When Should You Carry Out Due Diligence?
Due diligence should be carried out whenever an organisation is considering a decision or relationship that could introduce financial, operational, legal, regulatory, cyber, or reputational risk. It should begin before a commitment is made and continue throughout the relationship as circumstances change.
Due diligence should be carried out whenever an organisation is considering a decision or relationship that could introduce financial, operational, legal, regulatory, cyber, or reputational risk. It should begin before a commitment is made and continue throughout the relationship as circumstances change.
Due diligence is often treated as a check completed during onboarding. But approving a supplier, vendor, or business partner only confirms that it met the organisation’s requirements at a particular point in time.
Financial conditions can deteriorate. Ownership structures can change. Certifications can expire. New cyber vulnerabilities can emerge. Regulations and organisational requirements can also evolve.
Businesses therefore need to carry out due diligence at key stages throughout a relationship - not only before it begins.
When Is Due Diligence Used?
Due diligence can support many different types of business decisions.
Although due diligence is often associated with the beginning of a relationship, it should not end once a contract is signed. Supplier circumstances, regulations, ownership structures, and risk levels can all change over time.
Ongoing reviews help organisations ensure that the information behind their original decision remains accurate.
Before Onboarding A New Supplier Or Vendor
Due diligence should begin before a supplier is approved, given access to systems, or contracted to deliver goods or services.
Pre-onboarding checks help organisations understand whether the supplier:
-
Has the capability and capacity to deliver
-
Is financially stable
-
Meets relevant regulatory requirements
-
Holds appropriate insurance and certifications
-
Has suitable cybersecurity and data protection controls
-
Can maintain services during disruption
-
Meets required ethical and sustainability standards
Identifying concerns at this stage gives the organisation time to request further evidence, agree remediation actions, introduce contractual protections, or consider an alternative supplier.
The level of scrutiny should reflect the risk of the relationship. A supplier supporting a critical service or handling sensitive data will usually require more extensive due diligence than a low-value, low-risk provider.
When Appointing Contractors And Service Providers
Contractors, consultants, outsourcing providers, and other third parties can introduce risks even when they are not managed through a traditional procurement relationship.
Due diligence may be required when an external party will:
-
Access company premises
-
Connect to internal systems
-
Handle confidential or personal information
-
Represent the organisation externally
-
Make decisions on its behalf
-
Deliver a regulated or critical activity
-
Use subcontractors to provide the service
The checks should reflect the access, responsibility, and authority the third party will receive.
Before Entering A Strategic Partnership
Commercial partnerships can involve shared resources, data, customers, intellectual property, or reputation. Due diligence helps both parties understand the proposed arrangement before making a long-term commitment.
Assessments may examine:
-
Strategic and commercial alignment
-
Ownership and governance
-
Financial stability
-
Legal liabilities
-
Regulatory history
-
Operational capability
-
Cybersecurity and data protection
-
Reputation and ethical conduct
This helps the organisation identify risks that could affect the partnership, clarify responsibilities, and establish appropriate contractual protections.
Before Signing Or Renewing A Contract
Due diligence findings should be considered before a contract is finalised.
This allows the organisation to address identified risks through measures such as:
-
Specific service requirements
-
Data protection and security clauses
-
Audit and information rights
-
Insurance obligations
-
Business continuity requirements
-
Remediation commitments
-
Performance measures
-
Termination rights
Due diligence should also be refreshed before a significant contract is renewed or extended.
A supplier that met the organisation’s requirements several years earlier may have changed its ownership, delivery model, financial position, subcontractors, or control environment. Renewal provides an opportunity to confirm that the relationship remains appropriate.
When The Scope Of A Relationship Changes
A change to the service, contract, or supplier relationship can introduce risks that were not considered during the original assessment.
Additional due diligence may be needed when:
-
The supplier begins providing a new product or service
-
Contract value or duration increases significantly
-
The service becomes business-critical
-
The supplier gains access to additional systems or data
-
Delivery moves to a new country or location
-
New subcontractors are introduced
-
The organisation becomes more dependent on the supplier
-
The supplier’s responsibilities expand
Rather than relying on the original approval, the organisation should assess the new risks created by the change.
Following A Change In Ownership Or Control
Changes in ownership, leadership, or corporate structure can affect a supplier’s risk profile.
A merger, acquisition, investment, or change in beneficial ownership may introduce:
-
New parent-company dependencies
-
Different financial pressures
-
Changes to governance or leadership
-
New locations or subcontractors
-
Sanctions or conflicts-of-interest concerns
-
Changes to strategic priorities
-
Integration and service continuity risks
Due diligence helps determine whether the original basis for approval remains valid and whether further controls or contractual changes are required.
When Regulations Or Standards Change
Regulatory requirements, industry standards, and customer expectations evolve over time.
Organisations should review existing relationships when changes introduce new obligations relating to areas such as:
-
Data protection
-
Cybersecurity
-
Operational resilience
-
Modern Slavery
-
ESG reporting
-
Anti-bribery and corruption
-
Sanctions
-
Procurement and supply chain security
This may require suppliers to provide new information, update policies, demonstrate additional controls, or complete remediation activities.
A structured process helps organisations apply these changes consistently rather than responding separately to each supplier.
When Warning Signs Or Incidents Emerge
Due diligence should be refreshed when new information suggests that a supplier or third party’s risk profile may have changed.
Potential triggers include:
-
Financial deterioration or late payments
-
Adverse media coverage
-
Regulatory investigation or enforcement
-
A cyber incident or data breach
-
Repeated service failures
-
Loss of an important certification
-
Changes in senior leadership
-
Ethical or labour concerns
-
Disruption affecting a key location
-
Failure to complete agreed remediation
These events do not automatically mean the relationship must end. They indicate that further investigation is needed to understand the issue and decide on an appropriate response.
At The End Of A Business Relationship
Due diligence and risk management responsibilities can continue when a contract ends.
Offboarding checks may be needed to confirm that:
-
System and site access has been removed
-
Data has been returned, transferred, or securely deleted
-
Equipment and intellectual property have been recovered
-
Outstanding obligations have been completed
-
Subcontractor access has been closed
-
Records are retained for the required period
-
Service transition arrangements are working
This is especially important when replacing a critical provider or ending a relationship involving sensitive information.
Scheduled Reviews And Event-Triggered Due Diligence
An effective due diligence programme usually combines two approaches.
Scheduled reviews take place at defined intervals based on the supplier’s risk and criticality.
Event-triggered reviews take place when a specific change, incident, or warning sign emerges.
Using both approaches helps organisations avoid two common problems: reviewing suppliers too infrequently or repeatedly requesting the same information when nothing has changed.
It also ensures attention is focused where the risk is greatest.
Why Due Diligence Should Be Ongoing
A one-off assessment provides only a snapshot of risk.
Ongoing due diligence helps organisations identify changes earlier, maintain accurate records, and confirm that suppliers and third parties continue to meet the required standards.
It can include:
-
Keeping supplier information and documentation current
-
Monitoring financial, regulatory, cyber, and reputational indicators
-
Reviewing changes in ownership or subcontracting
-
Tracking certifications and insurance expiry dates
-
Following up on remediation actions
-
Reassessing relationships when their scope changes
This moves due diligence from a pre-contract hurdle to an active part of supplier and third-party risk management.
Key Takeaway: Carry Out Due Diligence Throughout The Relationship
Due diligence should be carried out before an organisation appoints a supplier, engages a third party, enters a partnership, makes an investment, or commits to another potentially significant business decision.
It should then continue at appropriate points throughout the relationship - including contract renewal, changes in scope or ownership, regulatory developments, emerging incidents, and periodic reviews.
Treating due diligence as an ongoing, risk-based process helps organisations identify changes earlier, make informed decisions, and build more resilient business relationships.
Are you relying on supplier information that may no longer be current?
See how Hellios helps organisations collect, validate, and maintain trusted supplier information throughout the relationship - supporting more consistent due diligence without repeatedly starting from scratch.
