Governance & Risk

Third-Party Due Diligence: What It Is & Why It Matters

Due diligence is the homework a business does on a third party before trusting it with data or a critical service.

In this explainer

  • Understand what third-party due diligence involves at a general level
  • Learn the typical areas examined before engaging a third party
  • See why due diligence is a precondition, not an afterthought
  • Know what evidence a provider might reasonably gather
  • Understand how due diligence differs from ongoing oversight

6 min

What it is

Third-party due diligence is the structured assessment a business carries out before it relies on another party for data handling or a critical service. It is the homework done in advance, so that a decision to engage is informed rather than hopeful. Due diligence aims to understand a prospective party's security, reliability and suitability before any data or dependency is placed in its hands.

Due diligence sits at the start of a relationship. It differs from ongoing oversight, which continues afterwards, but the two are connected: what you learn during due diligence shapes how closely you watch the relationship later. Skipping it means committing blind.

Key elements

The depth of due diligence should be proportionate to the risk, but it commonly examines a familiar set of areas, described here in general terms.

  • Security posture: how the party protects information and whether it can evidence its controls.
  • Reliability: the party's track record and ability to deliver consistently.
  • Obligations and terms: what the party commits to, including data protection and notification.
  • Suitability: whether the party is a sensible fit for the data and the role it would hold.
  • Evidence: documentation, references or independent assurance that supports the party's claims.

Why it matters for debt recovery

A debt-recovery provider depends on third parties for parts of its service, and the choices it makes about those parties affect your customers' data. Diligent assessment before engagement reduces the chance of an avoidable problem later, such as relying on a party that cannot protect data adequately or cannot deliver reliably. It is the difference between a considered supply chain and an accidental one.

For a prospective client, a provider that can describe its due diligence is showing that it does not take third parties on trust. That care is part of the wider accountability you are looking for when you hand over sensitive information, and it complements the assurance described across our security overview.

What to ask a provider

To understand a provider's diligence, focus on what it examines and what evidence it relies on before committing.

  • What do you assess about a third party before you rely on it?
  • How do you scale the depth of assessment to the risk involved?
  • What evidence do you ask for to support a third party's security claims?
  • What would cause you to decide against engaging a third party?

Strong answers describe a proportionate, evidence-based process. An approach that engages parties on reputation alone, with no checks, is a warning sign.

How Merion approaches it

Merion follows good practice by assessing a third party's security, reliability and suitability before relying on it, and by scaling the depth of that assessment to the risk involved. We look for evidence behind a party's claims rather than accepting them at face value, and what we learn shapes how the relationship is overseen afterwards.

We describe this at a principle level. Because the parties we work with and the way we assess them can change, we encourage prospective clients to confirm the current detail with us and to verify any provider's current due diligence and governance practices directly.

Key takeaways

  • Due diligence is the assessment done before engaging a third party, not after
  • Its depth should be proportionate to the risk the third party would carry
  • Looking for evidence behind claims is what separates diligence from assumption
  • Verify a provider's current due diligence practices directly

Frequently asked questions

How is due diligence different from ongoing oversight?

Due diligence is the upfront assessment before a relationship begins. Ongoing oversight continues afterwards. What you learn in due diligence informs how closely you oversee the relationship later.

Should every third party get the same level of due diligence?

Not necessarily. Good practice is to scale the depth of assessment to the risk involved, so a party handling sensitive data receives more scrutiny than a low-risk one.

What if a provider engages third parties on reputation alone?

That is a warning sign. Reputation is not evidence. A sound process looks for documentation or independent assurance that supports a party's security claims before committing.

Built on trust

Security and compliance you can verify

Merion handles every account on the facts, within the rules, and with data protected by design. Ask us anything.