Third-Party Risk

Third-Party Risk Management: The Investigative Layer a Platform Cannot Provide

A TPRM platform is a system of record, and a good one. It screens, scores and monitors a whole population continuously. What it does not do — by design — is verify.

Fortaris Capital Advisors · September 15, 2026 · 13 min read

A wall of small unmarked private mail-drop boxes in a mail-forwarding storefront, raked by a diagonal shaft of daylight, one compartment standing open on a completely empty dark interior.
The fourth gap no platform closes: whether the address on the questionnaire is a facility or a mail drop. Somebody has to go and look.

The short answer

Third-party risk management platforms are systems of record: they screen a whole vendor population against lists, collect questionnaires, and monitor scores continuously. They cannot verify. The investigative layer resolves what screening surfaces — real beneficial ownership, adverse-media attribution, unindexed litigation, and whether an operation physically exists — on the fraction of third parties where exposure justifies it.

What a TPRM platform is actually for

It is worth starting with what the tooling does well, because the argument for an investigative layer is weaker when it is made against a caricature. Third-party risk management platforms solve a genuine and difficult problem: an enterprise may have thousands or tens of thousands of third parties, each needing onboarding, screening, periodic review and an audit trail, and no human team can hold that population in view.

A platform does four things better than any investigator. It covers breadth, running the entire population continuously rather than a handful episodically. It never forgets to re-screen. It standardises the questionnaire and evidence workflow so that a programme can actually be audited — which matters enormously when a regulator asks what your process is. And it surfaces list matches and published adverse media within hours.

That is a system of record, and an organisation without one has a worse problem than the one this article describes. The point is narrower: none of those four functions is verification, and the vendors of these tools are generally candid about it. A watchlist screen answers a name-matching problem. A questionnaire returns whatever the third party chose to write. A financial or cyber score is a model output built from the third party's own disclosures and public footprint. Each is a legitimate input. None of them independently establishes a fact.

The four gaps a platform cannot close

The gaps are specific and they are structural rather than a matter of product maturity. No amount of additional data licensing closes them, because each requires a judgment or an action that a data pipeline cannot perform.

  • Adverse-media attribution. A platform returns articles matching a name. Whether the person in the article is your counterparty, a namesake, or a relative — and whether the allegation was later withdrawn, dismissed or upheld — is a resolution problem. Unresolved hits accumulate until a programme learns to ignore them, which is the worst of both outcomes: the alert fired and nobody acted.
  • Beneficial ownership behind nominees. Screening matches the names it is given. OFAC's 50 Percent Rule blocks property of an entity owned fifty per cent or more in the aggregate by blocked persons even where that entity never appears on the SDN List — an exposure that name-matching cannot detect by construction. Establishing real ownership means reading the corporate chain across registries, and where the chain crosses borders it means reading foreign ones. The domestic version of that difficulty is set out in the Corporate Transparency Act in 2026.
  • Unindexed litigation. Most commercial and employment disputes involving mid-sized suppliers are heard in state trial courts, county by county, on systems the commercial aggregators index unevenly. A clean database result is not a clean litigation record, and predecessor entities conceal the most telling pattern of all — dissolved companies that left judgments behind.
  • Physical existence. Whether the address is a facility, a shared office or a mail drop; whether the workforce, plant and certifications described in the questionnaire are real. This is not a data question at all. Somebody has to go and look.

Where the investigative layer plugs in

The right architecture is not investigation instead of a platform. It is a platform across the whole population with investigation triggered on the small fraction where exposure justifies the cost, and the findings returned into the platform so it remains the system of record.

In practice that is a four-step loop. Screen everything, continuously — that is what the tool is for. Tier the population by inherent risk, using exposure rather than spend alone. Define escalation triggers in advance, in writing, so that escalation is a rule rather than an individual's judgment call under deal pressure. And when a trigger fires, run an investigation whose output is a sourced written finding that goes back into the vendor record, converts into contract terms, and sets the date for re-verification.

The last step is the one most often lost. An investigation whose findings live in a PDF in somebody's mailbox has not improved the programme; it has answered one question once. The finding belongs in the system of record, because the system of record is what the next reviewer, the next auditor and the next regulator will read. The per-vendor version of this work — what an investigation covers on a single supplier and what it costs — is set out in vendor due diligence investigations. This piece is about the programme that decides which vendors get one.

Infographic showing two stacked layers connected by a loop: the platform layer, which screens the whole third-party population against lists, collects questionnaires, scores and monitors continuously; and beneath it the investigative layer, which resolves adverse-media attribution, reads beneficial ownership behind nominees, reaches unindexed state-court litigation and verifies physical existence. A downward arrow marks escalation triggers and an upward arrow marks findings returning into the platform as the system of record.
Screening across the whole population; investigation where risk triggers it; findings returned as the record.

The triggers worth defining in advance

Escalation criteria written before a specific vendor is in front of you are worth several times the same criteria written afterwards, because the moment a deal is under time pressure the honest answer to "does this one need more work?" becomes very flexible. These are the conditions worth committing to in policy.

  • Material spend or single-source dependency — where the relationship failing would interrupt operations rather than merely inconvenience them.
  • Access to customer data, funds, systems or premises. Access is a better trigger than spend: a small vendor with production database credentials outranks a large one supplying office furniture.
  • A government customer, or any intermediary, agent, distributor or consultant acting on your behalf in a jurisdiction where corruption risk is material — the category the FCPA framework treats as requiring documented, risk-based diligence.
  • Cross-border ownership, control or payment routing, particularly where payment is directed to a jurisdiction unrelated to the operation.
  • Sole-sourced awards, or any third party introduced from inside your own organisation. The most expensive vendor failures usually involve someone internal, and the vendor screens clean because the anomaly sits in your procurement file, not theirs.
  • Post-award anomalies — banking details changed by email, reluctance to permit a site visit, an unexplained change of ownership or registered address, or a sudden change in the individuals you deal with.
  • Third parties inherited through an acquisition, which enter the population without ever having passed your onboarding process at all.

What the regulators actually expect

No authority prescribes a tool, and it is worth being clear about that: an organisation cannot buy its way to compliance by licensing a platform. What the guidance consistently asks for is a risk-based, documented and refreshed process, and a demonstrated understanding of why each third party is there at all.

The Department of Justice's Evaluation of Corporate Compliance Programs asks whether a company understands the business rationale for engaging a third party, whether its diligence is risk-based and documented, and whether it is refreshed rather than performed once at onboarding. The DOJ and SEC's FCPA Resource Guide treats documented, risk-based third-party diligence as a hallmark of an effective programme, because a company can be liable for the conduct of agents acting on its behalf. For banks, the 2023 Interagency Guidance on Third-Party Relationships issued jointly by the Federal Reserve, FDIC and OCC frames third-party management as a lifecycle — planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination — with diligence proportionate to risk.

Alongside those sit the substantive rules the diligence has to satisfy: OFAC's 50 Percent Rule on ownership, FinCEN's customer due diligence standard with its twenty-five per cent equity prong and control prong, and, for technology and systems supply chains, NIST SP 800-161r1 as the reference framework into which findings are operationalised.

Read together, the expectation is not a dashboard. It is evidence that somebody with judgment looked at the third parties that mattered, wrote down what they found, and did something with it — which is the definition of an investigative layer rather than a screening one. The wider family of disciplines this belongs to is mapped in corporate investigation services.

Continuous monitoring and its blind spot

Continuous monitoring is the feature most often cited as making periodic investigation unnecessary, and it does genuinely close one gap: a list designation or a published article that appears after onboarding will be caught, where an annual review would have missed it for months.

Its blind spot is that it monitors the entity you registered. If ownership changes, if control passes to someone who is not named in the record, if the operating business is transferred to a newly formed company with the same premises and officers, or if the entity is renamed, the monitor keeps watching a description of the third party that is no longer accurate. Nothing alerts, because nothing about the registered name changed.

The practical answer is not more monitoring. It is periodic re-verification on the tiers where it matters — re-reading the ownership chain rather than re-running the screen — and treating specific events as re-verification triggers regardless of the calendar: a change of control, a change of registered address, a renewal at materially increased scope, or the banking-change and site-access anomalies above. Payment-diversion fraud lives in exactly this gap; the FBI's Internet Crime Complaint Center recorded roughly $2.77 billion in business email compromise losses in 2024, and the typical presentation is an ordinary invoice from a known supplier with new banking details.

The cost model that makes it work

The reason this architecture is affordable is arithmetic. Automated screening across a population costs a small amount per third party per year. A scoped investigation costs orders of magnitude more per subject. A programme that tried to investigate everything would be unaffordable, and a programme that investigates nothing is buying an audit trail rather than an assurance.

What makes the numbers work is that the fraction requiring investigation is genuinely small — typically a low single-digit percentage of a large population, concentrated in the tiers where access, spend, jurisdiction or introduction route creates real exposure. The relevant comparison is never the investigation fee against the vendor's contract value. It is the fee against the cost of the failure it is meant to prevent: a payment diverted, an operation interrupted, a sanctions exposure inherited, or a regulator asking why a third party with a documented history was onboarded without anyone looking.

Two governance points decide whether the model holds. Somebody must own the escalation decision and be senior enough to make it under commercial pressure. And the budget for investigation must sit with the risk function rather than with the business unit buying the service, because a budget held by the buyer is a budget that is never spent on the vendor the buyer wants.

Whether your programme has this layer

A short diagnostic, and each question has a documentary answer rather than an opinion.

Can you name the third parties escalated beyond screening in the last twelve months, and the trigger that escalated each? If the answer is none, the programme has a screening layer only. When a material adverse-media hit last fired, is there a record of how it was resolved — to whom the article referred and what was concluded — or was it closed as reviewed? For your highest-tier third parties, has anyone read the ownership chain, or only screened the name given at onboarding? Has anyone physically confirmed that your most critical suppliers' operations exist as described? And when a supplier changed its banking details in the last year, what verified it beyond a return call to a number in the email?

None of these findings mean the programme is failing. Most organisations of any size will answer honestly and find one or two gaps, and closing them is usually a policy change plus a modest budget rather than a new system. If the conclusion is that an external layer is needed, the criteria for selecting one are set out in how to choose a due diligence company, and the discipline itself in what investigative due diligence is.

Key takeaways

  • A TPRM platform is a system of record and a good one — breadth, continuity, workflow and auditability. None of those four functions is verification, and the vendors are generally candid about it.
  • Four gaps are structural rather than product immaturity: resolving an adverse-media hit to the right person, reading beneficial ownership behind nominees, reaching state-court litigation no national index aggregates, and confirming an operation physically exists.
  • The workable architecture is screening across the whole population with investigation triggered on a low single-digit fraction — and findings returned into the platform, because the system of record is what the next auditor reads.
  • Write escalation triggers before a specific vendor is in front of you. Access to data, funds, systems or premises is a better trigger than spend, and a vendor introduced from inside your own organisation deserves one of its own.
  • Continuous monitoring watches the entity you registered — so a change of control, a renamed entity or a transfer to a new company with the same premises passes silently. The answer is periodic re-verification of ownership, not more monitoring.

Frequently asked

10 questions

What is third-party risk management?

The programme by which an organisation identifies, assesses, contracts for, monitors and terminates its relationships with suppliers, vendors, agents, intermediaries and service providers. In most enterprises it is operated through a platform that maintains the inventory, screens against sanctions and watchlists, collects questionnaires, scores financial and cyber posture, and holds the audit trail across the relationship lifecycle.

What can a TPRM platform not do?

It cannot verify. Specifically it cannot resolve whether an adverse-media hit refers to your counterparty or a namesake and what the allegation came to; it cannot read a corporate chain to establish beneficial ownership behind nominee structures; it cannot reach litigation in the county courts that no national index fully aggregates; and it cannot confirm that a facility, workforce or certification physically exists. Each requires judgment or presence rather than data.

Does an investigative layer replace our TPRM platform?

No, and a proposal that suggests it should is the wrong proposal. The platform covers the whole population continuously, which no investigative team can replicate at scale, and it holds the auditable record. The investigative layer is triggered on the small fraction where exposure justifies the cost, and its output returns into the platform so that the record stays complete. Screening everywhere, investigation where risk triggers it.

What proportion of third parties should be investigated?

Typically a low single-digit percentage of a large population, concentrated where access, spend, jurisdiction or introduction route creates genuine exposure. The figure matters less than the mechanism: triggers defined in advance and in writing, so escalation is a policy rule rather than a judgment made under deal pressure by whoever is closest to the transaction.

What should trigger escalation from screening to investigation?

Material spend or single-source dependency; access to customer data, funds, systems or premises; a government customer or an intermediary acting on your behalf where corruption risk is material; cross-border ownership, control or payment routing, especially where payment goes to a jurisdiction unrelated to the operation; sole-sourced or internally introduced awards; post-award anomalies such as emailed banking changes or refusal of a site visit; and third parties inherited through an acquisition.

What do regulators expect from third-party due diligence?

Not a specific tool. The DOJ's Evaluation of Corporate Compliance Programs asks whether a company understands the business rationale for using each third party and whether diligence is risk-based, documented and refreshed. The FCPA Resource Guide treats documented risk-based third-party diligence as a hallmark of an effective programme. For banks, the 2023 Interagency Guidance from the Federal Reserve, FDIC and OCC frames the relationship as a lifecycle with diligence proportionate to risk.

Why does continuous monitoring miss ownership changes?

Because it monitors the entity that was registered. If control passes to someone not named in the record, the operating business is transferred to a newly formed company with the same premises and officers, or the entity is simply renamed, nothing about the monitored name has changed and no alert fires. Closing that gap requires periodically re-reading the ownership chain on the tiers that matter, plus event-driven re-verification on change of control or registered address.

How does the OFAC 50 Percent Rule affect vendor screening?

It means a name screen can return clean on an entity that is nevertheless blocked. Property of an entity owned fifty per cent or more, directly or indirectly and in the aggregate, by one or more blocked persons is itself blocked even though the entity is not named on the SDN List. Detecting that exposure requires establishing who actually owns the counterparty through the chain of entities holding it — which is ownership research, not list matching.

How much does the investigative layer cost?

Investigations are normally fixed-fee and tiered so a programme can budget them: a records-level verification of the entity, its principals, litigation, sanctions exposure and operating address as the base tier, with fuller investigative diligence including cross-border registry work, site verification and discreet human-source inquiry above it. The programme is affordable because only a small fraction of the population escalates — and the fee should be weighed against the failure it prevents, not against the vendor's contract value.

Who should own the escalation decision?

Someone in the risk or compliance function who is senior enough to hold the line under commercial pressure, with the investigation budget held there rather than by the business unit buying the service. A budget controlled by the buyer is structurally unlikely to be spent investigating the supplier the buyer has already chosen, which is how sole-sourced and internally introduced relationships — the two highest-risk categories — end up receiving the least scrutiny.

Sources & further reading

  1. 01U.S. Department of Justice, Criminal Division — Evaluation of Corporate Compliance ProgramsAsks whether a company understands the business rationale for engaging each third party and whether its diligence is risk-based, documented and refreshed rather than performed once at onboarding — the standard a programme is measured against after something goes wrong.
  2. 02DOJ and SEC — A Resource Guide to the U.S. Foreign Corrupt Practices ActTreats documented, risk-based third-party due diligence as a hallmark of an effective compliance program, on the basis that a company may be liable for the conduct of agents and intermediaries acting on its behalf.
  3. 03Interagency Guidance on Third-Party Relationships: Risk Management (Federal Reserve, FDIC, OCC, 2023)Frames third-party risk as a lifecycle — planning, due diligence and selection, contract negotiation, ongoing monitoring and termination — with the depth of diligence proportionate to the risk of the relationship rather than uniform across the population.
  4. 04OFAC — Revised Guidance on Entities Owned by Blocked Persons (the 50 Percent Rule)Property of an entity owned 50% or more in the aggregate by blocked persons is itself blocked even where the entity is not named on the SDN List — the exposure that name-matching screening cannot detect by construction.
  5. 05FinCEN — Customer Due Diligence Requirements for Financial Institutions, 31 CFR 1010.230Establishes the beneficial-ownership identification standard, with a 25% equity prong and a control prong — the benchmark most third-party programmes borrow when defining who counts as an owner of a counterparty.
  6. 06NIST SP 800-161r1 — Cybersecurity Supply Chain Risk Management Practices for Systems and OrganizationsThe reference framework for supplier risk in technology and systems supply chains, and the practice into which investigative findings are operationalised as controls and contract terms.
  7. 07FBI Internet Crime Complaint Center (IC3), Internet Crime Report 2024Approximately $2.77 billion in business email compromise losses in 2024 — the fraud family that lives precisely in the monitoring blind spot, presenting as an ordinary invoice from a known supplier with changed banking details.

Related practice

Corporate Intelligence

When the matter is real, Fortaris brings federal-grade investigative judgment to it — led by a Managing Director, in confidence.

Confidential intake

Send a confidential inquiry

Reviewed by a senior principal — usually the same day.

Your message is treated in confidence. For the most sensitive matters, call Kevin Cronin directly.

By providing a telephone number you agree that Fortaris may contact you about your inquiry by phone or text message. We do not send marketing texts. Message frequency varies; message and data rates may apply. Reply STOP to opt out or HELP for help. See our Privacy Policy and Terms.