Ethics Insight writing

How Should Investors Assess Third-Party and Distributor Risk Before Investment?

A practical way to judge whether third parties, distributors and intermediaries create a real integrity risk before you invest.

Third-party risk is one of the easiest things to acknowledge and one of the easiest things to assess badly.

Most businesses can tell you they use third parties. Fewer can tell you which of those relationships genuinely matter, where the pressure sits, or how problems would actually surface. That matters before investment because distributors, agents, introducers, logistics partners, suppliers, and other intermediaries can create distance between management and the reality of how work gets done.

The question is not “do they have a third-party policy?” The question is whether the business is exposed through people it does not fully control but still depends on, whether the risk is bribery, fraud, labour abuse, environmental harm, sanctions exposure, or plain operational fragility.

Start with the route to market

Before you review a vendor list, ask a simpler question: how does this business win work, move product, and get things done in practice?

If growth depends on distributors, local commercial partners, referral arrangements, tender support, customs clearance, politically connected market access, outsourced manufacturing, labour providers, or hard-to-monitor sourcing arrangements, third-party risk should move up your list quickly. If the business can sell directly, invoice cleanly, and oversee delivery closely, the risk may still exist, but it may look very different.

The main job at this stage is to identify where the business relies on outsiders to open doors, smooth friction, solve bureaucracy, stand between the company and the customer, or shield management from what is really happening further down the chain.

Work out which relationships matter most

A long list of suppliers is not the same as a risk map.

Focus first on third parties that can:

That usually means looking harder at distributors, agents, introducers, local partners, freight and customs intermediaries, labour providers, security providers, outsourced manufacturers, high-dependency contractors, and suppliers dealing in goods whose value, origin, or quality can move around quickly. Office stationery suppliers can wait.

Ask what management actually knows

A useful diligence conversation is not about whether management can recite the policy. It is about whether they can explain the relationship plainly.

Try questions like:

If answers stay vague, over-reassuring, or strangely commercial-only, that is useful in itself. Good management teams usually know where their third-party dependencies sit, even when their controls are still catching up.

Look for evidence beyond onboarding

Many businesses can show something happened before appointment. Far fewer can show what happens after.

Pre-investment, you are trying to establish whether third-party diligence is a living discipline or a one-off form at the start of the relationship.

Look for evidence of:

If the only evidence is a questionnaire plus a signed policy, assume you are seeing the administrative layer, not the operational one.

Pay attention to value, volume, and payment logic

Payment structures often tell you more than policy statements. So do products and flows that are easy to manipulate.

Commission rates, rebates, marketing support, discounts, credit terms, cash handling, and unusual success fees all deserve attention. So do goods that are hard to grade, easy to substitute, fluctuating sharply in value, or traded in large volumes with imperfect visibility. Depending on the business, that might include scrap, agricultural commodities, minerals, fuel, recycled inputs, or other products where quantity, quality, and price can all move around.

The point is not that any one of these proves misconduct. It is that poorly explained commercial arrangements can hide pressure, favouritism, side deals, theft, false invoicing, quality substitution, or value leakage.

Ask which payment arrangements, pricing patterns, or stock movements would make an independent finance or operations lead uncomfortable, and why. Then test whether those arrangements are exceptional, legacy, or treated as normal.

Look for operational conditions that make abuse easier

Some third-party risk sits less in intention than in the operating model itself.

Warning signs include rapid scaling without matching oversight, chronic subcontracting, labour churn, weak site supervision, unrealistic delivery promises, single-buyer dependency, or procurement teams forced to chase price above all else. In those conditions, management may not be instructing abuse, but it may be creating the environment in which labour exploitation, unsafe disposal, substitution, diversion, and falsified reporting become much easier.

That is why human rights and environmental risk should not be treated as a separate ethical appendix. They often sit in the same places as fraud and corruption risk: opaque chains, weak local oversight, thin margins, misaligned incentives, and strong pressure to keep good news flowing upwards.

Check where visibility drops away

Third-party risk gets worse where management loses line of sight.

That may be because the intermediary is overseas, because a founder or country lead “just knows them”, because performance data is thin, because site conditions are rarely seen first-hand, or because commercial urgency has outpaced oversight. Sometimes the risk is not a bad actor at all. It is a business that has scaled through relationships it no longer understands clearly.

One practical question helps here: if something went wrong tomorrow, how quickly would management know, and what evidence would they rely on first?

If the answer depends too heavily on trust, personal loyalty, sales results, or assurances passed up by the same intermediary in question, pause.

Separate genuine necessity from lazy dependence

Some intermediaries are necessary. New markets, fragmented customers, licensing complexity, and local delivery constraints can make them entirely sensible.

But diligence should still ask whether the relationship is doing something necessary or merely compensating for a weakness in the business. A distributor may be extending reach. Or it may be covering for the fact that the company cannot explain its own market, supervise its own sales process, trace its own supply chain, or manage its own compliance burden.

That distinction matters because investors are not only assessing current risk. They are assessing what the business will need as it grows.

Decide what kind of answer you need

Not every issue calls for the same response.

Sometimes you only need better explanation. Sometimes you need a narrower risk review focused on a handful of third parties. Sometimes you need conditions before close, a post-investment remediation plan, or a different growth assumption altogether.

What matters is leaving the process with a sharper answer to three questions:

  1. Which third parties create the real integrity, supply-chain, or operational exposure?
  2. What evidence supports management’s confidence in them?
  3. What would need to change for that exposure to be acceptable after investment?

That is a more useful outcome than a generic line saying “third-party risk noted”.

Third-party and distributor risk is not really a side issue. In many businesses, it is where commercial pressure, weak visibility, operational fragility, and plausible deniability meet. If investors do not examine that properly before investment, they often end up paying to discover it later.

More Ethics Insight writing