EU Regulatory Domain
One discipline, many instruments: due diligence on suppliers, service providers, customers and business partners.
Key facts
Most compliance failures enter through a third party, such as a supplier, ICT provider, intermediary, processor or customer.
From the CSDDD, NIS2 and DORA to the GDPR and the AMLR, eight EU regimes require third-party due diligence.
Inventory, due diligence, contracting, monitoring and exit form one lifecycle that avoids duplicated questionnaires and gaps.
Counterparties and beneficial owners must be screened against EU sanctions lists.
Most compliance failures enter through a third party: a supplier, an ICT provider, an intermediary, a processor or a customer. EU law has therefore turned third-party due diligence into an obligation in almost every regulatory domain. Managing it once, with a single method, avoids duplicated questionnaires and gaps between departments.
sustainability due diligence (CSDDD): risk-based identification and management of human-rights and environmental impacts in the chain of activities of very large companies, from July 2029;
cybersecurity (NIS2): supply-chain security, including the security practices of direct suppliers and service providers (Article 21);
financial-sector ICT (DORA): ICT third-party risk strategy, register of information, mandatory contractual provisions and exit strategies (Articles 28 to 30);
data protection (GDPR): selection of processors offering sufficient guarantees, written contracts and safeguards for international transfers (Article 28 and Chapter V);
anti-money laundering (AMLR): customer due diligence, beneficial-ownership identification and conditions for relying on third parties;
anti-corruption: due diligence on intermediaries, agents and business partners, a core element of any credible anti-corruption programme;
EU restrictive measures: screening of counterparties and beneficial owners against EU sanctions lists;
artificial intelligence (AI Act): verification of the documentation and instructions supplied by AI providers.
inventory and classification: a register of third parties, classified by criticality and risk;
due diligence: proportionate questionnaires, evidence and checks before onboarding;
contracting: clauses on compliance, audit rights, security, data protection, subcontracting and termination;
monitoring: periodic reviews, incident notification and performance indicators;
exit: documented exit plans for critical services.
Compliance Assessment: a review of the third-party register and of the risk-classification method;
Implementation Kits: due-diligence questionnaires, contractual clauses and register templates;
Compliance Secretariat: maintenance of the register and of review deadlines;
Alerts & Repository: monitoring of sanctions and supply-chain rules.
Related domains: Sustainability (CSRD/CSDDD) · Digital Operational Resilience · Cybersecurity (NIS2) · Anti-Money Laundering
Official texts: Directive (EU) 2024/1760 · Regulation (EU) 2022/2554
General information as of October 2026; it does not constitute legal advice. Confirm the applicable requirements with the competent authorities.
Related domains
Request a free review of your third-party register and risk-classification method.