Risk tiering and programme design
Segmenting your third-party population by the risk each relationship actually carries, so effort goes where exposure is. Defines what level of diligence each tier receives and what triggers a re-assessment.
Three courses in our catalogue tell clients to screen their suppliers. This is the service that does it. One assessment covering the three questions you actually have to answer about a counterparty: are they honest, are they secure, and can they give you the ESG data you now have to report.
Due diligence on the third parties you do business with, run as one assessment across integrity, information security and ESG rather than as three disconnected questionnaires from three departments.
Third-party exposure is where three separate obligations converge. Section 17A of the MACC Act makes a company liable for corruption committed by an associated person. A vendor with access to your systems or personal data is part of your PDPA and security posture. And Scope 3 reporting means your suppliers' emissions are now your disclosure. Most organisations address these in three places, with three questionnaires, and no consolidated view of any given supplier.
Run at the depth the relationship warrants. A high-value agent in a high-risk jurisdiction gets a different level of scrutiny from a stationery supplier, and the tiering is part of the design.
Segmenting your third-party population by the risk each relationship actually carries, so effort goes where exposure is. Defines what level of diligence each tier receives and what triggers a re-assessment.
Corporate and beneficial ownership verification, sanctions and watchlist screening, adverse media, politically exposed person identification, litigation and regulatory history, and conflict of interest against your own people. The evidence a section 17A adequate procedures defence depends on.
For third parties touching your systems or personal data: security posture, access model, data handling, sub-processing, certification status and incident history, assessed proportionately rather than by sending a 300-question spreadsheet.
Whether a supplier can provide the Scope 3 and sustainability data you now have to report, what their own practices look like on the matters material to you, and where a supplier engagement plan is needed.
The clauses and controls that should follow the findings: audit rights, security and data protection terms, anti-corruption warranties, ESG data obligations, sub-contractor flow-down and termination triggers.
Re-screening on a cycle set by tier, with event-driven review when ownership changes, adverse media appears, an incident occurs or the relationship materially changes. One-time diligence at onboarding ages quickly.
Anti-corruption, security and ESG diligence share most of their evidence. Running them together costs far less than three departments each building their own process.
Adequate procedures require diligence on associated persons that is documented and proportionate. This produces exactly that record.
A substantial share of breaches arrive through a third party. Knowing which vendors hold what access, and what their posture is, is a prerequisite to managing that.
Knowing which suppliers can supply data, and which need engagement, is what turns a Scope 3 ambition into a plan.
Findings come back as a recommendation with conditions, not as raw research. Procurement can proceed, proceed with controls, or decline, with the basis recorded.
Tiered re-screening and event triggers mean the picture stays current, which is where most third-party programmes quietly fail.
Building the third-party inventory and segmenting by risk, so the depth of diligence matches the exposure each relationship carries.
Defining what each tier receives, the red flags that escalate, the approval route and the re-assessment cycle.
Collecting from the third party and from independent sources: corporate records, beneficial ownership, screening databases, adverse media and security documentation.
Assessing the findings, and resolving red flags through follow-up enquiry rather than treating a hit as an automatic decline.
A clear recommendation with any conditions, contract clauses and controls that should accompany the relationship.
Ongoing re-screening on the tier cycle plus event-driven review, with findings fed back to the relationship owner.
The population segmented by risk, with the diligence level and re-assessment cycle defined for each tier.
Documented procedure covering scope, red flags, escalation, approval authority and record retention.
Findings across integrity, security and ESG, with a recommendation and any conditions attached.
Issues identified, the enquiries made, and how each was resolved or why the relationship proceeded regardless.
The terms that should follow the findings, covering audit rights, security, data protection, anti-corruption and ESG obligations.
The re-screening calendar by tier, and the findings from each refresh cycle.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
Related but not the same. AML CDD is a statutory obligation on reporting institutions with prescribed requirements. This is risk-based diligence on suppliers, agents, distributors and partners, driven by section 17A exposure, security risk and ESG reporting rather than by AMLA. Reporting institutions usually need both, and we make sure they do not duplicate.
It depends on tier. Lower tiers get corporate verification and database screening. Higher tiers add beneficial ownership tracing through layered structures, adverse media in multiple languages, litigation and regulatory history, site verification where warranted, and enhanced enquiry into red flags.
A hit is not automatically a decline. Most red flags resolve on enquiry: a common name, a resolved historical matter, or an entity that turns out to be unrelated. What matters is that the enquiry happened and the resolution is recorded, which is precisely what an adequate procedures defence relies on.
Yes. Corporate registry coverage and data availability vary considerably by jurisdiction, and we are explicit in the report about what could and could not be verified in a given country rather than presenting a gap as a clean result.
Under the PDPA and the confidentiality terms in the engagement. Screening results are held under access control with a defined retention period, and we do not retain more than the assessment requires.
No, and trying to is how these programmes collapse. Tiering exists precisely so that effort concentrates on the relationships carrying real exposure. Most third-party populations have a small share of counterparties that warrant genuine scrutiny.
That is usually the intent. We design the programme, run the first cycle, and hand over the procedure, templates and tiering. Many clients then run routine tiers internally and refer only enhanced cases to us.
Tell us roughly how many third parties you deal with, your sector, and whether this is driven by section 17A, a security concern, Scope 3 reporting or all three. We will come back with a tiering approach and a fixed quotation.