create a more proportionate experience for suppliers
-
Make assessments easier to repeat and defend
The objective is not to gather as much information as possible. It is to collect and verify the information needed to make a confident, proportionate decision.
Key Takeaway: Effective Due Diligence Brings Different Risk Areas Together
The main types of due diligence include supplier, third-party, financial, legal, operational, ESG, cybersecurity, reputational, commercial, and human rights assessments.
Each examines a different area of potential exposure. Used together, they help organisations develop a more complete understanding of suppliers, partners, and commercial opportunities.
A proportionate, risk-based approach ensures the right checks are applied to each relationship - supporting stronger governance, better decisions, and more resilient operations.
Are different teams repeatedly requesting the same supplier information for separate assessments?
See how Hellios brings financial, operational, cyber, compliance, and ESG information into one validated supplier profile - supporting more consistent due diligence without duplicated effort.
