Governance / Third-Party Risk

Third-Party and Supplier Due Diligence

Three courses in our catalogue tell clients to screen their suppliers. This is the service that does it. One assessment covering the three questions you actually have to answer about a counterparty: are they honest, are they secure, and can they give you the ESG data you now have to report.

Integrity screening for section 17A and ISO 37001 Security risk assessment for vendors touching your data ESG and Scope 3 supplier data readiness
Overview

Third-Party & Supplier Due Diligence

What it is

Due diligence on the third parties you do business with, run as one assessment across integrity, information security and ESG rather than as three disconnected questionnaires from three departments.

Why organisations need it

Third-party exposure is where three separate obligations converge. Section 17A of the MACC Act makes a company liable for corruption committed by an associated person. A vendor with access to your systems or personal data is part of your PDPA and security posture. And Scope 3 reporting means your suppliers' emissions are now your disclosure. Most organisations address these in three places, with three questionnaires, and no consolidated view of any given supplier.

Key features

What the engagement covers

Run at the depth the relationship warrants. A high-value agent in a high-risk jurisdiction gets a different level of scrutiny from a stationery supplier, and the tiering is part of the design.

Risk tiering and programme design

Segmenting your third-party population by the risk each relationship actually carries, so effort goes where exposure is. Defines what level of diligence each tier receives and what triggers a re-assessment.

Integrity due diligence

Corporate and beneficial ownership verification, sanctions and watchlist screening, adverse media, politically exposed person identification, litigation and regulatory history, and conflict of interest against your own people. The evidence a section 17A adequate procedures defence depends on.

Vendor security risk assessment

For third parties touching your systems or personal data: security posture, access model, data handling, sub-processing, certification status and incident history, assessed proportionately rather than by sending a 300-question spreadsheet.

ESG and supplier data readiness

Whether a supplier can provide the Scope 3 and sustainability data you now have to report, what their own practices look like on the matters material to you, and where a supplier engagement plan is needed.

Contract and control recommendations

The clauses and controls that should follow the findings: audit rights, security and data protection terms, anti-corruption warranties, ESG data obligations, sub-contractor flow-down and termination triggers.

Ongoing monitoring

Re-screening on a cycle set by tier, with event-driven review when ownership changes, adverse media appears, an incident occurs or the relationship materially changes. One-time diligence at onboarding ages quickly.

Business value

What the business gets out of it

Three obligations, one assessment

Anti-corruption, security and ESG diligence share most of their evidence. Running them together costs far less than three departments each building their own process.

The section 17A defence becomes evidenced

Adequate procedures require diligence on associated persons that is documented and proportionate. This produces exactly that record.

Suppliers stop being a blind spot in your security posture

A substantial share of breaches arrive through a third party. Knowing which vendors hold what access, and what their posture is, is a prerequisite to managing that.

Scope 3 data collection has a foundation

Knowing which suppliers can supply data, and which need engagement, is what turns a Scope 3 ambition into a plan.

Procurement gets a clear answer

Findings come back as a recommendation with conditions, not as raw research. Procurement can proceed, proceed with controls, or decline, with the basis recorded.

It stops being a onboarding-only exercise

Tiered re-screening and event triggers mean the picture stays current, which is where most third-party programmes quietly fail.

How it works

How the engagement runs

01

Population and tiering

Building the third-party inventory and segmenting by risk, so the depth of diligence matches the exposure each relationship carries.

02

Programme design

Defining what each tier receives, the red flags that escalate, the approval route and the re-assessment cycle.

03

Information gathering

Collecting from the third party and from independent sources: corporate records, beneficial ownership, screening databases, adverse media and security documentation.

04

Assessment and red flag resolution

Assessing the findings, and resolving red flags through follow-up enquiry rather than treating a hit as an automatic decline.

05

Recommendation and controls

A clear recommendation with any conditions, contract clauses and controls that should accompany the relationship.

06

Monitoring and refresh

Ongoing re-screening on the tier cycle plus event-driven review, with findings fed back to the relationship owner.

Deliverables

What you receive

Third-party inventory and risk tiering

The population segmented by risk, with the diligence level and re-assessment cycle defined for each tier.

Due diligence programme

Documented procedure covering scope, red flags, escalation, approval authority and record retention.

Per-counterparty diligence reports

Findings across integrity, security and ESG, with a recommendation and any conditions attached.

Red flag register

Issues identified, the enquiries made, and how each was resolved or why the relationship proceeded regardless.

Contract clause recommendations

The terms that should follow the findings, covering audit rights, security, data protection, anti-corruption and ESG obligations.

Monitoring schedule and refresh reports

The re-screening calendar by tier, and the findings from each refresh cycle.

Who it is for

Who this is built for

Industries

Construction and propertyOil, gas and energyManufacturingFinancial servicesGovernment-linked companiesHealthcareLogisticsBursa-listed issuers

Company sizes

Listed companiesLarge enterpriseMid-marketGroup structures with shared procurement

Departments

ProcurementIntegrity and governanceComplianceRiskIT and securityLegalSustainability
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

Is this the same as AML customer due diligence?

Related but not the same. AML CDD is a statutory obligation on reporting institutions with prescribed requirements. This is risk-based diligence on suppliers, agents, distributors and partners, driven by section 17A exposure, security risk and ESG reporting rather than by AMLA. Reporting institutions usually need both, and we make sure they do not duplicate.

How deep does the screening go?

It depends on tier. Lower tiers get corporate verification and database screening. Higher tiers add beneficial ownership tracing through layered structures, adverse media in multiple languages, litigation and regulatory history, site verification where warranted, and enhanced enquiry into red flags.

What happens if we find something?

A hit is not automatically a decline. Most red flags resolve on enquiry: a common name, a resolved historical matter, or an entity that turns out to be unrelated. What matters is that the enquiry happened and the resolution is recorded, which is precisely what an adequate procedures defence relies on.

Can you assess suppliers outside Malaysia?

Yes. Corporate registry coverage and data availability vary considerably by jurisdiction, and we are explicit in the report about what could and could not be verified in a given country rather than presenting a gap as a clean result.

How is the supplier's own data handled?

Under the PDPA and the confidentiality terms in the engagement. Screening results are held under access control with a defined retention period, and we do not retain more than the assessment requires.

Do we need this for every supplier?

No, and trying to is how these programmes collapse. Tiering exists precisely so that effort concentrates on the relationships carrying real exposure. Most third-party populations have a small share of counterparties that warrant genuine scrutiny.

Can our own team run this after you set it up?

That is usually the intent. We design the programme, run the first cycle, and hand over the procedure, templates and tiering. Many clients then run routine tiers internally and refer only enhanced cases to us.

Get started

One assessment instead of three questionnaires

Tell us roughly how many third parties you deal with, your sector, and whether this is driven by section 17A, a security concern, Scope 3 reporting or all three. We will come back with a tiering approach and a fixed quotation.