Quick Read

Organizations that outsource due diligence work to external vendors remain fully accountable under SPK DDMS2000:2026 Section 10.17, and cannot transfer this responsibility by delegating to a third party—particularly given documented corruption risks within parts of the research and investigations industry itself. The standard requires proportionate due diligence on vendors before engagement (including verification of their own anti-bribery controls and ISO 37001 status), contractual warranties covering lawful data sourcing, audit rights, and explicit termination provisions for bribery or fabrication. Effective operationalization of Section 10.17 treats vendor accountability as a control mechanism, not a liability shield.

Why This Whitepaper Exists

Due diligence organisations that outsource research to external screening vendors, investigators, or research firms often treat the outsourcing decision as a transfer of risk along with the work. It is not. SPK DDMS2000:2026 addresses this directly at Section 10.17, and does so with an unusually explicit acknowledgement: parts of the research and investigations industry carry a genuine corruption risk of their own, and an organisation that engages a vendor without accounting for this is not protected by having outsourced the work.

It is a known practice in parts of this industry for researchers or their local sources to pay registry clerks, court staff, database administrators, or officials for restricted access, faster turnaround, or favourable results. An organisation using a vendor whose underlying practices involve bribery, illegal data access, or fabrication is not shielded from responsibility by having outsourced the work.

What the Standard Actually Says

Section 10.17.1 establishes the governing principle: the organisation retains full accountability for the DDMS and its outcomes regardless of delegation to a third-party provider. Everything else in Section 10.17 exists to make that accountability operational rather than aspirational.

Section 10.17.2 requires due diligence on a prospective DD vendor before engagement, proportionate to the materiality of the work being delegated. This is due diligence on the due diligence provider itself — covering the vendor's ownership, licensing, and regulatory status; the vendor's own anti-bribery and compliance controls, with specific reference to whether the vendor holds an ISO 37001-conformant Anti-Bribery Management System; the vendor's data sourcing methodology and legal basis for the information it provides; and the vendor's own subcontracting practices and use of local researchers or agents.

Section 10.17.3 sets out what a contract with a DD vendor must contain, at minimum: a warranty that information provided was obtained through lawful means, without bribery, illegal data access, or breach of the source jurisdiction's data protection or privacy law; a requirement that the vendor disclose the general nature of its sourcing methodology sufficient for the organisation to assess reliability under Section 10.4.8; audit rights permitting the organisation, or Speeki as an authorised certification body, to review the vendor's DD-relevant processes and controls; disclosure of subcontracting with equivalent standards flowed down to subcontractors; and termination rights exercisable on discovery of bribery, fabrication, or unlawful data sourcing.

Why This Sector Warrants Explicit Treatment

Most vendor management frameworks treat all outsourced providers alike. Section 10.17 does not, because the research and investigations sector has a distinct risk profile from a typical supplier relationship. The product a DD vendor sells is information, and information obtained through improper means — a bribed registry clerk, an unauthorised database query, a court file accessed outside proper channels — can look identical, in the final report, to information obtained lawfully. The client organisation has no independent way to distinguish the two unless the vendor's sourcing methodology and controls have been examined in advance.

The table below sets out why the standard requires deeper scrutiny of this vendor category specifically, rather than treating it as an ordinary procurement relationship.

Vendor due diligence factor

Why it matters specifically for DD/research vendors

Vendor's own anti-bribery controls

A vendor with no ISO 37001-conformant system, or equivalent, has no structural check on how its own researchers or local agents obtain information

Data sourcing methodology and legal basis

Restricted registry access, court records, or official databases obtained through undisclosed payment to a gatekeeper are common in parts of this industry and are unlawful regardless of how the resulting report is presented

Subcontracting and local agent use

A vendor's own subcontractors and local researchers are frequently where sourcing practices are least visible to the client organisation

Ownership, licensing, and regulatory status

Establishes whether the vendor itself is a legitimate, accountable entity rather than an unregistered intermediary

Competence Does Not Transfer With Price

Section 10.17.4 requires that competence requirements equivalent to those for internal staff under Section 9.3 apply to vendor personnel performing DD work, verified through vendor attestation, sample review of vendor work product, or independent audit. The clause states directly that vendor competence is not established merely because the vendor is well known or highly priced — a reputational or cost signal is not a substitute for actual verification.

Section 10.17.5 requires periodic performance audits of each material DD vendor, at intervals not exceeding 12 months, assessing accuracy and completeness of vendor work product against the evidence standard at Section 10.4.8, timeliness against agreed service levels, and the vendor's own quality assurance and error-rate data where the vendor maintains it.

When Something Goes Wrong: The Lookback Requirement

The most consequential requirement in Section 10.17 is at Section 10.17.6, which applies the data integrity controls at Section 10.4.9 and 10.4.10 to vendor-supplied work product to the same standard as internally produced work. Where credible evidence emerges that a vendor obtained information through bribery, illegal access, or fabrication, the organisation is required to: immediately cease relying on the affected findings; re-perform the affected cases through an alternative source; review all other work product supplied by that vendor within a defined lookback period; and escalate to the governing body under Section 7.5.3, regardless of the vendor's standing or the materiality of the specific case that triggered the discovery.

The lookback requirement matters because the natural organisational instinct, on discovering a problem with one case, is to quietly correct that one case and move on. Section 10.17.6 does not allow this. If a vendor's practices are compromised, the compromise almost certainly did not begin with the case that happened to surface it — and the standard requires the organisation to find out how far back the problem goes, not just fix the visible instance.

No Black Boxes

Section 10.17.7 requires that a vendor's DD process be sufficiently documented and transparent that the organisation can itself explain, on audit, what the vendor did and why. A vendor's output is not to be treated as a black box the organisation is entitled to rely on without understanding its basis — the same principle the standard applies to AI-assisted findings at Section 10.16.3, that a conclusion is not evidence unless it is traceable to a verifiable underlying source.

Common Gaps Worth Checking

  • Vendors are selected primarily on reputation, price, or existing relationship, with no documented pre-engagement due diligence under Section 10.17.2.

  • Vendor contracts contain no lawful-sourcing warranty, no audit rights, and no disclosure requirement for subcontracting.

  • No periodic performance audit of vendor work product has ever been conducted.

  • The organisation cannot explain, for a sample of vendor-supplied findings, what the vendor actually did to reach its conclusion.

  • A concern about a specific vendor case was addressed by re-doing that case alone, with no lookback review of the vendor's other work product.

How Speeki Sentinel Certification Assesses This

Certification against SPK DDMS2000:2026 tests vendor management directly: whether pre-engagement due diligence was performed, whether contracts contain the required warranties and audit rights, whether performance audits have actually occurred, and whether the organisation can demonstrate a working lookback process rather than only a policy describing one. Vendor work product sampled during assessment is tested against the same evidence standard as internally produced work.

Speeki Sentinel is the certification product through which this assessment is delivered. Organisations may build and operate their own vendor management framework independently of Sentinel; certification is a separate, optional step available once an organisation believes its framework is ready to be independently tested.

Speeki is an accredited certification body. For current information on the specific accreditations Speeki holds and their scope, please refer to speeki.com rather than relying on this whitepaper, as accreditation status and scope are maintained centrally and can change.

Closing Note

An organisation that outsources due diligence work has not outsourced the question of whether that work was done honestly. Section 10.17 exists because the research and investigations industry is not exempt from the same integrity risks the rest of this standard addresses — and because the organisation that relies on a compromised vendor's findings bears the consequences exactly as if the compromise had occurred inside its own walls.