Companies should start with a risk-based due diligence framework that identifies where human rights and environmental harm are most likely to occur, especially across direct suppliers and, where needed, indirect suppliers. The program should include risk assessment, preventive controls, remediation, complaint channels, and documented reporting so leadership can prove obligations are being met and respond quickly when violations surface.
What a third-party due diligence program needs to cover
A useful program starts by separating direct suppliers from indirect exposure, then ranking both by the likelihood and severity of harm. That means understanding where labour exploitation, unsafe working conditions, child labour, forced labour, and environmental damage are most plausible, and where contractual control actually exists. Due diligence should be risk-based, repeatable, and documented enough to show why each supplier was assessed at that level.
The practical test is whether the company can explain its supplier universe, its risk criteria, and why some relationships require deeper review than others. If the program treats every vendor the same, it usually misses the places where human rights harm is most concentrated and wastes effort on low-value reviews.
How to structure diligence across the supplier lifecycle
The program should move through a clear lifecycle: onboarding screening, risk segmentation, contract controls, ongoing monitoring, escalation, and closure or exit when issues cannot be remediated. Each stage should define what evidence is required, who approves exceptions, and when a supplier is paused pending corrective action. For higher-risk tiers, the company should expect more frequent reassessment and stronger evidence of preventive controls.
That lifecycle should also include complaint intake and remediation pathways. A due diligence program is incomplete if it can identify harm but cannot route concerns to the right owner, preserve evidence, or track whether corrective action actually happened. Where leverage is limited, escalation should be explicit so legal, procurement, compliance, and business leadership can decide whether to continue, suspend, or unwind the relationship.
What good reporting and remediation look like in practice
Reporting should do more than satisfy a disclosure requirement. It should show the company’s risk methodology, the categories of suppliers reviewed, the main findings, the actions taken, and the status of unresolved issues. Internally, leadership needs enough reporting to see patterns over time, not just one-off violations, so that procurement decisions and supplier strategy reflect the actual risk picture.
Remediation is strongest when it is time-bound and measurable. For example, a supplier should not remain in a “remediation in progress” state indefinitely without a target date, owner, and verification step. In practice, the company should distinguish between issues that can be corrected through training, process change, or worker remedy and issues that indicate structural non-compliance or unwillingness to improve.
Risk and Threat Considerations
Third-party due diligence fails when it becomes a paperwork exercise disconnected from real supplier behaviour. The main exposure is hidden harm in lower-tier supply chains, where visibility drops and contractual leverage weakens, making it easier for abuses to persist until a complaint, audit failure, or public allegation forces action.
Failure mechanism: Companies over-rely on self-attestations, one-time audits, or first-tier contractual terms while ignoring subcontracting, labour brokers, and regional risk concentration. That creates a blind spot where harm can continue despite a formal program existing on paper.
Impact: The result can be ongoing human rights violations, delayed remediation, regulatory scrutiny, loss of buyer trust, and supplier disruption when the issue finally surfaces. In severe cases, the organisation may need to suspend sourcing quickly without having a credible backup plan.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | A risk-based supplier diligence program depends on a defined enterprise risk strategy. |
| GV.RM-04 — Risk Management Plan | The program needs repeatable supplier review, remediation, and reporting processes. | |
| GV.SC-01 — Supply Chain Risk Management | Third-party due diligence is a supply chain risk-management activity by subject matter. | |
| Recommendation — Define supplier human-rights review thresholds and escalation rules in the risk strategy. Document supplier due diligence, monitoring, and remediation in the risk management plan. Apply supply-chain risk controls to suppliers with human-rights exposure. | ||
| ISO/IEC 27001:2022 | A.5.19 — Information security in supplier relationships | Supplier governance and oversight are central to third-party due diligence structure. |
| A.5.20 — Addressing information security within supplier agreements | Supplier contracts should carry review, reporting, and corrective-action obligations. | |
| A.5.21 — Managing information security in the ICT supply chain | The program must manage downstream supplier dependencies and indirect exposure. | |
| Recommendation — Extend supplier governance to human-rights due diligence requirements. Write due diligence, audit, and remediation duties into supplier agreements. Assess sub-tier dependencies and control failures across the supply chain. | ||
| CIS Controls v8 | CIS-15 — Service Provider Management | Vendor oversight, assessments, and ongoing monitoring map directly to third-party diligence. |
| Recommendation — Inventory providers, assess risk, and monitor supplier compliance continuously. | ||
| NIST SP 800-53 Rev 5 | SR-6 — Supplier Assessments and Reviews | Supplier assessment is the core control activity for third-party diligence. |
| SR-5 — Acquisition Strategies, Tools, and Methods | Procurement controls should embed due-diligence requirements before and during sourcing. | |
| Recommendation — Perform periodic supplier assessments against human-rights risk criteria. Bake supplier due-diligence checkpoints into sourcing and procurement processes. | ||
Practitioner Guidance
What to prioritise: Start with a supplier inventory that distinguishes direct, indirect, and brokered relationships, then assign review depth by risk rather than by spend alone. High-risk geographies, labour-intensive sectors, and opaque subcontracting chains deserve the most scrutiny.
What to verify: Confirm that the company can evidence both preventive and responsive controls, including complaint handling, escalation, remediation tracking, and decision logs for exceptions. If the program cannot show why a supplier was rated low risk, it is not yet decision-grade.
Practitioner takeaway: The strongest programs do not try to inspect everything equally; they focus on the places where harm is most likely, preserve proof of decision-making, and keep remediation tied to real business leverage.
Related resources from NHI Mgmt Group
- How should security teams build a supply chain security program that keeps pace with third-party risk changes?
- Why do supply chain due diligence obligations create risk for companies with indirect suppliers?
- How should security teams manage third-party non-human identities in supply chain environments?
- What is the difference between securing internal build systems and managing third-party supply chain risk?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org