Quick Read
SPK DDMS2000:2026 Section 10.22 requires organisations to move beyond completed due diligence files to documented go/no-go decisions, classifying findings into four categories and producing one of three outcomes (Go, Conditional Go, or No-Go) with full traceability of decision-maker and rationale. Conditional Go decisions are particularly prone to failure because they defer rather than make a decision; Section 10.22.4 addresses this by mandating documented conditions, deadlines, accountability, and a default escalation consequence if conditions are not met, ensuring missed deadlines trigger fresh decisions rather than silent continuation.
Why This Whitepaper Exists
A completed due diligence file that sits on record without a documented decision has not achieved anything. The research happened, but nobody decided what it meant. SPK DDMS2000:2026 treats this specifically as the failure mode a management system exists to prevent, and Section 10.22 builds the decisioning layer that sits between DD execution and any relationship, transaction, or activity actually proceeding. This whitepaper sets out how that layer is meant to work in practice.
A completed DD file that simply sits on record without a documented decision is not a functioning management system — it is a filing exercise.
What the Standard Actually Says
Section 10.22 is cross-cutting: it applies to the output of every module in Sections 10.5 through 10.21, providing the common decisioning layer every module's findings pass through. Section 10.22.1 requires a documented findings assessment for every completed DD case, classifying the outcome as one of four categories: no material finding, a remediable red flag that can be addressed through defined mitigating action, a non-remediable red flag requiring escalation for a go/no-go decision, or an override-triggered finding requiring mandatory escalation regardless of remediability, consistent with the override provisions at Section 6.4.4 and Annex A.2.
Section 10.22.3 requires that every DD decision be one of three outcomes: Go, proceeding without conditions; Conditional Go, proceeding subject to defined, time-bound conditions; or No-Go, declining or terminating the relationship or activity. The decision, the decision-maker, the rationale, and the DD tier and finding classification behind it must all be recorded in the case record required at Section 13.1.1.
The Conditional Go Trap
A Conditional Go is the outcome most likely to quietly fail in practice, because it defers a decision rather than making one — and deferred decisions have a tendency to become permanent by default. Section 10.22.4 closes this specifically: for a Conditional Go, the organisation must document the specific conditions to be satisfied, the deadline by which they must be satisfied, the individual accountable for tracking satisfaction, and the consequence if the condition is not met by the deadline — which must default to escalation for a fresh No-Go determination, not to automatic continuation.
This last point is where most informal DD processes actually fail. Without a documented default, a missed Conditional Go deadline simply passes unnoticed, and the relationship continues exactly as if the condition had been satisfied. Section 10.22.4 makes silence the wrong outcome by design — the default has to be escalation, so a missed deadline produces a decision, not an absence of one.
Who Decides: The Approval Authority Matrix
Section 10.22.5 requires an approval authority matrix tiered to DD tier and finding classification, so that decisioning authority scales with both the depth of the underlying due diligence and the severity of what was found. The table below reflects the structure the standard itself sets out.
Finding classification | Typical approval level | Governing clause |
|---|---|---|
Tier 1–2 Go, no material finding | Analyst or first-level reviewer | Section 10.22.5 |
Tier 3 decision, or any Conditional Go | Second-level qualified reviewer | Section 10.22.5; Section 9.3.4 |
Tier 4 decision, or No-Go override of an otherwise clean file | Module owner or DD Function Owner | Section 10.22.5 |
Proceeding despite a non-remediable red flag | Module owner or DD Function Owner | Section 10.22.5 |
Override-triggered finding (e.g. confirmed sanctions match) | Governing body awareness required, regardless of transaction size | Section 10.22.5; Section 7.5.3 |
The last row deserves particular attention. An override-triggered finding — the kind of confirmed sanctions match or comparable non-negotiable factor identified in Annex A.2 — requires governing body-level awareness under Section 7.5.3 regardless of the transaction's size. A small deal with a confirmed override finding is treated with the same governance seriousness as a large one; materiality of the finding, not materiality of the transaction, drives the escalation.
Not Improvising the Response: The Red Flag Response Library
Section 10.22.2 requires the organisation to maintain a documented Red Flag Response Library, so that an analyst and reviewer are not required to improvise a response to a familiar finding pattern every time it recurs, while retaining the ability to escalate any finding that does not fit an existing pathway or presents unusual circumstances.
Annex E of the standard provides an illustrative starting library — informative guidance, not a mandated response — covering patterns such as an unresolved partial sanctions or PEP match, a confirmed sanctions or denied-party match, beneficial ownership that cannot be fully verified, and reluctance to provide end-use information in an export control context, among others. Organisations are expected to build their own library calibrated to their risk appetite under Section 6.6 and their Applicable Obligations Register under Section 6.1, using Annex E as a reference point rather than a finished document, and to review and update it at intervals not exceeding 24 months under Section 10.22.8, incorporating patterns identified through QA sampling and outcome tracking.
Watching the System, Not Just the Case
Section 10.22.7 requires the organisation to track Go, Conditional Go, and No-Go decision rates, remediation condition satisfaction rates, and decision timeliness as part of the performance monitoring at Section 12.1. Two patterns in this data are named specifically as signals requiring corrective action under Section 14.2: Conditional Go conditions routinely not being satisfied, and escalations being resolved by default rather than by active decision. Both patterns describe the same underlying failure — a decisioning framework that exists on paper but has stopped producing real decisions in practice — and the standard requires the organisation to be watching for exactly this.
Common Gaps Worth Checking
Completed DD files exist with no documented Go, Conditional Go, or No-Go decision recorded against them.
Conditional Go conditions have no tracked deadline, no named accountable owner, or no documented default consequence for a missed deadline.
Decision approval authority is informal — whoever is available signs off, regardless of the DD tier or finding classification involved.
No Red Flag Response Library exists, so recurring finding patterns are handled inconsistently between analysts and over time.
The organisation has never analysed its own Conditional Go satisfaction rate or escalation-by-default rate, despite the requirement at Section 10.22.7.
How Speeki Sentinel Certification Assesses This
Certification against SPK DDMS2000:2026 tests a sample of completed case files directly against Section 10.22: whether a documented decision exists for each, whether Conditional Go conditions carry a deadline, owner, and default consequence, and whether the approval authority applied matches the tier and finding classification involved. A file with thorough research but no recorded decision is treated as a gap against the standard, not a matter of paperwork.
Speeki Sentinel is the certification product through which this assessment is delivered. Organisations may build and operate their own decisioning framework and Red Flag Response Library independently of Sentinel; certification is a separate, optional step available once an organisation believes its framework is ready to be independently tested.
Speeki is an accredited certification body. For current information on the specific accreditations Speeki holds and their scope, please refer to speeki.com rather than relying on this whitepaper, as accreditation status and scope are maintained centrally and can change.
Closing Note
Due diligence that stops at research, without a decision, has produced a document rather than a control. Section 10.22 exists to make sure every finding a DDMS surfaces actually reaches a person with the authority to act on it, within a timeframe that does not quietly disappear, and with a record that can be reconstructed afterward. That is the difference between a management system and an archive.