The short answer
Vendor due diligence investigations are the investigative layer beneath third-party screening: establishing who actually owns and controls a supplier, what its litigation and regulatory record really shows, whether the operation physically exists, and how it came to be recommended. Screening platforms match names against lists and collect self-reported answers. An investigation verifies the things a vendor would prefer you took on trust.
Where screening stops
Most companies now run some form of third-party risk management, and the tooling is genuinely good. A vendor is onboarded, screened against sanctions and watchlists, scored for financial and cyber health, asked to complete a questionnaire, and monitored continuously thereafter. The dashboard turns green. What the dashboard is actually reporting, though, is narrower than most buyers realize: it is reporting that nothing the vendor is required to disclose, and nothing published under a name the platform was given, currently matches a list.
That is a meaningful result, and for the great majority of low-value, low-access suppliers it is the correct amount of work. It stops being sufficient at a predictable set of moments — when the spend is large, when the vendor touches customer data or operational continuity, when a government customer or a foreign jurisdiction is involved, when the relationship was sole-sourced, or when the introduction came from inside your own organization. At those moments the question changes from "does this vendor appear on a list" to "who am I actually dealing with", and that is an investigative question rather than a data question.
The distinction is the same one that separates a background check from investigative due diligence generally: screening confirms data points, investigation establishes facts — including facts a subject has taken deliberate steps to keep out of the databases. Vendor work is simply the counterparty-risk application of that discipline, and it sits inside the wider family of corporate investigation services.
What the platforms genuinely do well
It is worth being precise about this, because the case for investigation is weaker when it is made against a straw man. Screening platforms do four things better than any investigator: they cover breadth no human team could cover, running thousands of vendors continuously rather than a handful episodically; they never forget to re-screen; they standardize the questionnaire and evidence-collection workflow so a program can actually be audited; and they surface list matches and public adverse media within hours of publication.
None of that is the same as verification, and the vendors of these tools are usually candid about it. A watchlist screen answers a matching problem. A questionnaire answers whatever the vendor chose to write. A financial or cyber score is a model output built on data the vendor's own disclosures and public footprint supplied. Each is a legitimate input; none of them independently establishes a fact. The right architecture is therefore not investigation instead of screening — it is screening across the whole population, with investigation triggered by risk on the small fraction where the exposure justifies it.

Blind spot one: who actually owns the vendor
Ownership is the single most consequential thing a screening tool cannot resolve, and the reason is structural rather than technical: platforms match the names they are given, and the names on an incorporation filing are frequently not the people who control the company. A registered agent, a nominee director, a holding company two states away, and a family member as sole member of an LLC will all pass a name screen cleanly. Establishing real control means reading the corporate chain through the entities that hold it, cross-referencing officers and addresses across filings, and — where the chain leaves the country — pulling registries that answer a differently phrased question.
The sanctions consequence makes this concrete. Under OFAC's 50 Percent Rule, an entity owned fifty percent or more, directly or indirectly, in the aggregate, by one or more blocked persons is itself blocked — even though that entity never appears on the Specially Designated Nationals list. A name-matching screen of the vendor returns nothing, because there is nothing to match; the exposure lives in the ownership arithmetic, and only tracing ownership finds it. That is a compliance failure a green dashboard will actively conceal.
The domestic registry picture has also narrowed rather than widened; what beneficial-ownership reporting does and does not deliver for diligence purposes is covered in our piece on beneficial ownership and the Corporate Transparency Act. Where the counterparty or its principals sit outside the United States, this becomes the core of international due diligence, and where the question extends to where a principal's money came from, it becomes source of wealth verification.
Blind spot two: the litigation record nobody indexed
The second gap is jurisdictional. Federal court records are centrally searchable, and aggregated databases carry them well. Most commercial disputes involving a mid-sized supplier are not in federal court — they are in state trial courts, county by county, on systems that range from modern to a clerk's index, many of which are not aggregated into any commercial database at all. A vendor with a decade of breach-of-contract suits, mechanic's liens, wage claims, and unsatisfied judgments in the two counties where it operates can present as litigation-clean to a national screen.
The investigative answer is unglamorous: identify every jurisdiction the company and its principals have actually operated in, then search those courts directly, including under prior corporate names and predecessor entities. The predecessor point matters more than it sounds. A pattern of dissolved companies in the same line of business, each leaving unpaid judgments behind, is one of the most reliable adverse signals in commercial diligence — and it is invisible to any tool searching only the name on your contract.
The same principle applies to regulatory and enforcement history held at state level, and to liens and UCC filings that describe what a company has already pledged. The method for assembling this on a U.S. counterparty is set out in how to verify a U.S. company before signing.
Blind spot three: whether the operation actually exists
A supplier can be entirely real on paper and largely fictional in fact. The website is professional, the address resolves, the D-U-N-S number is valid, the certifications are attached to the questionnaire, and the facility is a mail drop, a co-working desk, or a warehouse that belongs to someone else. This is the failure mode behind most capacity fraud — the vendor that wins a contract it has no plant to fulfil and quietly brokers the work to whoever will take it — and behind a category of grant, aid and government-supply fraud that is otherwise hard to explain.
Verification here is physical and documentary rather than digital: confirming the address is an operating facility of the claimed type and scale, checking that the workforce, equipment, and certifications the vendor claims can be corroborated independently, and testing customer references that the vendor did not select. None of this requires anything intrusive. It requires someone to look, which is precisely what no platform can do — and, notably, what a green risk score can make feel unnecessary.
Blind spot four: the relationship nobody disclosed
The most expensive vendor problems are frequently not about the vendor at all. Procurement fraud runs through the relationship between the supplier and someone inside the buying organization: a manager who owns a share of the vendor through a spouse or an intermediate entity, a bid process arranged to produce a predetermined winner, an invoice stream inflated with a kickback built into the rate. The ACFE's Report to the Nations consistently finds corruption — the scheme family that includes kickbacks, bid-rigging, and conflicts of interest — present in close to half of reported occupational-fraud cases, with median losses well above the all-case median.
No third-party platform can see this, because the vendor screens clean; the anomaly is in your own organization, in a relationship nobody disclosed. Detecting it means comparing the vendor's ownership and address data against employee records, reading the procurement file for the tells of a shaped process — sole-source justifications, requirements written around one supplier's specification, a bid opened after the others were known — and, where it matters, asking the question directly under privilege. That is where vendor diligence hands over to internal and workplace investigation, and where the loss patterns are the ones described in our explainer on white-collar crime.
Blind spot five: what people who dealt with them will say
The last gap is the oldest form of intelligence there is. Adverse-media screening finds what was published. It does not find the dispute that was settled quietly, the contract terminated for cause without a filing, the pattern of change orders that former customers describe consistently and no one wrote down. That information exists, it is held by people, and it is obtainable lawfully by asking them — former customers, former employees, competitors, industry participants, and counsel who have dealt with the company before.
This work has to be done carefully or not at all. Inquiries are conducted without misrepresentation and without signalling to the market that a deal or a contract is in play; sources are assessed for motive before their information is weighted; and nothing reaches a report as fact unless it can be corroborated documentarily or by an independent second source. Handled properly, it is the single highest-yield component of a vendor investigation, and it is the one thing that no amount of monitoring subscription will ever produce.
The reputational discipline is the same one we apply on the transaction side — see the sanctions and reputational diligence playbook.
When to escalate from screening to an investigation
The point of a tiered program is that most vendors never need this. Escalation should be triggered by defined risk conditions, written into the third-party policy, so the decision is made by the framework rather than by whoever is under deadline pressure that week.
- Spend or dependency above a threshold the business could not absorb losing — the number should be set by continuity impact, not by procurement convenience.
- Access to customer data, funds, systems, or physical premises — anything where the vendor's failure becomes your incident.
- A government customer, a regulated end-use, or an FCPA-relevant intermediary relationship — third-party conduct is attributed to the company that engaged them.
- Cross-border ownership, operations, or payment routing, particularly where the chain passes through a jurisdiction with opaque registries.
- Sole-sourced, introduced internally, or won on an unusually favourable bid — the three conditions that most often accompany an undisclosed relationship.
- A post-award anomaly: change orders that keep arriving, banking details changed by email, invoices that do not reconcile to delivery, or a sudden reluctance to allow a site visit.
- Renewal after a control event — the vendor was acquired, its principals changed, or its ownership was restructured since the last review.
What the record is worth after the decision
A vendor investigation produces two things: a decision input, and a record. The record is frequently the more durable asset. The Justice Department and SEC's FCPA Resource Guide treats documented, risk-based third-party due diligence as a hallmark of an effective compliance program, and the Criminal Division's Evaluation of Corporate Compliance Programs asks specifically whether a company understands the business rationale for using a third party and whether its diligence is risk-based and refreshed. Those are questions answered by a file, not by a dashboard screenshot.
The same file does commercial work. Findings short of disqualification convert into contract terms — audit rights, ownership-change notification, subcontracting restrictions, banking-change verification protocols, and termination triggers written against the specific risk identified. Where the vendor sits in a technology or systems supply chain, NIST's supply-chain risk management guidance sets out the wider practice this fits into. And if the relationship later fails, a contemporaneous, sourced diligence record is what distinguishes a company that was deceived from one that did not look.
The transaction-grade version of this analysis, for when the counterparty is being acquired rather than engaged, is the enhanced due diligence checklist.
Scope, cost, and how a vendor investigation runs
The work is normally fixed-fee and tiered, which suits a program that has to budget across a vendor population. A records-level verification — corporate chain, principals, litigation in the relevant jurisdictions, sanctions and regulatory checks, address and operating verification — is the base tier and closes in days. Full investigative diligence adds discreet human-source inquiry, deeper cross-border registry work, and site verification, and typically runs one to three weeks. The cost drivers are the number of entities and principals, the number of jurisdictions, whether human inquiry is required, and speed.
Sequencing matters as much as scope. Diligence that arrives after the contract is signed is a compliance artifact; diligence that arrives while terms are still open is leverage. The practical pattern is to run the base tier at qualification for every vendor above the risk threshold, and to reserve the full tier for the ones the base tier flags or the exposure demands — a phased structure that keeps program cost proportionate and gives each phase a decision to inform.
Every engagement at Fortaris is led and worked at Managing Director level by professionals with federal investigative and forensic-accounting backgrounds, delivered as a sourced written report that separates verified fact from reported allegation, with stated scope and stated limits. How to test any provider — including us — against those criteria is set out in how to choose a corporate intelligence firm, and the practice itself sits under corporate intelligence and investigative services for the corporations that carry this risk.
Key takeaways
- Screening platforms answer a matching problem — lists, keywords, questionnaires, scores. An investigation answers an identity problem: who actually owns and controls the vendor, and what is verifiably true about it.
- OFAC's 50 Percent Rule blocks entities owned 50% or more in the aggregate by blocked persons even when they never appear on the SDN list — an exposure that name-matching screening cannot detect by design.
- Most commercial litigation against mid-sized suppliers sits in state trial courts that no national database fully aggregates, and predecessor entities hide the strongest adverse pattern of all: dissolved companies leaving unpaid judgments behind.
- The most expensive vendor failures involve someone inside the buying organization; the vendor screens clean because the anomaly is in your own procurement file.
- Run screening across the whole population and trigger investigation on defined risk conditions — spend, access, government or cross-border nexus, sole-sourcing, internal introduction, or a post-award anomaly.
Frequently asked
10 questionsWhat is vendor due diligence?
The verification a company performs on a supplier before engaging it, and periodically afterwards: confirming who owns and controls the business, what its litigation, regulatory and sanctions record shows, whether it can actually deliver what it has contracted to deliver, and whether the relationship carries an undisclosed conflict. It ranges from automated screening at the low-risk end to a full investigation where the exposure justifies it.
What is the difference between vendor screening and a vendor due diligence investigation?
Screening matches a vendor's name against sanctions, watchlist and adverse-media sources, collects a self-reported questionnaire, and produces a monitored score. An investigation independently establishes facts: it traces real ownership through the entities that hold it, searches the courts that actually heard the disputes, verifies that the operation physically exists, and gathers reputation from people who have dealt with the company. Screening is broad and continuous; investigation is deep and triggered by risk.
Which vendors justify an investigation rather than screening?
Those where the exposure is large enough to matter: high spend or single-source dependency, access to customer data, funds, systems or premises, a government customer or FCPA-relevant intermediary role, cross-border ownership or payment routing, a sole-sourced or internally introduced award, and any vendor showing a post-award anomaly such as emailed banking-detail changes or reluctance to permit a site visit.
What does a vendor due diligence investigation cover?
Corporate structure and beneficial ownership through the chain that holds it; principals and their track records, including predecessor entities; litigation, judgments and liens in the jurisdictions where the company actually operates; regulatory, licensing and sanctions exposure; operational verification that the address, facility, workforce and certifications are real; conflict-of-interest testing against your own employee and procurement records; and, where scoped, discreet human-source inquiry with former customers and counterparties.
Can't our third-party risk platform do all this?
It does part of it, well. Platforms provide breadth, continuous re-screening, workflow, and fast list and media matching across a whole vendor population — none of which an investigative team can replicate at scale. What they cannot do is verify. They match the names they are given, report what the vendor chose to disclose, and score from public footprint data. The right architecture is screening everywhere, investigation where risk triggers it.
How do you find out who really owns a vendor?
By reading the corporate chain rather than the cover page: state and foreign registry filings for the entity and its parents, officer and registered-agent cross-references across filings, address and telephone commonality, litigation and lien records naming principals, property records, and where relevant foreign registries and gazettes. The objective is control, not just title — nominee directors, holding companies and family members are the ordinary way title is separated from control.
What does the FCPA require for third-party due diligence?
The DOJ and SEC's FCPA Resource Guide does not prescribe a checklist; it treats documented, risk-based due diligence on third parties as a hallmark of an effective compliance program, because a company can be liable for the conduct of agents and intermediaries acting on its behalf. In practice that means diligence proportionate to the risk, a documented business rationale for using the third party, findings converted into contract terms, and refreshed review — the standard the Criminal Division's compliance-program guidance also applies.
How much does a vendor due diligence investigation cost?
It is normally fixed-fee and tiered so a program can budget it. A records-level verification of the entity, its principals, litigation in the relevant jurisdictions, sanctions exposure and operating address is the base tier. Full investigative diligence — deeper cross-border registry work, site verification and discreet human-source inquiry — sits above it. The drivers are the number of entities and principals, the number of jurisdictions, whether human inquiry is required, and speed.
How long does it take?
A base-tier verification on a domestic vendor typically closes within days. Full investigative diligence usually runs one to three weeks, and longer where foreign registries, courts, or site verification in another country are involved, because those sources answer on their own timetable. Where a decision cannot wait, the work is phased so an early read is available first and the deeper work continues in parallel.
What should we do if the investigation finds something?
Most findings do not disqualify a vendor — they reprice the risk. Adverse findings convert into contract terms: audit rights, ownership-change and subcontracting notification, banking-change verification protocols, escrow or performance security, and specific termination triggers. Disqualification is reserved for what cannot be managed contractually — sanctions or ownership exposure, an undisclosed internal conflict, or a pattern of concealment that makes every other representation unreliable.
Sources & further reading
- 01OFAC — Revised Guidance on Entities Owned by Blocked Persons (the 50 Percent Rule)Property of an entity owned 50% or more, directly or indirectly, in the aggregate by one or more blocked persons is itself blocked even though the entity is not named on the SDN List — the exposure that name-matching screening cannot detect.
- 02DOJ and SEC, FCPA Resource GuideTreats documented, risk-based third-party due diligence as a hallmark of an effective compliance program, and is the reason a vendor diligence file is a compliance asset as well as a commercial one.
- 03U.S. Department of Justice, Evaluation of Corporate Compliance ProgramsThe Criminal Division's guidance asks whether a company understands the business rationale for using a third party and whether its third-party diligence is risk-based, documented, and refreshed.
- 04ACFE — Report to the NationsThe global occupational-fraud study finds corruption — the scheme family covering kickbacks, bid-rigging and conflicts of interest — present in close to half of reported cases, with median losses well above the all-case median.
- 05FBI Internet Crime Complaint Center (IC3), Internet Crime Report 2024Approximately $2.77 billion in business email compromise losses in 2024 — the fraud family behind vendor-impersonation and emailed banking-detail changes.
- 06NIST SP 800-161r1 — Cybersecurity Supply Chain Risk Management PracticesThe reference framework for supplier risk in technology and systems supply chains, and the practice into which vendor diligence findings are operationalized.

