Quick Read

SPK DDMS2000:2026 Section 10.23 prohibits organisations from treating participation in shared industry due diligence initiatives as a substitute for their own risk assessment and obligations register, requiring instead a documented gap assessment that identifies and closes any material risks beyond the initiative's standard scope. Organisations remain the sole risk owner for any subject they rely on a shared initiative to assess, and cannot represent to regulators or auditors that such reliance alone satisfies their due diligence obligations where gaps remain unclosed. Widespread adoption of a scheme by other companies does not transfer or dilute an organisation's own due diligence responsibility.

Why This Whitepaper Exists

Joint industry due diligence initiatives, multi-stakeholder platforms, and shared audit schemes offer something genuinely useful: pooled knowledge, reduced cost, and due diligence at a scale no single organisation could achieve alone. SPK DDMS2000:2026 does not discourage participation in them. What Section 10.23 addresses directly is a specific and common misuse of these schemes — organisations treating membership in a shared initiative as a way of transferring or diluting their own due diligence risk, when no such transfer actually occurs.

An organisation's risk profile is its own; a shared initiative's standard scope is built for the average participating member, not for the specific risk profile, jurisdiction mix, or risk appetite of any single organisation.

What the Standard Actually Says

Section 10.23.1 requires the organisation to treat participation in, or reliance upon, a collaborative or industry-shared due diligence initiative as one component or input to its DDMS — not as a substitute for its own risk assessment, risk appetite determination, or Applicable Obligations Register. The organisation remains the risk owner for any subject it relies on the initiative to assess, regardless of the initiative's governance, reputation, or the number of other companies relying on it.

Section 10.23.2 requires a documented gap assessment, before relying on a shared initiative's output for a given subject or module, comparing the initiative's standard scope and methodology against the organisation's own risk profile, Applicable Obligations Register, and risk appetite. Any material risk factor relevant to the organisation that the shared initiative's standard scope does not cover must be identified and closed through supplementary organisation-specific due diligence.

Section 10.23.3 is explicit about what an organisation may not do: it may not represent to a regulator, certification body, auditor, or counterparty that reliance on a shared initiative alone satisfies its due diligence obligations where its own gap assessment has identified risk beyond the initiative's scope, and it may not treat enrolment in or payment to a shared initiative as a proxy for having conducted due diligence where the gap assessment has not been performed or has identified unclosed gaps.

Why “Everyone Else Uses This Scheme Too” Is Not a Defence

The most common informal justification for relying entirely on a shared scheme is that many other companies rely on the same one. Section 10.23.1 addresses this directly by naming it: the organisation remains the risk owner regardless of the number of other companies relying on the same initiative. Widespread adoption is evidence of a scheme's convenience and cost efficiency. It is not evidence that the scheme's generic scope happens to match any particular organisation's specific risk profile.

The table below illustrates the gap the standard is asking organisations to close — the difference between what a shared scheme was built to assess, and what any single participating organisation actually needs to know.

What a shared scheme typically covers

What it typically cannot tell you

A generic assessment against the scheme's own standard questionnaire or audit protocol

Whether that protocol covers the specific risk factors material to your organisation's relationship with the subject

A point-in-time audit or certification result

Whether the result remains current relative to your own re-screening triggers and risk tiering

Coverage appropriate to the average or typical participating member

Coverage appropriate to your organisation's specific transaction value, jurisdiction exposure, or product line with that subject

Assurance the scheme's own governance considers adequate

Whether that governance's rigour and independence meet your own evidence standard under Section 10.4.8

Decision Authority Cannot Be Delegated to the Scheme

Section 10.23.4 requires the organisation to retain its own Go, Conditional Go, and No-Go decision authority under Section 10.22.3 for any subject assessed in whole or in part through a shared initiative. That authority must not be delegated to, or treated as automatically determined by, the shared initiative's own governance body, scoring methodology, or certification outcome. A shared scheme's own pass or fail result is an input to the organisation's decision, not the decision itself.

Scrutinising the Scheme Itself

Section 10.23.5 requires the organisation to periodically assess the credibility, methodology, independence, and effective rigour of any shared initiative it materially relies upon, at intervals not exceeding 24 months, applying comparable scrutiny to that required for an individual DD vendor under Section 10.17.2. The clause makes a point of stating that industry initiatives are not inherently more reliable than a commercial vendor simply because they are collectively governed or widely adopted — collective governance is a structural feature, not a guarantee of rigour.

Where a shared assessment covers a common subject audited once for multiple member organisations, Section 10.23.6 requires the organisation to verify the assessment's currency, verify it was conducted to a methodology consistent with the organisation's own evidence standard at Section 10.4.8, and assess whether the shared assessment adequately covers risk factors specific to the organisation's own relationship with that subject — a particular product line, transaction value, or jurisdiction exposure not common to other members relying on the same assessment.

Making Reliance Auditable

Section 10.23.7 requires the organisation to record, in its Applicable Obligations Register, which collaborative or industry-shared initiatives it relies upon, for which modules and subject types, the gap assessment conducted under Section 10.23.2, and the supplementary due diligence performed to close any identified gap. This is the mechanism that turns reliance on a shared scheme into an auditable, documented decision — rather than an informal assumption that was never actually tested or written down.

Common Gaps Worth Checking

  • A shared industry assessment is accepted as complete due diligence with no documented gap assessment against the organisation's own risk profile.

  • Go/No-Go decisions on subjects covered by a shared scheme are made automatically based on the scheme's own pass/fail outcome, with no independent organisational review.

  • The shared initiative itself has never been assessed for its own credibility, methodology, or independence.

  • Reliance on the shared scheme is not recorded anywhere in the Applicable Obligations Register, so it cannot be reconstructed or audited later.

How Speeki Sentinel Certification Assesses This

Certification against SPK DDMS2000:2026 tests whether reliance on any collaborative or industry-shared initiative is supported by a genuine, documented gap assessment, and whether decision authority for subjects covered by such schemes remained with the organisation rather than being delegated to the scheme's own outcome. Reliance without a documented gap assessment is treated as a gap against Section 10.23, regardless of how well regarded the underlying scheme may be.

Speeki Sentinel is the certification product through which this assessment is delivered. Organisations may participate in industry-shared initiatives and build the gap-assessment discipline Section 10.23 requires independently of Sentinel; certification is a separate, optional step available once an organisation believes its approach is ready to be independently tested.

Speeki is an accredited certification body. For current information on the specific accreditations Speeki holds and their scope, please refer to speeki.com rather than relying on this whitepaper, as accreditation status and scope are maintained centrally and can change.

Closing Note

A shared industry initiative can be a genuinely valuable component of a due diligence programme. It cannot be the whole programme, because it was never built to answer any single organisation's specific risk question. Section 10.23 asks organisations to use these schemes for what they are — a useful input, tested against the organisation's own risk profile — rather than as a way of quietly transferring a risk that, under this standard, never actually leaves the organisation that owns it.