Home / Solutions / Financial services
Solution

Third Party Due Diligence for Financial Services
Evidenced, repeatable and current

In financial services the diligence itself is rarely the problem. Showing that it was done, that it was done consistently, and that it is still true today is where third party programmes come apart.

Evidence retained with datesScreening that keeps running
What a third party programme has to prove

Not that you checked, but that you can show it

Regulated diligence is judged on evidence and consistency. A programme that works well but cannot be demonstrated is treated as one that does not work.

Outcome

Evidence is retrieval rather than assembly

Checks, documents, approvals and dates sit on the vendor record, so producing the diligence file is a filter rather than a project.

In practiceRequests answered in minutes instead of consuming a fortnight.
Outcome

Diligence is consistent across the population

Questionnaires and rules apply on creation rather than depending on who onboarded the vendor, so the population behaves the same way.

In practiceNo variation between vendors onboarded in a quiet month and a busy one.
Outcome

The position stays current

Screening runs continuously and documents track to expiry, so a vendor cleared two years ago is not still recorded as cleared by default.

In practiceA third party population that reflects today rather than approval dates.
Third party diligence

Where programmes usually fail review

Rarely on the substance. Usually on evidence, consistency, or currency.

Book a demo
The challenge

Spread across systems

Checks live in email, documents in a drive and approvals in a workflow tool, so producing a file means assembling from three places.

LocationSeveral
Producing itDays
GapsFound late
With VendorHub

On one vendor record

Responses, documents, screening history, score breakdown and approvals sit together with their dates.

LocationOne record
Producing itMinutes
GapsFound early
The challenge

Depends who onboarded

Diligence quality varies with the person and the workload, and the variation is visible the moment a reviewer samples across the population.

DriverPeople
VariationVisible
Reads asNo programme
With VendorHub

Applied by the questionnaire

Rules and required documents attach on creation, so vendors onboarded months apart look the same.

DriverStructure
VariationMinimal
Reads asA programme
The challenge

Annual review

A vendor is reviewed once a year, which means a listing appearing in month two is unaddressed for ten.

CycleAnnual
GapUp to a year
RiskCarried
With VendorHub

Continuous monitoring

Screening and scores update as the underlying records change rather than on a review calendar.

CycleContinuous
GapNone
RiskManaged
The challenge

A rating you cannot explain

A proprietary risk grade cannot be broken down, so it is either accepted on faith or ignored entirely.

SourcesHidden
WeightsUnknown
DefensibleNo
With VendorHub

A score that opens

Each category shows the public records behind it and the weight it carries.

SourcesNamed
WeightsShown
DefensibleYes
Questions we get asked

About third party due diligence

How is vendor due diligence evidenced?
Checks, documents, approvals and screening history sit on the vendor record with their dates and the named people involved, so producing the file is retrieval rather than assembly.
How often are vendors re-screened?
Continuously rather than annually. That difference is usually the gap a reviewer identifies first in a third party programme.
Is the risk score explainable?
Yes. Each category opens to the public records behind it and the weight it carries, so a rating can be broken down rather than accepted on faith.
How do we keep diligence consistent across vendors?
Questionnaires and rules apply on creation rather than depending on who ran the onboarding, so vendors onboarded months apart are treated the same way.
Can we run different diligence for different vendor tiers?
Yes. Separate questionnaires per vendor type mean a critical vendor and a low risk supplier are not asked the same things.
Does VendorHub make the risk decision?
No. It collects, screens, scores and records. Whether a vendor is acceptable is your determination, and the record shows who made it.
Can we export the third party population?
Yes, in full, with scores, categories and document links included.
Related

Other parts of the workspace

SOLUTION

EP Score

A qualification score built from public records, with weights shown.

Read more
SOLUTION

Screening and monitoring

Continuous checks rather than an annual review.

Read more
SOLUTION

Approvals and activity

Who decided what, and when.

Read more

Bring a vendor you onboarded a while back

We will re-screen them and produce their diligence file on the call.