EU Regulatory Domain

Third-Party & Supply Chain

One discipline, many instruments: due diligence on suppliers, service providers, customers and business partners.

Key facts

Third-party risk at a glance

Where failures enter

Most compliance failures enter through a third party, such as a supplier, ICT provider, intermediary, processor or customer.

Eight regimes, one duty

From the CSDDD, NIS2 and DORA to the GDPR and the AMLR, eight EU regimes require third-party due diligence.

A single lifecycle

Inventory, due diligence, contracting, monitoring and exit form one lifecycle that avoids duplicated questionnaires and gaps.

Sanctions screening

Counterparties and beneficial owners must be screened against EU sanctions lists.

Overview

Most compliance failures enter through a third party: a supplier, an ICT provider, an intermediary, a processor or a customer. EU law has therefore turned third-party due diligence into an obligation in almost every regulatory domain. Managing it once, with a single method, avoids duplicated questionnaires and gaps between departments.

Where EU law requires third-party due diligence

  • sustainability due diligence (CSDDD): risk-based identification and management of human-rights and environmental impacts in the chain of activities of very large companies, from July 2029;

  • cybersecurity (NIS2): supply-chain security, including the security practices of direct suppliers and service providers (Article 21);

  • financial-sector ICT (DORA): ICT third-party risk strategy, register of information, mandatory contractual provisions and exit strategies (Articles 28 to 30);

  • data protection (GDPR): selection of processors offering sufficient guarantees, written contracts and safeguards for international transfers (Article 28 and Chapter V);

  • anti-money laundering (AMLR): customer due diligence, beneficial-ownership identification and conditions for relying on third parties;

  • anti-corruption: due diligence on intermediaries, agents and business partners, a core element of any credible anti-corruption programme;

  • EU restrictive measures: screening of counterparties and beneficial owners against EU sanctions lists;

  • artificial intelligence (AI Act): verification of the documentation and instructions supplied by AI providers.

A single lifecycle

  • inventory and classification: a register of third parties, classified by criticality and risk;

  • due diligence: proportionate questionnaires, evidence and checks before onboarding;

  • contracting: clauses on compliance, audit rights, security, data protection, subcontracting and termination;

  • monitoring: periodic reviews, incident notification and performance indicators;

  • exit: documented exit plans for critical services.

How we can help

Related domains: Sustainability (CSRD/CSDDD) · Digital Operational Resilience · Cybersecurity (NIS2) · Anti-Money Laundering

Official texts: Directive (EU) 2024/1760 · Regulation (EU) 2022/2554

General information as of October 2026; it does not constitute legal advice. Confirm the applicable requirements with the competent authorities.

Related domains

Where third-party risk meets other rules

Sustainability (CSRD/CSDDD)

CSDDD due diligence across the chain of activities

Digital Operational Resilience

ICT third-party risk, the register of information and exit strategies

Cybersecurity (NIS2)

Supply-chain security under Article 21

Manage all your third parties with one method

Request a free review of your third-party register and risk-classification method.