Quick Read
SPK DDMS2000:2026 is Speeki's proprietary due diligence management system standard, with copyright and all intellectual property rights retained by Speeki Pte Ltd. Adopting organisations receive a limited, non-exclusive licence to use the standard internally for implementation and governance purposes, but are prohibited from incorporating it into commercial services, software products, competing frameworks, or public-facing platforms without written consent. Certification and assessment rights against this standard are reserved exclusively to Speeki and authorised certification bodies.
SPK DDMS2000:2026(E)
Copyright and Licensing Notice
© Speeki Pte Ltd 2026. All rights reserved.
1. Copyright
SPK DDMS2000:2026 is the proprietary intellectual property of Speeki Pte Ltd. All rights in this standard — including copyright in its structure, requirements, definitions, guidance, and all other content — are owned by Speeki. No part of this standard may be reproduced, distributed, translated, adapted, or transmitted in any form or by any means, electronic or mechanical, without the prior written permission of Speeki, except as expressly permitted under the licences set out below.
2. Licence for Adopting Organisations
Organisations that have adopted SPK DDMS2000:2026 as the basis for their due diligence management system are granted a limited, non-exclusive, non-transferable licence to:
reproduce and distribute copies of this standard within the organisation, for the sole purpose of internal use in connection with the adoption, implementation, and operation of SPK DDMS2000:2026;
reference and quote the requirements, definitions, and guidance of this standard in internal documents, policies, procedures, training materials, and governance records, where the purpose is to implement the standard within the organisation.
This licence is granted to the adopting organisation only. It is personal, non-transferable, and does not extend to any related entity, affiliate, or third party unless that entity is itself directly implementing the standard within its own operations.
3. Restrictions
The licence granted in Section 2 does not extend to, and the following uses are expressly prohibited without the prior written consent of Speeki:
Service providers, management consultants, advisory firms, legal and professional services firms, and other third-party providers may not incorporate, reproduce, or adapt the requirements, structure, or content of this standard into commercial services, proposals, deliverables, reports, or frameworks provided or sold to clients.
Software vendors, technology companies, and platform or application providers may not incorporate, embed, encode, reproduce, or adapt the requirements, structure, or content of this standard, in whole or in part, into any software product, SaaS platform, application, automated assessment tool, AI model, or other technology product or service.
No person or entity may use this standard, or any material derived from it, to create, develop, publish, or market any competing due diligence standard, certification scheme, or assessment framework.
No person or entity may post, publish, or make available this standard, or any substantial extract of it, on any website, extranet, portal, or platform accessible to persons outside the adopting organisation without the prior written consent of Speeki.
4. Certification Rights
The right to assess organisations against, and to issue certificates of conformity with, SPK DDMS2000:2026 is reserved exclusively to Speeki Pte Ltd and to bodies that Speeki has formally authorised in writing to act as certification bodies under this standard. No organisation, body, or individual may:
issue SPK DDMS2000:2026 certificates, certification letters, compliance statements, or equivalent recognition documents;
conduct SPK DDMS2000:2026 certification assessments or third-party conformity assessments against this standard; or
represent to any third party that an organisation has been assessed against or found conformant with SPK DDMS2000:2026,
without written authorisation from Speeki. Any certificate, report, or claim purporting to demonstrate SPK DDMS2000:2026 certification or conformity that has not been issued by Speeki or a Speeki-authorised body is invalid and may constitute a misrepresentation.
5. Licence Enquiries and Permissions
Enquiries regarding commercial licences, authorisation to act as a certification body, or any use of this standard not expressly permitted above should be directed to Speeki at speeki.com. Speeki reserves the right to update these licensing terms at each edition review.
Foreword
The Speeki Due Diligence Management System (SPK DDMS2000:2026) is the proprietary standard developed by Speeki as the basis for its due diligence management system (DDMS) certification programme. SPK DDMS2000:2026 certification is a single-outcome assessment: an organisation either satisfies the requirements of the standard and is awarded certification, or it does not. There are no graduated levels, tiers, or categories. This approach reflects how established management system certification works across ISO standards, and positions SPK DDMS2000:2026 as a credible, substantive certification rather than a participation award.
Organisations face due diligence obligations from many directions at once — anti-bribery law, anti-money laundering law, export control regimes, human rights and environmental vigilance law, forced labour and import compliance regimes, employment and privacy law, environmental and health & safety liability, and cyber/data privacy risk — each with its own scope, thresholds, evidentiary standard, and pace of change. No single law or guide addresses due diligence as a unified organisational discipline. SPK DDMS2000:2026 is a whole-of-programme standard addressing the complete lifecycle of due diligence management — from initial context setting and risk understanding, through governance, strategy, operational controls, competence, performance monitoring, and disclosure. It is broader than any single ISO domain standard, covering the full due diligence spectrum in one integrated management system.
SPK DDMS2000:2026 does not itself determine an organisation’s specific due diligence obligations under any law. Organisations retain full responsibility for identifying which laws and regulations apply to them, in which jurisdictions, for which subject types. What the standard requires is that this identification is done deliberately, documented as a formal position, and executed against consistently.
The standard also draws normative requirements from internationally recognised ISO management system standards — ISO 37001, ISO 14001, ISO 45001, ISO/IEC 27001, ISO/IEC 42001, ISO 26000, and ISO 31000 — referenced at the clause level where their requirements apply to the relevant section. Organisations that hold ISO certifications in relevant domains will find that existing certifications reduce the assessment effort for corresponding SPK DDMS2000:2026 clauses.
The requirements in Sections 5–13 represent a complete and substantive due diligence management system. They are designed to be achievable by a well-managed organisation that has committed to systematic due diligence governance, strategy, and operations — but not so demanding that only the largest multinationals can satisfy them.
The aim is a certification that means something.
Informative implementation guidance for each section is provided in Annex A. Annex A uses ‘should’ language throughout.
Departure from SPK DDMS2000:2026 Annex A guidance does not constitute a non-conformity.
This is Edition 1.0. Speeki will review SPK DDMS2000:2026 at intervals not exceeding three years.
1. Scope
This standard specifies requirements for a due diligence management system (DDMS) applicable to any organisation regardless of type, size, sector, or geography. The standard is designed for use as the basis for third-party assessment and certification by Speeki as an accredited certification body.
The standard applies to due diligence conducted on: natural persons (employees, executives, board candidates, agents, consultants); suppliers and vendors; channel partners, distributors, and intermediaries; customers and counterparties (including AML/KYC, export control, and brand/reputational contexts); sites, facilities, assets, and vendors (environmental, health & safety, and cyber/data privacy contexts); and joint venture and M&A counterparties. Certification is awarded on a pass/not-pass basis: the organisation satisfies all normative requirements of SPK DDMS2000:2026 or it does not. Partial compliance does not result in certification.
SPK DDMS2000:2026 does not prescribe which specific laws apply to any organisation, nor does it prescribe risk tolerance or thresholds. It specifies the management system requirements — governance, process, competence, monitoring, and reporting — that must demonstrably be in place and operating before certification is awarded.
2. Normative References
Reference | Title / Description |
|---|---|
ISO 37001:2025 | Anti-bribery management systems — Requirements with guidance for use |
ISO 14001:2015 | Environmental management systems — Requirements with guidance for use |
ISO 45001:2018 | Occupational health and safety management systems — Requirements |
ISO/IEC 27001:2022 | Information security management systems — Requirements |
ISO/IEC 42001:2023 | Artificial intelligence management systems |
ISO 26000:2010 | Guidance on social responsibility (informative reference) |
ISO 19011:2018 | Guidelines for auditing management systems |
ISO 31000:2018 | Risk management — Guidelines |
OECD Due Diligence Guidance for Responsible Business Conduct | Due diligence methodology referenced by multiple national vigilance laws |
UN Guiding Principles on Business and Human Rights (UNGP) | Foundational human rights due diligence framework |
FATF Recommendations; Wolfsberg Principles | AML/KYC methodology |
IFC Performance Standards | Environmental and social risk management |
ILO Combating Forced Labour: A Handbook for Employers and Business | Forced labour due diligence guidance |
Regulation (EU) 2024/3015 (EU Forced Labour Regulation, EUFLR) | Prohibits products made with forced labour on the EU market; referenced by category, per Section 10.9 |
Regulation (EU) 2023/1115, as amended by Regulation (EU) 2025/2650 (EU Deforestation Regulation, EUDR) | Prohibits deforestation-linked commodities and derived products on the EU market; referenced by category, per Section 10.19 |
Regulation (EU) 2017/821 (EU Conflict Minerals Regulation) | Supply chain due diligence for tin, tantalum, tungsten, and gold; referenced by category, per Section 10.19 |
ISO 37301:2021 | Compliance management systems — Requirements with guidance for use |
ISO 20400:2017 | Sustainable procurement — Guidance |
ISO 37009 (under preparation) | Conflict of interest in organizations — Guidelines; referenced by category for the case-level conflict of interest requirements at Section 9.2.3–9.2.4 |
ISO 37002:2021 | Whistleblowing management systems — Guidelines |
ISO/TS 37008 | Internal investigations of organizations — Guidance |
3. Terms and Definitions
Organisation | A person or group of people that has its own functions with responsibilities, authorities, and relationships to achieve its objectives. For the purposes of this standard, organisation refers to the entity whose DDMS is being assessed for SPK DDMS2000:2026 certification. |
Governing body | The person or group of persons that has ultimate responsibility and authority for an organisation’s activities, governance, and policies. Where no separate governing body exists, the governing body requirements of this standard apply to senior leadership. |
Senior leadership | The person or group of people who direct and control the organisation at the highest executive level. Senior leadership and top management are synonymous for the purposes of this standard. |
Interested party (preferred term) / Stakeholder (admitted term) | A person or organisation that can affect, be affected by, or perceive itself to be affected by a decision or activity of the organisation. |
Subject | The person or entity on whom due diligence is being conducted. |
Subject type | The category of subject (natural person, supplier, channel partner, counterparty, JV/M&A target, etc.). |
DD Function Owner | The senior executive or equivalent designated role responsible for leading and managing the DDMS. Shall have sufficient seniority, authority, and independence to discharge the responsibilities defined in Section 9, and direct access to the governing body as required under Section 7.5. |
Inherent risk (gross risk) | The level of risk presented by a subject before any due diligence measures or controls are applied. “Gross risk” is an admitted synonym used interchangeably with inherent risk in this standard, reflecting common enterprise risk management usage. |
Residual risk (net risk) | The level of risk remaining after due diligence measures and controls are applied. “Net risk” is an admitted synonym used interchangeably with residual risk in this standard. Net/residual risk is assessed against the risk appetite at Section 6.6 as part of the risk evaluation step at Section 6.7.4. |
DD Tier | The depth/intensity of due diligence assigned to a subject based on its risk classification. |
Risk appetite | The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as formally determined and documented under Section 6.6. |
Applicable Obligations Register | The organisation’s documented record of which laws, regulations, and internal policies apply to its due diligence activity, by subject type and jurisdiction, established under Section 6.1. |
Position Statement | The organisation’s documented interpretation of, and approach to, a specific applicable obligation. |
Re-screening trigger | A defined event or time interval that requires a subject’s due diligence to be refreshed, per the general ongoing due diligence obligation at Section 10.24. |
Beneficial ownership | Natural persons who ultimately own or control an entity. |
Remediation / Access to Remedy | The provision of, or cooperation in, appropriate redress for harm the organisation has caused, contributed to, or is directly linked to through a business relationship, per Section 10.18. Distinct from prevention and mitigation, which address exposure to future harm. |
Leverage | The organisation’s ability to effect change in the practices of a business relationship (e.g. a supplier or counterparty) responsible for causing an adverse impact, used as the basis for determining the organisation’s remediation obligation under Section 10.18.1(b) where it is directly linked to, but did not cause or contribute to, the harm. |
Grievance mechanism | A state-based or non-state-based, judicial or non-judicial process through which affected stakeholders may raise concerns and seek remedy, assessed against the UN Guiding Principles’ effectiveness criteria at Section 10.18.2. |
Whistleblowing / speak-up channel | A channel, distinct from the grievance mechanism, through which personnel and, where the organisation elects, external parties may report suspected misconduct, including DDMS non-conformity, per Section 10.21. |
Enhanced due diligence | Due diligence conducted at a depth beyond the organisation’s standard tiering methodology, applied to subjects or transactions connected to conflict-affected or high-risk areas, or to any factor the organisation has designated as a mandatory override under Section 6.4.3. |
Sanctions | Trade, financial, or economic restrictions imposed by a government or international body on a jurisdiction, entity, or individual, assessed under Section 10.20, distinct from AML/KYC screening (Section 10.6) and export control screening (Section 10.7) though operationally related to both. |
Deforestation-free | A product that does not contain, has not been fed with, or has not been made using commodities produced on land subject to deforestation or forest degradation after the reference date specified in the applicable regulation, per Section 10.19.2. |
Competence | The ability to apply knowledge and skills to achieve intended results. Competence may be demonstrated through education, training, experience, or qualification, and shall be independently verified per Section 9.3, not assumed from training attendance alone. |
Effectiveness | The extent to which planned activities are realised and planned results are achieved. |
Non-conformity | Non-fulfilment of a requirement of this standard. A major non-conformity is a systemic failure to satisfy a requirement, or a pattern of isolated failures indicating a systemic weakness. A minor non-conformity is an isolated failure that does not indicate a systemic breakdown. |
Material change | A change to the DDMS meeting the classification criteria at Section 8.5.5, requiring approval from the DD Function Owner or governing body rather than a module owner, distinct from a minor change that can be approved at module-owner level. |
Red flag | A DD finding indicating potential risk requiring assessment under Section 10.22, classified as remediable or non-remediable per Section 10.22.1, and addressed using the Red Flag Response Library at Annex E where applicable. |
Go / Conditional Go / No-Go | The three permissible outcomes of a DD decision under Section 10.22.3: proceeding without conditions; proceeding subject to defined, time-bound conditions; or declining/terminating the relationship or activity. |
DD conflict of interest | A personal, familial, financial, or prior professional relationship, or a direct commercial incentive in an outcome, that could reasonably be seen to affect an individual’s objectivity in conducting, reviewing, or approving DD on a specific subject, per Section 9.2.3–9.2.4. Distinct from the DD function’s organisational independence at Section 7.5.1, which concerns the function as a whole rather than an individual case. |
Data integrity (DD records) | The property of a DD case record being complete, accurate, attributable, and unaltered other than through an authorised, logged review process, per Section 10.4.9. A confirmed integrity failure (falsification, fabrication, or unauthorised backdating) is a major non-conformity per Section 10.4.10. |
DD vendor | A third-party provider to whom the organisation outsources or delegates any DD activity, including screening vendors, background-check administrators, investigators, research firms, and law firms conducting DD on the organisation’s behalf, governed by Section 10.17. Outsourcing does not transfer accountability for the DDMS or its outcomes. |
Collaborative / industry DD initiative | A joint industry due diligence initiative, multi-stakeholder platform, shared audit scheme, or industry-run assessment utility that the organisation participates in or relies upon, governed by Section 10.23. Reliance on such an initiative does not transfer the organisation’s own risk ownership, and the initiative’s standard scope is not presumed to match the organisation’s own risk profile without a documented gap assessment. |
Non-compliance | Non-fulfilment of a compliance obligation identified in the Applicable Obligations Register under Section 6.1. Distinct from DDMS non-conformity, though a non-compliance may also constitute a non-conformity where the organisation’s own controls have failed. |
DD incident | An event in which due diligence was not conducted, was conducted inadequately, or failed to identify a material risk that a conforming DDMS should have identified. |
Due diligence culture | The values, ethics, beliefs, and conduct related to due diligence — including validating counterparties — that exist throughout an organisation and produce behavioural norms that support or undermine the DDMS’s intended outcomes, per Section 7.4. |
Corrective action | Action to eliminate the root cause of a non-conformity and prevent recurrence, distinct from immediate correction and from continual improvement. |
SPK DDMS2000:2026 Certification | The single-outcome certification awarded by Speeki to an organisation that satisfies all normative requirements of this standard. An organisation is either certified or not certified. |
Speeki Sentinel | Speeki's certification against SPK DDMS2000:2026 — not a platform or system an organisation adopts independently. There is no pathway to Speeki Sentinel certification other than building a DDMS that conforms to this standard and having that conformance independently verified by Speeki. Certification itself is optional; Sentinel has no existence or role apart from it. |
Self-declaration / questionnaire | A structured set of questions completed by the subject about itself, used as a data collection mechanism under Section 10.4.13. A questionnaire is a legitimate and valid means of gathering information, but the information it produces is self-reported rather than independently verified and shall not be relied upon alone as satisfying the corroboration requirement for Tier 2 DD and above under Section 10.4.8. |
Shall | Indicates a normative requirement of this standard. Non-fulfilment of a shall requirement constitutes a non-conformity and may prevent certification or result in suspension or withdrawal of an existing certificate. |
Should | Indicates a recommendation. Should requirements appear only in Annex A (Implementation Guidelines). Departure from a should requirement does not constitute a non-conformity against this standard. |
May | Indicates a possibility or permission. May does not indicate a requirement. |
4. How to Read This Standard
SPK DDMS2000:2026 is structured in nine substantive sections (Sections 5–13), followed by Section 14 (Improvement). Within each section, requirements are grouped by topic and presented in a numbered requirements table. Each row begins with ‘The organisation shall’ followed by a specific normative requirement. Every requirement in every table must be satisfied for certification.
Requirement references use the format Clause. Requirement (e.g. 6.4.2 = Clause 6.4, Requirement 2). Assessors use these references when raising findings. Cross-references to applicable ISO standards are provided at the end of each section. Annex A provides informative implementation guidance for each section of the standard.
Certification scope: Certification applies to the scope defined by the organisation under Clause 5.2. Requirements in Clauses 10.5–10.24 (the due diligence modules) apply to the extent that the relevant subject type and domain is material within the certified scope, per the Subject-Type × Module mapping at Annex B. An organisation must document and justify any determination that a module does not apply.
5. Business Context
5.1 Organisational Context
Req. | 5.1 — Organisational Context |
|---|---|
5.1.1 | The organisation shall determine and document the internal and external context relevant to due diligence management, addressing at minimum: the organisation’s business model, industry and sector, key products and services, geographic footprint, ownership and governance structure, and the primary drivers for the DDMS spanning regulatory requirements, investor and financial institution expectations, customer requirements, employee expectations, and reputational considerations. |
5.1.2 | The organisation shall assess and document the current state of existing due diligence activity across the organisation, including processes already in place, policies adopted, certifications held, and any prior due diligence incidents or near-misses, identifying gaps against the intended DDMS scope. |
5.1.3 | The organisation shall assess the organisation’s inherent exposure to due diligence risk across each subject type it deals with — personnel, suppliers, channel partners, customers/counterparties, and JV/M&A activity — documenting this as the organisation’s due diligence exposure footprint, as the basis for scoping the modules in Section 10. |
5.1.4 | The organisation shall determine the governance model for the DDMS — whether centrally directed or distributed across business units and regions — and document the model, its rationale, the allocation of budget and resources, and the treatment of subsidiaries, joint ventures, and minority investments with respect to DDMS coverage. |
5.1.5 | The organisation shall maintain context documentation as current documented information reviewed at intervals not exceeding 24 months and demonstrate that context reviews are used to update the risk assessment methodology (Section 6.4) and programme priorities. |
Cross-references: ISO 37001:2025 Clause 4.1; ISO 14001:2015 Clause 4.1; ISO 45001:2018 Clause 4.1; ISO/IEC 27001:2022 Clause 4.1
5.2 Scope
Req. | 5.2 — Scope |
|---|---|
5.2.1 | The organisation shall define and document the geographical scope of the DDMS specifying the countries, regions, and legal entities included, and the organisational boundary, with documented rationale. |
5.2.2 | The organisation shall document the treatment of subsidiaries, joint ventures, and minority investments with respect to the DDMS scope, including whether they are required to adopt the programme, maintain their own equivalent, or are excluded with documented rationale. |
5.2.3 | The organisation shall determine and document which subject types (per Section 1) and which of the modules in Section 10.5–10.24 apply to the organisation, per the Subject-Type × Module mapping methodology at Annex B. |
5.2.4 | The organisation shall document the rationale for any scope exclusions — a subject type or module determined not to apply — and confirm through documented analysis that no exclusion results in a material due diligence risk being unmanaged. |
5.2.5 | The organisation shall review scope boundaries annually. |
Cross-references: ISO 37001:2025 Clause 4.3; ISO 14001:2015 Clause 4.3; ISO 45001:2018 Clause 4.3
5.3 Research
Req. | 5.3 — Research |
|---|---|
5.3.1 | The organisation shall conduct and document research to identify all obligations applicable to the organisation’s due diligence activity, covering: (a) a legal and regulatory obligation review across all material jurisdictions for each applicable subject type; (b) competitor and peer due diligence practice analysis reviewing at least three material industry peers; and (c) business case development demonstrating how each module’s activity connects to financial, operational, or reputational value. |
5.3.2 | The organisation shall maintain a current research base, reviewed and updated annually, incorporating regulatory development tracking (see Annex D), investor and counterparty DD expectation analysis, and peer benchmarking data. |
5.3.3 | The organisation shall document how specific research findings have directly influenced the Applicable Obligations Register (Section 6.1), the risk appetite determination (Section 6.6), and resource allocation decisions, creating a traceable connection between evidence and programme design. |
Cross-references: ISO 26000:2010 Clause 5.2
5.4 Benchmarking
Req. | 5.4 — Benchmarking |
|---|---|
5.4.1 | The organisation shall conduct benchmarking analysis covering all material due diligence modules, referencing peer practice, applicable regulatory guidance, and available industry standards. |
5.4.2 | The organisation shall use benchmarking outcomes as a primary input to objective-setting under Section 8, documenting how benchmarks have calibrated the ambition of each objective, and address any finding that the organisation is materially below peer practice with a documented action plan. |
Cross-references: ISO 37001:2025 Clause 5.1
5.5 Value Propositions
Req. | 5.5 — Value Propositions |
|---|---|
5.5.1 | The organisation shall develop and document value propositions for the DDMS tailored to: (a) executives and senior leadership — financial performance, competitive advantage, and risk mitigation; (b) management — operational efficiency and risk management; (c) employees — workplace integrity and personal accountability; (d) the governing body — governance quality, investor relations, regulatory compliance, and long-term enterprise value. |
5.5.2 | The organisation shall ensure each value proposition is substantiated by documented evidence from the research conducted under Section 5.3, with specific financial, operational, or reputational justifications provided for DDMS investment across each module. |
5.5.3 | The organisation shall review and update value propositions annually, incorporate updated research and stakeholder feedback, and demonstrate that they have been used to secure and maintain leadership support and resource allocation for the DDMS. |
Cross-references: ISO 26000:2010 Clause 5.2; ISO 37001:2025 Clause 5.1
6. Understanding Risks
This Section follows the risk management process structure set out in ISO 31000:2018 — establishing context (carried forward from Section 5), risk identification (Section 6.3), risk analysis (Section 6.4), risk evaluation (Sections 6.6–6.7), and risk treatment (implemented through the controls at Section 10.4 and the modules at Section 10.5–10.24) — with monitoring and review (Section 12) and communication and consultation with stakeholders (Section 6.2) applied throughout rather than as one-off steps. Organisations already operating an ISO 31000-aligned enterprise risk management process should integrate this Section into that process rather than running a parallel, disconnected risk methodology for DD purposes alone.
6.1 Obligations
Obligations are the starting point of the entire DDMS. This standard does not tell the organisation what the law requires. It requires the organisation to know what the law requires, declare that position formally, and execute consistently against its own declaration. Certification tests whether the Applicable Obligations Register exists, is current, and is being followed in practice — not whether the underlying legal position is correct. This preserves the certification body’s independence: SPK DDMS2000:2026 certifies the existence and integrity of a due diligence system, never the correctness of a legal conclusion.
SPK DDMS2000:2026 is designed so that full conformance necessarily satisfies the OECD’s six-step due diligence framework (embed; identify and assess; cease, prevent, or mitigate; track; communicate; remediate) — the process description underlying the OECD Guidelines, the OECD Due Diligence Guidance for Responsible Business Conduct, and CSDDD/CS3D alike. See Annex D.1 for the full clause-by-clause crosswalk.
Req. | 6.1 — Obligations |
|---|---|
6.1.1 | The organisation shall identify and document all obligations applicable to its due diligence activity, by subject type and jurisdiction, in an Applicable Obligations Register, classified as: (a) mandatory obligations — laws, regulations, and binding requirements across all jurisdictions of material operation, including anti-bribery law, AML/KYC law, export control regimes, human rights and environmental vigilance law, forced labour and import compliance regimes, and applicable employment and data protection law; and (b) voluntary obligations — frameworks, codes, and standards the organisation has chosen to adopt. |
6.1.2 | The organisation shall assess applicability of each obligation on its own terms rather than by analogy to a different obligation’s thresholds, and shall not assume an obligation is inapplicable solely because the organisation falls below the size, employee, or revenue threshold of an unrelated regime — thresholds vary materially between regimes even within the same regulatory family (e.g. CSDDD applies only above 5,000 employees and €1.5bn turnover following the Omnibus I amendment, while the EU Forced Labour Regulation applies to any operator placing, making available, or exporting an in-scope product on the EU market, regardless of size). A small or mid-market organisation shall specifically verify EUFLR, EUDR, and comparable no-threshold or low-threshold regimes rather than concluding it is out of scope for EU due diligence law generally because it falls below CSDDD’s threshold. |
6.1.3 | The organisation shall document for each obligation: the source, nature, and jurisdiction; the subject type(s) and module(s) it governs (per Section 10); a documented Position Statement — what the organisation will and will not collect, verify, retain, or act upon, and why; the legal basis or justification for that position; ownership — who approved the position; and the review cadence. |
6.1.4 | The organisation shall use the Applicable Obligations Register as the primary input to scoping the modules under Section 10 and the risk appetite determination under Section 6.6. |
6.1.5 | The organisation shall review and update the Applicable Obligations Register at least annually and whenever the organisation enters new jurisdictions, takes on new subject types, or when applicable regulations change materially, including changes tracked in Annex D. Changes shall be reported to the governing body. |
Cross-references: ISO 37001:2025 Clauses 4.5, 6.2; ISO 14001:2015 Clause 6.1.3
6.2 Stakeholder Analysis
Req. | 6.2 — Stakeholder Analysis |
|---|---|
6.2.1 | The organisation shall identify and document all material internal and external stakeholders relevant to the DDMS, including internal stakeholders (employees, management, governing body) and external stakeholders (investors, lenders, customers, suppliers, regulators, affected communities, and affected individuals such as DD subjects and their representatives). For each group, document their DD-related interests and concerns and the appropriate mechanism and frequency for engagement. |
6.2.2 | The organisation shall use identified stakeholder groups as active inputs to the risk identification and assessment process under Sections 6.3–6.4, particularly the perspectives of functions that initiate relationships with new counterparties (sales, procurement, HR, business development, deal teams), and the perspectives of any affected individuals or communities where the organisation’s DD activity has human rights or environmental implications. |
6.2.3 | The organisation shall maintain ongoing stakeholder engagement channels appropriate to each group, document the outcomes and views expressed, and update the stakeholder analysis whenever significant changes in context, subject-type exposure, or module scope occur. |
6.2.4 | The organisation shall use stakeholder input as a direct input to the design of the DDMS, not only to risk identification — including the scope determination at Section 5.2, the risk appetite determination at Section 6.6, and the design or review of the grievance mechanism at Section 10.18.2 — and shall document specific instances where stakeholder input has influenced these design decisions, distinguishing genuine engagement from consultation that does not change the outcome. |
6.2.5 | The organisation shall give particular attention to stakeholders at heightened risk of harm or marginalisation in connection with the organisation’s DD activity — including workers in weak labour-market or enforcement contexts, indigenous peoples, human rights defenders, and affected communities in conflict-affected or high-risk areas per Section 6.3.5 — and shall ensure engagement channels are genuinely accessible to these groups rather than defaulting to channels that assume literacy, language, technology access, or freedom from reprisal that such groups may not have. |
Cross-references: ISO 26000:2010 Clause 5.2; ISO 37001:2025 Clause 4.2; UN Guiding Principles on Business and Human Rights
6.3 Subject and Risk Identification
Req. | 6.3 — Subject and Risk Identification |
|---|---|
6.3.1 | The organisation shall identify and document the full universe of subject types and inherent risk factors relevant to its due diligence activity, considering at minimum: geography, sector, transaction or relationship value, red-flag indicators, PEP exposure, sanctions exposure, beneficial ownership complexity, export control classification exposure, and prior adverse findings. |
6.3.2 | The organisation shall conduct risk identification through a structured process drawing on the organisation’s context (Section 5.1), the Applicable Obligations Register (Section 6.1), and stakeholder input (Section 6.2), and shall consider the full range of modules at Section 10.5–10.24 when scoping which risk factors apply. |
6.3.3 | The organisation shall document each identified risk factor with its source, the module(s) it is relevant to, and the subject type(s) it applies to, and shall maintain the inventory as current, reviewed and updated at least annually and whenever a new subject type or module comes into scope. |
6.3.4 | The organisation shall define and document the depth of supply chain mapping required for each applicable module — direct (Tier 1) relationships, or extended mapping to Tier 2 and beyond — based on the evidentiary depth required by the applicable regime identified in the Applicable Obligations Register (e.g. the extended mapping typically required for rebuttable-presumption or commodity-traceability regimes under Sections 10.9 and 10.19) rather than applying a single mapping depth uniformly across all modules. |
6.3.5 | The organisation shall identify subjects and transactions connected to conflict-affected or high-risk areas, and shall apply enhanced due diligence in these cases consistent with the OECD Due Diligence Guidance’s specific recommendations for such areas — including heightened risk assessment, more frequent re-screening, and, where warranted, senior-level sign-off before a relationship proceeds — rather than treating conflict-affected area exposure as simply one more factor in the generic aggregate score. |
Cross-references: ISO 31000:2018 (Risk management — Guidelines); OECD Due Diligence Guidance for Responsible Business Conduct; OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas; UN Guiding Principles
6.4 Risk Assessment — the Tiering Methodology
This standard is risk-based by design, and the risk itself is the organisation’s to define. SPK DDMS2000:2026 does not prescribe a universal risk tolerance, a universal set of red flags, or universal tier thresholds — every organisation operates in different sectors, jurisdictions, and markets, and faces a different mix of legal obligation, commercial pressure, and reputational exposure. What the standard requires is that the organisation makes this a deliberate, owned, documented decision, rather than an unstated default that emerges accidentally from whatever an analyst happens to do on a given day.
Req. | 6.4 — Risk Assessment |
|---|---|
6.4.1 | The organisation shall analyse each identified risk factor in terms of its likelihood and potential consequence, consistent with ISO 31000:2018 risk analysis principles, before translating the analysis into a tier determination — a factor’s contribution to the tiering methodology shall be traceable to a documented likelihood and consequence assessment, not asserted as a bare score. |
6.4.2 | The organisation shall translate the risk analysis into a subject classification × inherent (gross) risk factor → DD Tier methodology, setting its own thresholds, weightings, and factor definitions consistent with its risk appetite (Section 6.6). See Annex A.2 for an illustrative worked model. |
6.4.3 | The organisation shall document the rationale for its chosen thresholds — why a given combination of factors triggers one tier rather than another — so the methodology is defensible and auditable, not simply asserted. |
6.4.4 | The organisation shall document override provisions for factors it treats as non-negotiable regardless of aggregate score (e.g. a confirmed sanctions hit, a comprehensive-sanctions jurisdiction, or a confirmed serious health and safety incident), consistent with the override logic at Annex A.2. |
6.4.5 | The organisation shall define module-specific tiering logic where the generic aggregate-score model at Annex A.2 is not appropriate — including for Section 10.9 (rebuttable-presumption regimes), Section 10.10 (role-sensitivity-based tiering for personnel), and Section 10.12 (discretionary brand criteria) — consistent with the module-specific notes at Annex A.2. |
6.4.6 | The organisation shall exercise caution where it converts the outputs of risk assessments, questionnaires, background checks, or other DD activity into a numeric or coded score: scoring is an acceptable and often useful way to aggregate and compare findings consistently, but it shall not be used in a way that obscures the underlying qualitative judgement behind a score, creates false precision (treating a score as more objective or exact than the inputs justify), or allows a material finding to be diluted through averaging against unrelated low-risk factors. Any scoring methodology used shall be documented sufficiently that the specific findings behind a given score can be reconstructed and reviewed, consistent with the evidence standard at Section 10.4.8, and shall not be treated as a substitute for the analyst's and reviewer's own judgement under Section 10.22. |
6.4.7 | The organisation shall document and justify the methodology it uses to assess country or jurisdiction risk within its risk factor scoring and shall not adopt a publicly available country risk index or list as its jurisdiction risk factor without adapting it to the organisation's own business. A public index (e.g. a corruption perceptions index, a sanctions exposure list, or a financial crime risk ranking) reflects a general assessment for an average or unspecified organisation; it does not, on its own, reflect the specific sectors the organisation operates in, the nature of its activities in a given country, or the organisation's own risk appetite and tolerance as determined under Section 6.6. Where the organisation relies on a public index as an input, it shall document how that index has been weighted, adjusted, or supplemented to reflect its own footprint and risk tolerance, rather than applying the index's ratings unmodified. |
Cross-references: ISO 31000:2018; FATF Recommendations
6.5 Tier Grouping
Req. | 6.5 — Tier Grouping |
|---|---|
6.5.1 | The organisation shall group its due diligence activity into a coherent set of DD Tiers (per Section 6.4), sufficiently specific to be distinctly managed and evidenced, and sufficiently broad to provide a coherent, manageable framework across all applicable modules. |
6.5.2 | The organisation shall document the evidentiary and competence requirements attached to each tier, cross-referencing the evidence standards at Section 9.5 and the competence requirements at Section 9.3. |
6.5.3 | The organisation shall ensure the tier structure is agreed by senior leadership before proceeding to the risk appetite determination under Section 6.6. |
6.6 Risk Appetite and Tolerance Determination
Req. | 6.6 — Risk Appetite and Tolerance Determination |
|---|---|
6.6.1 | The organisation shall formally determine and document its risk appetite and risk tolerance for due diligence purposes — how much residual risk it is willing to accept, by subject type and module — and where it is not willing to accept residual risk at all, regardless of commercial pressure. |
6.6.2 | The organisation shall submit the risk appetite determination and tiering methodology to the governing body (or an appropriately senior level per Section 7.5) for formal approval before use as the basis for the DDMS. |
6.6.3 | The organisation shall review its risk appetite and tiering methodology at planned intervals and following material changes in context (new markets, new subject types, regulatory change tracked in Annex D, or adverse outcomes surfaced through Section 12.1) and record the review and any resulting changes. |
Note: Certification tests whether this determination exists, was properly approved, is being followed consistently, and is periodically reviewed — not whether Speeki or any auditor agrees with where the organisation has set its own risk tolerance.
6.7 Controls and Gap Assessment
Req. | 6.7 — Controls and Gap Assessment |
|---|---|
6.7.1 | The organisation shall conduct and document a controls and gap assessment for each module identified as applicable under Section 5.2, evaluating existing controls, their adequacy relative to the risk tiering under Section 6.4, and control gaps. |
6.7.2 | The organisation shall assess the residual (net) risk profile after considering existing controls, prioritising modules where residual risk is highest or gaps are most significant. |
6.7.3 | The organisation shall produce a documented assessment output connecting directly to the objectives under Section 8.1 and the annual action plan under Section 8.4. The assessment shall be reviewed at each management review cycle (Section 12.3). |
6.7.4 | The organisation shall conduct a documented risk evaluation, consistent with ISO 31000:2018 risk evaluation principles, comparing the assessed residual (net) risk under Section 6.7.2 against the risk appetite and tolerance determined under Section 6.6, for each applicable module. Where residual risk exceeds the organisation’s stated appetite even after existing controls are considered, the organisation shall not treat this as an acceptable steady state; it shall either strengthen controls (risk treatment), escalate the specific gap to the governing body for a documented risk acceptance decision under Section 7.5, or reduce exposure by declining or exiting the relationship or activity giving rise to the excess risk. |
6.7.5 | The organisation shall record any instance where residual risk was knowingly accepted above the organisation’s stated appetite, including the approving authority and the review date for that acceptance, and shall treat an unreviewed or unapproved acceptance of excess residual risk as a nonconformity under Section 14.2. |
Cross-references: ISO 31000:2018 (risk evaluation and risk treatment); ISO 37001:2025 Clause 4.5 (Bribery risk assessment)
7. Buy-in and Leadership Commitment
7.1 Stakeholder Buy-in
Req. | 7.1 — Stakeholder Buy-in |
|---|---|
7.1.1 | The organisation shall secure and document buy-in from each internal function with material DDMS responsibilities, including at minimum human resources, finance, legal and compliance, procurement, sales/business development, and operations. |
7.1.2 | The organisation shall manage external stakeholder buy-in through documented communications appropriate to each stakeholder group identified at Section 6.2.1, including material suppliers and counterparties on DD expectations, and, where the organisation’s DD activity has human rights or environmental implications, affected communities, worker representatives, or civil society organisations relevant to that impact. |
7.1.3 | The organisation shall maintain active buy-in through annual confirmation from material internal functions of their current DDMS responsibilities, and shall demonstrate, through the engagement records at Section 6.2.3, that external stakeholder input has been genuinely considered rather than solicited as a formality. |
Cross-references: ISO 37001:2025 Clause 5.1; ISO 26000:2010 Clause 5.3
7.2 Executive and Board Buy-in
Req. | 7.2 — Executive and Board Buy-in |
|---|---|
7.2.1 | The organisation shall secure documented approval and endorsement of the DDMS from the CEO or equivalent, including formal sign-off of the DD policy (Section 10.1). |
7.2.2 | The organisation shall assign named oversight responsibility for the DDMS to a designated governing body member or committee, and ensure the governing body receives DDMS performance reports at intervals not exceeding 6 months. |
7.2.3 | The organisation shall ensure due diligence risks appear in the enterprise risk register reviewed by the governing body. |
7.2.4 | The organisation shall include DDMS performance accountability in the documented performance objectives of the CEO and other senior leaders with material DDMS responsibilities. |
Cross-references: ISO 37001:2025 Clauses 5.1.1, 5.3.1
7.3 Employee Buy-in
Req. | 7.3 — Employee Buy-in |
|---|---|
7.3.1 | The organisation shall solicit and document feedback from a representative sample of employees on the DDMS, and communicate the programme’s purpose, scope, and employee contribution to all relevant personnel. |
7.3.2 | The organisation shall demonstrate that employee feedback has influenced DDMS design or implementation and ensure employees in DD-relevant roles can articulate their specific DDMS responsibilities and understand which modules and DD tiers are relevant to their work. |
Cross-references: ISO 37001:2025 Clause 7.3
7.4 Due Diligence Culture
Validating counterparties — whoever they are, and however senior or time-pressured the relationship — must be treated as a normal, expected part of doing business rather than a bureaucratic afterthought or a signal of distrust.
Req. | 7.4 — Due Diligence Culture |
|---|---|
7.4.1 | The organisation shall develop, maintain, and promote a due diligence culture at all levels of the organisation, embedding the values, behaviours, and conduct standards required to achieve the DDMS’s intended outcomes. |
7.4.2 | The organisation shall ensure top management visibly supports DD outcomes even where they slow down or block a commercially desirable relationship and shall not permit DD requirements to be waived informally under deal pressure. A gap between stated commitment and observed leadership behaviour is a non-conformity against this clause. |
7.4.3 | The organisation shall ensure staff who raise DD concerns, escalate red flags, or decline to proceed pending DD completion are not penalised or side-lined for doing so. |
7.4.4 | The organisation shall embed DD awareness into onboarding and periodic training for roles that initiate relationships with new counterparties (Section 11.3). |
7.4.5 | The organisation shall periodically assess, as part of management review (Section 12.3), whether this culture is actually being lived in practice — not only whether the DDMS’s procedural requirements are being met on paper. |
Cross-references: ISO 37001:2025 Clause 5.1.2; ISO 26000:2010 Clause 6.4
7.5 Governing Body Governance
Req. | 7.5 — Governing Body Governance |
|---|---|
7.5.1 | The organisation shall establish and maintain the following governance principles as non-negotiable conditions of the DDMS: (a) Direct access — the DD Function Owner shall have direct access to the governing body; (b) Independence — the DD function shall operate free from undue interference from any business unit whose activities it oversees; (c) Authority — the DD function shall have authority to direct corrective action across organisational functions. |
7.5.2 | The organisation shall formally approve the DD policy (Section 10.1) at governing body level, and shall not issue, materially amend, or withdraw the DD policy without governing body approval. |
7.5.3 | The organisation shall ensure material DD failures are reported to the governing body promptly and without deferral to the next scheduled cycle, including confirmed sanctions or denied-party matches proceeded against, material regulatory breaches, and serious incidents identified through modules 10.9 or 10.14. |
7.5.4 | The organisation shall actively exercise oversight of the DD Function Owner’s management of the DDMS, including formal performance assessment against documented objectives at the annual performance review, and holding the DD Function Owner accountable for the timely escalation of material DD failures. |
7.5.5 | The organisation shall review and confirm at intervals not exceeding 24 months that the organisation’s remuneration structures, sales incentives, and commercial targets do not create pressure that works against the DDMS or the culture required under Section 7.4 — for example, incentive structures that reward speed to close a deal without regard to DD completion status. |
7.5.6 | The organisation shall include DD as a standing agenda item at governing body meetings at intervals not exceeding 6 months, with substantive discussion of DDMS performance, material risks, and regulatory developments tracked in Annex D, and shall formally document material DD-related governing body decisions. |
Cross-references: ISO 37001:2025 Clauses 5.1, 5.1.3, 5.3.1
8. Objectives and Strategy
8.1 Due Diligence Objectives
Req. | 8.1 — Due Diligence Objectives |
|---|---|
8.1.1 | The organisation shall establish documented DD objectives for each applicable module and subject type, with assigned ownership, defined timeframes, and explicit alignment to the DD policy (Section 10.1) and the risk assessment under Section 6. |
8.1.2 | The organisation shall develop objectives through cross-functional involvement, engaging subject-matter owners for each applicable module, incorporating stakeholder input gathered under Section 6.2 (particularly where objectives concern grievance mechanism performance, remediation, or affected-community impact), and referencing the benchmarking outcomes at Section 5.4 when defining objectives. |
8.1.3 | The organisation shall cascade objectives to relevant business units and functions with documented implementation plans, review all objectives at intervals not exceeding 12 months, and update them where context, risk assessment, or Annex D regulatory tracking has changed materially. |
Cross-references: ISO 37001:2025 Clause 6.2
8.2 SMART Goals
Req. | 8.2 — SMART Goals |
|---|---|
8.2.1 | The organisation shall express DD objectives as Specific, Measurable, Achievable, Relevant, and Time-bound goals — e.g. screening coverage targets, re-screening cycle adherence, time-to-close for enhanced DD, remediation closure rates, QA sampling coverage — with documented baseline, target value, measurement methodology, and assigned owner. |
8.2.2 | The organisation shall track SMART goal performance at intervals not exceeding quarterly and report status to the responsible module owner, with a documented corrective action plan for any goal at risk of not being achieved within the defined timeframe. |
8.3 Success Criteria
Req. | 8.3 — Success Criteria |
|---|---|
8.3.1 | The organisation shall define success criteria for the DDMS overall and for each applicable module, articulating what constitutes success from the perspective of the governing body, senior leadership, and the DD function. |
8.3.2 | The organisation shall incorporate success criteria evaluation into the management review under Section 12.3 and assess and report on the degree to which criteria have been met or missed. |
8.4 Actions to Achieve Objectives
Req. | 8.4 — Actions to Achieve Objectives |
|---|---|
8.4.1 | The organisation shall, for each DD objective and SMART goal, define and document a set of concrete actions specifying: what will be done; who is responsible; what resources are required; when the action will be completed; and how completion will be measured. |
8.4.2 | The organisation shall consolidate all documented actions into an annual DD action plan, covering all applicable modules, consistent with the controls and gap assessment under Section 6.7 and the resourcing under Section 9.5. The annual action plan shall be reviewed and approved by senior leadership. |
8.4.3 | The organisation shall monitor progress against documented actions as part of the KPI tracking process under Section 12.2, reporting action status — on track, at risk, or overdue — to management at each management review. |
8.4.4 | The organisation shall, where an action is not completed within the planned timeframe, either (a) revise the timeline with documented justification and approval; or (b) initiate a corrective action under Section 14.2 where the delay is attributable to a control failure or resource shortfall. |
8.5 Planning of Changes
Req. | 8.5 — Planning of Changes | |
|---|---|---|
8.5.1 | The organisation shall, where it determines the need to change the DDMS — including changes to scope, risk appetite, tiering thresholds, governance structure, or operational controls — carry out those changes in a planned and controlled manner before implementation and shall not implement material changes (e.g. relaxing a tier threshold) without documented risk assessment and appropriate sign-off. | |
8.5.2 | The organisation shall, when planning any DDMS change, consider and document the purpose of the change, its potential consequences for the ongoing integrity of the system, and the resources and reallocation of responsibilities required. | |
8.5.3 | The organisation shall communicate planned material changes to all affected personnel before implementation and review the effectiveness of each material change at the next management review cycle. | |
8.5.4 | The organisation shall define and document specific triggers that require a change to be evaluated under this clause, including at minimum: a regulatory change tracked in Annex D; entry into a new jurisdiction, subject type, or module (Section 5.2); a material acquisition, divestment, or restructuring; a change in a key role under Section 9.1–9.2; adoption or material update of an AI tool under Section 10.16.1; and any recurring or systemic nonconformity identified under Section 14.2 that indicates the current design is no longer adequate. | |
8.5.5 | The organisation shall classify each proposed change as minor or material, using documented classification criteria, and require approval commensurate with the classification — minor changes may be approved by the relevant module owner (Section 9.1.2), while material changes (including any change to risk appetite under Section 6.6, or any change that relaxes a tiering threshold or evidence standard under Section 10.4.8) shall require approval from the DD Function Owner or, where the change is significant enough to meet the reporting threshold at Section 7.5.3, the governing body. | |
8.5.6 | The organisation shall assess and document the potential impact of a proposed change on other applicable modules before implementation, given that subjects, tiering methodology, and evidence standards are shared across modules under Section 10, and a change intended to affect one module may have unintended consequences for another. | |
8.5.7 | The organisation shall maintain version control over DDMS governing documents (the DD policy, the Applicable Obligations Register, Position Statements, the risk appetite determination, and module procedures), retaining prior versions and the rationale for each change, sufficient to reconstruct what the DDMS required at any point in time for audit or investigation purposes. | |
Cross-references: ISO 14001:2015 Clause 6.3; ISO 37001:2025 Clause 6.3; ISO 45001:2018 Clause 6.3; ISO 50001:2018 Clause 6.3
9. Roles, Competence, and Accountability
9.1 Ownership
Req. | 9.1 — Ownership |
|---|---|
9.1.1 | The organisation shall designate a DD Function Owner (per Section 3) with overall accountability for the DDMS, documented authority to establish, implement, monitor, and report on the programme, and a documented reporting line and access to the CEO and governing body per Section 7.5. |
9.1.2 | The organisation shall designate module-level owners for each applicable module under Section 10 where organisational scale warrants separation of ownership (e.g. a distinct owner for export control per Section 10.7.6) and document each owner’s reporting line to the DD Function Owner. |
9.1.3 | The organisation shall review the DD governance structure annually and confirm it remains adequate given the organisation’s size, DDMS scope, and programme maturity. |
Cross-references: ISO 37001:2025 Clauses 5.3.2, 5.1.3
9.2 Roles and Responsibilities
Req. | 9.2 — Roles and Responsibilities |
|---|---|
9.2.1 | The organisation shall document roles and responsibilities for DD analysts, second-level reviewers, module owners, and the DD Function Owner, specifying for each role its specific responsibilities and authority to act. |
9.2.2 | The organisation shall document escalation pathways for each module, including who has authority to hold, decline, or approve a relationship against DD findings, and shall maintain a current DDMS responsibility matrix reviewed at intervals not exceeding 12 months. |
9.2.3 | The organisation shall require any individual assigned to conduct, review, or approve DD on a specific subject to declare any personal, familial, financial, or prior professional relationship with that subject or its principals before commencing work on the case, and shall reassign the case to an unconflicted individual where a declared relationship could reasonably be seen to affect the individual’s objectivity. |
9.2.4 | The organisation shall ensure that an individual with a direct commercial incentive in a relationship or transaction proceeding — including deal-team members, sales personnel, or relationship owners compensated on the basis of the relationship closing — is not the sole decision-maker for a Go, Conditional Go, or No-Go determination on that subject under Section 10.22.3, and shall require independent review consistent with the segregation-of-duties principle underlying Section 9.3.4. |
Cross-references: ISO 14001:2015 Clause 5.3; ISO 37001:2025 Clause 5.3.3 (Delegated decision-making, addressing conflicts of interest) and Clause 3.29 (conflict of interest definition); ISO 37009 (under preparation)
9.3 Competencies
Weak due diligence is, in practice, more often a competence failure than a process failure. Competence is treated in this standard as a hard conformance requirement, not a general HR matter.
Req. | 9.3 — Competencies |
|---|---|
9.3.1 | The organisation shall define role-specific competence requirements for each module in Section 10, distinguishing at minimum between AML/KYC analysts, export control specialists, HREDD supplier assessors, forced-labour/import-compliance investigators, background-check administrators, anti-bribery reviewers, and brand/reputational reviewers. |
9.3.2 | The organisation shall require that any individual conducting Tier 3 or Tier 4 DD hold demonstrated competence appropriate to that tier before being authorised to do so unsupervised and maintain authorisation records. |
9.3.3 | The organisation shall verify competence through means beyond training attendance — assessed casework, sign-off by a qualified reviewer, recognised qualification, or documented internal competency assessment. |
9.3.4 | The organisation shall require second-level qualified review and sign-off for Tier 3 and Tier 4 findings before reliance, distinct from the original analyst. |
9.3.5 | The organisation shall establish ongoing competence maintenance requirements and suspend authorisation to conduct unsupervised DD if these are not maintained. |
9.3.6 | The organisation shall apply the same competence requirements to outsourced or third-party DD providers as to internal staff. |
9.3.7 | The organisation shall treat competence failures as nonconformities under Section 14.2, feeding back into individual authorisation status and, where systemic, into training and hiring standards. |
9.3.8 | The organisation shall, where AI-assisted tools support DD research, ensure a competent human remains accountable for reviewing and accepting the output, and ensure competence requirements explicitly cover the ability to critically evaluate AI-assisted output (see Section 10.16). |
9.3.9 | The organisation shall define research methodology and source-evaluation competence as its own named requirement distinct from module-specific knowledge, covering at minimum: distinguishing primary from secondary sources; assessing source currency, independence, and reliability; corroborating a material adverse finding across more than one independent source before it is relied upon; and, where DD activity extends to non-English-language or cross-jurisdictional sources, the competence (directly held or accessed through a qualified linguist or local researcher) to assess those sources without relying on machine translation alone for a material finding. |
9.3.10 | The organisation shall conduct periodic calibration exercises in which two or more analysts independently assess the same case or a standardised test case, and compare conclusions and tier determinations, to verify that competence is producing consistent outcomes across individuals rather than depending on who happens to perform the work; material inconsistency identified through calibration shall be addressed under Section 14.2. |
9.3.11 | The organisation shall distinguish between suspension of authorisation (temporary, pending remediation such as retraining) and decertification (formal withdrawal of authorisation requiring the individual to requalify from the applicable competence-verification step at Section 9.3.3 before being reauthorised), and shall apply decertification where a competence failure is repeated, severe, or indicates the original verification was inadequate. |
Cross-references: ISO 37001:2025 Clause 7.2; ISO/IEC 42001:2023 Clause 7.2; ISO 19011:2018 Clause 7 (competence of auditors, applied by analogy to DD analysts)
9.4 Accountability
Req. | 9.4 — Accountability |
|---|---|
9.4.1 | The organisation shall communicate to all personnel their individual accountability for DDMS performance within their role and hold module owners and the DD Function Owner accountable for module and DDMS performance respectively, assessed against the metrics defined in Section 12. |
9.4.2 | The organisation shall operate documented mechanisms for personnel to raise DD concerns and report potential non-conformities without fear of retaliation, consistent with the culture protections at Section 7.4.3, and ensure accountability for DD performance is maintained when activities are outsourced under Section 10.17. |
Cross-references: ISO 37001:2025 Clause 5.3.1 (Roles, responsibilities and authorities — General)
9.5 Resources
Req. | 9.5 — Resources |
|---|---|
9.5.1 | The organisation shall determine and provide the human, technical, and financial resources needed for the establishment, implementation, maintenance, and continual improvement of the DDMS, proportionate to DD volume, cycle time, and QA results (Section 12). |
9.5.2 | The organisation shall ensure resources allocated to the DDMS are proportionate to the scope, complexity, and risk profile of the programme, and that resource constraints do not prevent the organisation from satisfying the requirements of this standard. |
9.5.3 | The organisation shall document DDMS resource requirements, including DD function headcount and competence profile, screening and case management technology, external service provision, and training budget, and review resourcing at each management review cycle. |
Cross-references: ISO 37001:2025 Clause 7.1
10. Policies, Controls, and Operations
10.1 Due Diligence Policy
Req. | 10.1 — Due Diligence Policy |
|---|---|
10.1.1 | The organisation shall establish, document, and communicate a DD policy that: commits to meeting all applicable legal and regulatory DD obligations; commits to the culture principles at Section 7.4; commits to continual improvement of the DDMS; is approved by the governing body and signed by the CEO or equivalent; is written in plain language accessible to all personnel; and is reviewed and reapproved by the governing body at intervals not exceeding 24 months. |
10.1.2 | The organisation shall ensure the DD policy addresses all applicable modules under Section 10.5–10.24 and is supported by module-specific operational procedures under Section 10.3. |
10.1.3 | The organisation shall make the DD policy accessible to relevant external counterparties (suppliers, channel partners) where appropriate and demonstrate through management review records that the policy drives documented management decisions. |
Cross-references: ISO 37001:2025 Clause 5.2; ISO 14001:2015 Clause 5.2; ISO 45001:2018 Clause 5.2
10.2 Principles and Guidelines
Req. | 10.2 — Principles and Guidelines |
|---|---|
10.2.1 | The organisation shall document and communicate guiding principles for the DDMS, articulating the “know it, document it, execute against it” discipline established in Section 6.1 and the values the organisation applies across all applicable modules. |
10.2.2 | The organisation shall develop guidelines that translate guiding principles into practical direction for each applicable module, review principles and guidelines at intervals not exceeding 24 months and demonstrate through governance records how they have influenced operational decisions. |
Cross-references: ISO 37001:2025 Clause 5.2; ISO 26000:2010 Clause 4
10.3 Procedures
Req. | 10.3 — Procedures |
|---|---|
10.3.1 | The organisation shall maintain documented procedures for each applicable module in Section 10.5–10.24, sufficient for a competent analyst to execute consistently, covering at minimum the screening, verification, escalation, and sign-off steps for each DD tier. |
10.3.2 | The organisation shall maintain current, accessible, and version-controlled procedures, reviewed at intervals not exceeding 12 months to confirm they reflect current policy, the Applicable Obligations Register, and the risk assessment methodology under Section 6.4. |
Cross-references: ISO 37001:2025 Clauses 8.1, 8.2
10.4 Controls
Req. | 10.4 — Controls |
|---|---|
10.4.1 | The organisation shall establish, document, and maintain a DDMS control framework that identifies, designs, and operates the controls required to implement the actions under Section 8.4, achieve the DD objectives under Section 8.1, and manage the risks and gaps identified in the controls and gap assessment under Section 6.7. The control framework shall cover each applicable module and specify, for each control, its objective, type (preventive, detective, or corrective), owner, operating frequency, and the evidence it produces. |
10.4.2 | The organisation shall establish and operate financial controls integrating DD into the organisation’s financial management, including budget allocation for material DD actions, and financial authorisation controls ensuring material DD expenditure (e.g. enhanced field verification, external investigators) is approved at the appropriate level of authority. |
10.4.3 | The organisation shall establish and operate operational controls governing DD execution across each applicable module (Sections 10.5–10.24), including documented procedures, screening tools, and monitoring mechanisms appropriate to each module. Where an ISO management system standard applies to a module (per the cross-references at Sections 10.5–10.24), the controls for that module shall be designed to integrate with, rather than duplicate, the requirements of the applicable standard. |
10.4.4 | The organisation shall establish and operate onboarding and procurement controls that embed DD requirements into the organisation’s counterparty onboarding processes, including DD qualification criteria incorporated into onboarding and approval processes for all material subject types, and approval controls that require DD to be completed, or a documented exception approved, before a material relationship proceeds. |
10.4.5 | The organisation shall establish and operate Internal Controls for DD Reporting — data governance controls that ensure the accuracy, completeness, and consistency of DD data used in performance management, internal reporting, and the Applicable Obligations Register — covering documented data collection responsibilities, validation and independent review before data is relied upon, and change control for methodology updates, tested as part of the internal audit programme under Section 12.5. |
10.4.6 | The organisation shall establish and operate people controls governing DD-relevant behaviour, including induction processes communicating DD values from the first day of employment for DD-relevant roles, performance management processes that hold individuals accountable for DD conduct, and speak-up controls consistent with Section 9.4.2. |
10.4.7 | The organisation shall test and review the DDMS control framework at intervals not exceeding 12 months, identifying control failures and control gaps, and address all identified failures and material gaps through the corrective action process under Section 14.2 with documented remediation plans, responsible owners, and target closure dates. |
10.4.8 | The organisation shall define and document an evidence and source quality standard, tiered to the DD tier (Section 6.4), specifying: for Tier 1–2, single-source screening results are ordinarily sufficient absent a hit; for Tier 3, a material finding shall be corroborated across at least two independent sources, at least one of which is a primary source (e.g. a corporate registry, court record, or regulatory filing) rather than secondary commentary or aggregated screening output; for Tier 4, corroboration shall additionally include, where feasible, independent field or third-party verification. This standard is the operative reference for the QA evidence testing at Section 12.1.8 and the analyst competence requirement at Section 9.3.9. A questionnaire completed by the subject, or any other self-declared response the subject provides about itself, is a legitimate data collection mechanism in its own right, but shall not, on its own, be treated as satisfying the corroboration requirement for Tier 3 or Tier 4 above — self-declared information is one input to be tested against independent sources, not a substitute for them. |
10.4.9 | The organisation shall establish controls to prevent, detect, and respond to falsification, fabrication, or unauthorised backdating of DD records, including at minimum: system-level timestamping and edit logging of case records that cannot be altered by the case-working analyst after submission for review; a prohibition on an analyst or reviewer amending a case record to conceal a missed deadline, a skipped step, or an unaddressed finding; and inclusion of data integrity indicators (e.g. implausible timestamps, missing edit history, evidence that does not match its cited source) as a specific QA testing category under Section 12.1.2, distinct from ordinary methodology or competence findings. |
10.4.10 | The organisation shall treat a confirmed instance of DD record falsification as a major non-conformity under Section 3, subject to immediate case re-performance by an unconflicted analyst, decertification of the individual responsible under Section 9.3.11, and governing body notification consistent with Section 7.5.3, regardless of whether the underlying subject was ultimately high-risk. |
10.4.11 | The organisation shall validate the currency, comprehensiveness, and fitness for purpose of third-party data sources relied upon for DD — including sanctions and PEP list providers, adverse media aggregators, corporate registry services, and credit or litigation databases — at intervals not exceeding 12 months, assessing at minimum: update frequency and latency relative to the primary source; jurisdictional and language coverage relative to the organisation’s subject-type exposure under Section 5.1.3; and known gaps or limitations disclosed by the provider or identified through the organisation’s own QA sampling under Section 12.1.2. |
10.4.12 | The organisation shall document the rationale for its selection of each material screening or data source provider, review that rationale whenever a coverage gap is identified through Section 10.4.11 or a QA finding under Section 12.1.8, and shall not rely on a single data source for a Tier 3 or Tier 4 finding where that source’s own disclosed coverage limitations are relevant to the subject being assessed (e.g. a screening provider with disclosed weak coverage of a jurisdiction relevant to the subject). |
10.4.13 | The organisation shall treat questionnaires and other self-declaration instruments as a valid data collection mechanism, distinct from verification: a questionnaire tells the organisation what the subject says about itself, not what is independently true. The organisation shall not rely on a completed questionnaire alone as the basis for a Tier 2 or above DD conclusion without corroborating the material answers against independent sources consistent with the evidence standard at Section 10.4.8, and shall document, where a questionnaire response is relied upon without independent corroboration, the specific reason corroboration was not obtained and the residual risk this creates. |
Cross-references: ISO 37001:2025 Clause 8; ISO 14001:2015 Clause 8.1; ISO 45001:2018 Clause 8.1; COSO Internal Control Framework; ISO/IEC 27001:2022 (data integrity controls, referenced by category)
10.5 Anti-Bribery and Third-Party Integrity
Scope of subjects: agents, intermediaries, consultants, distributors, and other third parties acting on the organisation’s behalf, particularly where compensation is contingent, discretionary, or not fully transparent. Third-party due diligence is consistently the most litigated and enforced element of anti-bribery compliance programmes; this module treats it as a distinct, evidenced discipline rather than a box on a vendor onboarding form.
Req. | 10.5 — Anti-Bribery and Third-Party Integrity DD |
|---|---|
10.5.1 | The organisation shall maintain a documented methodology for identifying which third-party relationships require anti-bribery DD, based on factors including at minimum: (a) government interaction on the organisation’s behalf, direct or indirect; (b) use of a shell, nominee, or otherwise opaque corporate structure; (c) jurisdiction corruption risk, referencing an internationally recognised corruption perception index or equivalent; (d) payment structure opacity, including success fees, unusually high commissions, or cash payment requests; and (e) prior adverse findings against the third party or its principals. |
10.5.2 | The organisation shall apply the DD tier (Section 6.4) proportionate to the risk identified, with Tier 3 or above required for any third party with direct government interaction on the organisation’s behalf, and Tier 4 required where the third party will interact with a government official with discretionary authority over a licence, permit, contract award, or regulatory outcome material to the organisation. |
10.5.3 | The organisation shall screen third parties against sanctions and adverse media sources prior to engagement and at re-screening intervals defined in the Applicable Obligations Register and shall not permit an engagement to proceed while a screening result is pending without documented senior approval and a defined remediation timeline. |
10.5.4 | The organisation shall document the business rationale and risk assessment for each third-party engagement, including why the third party is needed, what services will genuinely be performed, and how compensation is structured and justified relative to market rates for equivalent services. |
10.5.5 | The organisation shall incorporate anti-bribery obligations into the contractual terms of material third-party relationships, including audit rights, termination rights for breach, and a requirement that the third party not make payments prohibited under applicable anti-bribery law on the organisation’s behalf. |
10.5.6 | The organisation shall, where it maintains a certified or self-declared Anti-Bribery Management System conformant to ISO 37001, demonstrate specifically how this module’s third-party due diligence activity integrates with, rather than duplicates, that system’s third-party due diligence controls, and shall document which system is the system of record for third-party risk data. |
Cross-references: ISO 37001:2025 Clauses 8.2, 8.4
10.6 AML/KYC
Scope of subjects: customers, investors, and financial counterparties. This module carries among the highest evidentiary prescriptiveness in this standard, drawing on the FATF Recommendations and Wolfsberg Principles as the most mature due diligence tradition of the nineteen modules.
Req. | 10.6 — AML/KYC DD |
|---|---|
10.6.1 | The organisation shall verify beneficial ownership to the level required by its Applicable Obligations Register, using primary source documentation wherever reasonably available — including corporate registry extracts, notarised ownership declarations, or equivalent — and shall document any instance where beneficial ownership cannot be fully verified, together with the risk-based decision taken as a result. |
10.6.2 | The organisation shall screen subjects against sanctions lists and PEP databases prior to onboarding and at re-screening intervals defined in the Applicable Obligations Register, using screening sources and matching methodology appropriate to the assigned DD tier. |
10.6.3 | The organisation shall assess and document source-of-funds and source-of-wealth information proportionate to the assigned DD tier, escalating to Tier 3 or above wherever the subject’s declared source of funds cannot be readily reconciled with their known profile or activity. |
10.6.4 | The organisation shall escalate and investigate any sanctions or PEP hit before the relationship proceeds, with a documented rationale, approving authority, and any enhanced monitoring conditions attached to any decision to proceed despite a hit. |
10.6.5 | The organisation shall maintain an audit trail sufficient to demonstrate the specific verification steps taken, the documents relied upon, and the identity of the person who performed and who reviewed the verification, distinct from a narrative risk summary alone. |
10.6.6 | The organisation shall conduct ongoing transaction or relationship monitoring proportionate to the DD tier, with defined triggers for unscheduled re-assessment where subject behaviour is materially inconsistent with its documented profile. |
Cross-references: FATF Recommendations; Wolfsberg Principles; ISO 37301:2021 Clause 8.2
10.7 Export Control
Scope of subjects: customers, resellers, distributors, and end users of goods, technology, or software crossing borders. For some organisations — particularly those in defence, dual-use technology, semiconductors, cryptography, or cloud/software with cross-border access — this module carries among the highest enterprise risk in this standard and shall be resourced and governed accordingly rather than treated as a subset of customer AML/KYC.
Req. | 10.7 — Export Control DD |
|---|---|
10.7.1 | The organisation shall screen customers, resellers, and end users against restricted, denied, and debarred party lists relevant to its jurisdiction(s) of manufacture, transshipment, and re-export, prior to transacting and at re-screening intervals defined in the Applicable Obligations Register. |
10.7.2 | The organisation shall conduct end-use and end-user due diligence proportionate to the classification of the goods, technology, or software involved, including documented assessment of red-flag indicators such as reluctance to provide end-use information, unusual shipping routes or intermediate consignees, and any mismatch between the stated end use and the customer’s known business activity. |
10.7.3 | The organisation shall assess and document dual-use goods classification and any licensing requirement before export, retaining evidence of the classification determination and, where a licence is required, the licence itself and its conditions. |
10.7.4 | The organisation shall consider deemed export risk — the transfer of controlled technology or software to foreign nationals within the organisation’s own operations, including via employment, secondment, or system access — as part of this module, in coordination with Section 10.11 (Personnel), rather than treating it solely as a personnel matter. |
10.7.5 | The organisation shall record in the Applicable Obligations Register which export control regime(s) apply to its activity and shall not rely on a single jurisdiction’s regime where the organisation’s manufacture, transshipment, or re-export activity brings it within the scope of more than one regime. |
10.7.6 | The organisation shall designate an accountable owner for export control DD distinct from the AML/KYC owner where its risk profile — sector, product classification, or customer geography — justifies separation of these functions and shall document the rationale where a single owner is retained. |
10.7.7 | The organisation shall maintain a documented process for responding to a denied-party match, a licence denial, or an enforcement inquiry, including who has authority to hold or terminate a transaction and the evidence retention required to support the organisation’s position. |
Cross-references: US EAR/ITAR (referenced by category, per Section 2); EU Dual-Use Regulation (referenced by category)
10.8 Supplier and Channel Partner HREDD
Scope of subjects: suppliers, channel partners, and distributors, assessed for human rights and environmental impact across the organisation’s own operations, subsidiaries, and chain of activities.
Req. | 10.8 — Supplier and Channel Partner HREDD |
|---|---|
10.8.1 | The organisation shall conduct risk mapping to identify and prioritise actual and potential adverse human rights and environmental impacts across its supplier and channel partner base, focusing on areas where impacts are most likely and most severe, consistent with a risk-based rather than a blanket-coverage approach. |
10.8.2 | The organisation shall maintain a documented policy statement on human rights and environmental due diligence, communicated to relevant suppliers and channel partners, and shall incorporate this policy by reference into material supplier and channel partner contracts. |
10.8.3 | The organisation shall establish an alert and grievance mechanism accessible to affected stakeholders — including, where relevant, workers in the supplier’s own operations — and shall document how alerts are received, triaged, investigated, and closed. |
10.8.4 | The organisation shall take preventive and, where impacts are identified, remedial action proportionate to the severity and likelihood of the impact, including a documented escalation and, where necessary, relationship-suspension pathway for suppliers who do not engage with remediation. |
10.8.5 | The organisation shall monitor the effectiveness of measures taken and document the results, including whether remediation actually resolved the underlying impact rather than only the immediate symptom. |
10.8.6 | The organisation shall record in the Applicable Obligations Register which specific laws (e.g. CSDDD, LkSG, French Duty of Vigilance Law, Norway Transparency Act, per Annex D) this module is intended to address for the organisation and shall review this mapping whenever Annex D is updated. |
Cross-references: OECD Due Diligence Guidance for Responsible Business Conduct; UN Guiding Principles on Business and Human Rights; IFC Performance Standards
10.9 Forced Labour and Import Compliance
Scope of subjects: suppliers and supply chain tiers where forced labour or import-restriction risk is identified, distinct from Section 10.8 in evidentiary logic — this module addresses two distinct regime types: (a) rebuttable-presumption regimes (e.g. US UFLPA), which require the organisation to affirmatively prove the absence of forced labour once a presumption is triggered; and (b) strict-liability product-ban regimes (e.g. EU Forced Labour Regulation, EUFLR), which impose no independent due diligence obligation but ban a product outright if forced labour is found anywhere in its production, and in which voluntary due diligence is explicitly taken into account by enforcing authorities and can help avoid or shorten an investigation. Organisations shall not treat these two regime types as interchangeable; the evidentiary posture required differs materially.
Req. | 10.9 — Forced Labour and Import Compliance DD |
|---|---|
10.9.1 | The organisation shall identify geographic and sector-level forced labour risk exposure, including regions or entities subject to rebuttable-presumption import regimes and products subject to strict-liability ban regimes identified in Annex D, and shall map this exposure against the organisation’s own supply chain tiers rather than its immediate suppliers alone. |
10.9.2 | The organisation shall, where a rebuttable-presumption regime applies per the Applicable Obligations Register, maintain supply chain traceability documentation to the depth required to rebut the presumption — potentially extending beyond Tier 1 suppliers — and shall not rely on a general risk narrative alone in these cases. |
10.9.3 | The organisation shall, where a strict-liability product-ban regime applies (e.g. EUFLR), maintain voluntary due diligence records sufficient to be presented to an enforcing authority as evidence of risk identification and mitigation efforts, consistent with the OECD six-step framework at Annex D.1, recognising that such records may reduce the likelihood of an investigation being opened or may shorten its duration, notwithstanding that the underlying prohibition is one of strict liability rather than a due-diligence-defence standard. |
10.9.4 | The organisation shall monitor any public forced-labour risk database maintained by a relevant authority (e.g. the EUFLR Forced Labour Risk Database) for products or geographies matching the organisation’s supply chain and shall treat a match as a mandatory trigger for enhanced due diligence under this module. |
10.9.5 | The organisation shall obtain and retain supplier attestations and, where proportionate to risk, independent verification of labour conditions, including audit or assessment reports from a competent independent party. |
10.9.6 | The organisation shall maintain a documented process for responding to detention, seizure, import-denial, or product-ban actions, including designated ownership of the response, evidence retrieval procedures capable of meeting the enforcing authority’s evidence-request deadlines (which may be as short as 30 working days under EUFLR guidance), and a documented pathway for demonstrating elimination of forced labour from a supply chain sufficient to support a product’s return to market where the regime permits this. |
Cross-references: ILO Combating Forced Labour: A Handbook for Employers and Business; Regulation (EU) 2024/3015 (EU Forced Labour Regulation); Annex D.1 (OECD six-step crosswalk)
10.10 Personnel and Hiring
Scope of subjects: natural persons — new employees, executives, and board candidates. This module is structurally distinct from the entity-focused modules in this Section (10.5–10.9, 10.13–10.15, 10.19, and 10.20): it is bounded by individual privacy and employment law as a countervailing legal constraint, not merely a risk-assessment question. This standard does not prescribe what personal information may be collected, verified, or retained in any jurisdiction; it requires that the organisation’s own position be lawful, defensible, and consistently followed.
Req. | 10.10 — Personnel and Hiring DD |
|---|---|
10.10.1 | The organisation shall determine and document, per role or role category, the scope of background screening to be conducted, and the legal basis for it, within its Applicable Obligations Register and Position Statement (Section 6.1). |
10.10.2 | The organisation shall apply the DD tier proportionate to role sensitivity — including financial authority, regulated-industry fit-and-proper requirements, safeguarding responsibility, or access to export-controlled technology per Section 10.7.4 — rather than applying uniform screening depth to all hires regardless of role. |
10.10.3 | The organisation shall obtain any consent or provide any disclosure required under applicable law before conducting screening and shall not conduct screening beyond the scope disclosed to the individual without a further lawful basis. |
10.10.4 | The organisation shall retain personnel DD records only for the period justified by its own documented position, and no longer, and shall document the deletion or anonymisation process applied at the end of that period. |
10.10.5 | The organisation shall demonstrate that its Position Statement was reviewed for legal and ethical defensibility — including consideration of proportionality and any applicable anti-discrimination law — and is being followed consistently in practice. This is the auditable requirement; the standard does not test the correctness of the underlying legal position. |
10.11 JV/M&A Counterparty
Scope of subjects: joint venture and M&A counterparties, assessed as a synthesis exercise drawing on modules 10.5–10.9, 10.13, 10.14, 10.15, 10.19, and 10.20 as relevant to deal type, asset profile, and counterparty profile — JV/M&A due diligence routinely spans anti-bribery, AML/KYC, export control, forced labour, environmental, health and safety, cyber, deforestation/minerals, and sanctions risk, not solely the entity-integrity modules.
Req. | 10.11 — JV/M&A Counterparty DD |
|---|---|
10.11.1 | The organisation shall determine which of Sections 10.5–10.9, 10.13, 10.14, 10.15, 10.19, and 10.20 apply to a given transaction based on counterparty type, asset profile, structure, and jurisdiction, documenting the rationale for any module determined not to apply to a specific transaction. |
10.11.2 | The organisation shall document DD findings in a form suitable for transaction decision-making and post-closing integration planning, including identified risks, proposed risk allocation mechanisms (indemnities, escrow, conditions precedent), and any recommendation to proceed, proceed with conditions, or decline. |
10.11.3 | The organisation shall document any scope limitations arising from deal time constraints — including any DD not completed before signing or closing — and the plan and timeline to close those limitations post-closing. |
10.11.4 | The organisation shall integrate JV/M&A DD findings into post-closing integration planning, ensuring that risks identified during DD are carried forward into the acquired or combined entity’s ongoing DDMS coverage under the relevant modules. |
10.12 Brand and Reputational
Scope of subjects: customers, endorsers, sponsorship/partnership counterparties, and other associations the organisation enters into voluntarily. This module is discretionary and values-driven, not compliance-driven. The other modules in this Section (10.5–10.11 and 10.13–10.23) exist to satisfy a legal or regulatory floor the organisation must meet regardless of preference. This module exists to satisfy the organisation’s own values and risk appetite — there is no external legal minimum requiring an organisation to decline a legally compliant counterparty it simply does not wish to be associated with. Because this module is discretionary, it carries its own distinct risk: applied inconsistently or on undisclosed criteria, it can itself create discrimination, defamation, or unfair-dealing exposure, and shall be governed with particular care.
Req. | 10.12 — Brand and Reputational DD |
|---|---|
10.12.1 | The organisation shall maintain a documented brand and reputational risk policy, approved by top management, that defines the organisation’s own criteria for association risk — such as sanctioned political causes, extremism, adverse public controversy, or values misalignment — distinct from and in addition to the legal and regulatory criteria in the other modules of this Section (10.5–10.11 and 10.13–10.23). |
10.12.2 | The organisation shall apply these criteria consistently, using documented, non-discriminatory decision factors, and shall record the rationale for any decision to decline or terminate a relationship on brand or reputational grounds. |
10.12.3 | The organisation shall distinguish clearly, in internal records and in any external communication, between a decision made on legal or regulatory DD grounds (the other modules of this Section, 10.5–10.11 and 10.13–10.23) and a decision made on brand or reputational grounds (this module). |
10.12.4 | The organisation shall periodically review brand and reputational DD decisions as part of management review (Section 12.3) to confirm the policy is being applied consistently rather than ad hoc or reactively. |
10.12.5 | The organisation shall ensure this module is not used as a pretext to circumvent anti-discrimination, competition, or fair-dealing law applicable to the organisation, and should seek its own legal advice before declining a relationship on brand or reputational grounds alone where there is any doubt. |
10.13 Environmental
Scope of subjects: sites, facilities, and assets — the organisation’s own, or those of an M&A/JV target or major supplier/landlord — assessed for environmental liability, contamination, permit compliance, and regulatory exposure. Distinct from Section 10.8’s supply-chain focus: this module addresses environmental risk attached to a specific site or asset, most acute in M&A, real estate, and industrial contexts.
Req. | 10.13 — Environmental DD |
|---|---|
10.13.1 | The organisation shall assess environmental liability and compliance status — including contamination history, permit status, outstanding regulatory notices, and remediation obligations — proportionate to the DD tier and the nature of the asset or transaction. |
10.13.2 | The organisation shall, where it maintains an environmental management system conformant to ISO 14001, cross-reference and rely on that system’s site data and controls rather than duplicating them under this module. |
10.13.3 | The organisation shall, in M&A/JV contexts, document environmental findings in a form suitable for transaction risk allocation — including indemnities, escrow, or remediation conditions — and feed them into Section 10.11. |
10.13.4 | The organisation shall record in the Applicable Obligations Register the specific environmental laws and permit regimes relevant to the organisation’s sites and jurisdictions. |
Cross-references: ISO 14001:2015 (all clauses)
10.14 Health and Safety
Scope of subjects: the organisation’s own workplaces and contractors, and those of M&A/JV targets and major suppliers, assessed for occupational health and safety conditions and compliance.
Req. | 10.14 — Health and Safety DD |
|---|---|
10.14.1 | The organisation shall assess health and safety compliance status and incident and injury history proportionate to the DD tier, particularly for high-risk sectors — construction, manufacturing, extractives, logistics — and for M&A/JV targets and contractors. |
10.14.2 | The organisation shall, where it maintains a health and safety management system conformant to ISO 45001, cross-reference and rely on that system’s controls and incident data rather than duplicating them under this module. |
10.14.3 | The organisation shall treat confirmed serious or fatal incident history at a subject as a mandatory escalation trigger, regardless of aggregate risk score, consistent with the override logic at Annex A.2. |
10.14.4 | The organisation shall record in the Applicable Obligations Register the specific occupational health and safety laws relevant to the organisation’s operations and jurisdictions. |
Cross-references: ISO 45001:2018 (all clauses)
10.15 Cyber and Data Privacy
Scope of subjects: vendors, suppliers, and counterparties who will process the organisation’s data, connect to its systems, or otherwise present a cyber risk surface — increasingly a standard part of vendor onboarding and M&A DD.
Req. | 10.15 Cyber and Data Privacy DD |
|---|---|
10.15.1 | The organisation shall assess a subject’s data privacy and cyber security posture proportionate to the DD tier and the sensitivity of data or system access involved, using evidence such as independent certifications (ISO/IEC 27001, SOC 2), penetration test results, breach history, and data processing terms. |
10.15.2 | The organisation shall, where it maintains an information security management system conformant to ISO/IEC 27001, cross-reference and rely on that system’s vendor risk assessment controls rather than duplicating them under this module. |
10.15.3 | The organisation shall verify the subject’s data processing terms and sub-processor arrangements are consistent with the organisation’s own data protection obligations before data sharing begins. |
10.15.4 | The organisation shall treat a subject’s confirmed prior data breach or unresolved critical security finding as a mandatory escalation trigger, regardless of aggregate risk score. |
10.15.5 | The organisation shall re-screen or re-assess vendor cyber posture at defined intervals and following any material change in the nature of data or system access granted. |
10.15.6 | The organisation shall record in the Applicable Obligations Register the specific data protection laws (e.g. GDPR, PDPA, sector-specific data rules) relevant to the organisation’s jurisdictions and data flows. |
Cross-references: ISO/IEC 27001:2022 (all clauses)
10.16 AI Governance in Due Diligence
AI-assisted tools — including generative AI, automated screening engines, and AI-assisted research aggregation — are now widely used within DD research, and their use materially changes the assurance question: an AI-assisted finding can look as polished and confident as a properly researched one while being wrong, hallucinated, based on stale or unlicensed data, or silently biased in what it surfaces or omits. This module-crossing requirement applies to AI use in any of the nineteen modules of this Section.
Req. | 10.16 — AI Governance in Due Diligence |
|---|---|
10.16.1 | The organisation shall maintain an inventory of AI tools used in any part of the DD lifecycle — research, screening, drafting, summarisation, translation, or risk scoring — recording for each tool its intended use, data sources, and known limitations. |
10.16.2 | The organisation shall determine and document, per tool and per use case, the level of human review required before an AI-assisted output can be relied upon, calibrated to the DD tier — higher-tier DD shall require a higher standard of human verification of AI-assisted findings, not less, given the greater consequence of error. |
10.16.3 | The organisation shall prohibit reliance on AI-generated findings that cannot be traced to a verifiable underlying source; an AI summary or conclusion is not itself evidence, and the organisation shall retain and be able to produce the underlying source material a finding is based on. |
10.16.4 | The organisation shall assess and document known failure modes relevant to DD use — hallucination, training-data staleness, source fabrication, and bias in what the tool surfaces or deprioritises (e.g. uneven coverage of non-English-language adverse media, or weaker coverage of certain jurisdictions) — and put mitigations in place proportionate to the risk. |
10.16.5 | The organisation shall, where it maintains an AI management system conformant to ISO/IEC 42001, cross-reference and rely on that system’s controls (model risk assessment, data governance, incident management) rather than establishing parallel controls under this module. |
10.16.6 | The organisation shall log AI tool use at the individual DD-file level, sufficient to demonstrate on audit which parts of a given finding were AI-assisted and what human verification was applied to them. |
10.16.7 | The organisation shall include AI-related errors identified through QA sampling (Section 12.1) as their own tracked category, distinct from human analyst error, so that AI-tool performance and human-oversight effectiveness can each be evaluated on their own trend line. |
Cross-references: ISO/IEC 42001:2023 (all clauses)
10.17 Vendor and Outsourced DD Provider Management
Scope of subjects: third-party providers to whom the organisation outsources or delegates any DD activity, including screening vendors, background-check administrators, investigators, research firms, and law firms conducting DD on the organisation’s behalf. Outsourcing a DD activity does not outsource accountability for it: the organisation remains fully responsible for the outcome regardless of who performed the underlying work. The research and investigations vendor industry carries a particular corruption risk that this standard treats explicitly rather than leaving implicit within general anti-bribery controls: it is a known practice in parts of this industry for researchers or their local sources to pay registry clerks, court staff, database administrators, or officials for restricted access, faster turnaround, or favourable results, and for vendors to under-disclose subcontracting or the true origin of information provided to a client. An organisation using a vendor whose underlying practices involve bribery, illegal data access, or fabrication is not shielded from responsibility by having outsourced the work, and evidence obtained through such means cannot satisfy the evidence standard at Section 10.4.8.
Req. | 10.17 Vendor and Outsourced DD Provider Management |
|---|---|
10.17.1 | The organisation shall apply the requirements of this Section to any DD activity outsourced or delegated to a third-party provider, retaining full accountability for the DDMS and its outcomes regardless of delegation, consistent with the competence requirements for outsourced providers at Section 9.3.6. |
10.17.2 | The organisation shall conduct due diligence on a prospective DD vendor before engagement, proportionate to the materiality of the work to be delegated, covering at minimum: the vendor’s ownership, licensing, and regulatory status where applicable; the vendor’s own anti-bribery and compliance controls, referencing an ISO 37001-conformant Anti-Bribery Management System where the vendor holds one; the vendor’s data sourcing methodology and legal basis for the information it provides; and the vendor’s own subcontracting practices and use of local researchers or agents. |
10.17.3 | The organisation shall incorporate into its contract with any DD vendor, at minimum: a warranty that information provided was obtained through lawful means, without bribery, illegal data access (including hacking, pretexting, or unauthorised database access), or breach of the source jurisdiction’s data protection or privacy law; a requirement that the vendor disclose the general nature of its sourcing methodology sufficient for the organisation to assess reliability under Section 10.4.8, without requiring disclosure that would itself compromise a source’s safety or a legitimate confidential method; audit rights permitting the organisation, or Speeki as an authorised certification body, to review the vendor’s DD-relevant processes and controls; a requirement to disclose any subcontracting or use of local agents, with equivalent standards flowed down to those subcontractors; and termination rights exercisable on discovery of bribery, fabrication, or unlawful data sourcing. |
10.17.4 | The organisation shall apply competence requirements to vendor personnel performing DD work equivalent to those required of internal staff under Section 9.3, verified through vendor attestation, sample review of vendor work product, or independent audit, and shall not accept vendor competence as established merely because the vendor is well known or highly priced. |
10.17.5 | The organisation shall conduct periodic performance audits of each material DD vendor, at intervals not exceeding 12 months, assessing accuracy and completeness of vendor work product against the evidence standard at Section 10.4.8; timeliness against agreed service levels; responsiveness to escalations and corrections; and the vendor’s own QA and error-rate data, requested from the vendor where the vendor maintains it. |
10.17.6 | The organisation shall apply the data integrity controls at Section 10.4.9–10.4.10 to vendor-supplied work product to the same standard as internally produced work, and shall treat credible evidence that a vendor obtained information through bribery, illegal access, or fabrication as a data integrity failure requiring: immediate cessation of reliance on the affected findings; re-performance of the affected cases through an alternative source; review of all other work product supplied by that vendor within a defined lookback period; and escalation to the governing body under Section 7.5.3 regardless of the vendor’s standing or the materiality of the specific case. |
10.17.7 | The organisation shall require the vendor’s DD process to be sufficiently documented and transparent to the organisation that the organisation can itself explain, on audit, what the vendor did and why — a vendor’s DD output shall not be treated as a “black box” the organisation is entitled to rely on without understanding its basis, consistent with the AI governance principle at Section 10.16.3 that a finding is not evidence unless it is traceable to a verifiable underlying source. |
10.17.8 | The organisation shall maintain a documented vendor exit and transition plan for each material DD vendor, addressing data return or destruction, continuity of DD coverage during a vendor transition, and retention of the organisation’s own case records independent of the vendor’s systems, consistent with the documentation requirements at Section 13.1. |
10.17.9 | The organisation shall review its portfolio of DD vendors as part of the DDMS effectiveness assessment at Section 12.4, including whether vendor concentration creates a single point of failure or an unmanaged dependency on a provider whose own practices cannot be adequately verified. |
Cross-references: ISO 37001:2025 (Anti-bribery management systems, applied to vendor due diligence per Section 10.5); ISO 37301:2021 (Compliance management systems); ISO 20400:2017 (Sustainable procurement, referenced by category for vendor management principles)
10.18 Remediation and Access to Remedy
Remediation is a distinct discipline from prevention and mitigation, and this standard treats it as such. Preventing harm and mitigating identified risk (Sections 10.4, 10.8.4) address exposure going forward; remediation addresses harm that has already occurred, whether caused directly by the organisation, contributed to by the organisation, or directly linked to the organisation’s operations, products, or services through a business relationship. Remediation is a rapidly strengthening element of due diligence legislation — the UN Guiding Principles’ access-to-remedy pillar, CSDDD’s remediation obligation, LkSG’s remedial measures, and EUFLR’s return-to-market pathway (Section 10.9.6) all converge on the same expectation: an organisation must be able to provide for, or cooperate in, remedy when its own DD or a third party identifies that harm has occurred. This module is cross-cutting and applies across all modules in Section 10.5–10.24 where adverse impact on a person, community, or the environment is identified, not solely within Section 10.8.
Req. | 10.18 Remediation and Access to Remedy |
|---|---|
10.18.1 | The organisation shall maintain a documented remediation policy distinguishing the organisation’s remediation obligation according to its degree of involvement in an identified harm: (a) where the organisation caused or contributed to the harm, it shall provide for or cooperate in remediation; (b) where the organisation is directly linked to the harm through a business relationship but did not cause or contribute to it, it shall use its leverage to encourage the responsible party to provide remedy, and shall assess and document the limits of that leverage. |
10.18.2 | The organisation shall maintain or provide access to a grievance mechanism meeting the effectiveness criteria recognised under the UN Guiding Principles — legitimate, accessible, predictable, equitable, transparent, rights-compatible, and a source of continuous learning — extending the alert/grievance mechanism at Section 10.8.3 across all applicable modules rather than confining it to supplier HREDD alone. The mechanism’s design and periodic review shall be based on genuine engagement and dialogue with the stakeholder groups it is intended to serve, consistent with Section 6.2.4, and the organisation shall document how their input shaped the mechanism (e.g. channel format, language, anonymity options, and accessibility) rather than asserting the criteria are met without stakeholder-sourced evidence. |
10.18.3 | The organisation shall determine and document the range of remedy appropriate to the nature and severity of the harm, which may include an apology, restitution, rehabilitation, financial or non-financial compensation, prevention of further harm through changed practice, or cooperation with a judicial or non-judicial remedy mechanism and shall not presume that a single remedy type is adequate for all cases. |
10.18.4 | The organisation shall track each remediation case from identification to closure, recording the harm identified, the remedy provided or facilitated, the affected party’s engagement in determining the remedy, and the basis for considering the matter resolved, and shall not close a remediation case solely on the basis that a payment or action was made without evidence that the affected party considers the harm addressed, where feasible to obtain. |
10.18.5 | The organisation shall ensure that no person who raises a grievance, seeks remedy, or participates in a remediation process is penalised, retaliated against, or disadvantaged as a result, consistent with the non-retaliation protections at Section 7.4.3 and Section 9.4.2. |
10.18.6 | The organisation shall report remediation activity — case volume, remedy types provided, and closure rates — as part of the performance monitoring at Section 12.1 and shall escalate any pattern of recurring harm from the same subject or root cause to the corrective action process at Section 14.2 rather than treating each case as isolated. |
10.18.7 | The organisation shall, where a regulatory or enforcement authority requires evidence of remediation as a condition of restoring market access, licensing, or ceasing an investigation (e.g. the EUFLR return-to-market pathway at Section 10.9.6, or a CSDDD-equivalent remediation obligation identified in the Applicable Obligations Register), maintain documentation sufficient to demonstrate the remedy was effective and sustained, not merely initiated. |
Cross-references: UN Guiding Principles on Business and Human Rights (Pillar III — Access to Remedy); OECD Due Diligence Guidance for Responsible Business Conduct (Step 6); Annex D.1 (OECD six-step crosswalk)
10.19 Deforestation, Land Use, and Conflict Minerals
Scope of subjects: suppliers and supply chain tiers producing or trading in commodities linked to deforestation (cattle, cocoa, coffee, palm oil, rubber, soya, wood, and derived products) or conflict minerals (tin, tantalum, tungsten, gold, and their ores). Distinct from Sections 10.8–10.9 in evidentiary logic: deforestation and conflict-mineral regimes require commodity-level and, in the case of deforestation, geolocation-level traceability and a formal due diligence statement or equivalent filing, rather than a general risk narrative or supplier attestation alone.
Req. | 10.19 Deforestation, Land Use, and Conflict Minerals DD |
|---|---|
10.19.1 | The organisation shall determine whether it places, makes available, or exports products in scope of an applicable deforestation regime (e.g. the EU Deforestation Regulation) or conflict minerals regime (e.g. the EU Conflict Minerals Regulation, or equivalent), and record this determination and the applicable obligation in the Applicable Obligations Register. |
10.19.2 | The organisation shall, where a deforestation regime applies, maintain commodity-level traceability sufficient to demonstrate the product is deforestation-free as of the regime’s reference date, legally produced under the laws of the country of production, and covered by a due diligence statement or equivalent filing, including geolocation data for the plot(s) of production where required. |
10.19.3 | The organisation shall, where a conflict minerals regime applies, conduct supply chain due diligence to the smelter or refiner level for tin, tantalum, tungsten, and gold, consistent with the OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas, and retain evidence of smelter/refiner identification and risk assessment. |
10.19.4 | The organisation shall monitor regulatory scope changes (product lists, thresholds, filing systems) for applicable deforestation and conflict minerals regimes at intervals not exceeding 12 months, consistent with the Annex D review cadence, given the frequency with which these regimes have been amended and postponed. |
10.19.5 | The organisation shall integrate findings from this module with Section 10.9 (Forced Labour and Import Compliance) and Section 10.8 (Supplier and Channel Partner HREDD) where a supplier or commodity presents risk across more than one regime, rather than running duplicative, siloed assessments. |
Cross-references: Regulation (EU) 2023/1115 as amended by Regulation (EU) 2025/2650 (EU Deforestation Regulation); Regulation (EU) 2017/821 (EU Conflict Minerals Regulation); OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas
10.20 Sanctions Compliance
Scope of subjects: any subject type — customers, suppliers, channel partners, counterparties, JV/M&A targets — assessed specifically for trade and financial sanctions exposure. Sanctions screening appears as a control within Sections 10.6 (AML/KYC) and 10.7 (Export Control), but this module exists because sanctions compliance has its own regulatory logic — sectoral sanctions, secondary sanctions exposure, ownership/control aggregation rules (e.g. the EU and UK 50% rule), and general licence regimes — that a generic AML or export screening process does not fully capture, particularly given current geopolitical volatility.
Req. | 10.20 Sanctions Compliance DD |
|---|---|
10.20.1 | The organisation shall determine and document which sanctions regimes apply to its activity by jurisdiction of incorporation, operation, currency exposure, and nationality of ownership, recognising that an organisation may be subject to more than one regime simultaneously with differing scope and extraterritorial reach. |
10.20.2 | The organisation shall apply ownership and control aggregation rules consistent with the applicable regime (e.g. assessing whether a subject is 50% or more owned, in aggregate, by one or more sanctioned persons) rather than relying on direct-name screening alone. |
10.20.3 | The organisation shall assess secondary sanctions exposure — where dealing with a non-sanctioned counterparty could itself trigger sanctions risk because of that counterparty’s own dealings — for subjects and transactions in higher-risk jurisdictions or sectors identified in the Applicable Obligations Register. |
10.20.4 | The organisation shall maintain a documented process for evaluating whether a general or specific licence, exemption, or authorisation is available before proceeding with a transaction that would otherwise be restricted and retain the licence or authorisation as part of the case record. |
10.20.5 | The organisation shall treat a confirmed sanctions match as an immediate hold trigger across all modules in which the subject appears, consistent with the override provisions at Annex A.2, and shall not permit the transaction or relationship to proceed pending resolution. |
10.20.6 | The organisation shall designate accountable ownership for sanctions compliance, which may be combined with or distinct from the AML/KYC owner (Section 10.6) and export control owner (Section 10.7.6) depending on the organisation’s risk profile, and shall document the rationale for its chosen structure. |
Cross-references: ISO 37301:2021 (Compliance management systems); relevant national sanctions regimes referenced by category, per Section 2
10.21 Whistleblowing and Speak-Up Channels
Scope of subjects: the organisation’s own personnel and, where the organisation elects, external parties (suppliers, contractors, affected communities) who wish to report suspected misconduct, including DD-related misconduct. Distinct from Section 10.18’s grievance mechanism, which is oriented toward subjects of DD activity and affected stakeholders seeking remedy for harm; this module addresses internal and external reporting of suspected wrongdoing — including failures of the DDMS itself — and the organisation’s obligation to investigate what is reported. Organisations should note that internal whistleblowing channels are not the only route by which allegations can reach the organisation or a regulator: several regimes now operate their own external submission points independent of the organisation’s own channels (e.g. the EUFLR Single Portal, through which civil society or third parties may submit forced-labour allegations directly to the European Commission), meaning an organisation’s internal channel effectiveness cannot be assumed to control whether or how an allegation surfaces.
Req. | 10.21 Whistleblowing and Speak-Up Channels |
|---|---|
10.21.1 | The organisation shall establish and maintain a whistleblowing or speak-up channel, accessible to personnel and, where determined under Section 10.21.2, external parties, for reporting suspected misconduct including DD-related non-conformity, competence failure, or circumvention of DDMS controls, consistent with the principles of ISO 37002 (Whistleblowing management systems). |
10.21.2 | The organisation shall determine and document whether its whistleblowing channel is open to external parties (suppliers, contractors, affected communities) in addition to personnel, and shall ensure the channel is distinct from, but may be operationally linked to, the grievance mechanism at Section 10.18.2. |
10.21.3 | The organisation shall protect the confidentiality of a reporting person’s identity to the extent permitted by law and shall apply the non-retaliation protections at Sections 7.4.3, 9.4.2, and 10.18.5 to any person who makes a report in good faith, regardless of whether the report is substantiated. |
10.21.4 | The organisation shall conduct investigations arising from whistleblowing reports in a manner consistent with the principles of ISO/TS 37008 (Internal investigations of organizations — Guidance), including proportionality, independence of the investigator from the subject matter, procedural fairness to any person implicated, and documented evidence handling. |
10.21.5 | The organisation shall track whistleblowing report volume, category, investigation outcome, and time-to-resolution as part of the performance monitoring at Section 12.1 and shall treat a pattern of reports concerning the same DD module or business unit as a trigger for review under Section 14.2. |
10.21.6 | The organisation shall report material whistleblowing outcomes concerning DD conduct to the governing body consistent with the escalation requirements at Section 7.5.3. |
Cross-references: ISO 37002:2021 (Whistleblowing management systems — Guidelines); ISO/TS 37008 (Internal investigations of organizations — Guidance)
10.22 Findings Assessment and Decisioning
A completed DD file that simply sits on record without a documented decision is not a functioning management system — it is a filing exercise, the exact failure mode this standard exists to prevent (see the introduction to Section 12). Every DD case that produces a finding requires a deliberate decision: is the finding remediable, what happens if it is not, who has authority to decide, and what happens next. This module is cross-cutting and applies to the output of every module in Sections 10.5–10.24, providing the common decisioning layer that sits after DD execution and before a relationship, transaction, or activity proceeds.
Req. | 10.22 Findings Assessment and Decisioning |
|---|---|
10.22.1 | The organisation shall require a documented findings assessment for every completed DD case, classifying the outcome as: (a) no material finding — proceed; (b) a remediable red flag — a finding that can be addressed through defined mitigating action without declining the relationship; (c) a non-remediable red flag — a finding that cannot be adequately mitigated and requires escalation for a go/no-go decision; or (d) an override-triggered finding requiring mandatory escalation regardless of remediability, consistent with the override provisions at Section 6.4.4 and Annex A.2. |
10.22.2 | The organisation shall maintain a documented Red Flag Response Library (see Annex E) setting out standard response pathways for commonly encountered red flag categories per module, so that an analyst and reviewer are not required to improvise a response to a familiar finding pattern each time it recurs, while retaining the ability to escalate any finding that does not fit an existing pathway or that presents unusual circumstances. |
10.22.3 | The organisation shall require that every DD decision be one of: Go (proceed without conditions); Conditional Go (proceed subject to defined, time-bound remediation or monitoring conditions); or No-Go (decline or terminate the relationship or activity), and shall record the decision, the decision-maker, the rationale, and the DD tier and finding classification that produced it in the case record required at Section 13.1.1. |
10.22.4 | The organisation shall, for a Conditional Go decision, document the specific condition(s) to be satisfied, the deadline by which they must be satisfied, the individual accountable for tracking satisfaction, and the consequence if the condition is not met by the deadline (which shall default to escalation for a fresh No-Go determination, not to automatic continuation). |
10.22.5 | The organisation shall define and document an approval authority matrix for DD decisions, tiered to the DD tier and finding classification — Tier 1–2 Go decisions may be approved by the analyst or first-level reviewer; Tier 3 decisions and any Conditional Go require second-level sign-off consistent with Section 9.3.4; Tier 4 decisions, any No-Go override of an otherwise-clean file, and any decision to proceed despite a non-remediable red flag require approval from the module owner or DD Function Owner; and any decision to proceed despite an override-triggered finding under Section 10.22.1(d) requires governing body-level awareness consistent with Section 7.5.3, regardless of transaction size. |
10.22.6 | The organisation shall define escalation pathways and response timeframes appropriate to the urgency of the finding — a confirmed sanctions match requires immediate hold and escalation per Section 10.20.5, while a lower-severity finding may follow a standard escalation timeframe defined in the Red Flag Response Library — and shall not permit a material finding to remain undecided for longer than a documented maximum case-decision timeframe per DD tier. |
10.22.7 | The organisation shall track Go, Conditional Go, and No-Go decision rates, remediation condition satisfaction rates, and decision timeliness against the timeframes at Section 10.22.6 as part of the performance monitoring at Section 12.1 and shall analyse any pattern of Conditional Go conditions routinely not being satisfied, or of escalations being resolved by default rather than active decision, as a signal requiring corrective action under Section 14.2. |
10.22.8 | The organisation shall periodically review and update the Red Flag Response Library at intervals not exceeding 24 months, incorporating patterns identified through QA sampling (Section 12.1.2), outcome tracking (Section 12.1.7), and regulatory developments tracked in Annex D, so that the library remains a living reference rather than a static document that falls out of step with actual practice. |
Cross-references: ISO 31000:2018 (risk treatment and decision-making); Annex A.2 (override provisions); Annex E (Red Flag Response Library)
10.23 Collaborative and Industry Due Diligence Initiatives
Scope of subjects: joint industry due diligence initiatives, multi-stakeholder platforms, shared audit schemes, and industry-run assessment or certification utilities (e.g. shared supplier audit platforms, sector-wide KYC utilities, collaborative sustainability assessment schemes) that the organisation participates in or relies upon as part of its DDMS. The OECD Due Diligence Guidance recognises that industry and multi-stakeholder initiatives can help companies pool knowledge, reduce cost, and scale effective due diligence — but also observes that the landscape of such initiatives varies significantly in scope, focus, and credibility. This module exists because participation in a shared industry initiative is frequently, and wrongly, treated by organisations as a way of transferring or diluting their own DD risk ownership. It does not. The organisation’s risk profile is its own; a shared initiative’s standard scope is built for the average participating member, not for the specific risk profile, jurisdiction mix, or risk appetite of any single organisation, and an organisation shall not use participation in a shared initiative as a means of walking away from obligations it would otherwise have under this standard.
Req. | 10.23 Collaborative and Industry Due Diligence Initiatives |
|---|---|
10.23.1 | The organisation shall treat participation in, or reliance upon, a collaborative or industry-shared DD initiative as one component or input to its DDMS, not as a substitute for its own risk assessment (Section 6.4), risk appetite determination (Section 6.6), or the Applicable Obligations Register (Section 6.1). The organisation remains the risk owner for any subject it relies on the initiative to assess, regardless of the initiative’s governance, reputation, or the number of other companies relying on it. |
10.23.2 | The organisation shall, before relying on a shared initiative’s output for a given subject or module, conduct a documented gap assessment comparing the initiative’s standard scope and methodology against the organisation’s own risk profile, Applicable Obligations Register, and risk appetite, and shall identify and close through supplementary organisation-specific DD any material risk factor relevant to the organisation that the shared initiative’s standard scope does not cover. |
10.23.3 | The organisation shall not represent to a regulator, certification body, auditor, or counterparty that reliance on a collaborative or industry-shared initiative alone satisfies its DD obligations under this standard where its own gap assessment under Section 10.23.2 has identified risk beyond the initiative’s scope, and shall not use enrolment in or payment to a shared initiative as a proxy for having conducted due diligence where the gap assessment has not been performed or has identified unclosed gaps. |
10.23.4 | The organisation shall retain its own Go, Conditional Go, and No-Go decision authority under Section 10.22.3 for any subject assessed in whole or in part through a shared initiative; that decision authority shall not be delegated to, or treated as automatically determined by, the shared initiative’s own governance body, scoring methodology, or certification outcome. |
10.23.5 | The organisation shall periodically assess the credibility, methodology, independence, and effective rigour of any shared initiative it materially relies upon, at intervals not exceeding 24 months, applying comparable scrutiny to that required for an individual DD vendor under Section 10.17.2, recognising that industry initiatives are not inherently more reliable than a commercial vendor simply because they are collectively governed or widely adopted. |
10.23.6 | The organisation shall, where a shared assessment of a common subject (e.g. a supplier audited once for multiple member companies) is relied upon, verify the assessment’s currency, verify that it was conducted to a methodology consistent with the organisation’s own evidence standard at Section 10.4.8, and assess whether the shared assessment adequately covers risk factors specific to the organisation’s own relationship with that subject (e.g. a product line, transaction value, or jurisdiction exposure not common to other members relying on the same assessment). |
10.23.7 | The organisation shall record in the Applicable Obligations Register which collaborative or industry-shared initiatives it relies upon, for which modules and subject types, the gap assessment conducted under Section 10.23.2, and the supplementary DD performed to close any identified gap, so that reliance on a shared initiative is itself an auditable, documented decision rather than an informal assumption. |
Cross-references: OECD Due Diligence Guidance for Responsible Business Conduct (industry and multi-stakeholder initiatives); ISO 20400:2017 (Sustainable procurement — Guidance)
10.24 Ongoing and Periodic Due Diligence
Scope: this module is cross-cutting and applies across all modules in Section 10.5–10.21 where a subject-level due diligence conclusion has been reached. A due diligence conclusion reflects the subject and the context as they existed at the time it was reached; both change over time, and this module establishes the general obligation to reassess a subject at intervals and in response to events, rather than treating an original conclusion as permanent. Where a module elsewhere in this Section specifies its own re-screening requirement (e.g. Section 10.5.3, Section 10.6.2, Section 10.6.6, Section 10.7.1, Section 10.15.5), that requirement is an implementation of the general obligation established here; where a module does not separately specify one, this module applies as the default.
Req. | 10.24 Ongoing and Periodic Due Diligence |
|---|---|
10.24.1 | The organisation shall treat every subject-level due diligence conclusion as time-bound rather than permanent, and shall determine and document a re-screening cadence for each module and subject type, based on: (a) the DD tier assigned to the subject under Section 6.4; and (b) the specific risk factors identified during the original due diligence itself, rather than applying a single uniform interval across all subjects regardless of what was actually found. |
10.24.2 | The organisation shall define both a time-based re-screening cadence and event-based re-screening triggers for each applicable module and shall not rely on a calendar interval alone. Event-based triggers shall include, at minimum: a change in the subject's ownership or control; a change in the subject's sanctions, PEP, or denied-party status; material adverse media concerning the subject; a material change in the subject's business activity, product, or geography; a material change in the nature or value of the organisation's own relationship with the subject; and a regulatory change tracked in Annex D relevant to the subject's risk profile. |
10.24.3 | The organisation shall calibrate re-screening frequency and trigger sensitivity to risk: a higher DD tier shall receive more frequent re-screening and a wider set of triggers than a lower tier, and a specific risk factor identified but mitigated rather than eliminated during the original due diligence (for example, a finding resolved through a Conditional Go condition under Section 10.22.4) shall directly inform that subject's individual re-screening cadence, rather than defaulting to the generic cadence for its tier alone. |
10.24.4 | The organisation shall treat a subject whose re-screening has become overdue against its documented cadence as itself a finding requiring assessment under Section 10.22.1 and shall not permit an overdue subject to continue in an active relationship indefinitely without a documented decision to re-screen, hold, or escalate. |
10.24.5 | The organisation shall track re-screening compliance and overdue rates as part of the performance monitoring at Section 12.1.1 and shall analyse any sustained pattern of overdue re-screening as a signal requiring corrective action under Section 14.2, consistent with the standard's treatment of silent procedural drift elsewhere in this Section. |
10.24.6 | The organisation shall apply this module as the default re-screening obligation for any module in Section 10.5–10.21 that does not separately specify its own re-screening requirement and shall ensure that a module-specific re-screening clause, where one exists, is read as satisfying rather than replacing the general obligation established here. |
Cross-references: ISO 31000:2018 (risk monitoring and review); Section 3 (Re-screening trigger definition); Section 6.4 (DD Tier); Section 10.22 (Findings Assessment and Decisioning); Section 12.1.1 (re-screening compliance rate)
11. Awareness, Communication, and Training
11.1 Awareness
Req. | 11.1 — Awareness |
|---|---|
11.1.1 | The organisation shall ensure personnel are aware of the DD policy, their individual contribution to DDMS effectiveness, and the implications — including under Section 14.2 — of not conforming with DDMS requirements. |
11.1.2 | The organisation shall ensure personnel in roles that initiate relationships with new counterparties (sales, procurement, HR, business development, deal teams) are specifically aware of the DD culture requirements at Section 7.4 and the escalation pathways at Section 9.2.2. |
11.2 Communications
Req. | 11.2 — Communications |
|---|---|
11.2.1 | The organisation shall determine internal and external communications relevant to the DDMS, including what, when, with whom, and how to communicate, and shall communicate material DD policy changes to affected personnel before implementation consistent with Section 8.5.3. |
11.2.2 | The organisation shall communicate DD expectations to material external counterparties (suppliers, channel partners) where relevant to the applicable modules under Section 10.5–10.24. |
11.3 Training
Req. | 11.3 — Training |
|---|---|
11.3.1 | The organisation shall provide role-specific DD training consistent with the competence requirements in Section 9.3, including for roles that initiate relationships with new counterparties, calibrated to the modules and DD tiers each role is exposed to. |
11.3.2 | The organisation shall provide DD induction training to new employees in DD-relevant roles as part of onboarding, and refresher training at intervals not exceeding 24 months, incorporating updates from Annex D regulatory tracking and QA findings under Section 12.1.5 where relevant. |
12. Performance, Monitoring, and Audit
A DDMS that is only ever assessed by whether individual case files exist is not being managed as a system — it is being managed as a filing exercise.
12.1 Monitoring
Req. | 12.1 — Monitoring |
|---|---|
12.1.1 | The organisation shall define and track quantitative performance metrics for the DDMS and each module, including volume of DD by tier and module, cycle time, re-screening compliance rate, escalation rate and resolution time, and remediation closure rate. |
12.1.2 | The organisation shall conduct regular QA sampling of completed DD files, independent of the analyst and reviewer who produced them, assessing whether the methodology was correctly applied and whether available red flags were identified and acted upon — not only whether a file exists. |
12.1.3 | The organisation shall set a minimum QA sampling rate per module and DD tier, weighted toward higher tiers. |
12.1.4 | The organisation shall track QA error and finding rates over time, by module, tier, and where volume allows, by analyst or team. |
12.1.5 | The organisation shall analyse root causes of QA findings — competence gaps, methodology gaps, data source gaps, and workload/resourcing pressure — rather than treating each as an isolated incident. |
12.1.6 | The organisation shall periodically test the DDMS’s detection capability using known or simulated adverse scenarios to verify the system and its analysts can actually find what they are supposed to find. |
12.1.7 | The organisation shall track and analyse outcomes of decisions made on the basis of DD, as feedback into whether the risk tiering methodology (Section 6.4) is well-calibrated. |
12.1.8 | The organisation shall apply a documented evidence and source quality standard to DD findings, proportionate to the DD tier, requiring at minimum that a finding material to a Tier 3 or Tier 4 conclusion be corroborated across more than one independent source, per the competence requirement at Section 9.3.9, and that QA sampling under Section 12.1.2 specifically test whether this standard was met, not only whether a conclusion was reached. |
12.1.9 | The organisation shall distinguish, within QA error and finding rates tracked under Section 12.1.4, between false-negative errors (a material risk was present and not identified or acted upon) and false-positive errors (a finding was raised or a tier escalated without adequate basis) and shall report these as separate categories to management review, given that the two error types carry materially different consequences and may indicate different root causes. |
12.1.10 | The organisation shall conduct or commission independent QA calibration — using a reviewer external to the team whose work is being sampled, which may include an external party — at intervals not exceeding 24 months, to test whether internal QA sampling under Section 12.1.2 remains rigorous and has not become self-referential over time. |
12.2 Dashboards and KPI Tracking
Req. | 12.2 — Dashboards and KPI Tracking |
|---|---|
12.2.1 | The organisation shall maintain a live or regularly updated dashboard, accessible to the DD Function Owner and relevant management, presenting the metrics at Section 12.1 in a form that supports active management rather than only retrospective reporting. |
12.2.2 | The organisation shall define the specific metrics, visualisations, and drill-down capability the dashboard provides for each applicable module, sufficient for the DD Function Owner to identify an underperforming module or emerging trend without waiting for the next formal reporting cycle. |
12.2.3 | The organisation shall review and update the dashboard's design at intervals not exceeding 12 months to confirm it remains aligned to current objectives (Section 8.1), risk tiering (Section 6.4), and the metrics tracked under Section 12.1, rather than persisting unchanged as the DDMS itself evolves. |
12.3 Management Reviews
Req. | 12.3 — Management Reviews |
|---|---|
12.3.1 | The organisation shall review the DDMS at planned intervals, including the performance metrics, QA findings, and root-cause analysis from Section 12.1. |
12.3.2 | The organisation shall review trends in error and finding rates, and whether corrective actions have actually reduced recurrence. |
12.3.3 | The organisation shall review whether the DD culture (Section 7.4) is being lived in practice, informed by data rather than policy attestation alone. |
12.3.4 | The organisation shall review resourcing and competence adequacy (Section 9) in light of DD volume, cycle time, and QA results. |
12.3.5 | The organisation shall record decisions and actions arising from the review, with accountable owners and timeframes, tracked to closure. |
12.4 DDMS Effectiveness Assessment
Req. | 12.4 — DDMS Effectiveness Assessment |
|---|---|
12.4.1 | The organisation shall conduct an annual assessment of DDMS effectiveness against three dimensions: suitability — whether the DDMS remains appropriate to the organisation’s current context and risk profile; adequacy — whether the DDMS has sufficient scope and resourcing to cover all applicable modules; and effectiveness — whether the DDMS achieves its intended outcomes, evidenced by the detection-capability testing at Section 12.1.6 and the outcome tracking at Section 12.1.7. |
12.4.2 | The organisation shall report the DDMS effectiveness assessment to the governing body as part of the reporting cadence established at Section 7.2.2. |
12.5 Internal Audit
Req. | 12.5 — Internal Audit |
|---|---|
12.5.1 | The organisation shall conduct internal audits of the DDMS at planned intervals not exceeding 12 months, covering conformance to this standard and to its own Applicable Obligations Register and Position Statements, using auditors independent of the DD activity being audited, in accordance with ISO 19011:2018. |
12.5.2 | The organisation shall maintain a documented audit programme defining objectives, scope, frequency, resources, and responsibilities, and shall report audit findings to senior leadership and the governing body, feeding into the corrective action process under Section 14.2. |
Cross-references: ISO 19011:2018
12.6 Due Diligence Function Review
Req. | 12.6 Due Diligence Function Review |
|---|---|
12.6.1 | The organisation shall conduct a periodic review, at intervals not exceeding 24 months of the DD function’s structure, resourcing, and reporting lines to confirm continued independence and adequacy per Section 7.5 and shall document any structural changes recommended as a result. |
12.6.2 | The organisation shall assess, as part of this review, whether the DD function's headcount, competence profile, and technology are proportionate to current DD volume, cycle time, and QA results under Section 12.1, and whether the governance principles at Section 7.5.1 (direct access, independence, authority) remain genuinely in effect rather than nominally in effect. |
12.6.3 | The organisation shall report the outcome of this review to the governing body, including any recommendation to change the DD function's structure, reporting line, or resourcing. |
13. Documentation, Disclosure, and Certification
13.1 Documentation
Req. | 13.1 — Documentation |
|---|---|
13.1.1 | The organisation shall maintain documented information including the Applicable Obligations Register and Position Statements (Section 6.1); the risk appetite determination and tiering methodology (Sections 6.4, 6.6); case-level DD records sufficient to demonstrate methodology, tier, evidence, and sign-off; competence records (Section 9.3); AI tool use logs (Section 10.16.6); and performance/QA data (Section 12). |
13.1.2 | The organisation shall set retention periods per record type in the Applicable Obligations Register, reflecting specific legal or regulatory retention requirements where they exist, and the organisation’s own documented position where none exists, per the “know it, document it, execute against it” principle at Section 6.1. |
13.1.3 | The organisation shall protect documented information against unauthorised access, alteration, or loss, and shall ensure it is available in a form usable for internal audit (Section 12.5) and, where the organisation seeks it, external certification review. |
13.1.4 | The organisation shall maintain a documented process for responding to a natural person’s request to access, correct, or request deletion of personal data held about them as a DD subject, consistent with applicable data protection law identified in the Applicable Obligations Register, and shall determine and document any lawful basis for withholding all or part of a DD record from such a request (e.g. an active investigation, or a legal retention obligation) rather than granting or refusing all requests uniformly. |
13.2 Due Diligence Disclosure
Req. | 13.2 — Due Diligence Disclosure |
|---|---|
13.2.1 | The organisation shall determine whether and how DDMS conformance is disclosed externally (e.g. to investors, regulators, or business partners), consistent with the Applicable Obligations Register. |
13.2.2 | The organisation shall, where it elects to disclose DDMS conformance, ensure disclosures are accurate, substantiated by the documentation at Section 13.1, and do not overstate the organisation’s certification status (see Section 13.5). |
13.3 External Filings
Req. | 13.3 — External Filings |
|---|---|
13.3.1 | The organisation shall identify and maintain a process for any regulatory filings or notifications arising from DD activity (e.g. suspicious activity reports under Section 10.6, export licence filings under Section 10.7, forced-labour import responses under Section 10.9.4) consistent with the Applicable Obligations Register. |
13.3.2 | The organisation shall designate accountable ownership for each category of external filing and document the approval process required before a filing is submitted. |
13.4 Counterparty and Partner Disclosure
Req. | 13.4 Counterparty and Partner Disclosure |
|---|---|
13.4.1 | The organisation shall determine its approach to sharing DDMS conformance status with counterparties and partners who request it, consistent with confidentiality and data protection obligations, and shall not disclose the substance of individual case-level DD findings to third parties without a lawful basis. |
13.4.2 | The organisation shall maintain a standard form of conformance statement or summary suitable for sharing with counterparties and partners, distinguishing self-assessed conformance from independently verified Speeki certification (Section 13.5.2), so that a counterparty is not misled as to the nature of the assurance being provided. |
13.5 ISO and Related Certifications
Req. | 13.5 ISO and Related Certifications |
|---|---|
13.5.1 | The organisation shall document all ISO certifications relevant to Section 10 modules (37001, 14001, 45001, 27001, 42001) and demonstrate how these are cross-referenced rather than duplicated within the DDMS, per the relevant module requirements at Sections 10.5, 10.13, 10.14, 10.15, and 10.16. |
13.5.2 | The organisation shall represent its SPK DDMS2000:2026 certification status accurately in accordance with the certification rights and restrictions at the Copyright and Licensing Notice and shall not represent conformance with this standard absent a current, valid Speeki-issued certificate. |
14. Improvement
14.1 Continual Improvement
Req. | 14.1 — Continual Improvement |
|---|---|
14.1.1 | The organisation shall use the outputs of Section 12 (performance data, QA trends, root-cause analysis, detection-capability testing, and outcome tracking) as the primary evidence base for improving the DDMS — its methodology, tiering thresholds, competence requirements, and resourcing — rather than treating improvement as a general aspiration disconnected from measured performance. |
14.1.2 | The organisation shall demonstrate continual improvement across the three dimensions assessed at Section 12.4 — suitability, adequacy, and effectiveness — with documented evidence of specific changes made to the DDMS as a result of each annual assessment. |
14.2 Non-conformity and Corrective Action
Req. | 14.2 — Non-conformity and Corrective Action |
|---|---|
14.2.1 | The organisation shall treat QA findings, missed red flags, competence failures (Section 9.3.7), and internal/certification audit findings as nonconformities subject to root-cause corrective action. |
14.2.2 | The organisation shall verify that corrective actions actually reduce recurrence, using the trend data from Section 12.1, rather than closing a corrective action on the basis that a single instance was remediated. |
14.2.3 | The organisation shall escalate recurring or systemic nonconformities to management review (Section 12.3) rather than allowing them to be closed repeatedly at the same level without escalation. |
ANNEX A — Implementation Guidelines (Informative)
Annex A provides ‘should’ guidance only. Departure from Annex A does not constitute a non-conformity.
A.1 Business Context (Section 5)
Organisations should begin context-setting by mapping their subject-type footprint (which of the nineteen modules are even plausible) before attempting detailed risk factor definition.
A.2 Understanding Risks (Section 6)
Organisations should pilot their tiering methodology against a sample of historical DD files before formal roll-out, to sanity-check thresholds against known outcomes.
Scoring the outputs of risk assessments, questionnaires, background checks, and similar DD activity is an acceptable and often useful practice for aggregating and comparing findings consistently, and organisations should feel free to use a model such as the one below. Organisations should nonetheless remain alert to the limits of any scoring model: a numeric score can create an impression of precision and objectivity the underlying judgement calls do not always support, and a genuinely serious finding can be diluted, and effectively hidden, if it is simply averaged together with several unrelated low-risk factors.
Illustrative Risk Factor Scoring
The jurisdiction risk factor in the model below is illustrative only. Organisations shall not adopt the labels shown (e.g. “low-risk OECD”, “high-risk/sanctioned-adjacent”) or any public country risk index directly as their own jurisdiction risk factor without adapting them to their own sectors, activities, and risk tolerance, consistent with Section 6.4.7.
Factor | 0 | 1 | 2 | 3 |
|---|---|---|---|---|
Jurisdiction risk | Low-risk OECD | Moderate | Elevated | High-risk/sanctioned-adjacent |
Sector risk | Low inherent risk | Some exposure | Known higher-risk sector | Extractives/defence/high-risk |
Relationship/transaction value | Immaterial | Moderate | Significant | Material to the organisation |
Ownership/structural opacity | Fully transparent | Minor gaps | Layered structure | Shell/nominee indicators |
Government interaction | None | Indirect | Regular | Direct, on organisation’s behalf |
Screening hits | None | Resolved false positive | Unresolved partial match | Confirmed hit |
Prior adverse findings | None | Minor, remediated | Moderate, open | Material, unremediated |
Illustrative Tier Bands
Aggregate score | DD Tier |
|---|---|
0–4 | Tier 1 — Screening only |
5–9 | Tier 2 — Standard DD |
10–14 | Tier 3 — Enhanced DD |
15+ | Tier 4 — Field-verified DD |
Override: any confirmed sanctions/PEP hit, or comprehensive-sanctions jurisdiction should trigger at minimum Tier 3 regardless of aggregate score.
A.3 Buy-in and Leadership Commitment (Section 7)
Organisations should consider a standing DD culture item on governing body agendas, not just an annual review.
A.4 Objectives and Strategy (Section 8)
Objectives should be reviewed at the same cadence as the risk appetite determination (Section 6.6) to keep them synchronised.
A.5 Roles, Competence, and Accountability (Section 9)
Organisations should consider a “Sentinel-qualified DD analyst” style internal credentialing track for Tier 3/4 authorisation.
A.6 Policies, Controls, and Operations (Section 10)
Organisations new to a module should start with Tier 1/2 processes and mature toward Tier 3/4 capability rather than attempting full-depth DD across all subjects immediately.
A.7 Awareness, Communication, and Training (Section 11)
Training should use real (anonymised) case studies from the organisation’s own QA findings where available.
A.8 Performance, Monitoring, and Audit (Section 12)
Organisations should benchmark QA sampling rates against sector peers as a sanity check, while retaining their own documented rationale.
A.9 Documentation, Disclosure, and Certification (Section 13)
Organisations should consider a standard external-facing DDMS conformance statement for use with investors and major counterparties.
A.10 Improvement (Section 14)
Organisations should track corrective action cycle time as its own metric, not only closure rate.
ANNEX B — Subject-Type × Module Control Mapping
This matrix is an illustrative example only and is deliberately conservative: most modules are marked as potentially applicable (○) to most subject types, since due diligence obligations frequently extend further than organisations initially assume. Applicability also depends materially on jurisdiction — a factor that may be highly relevant in one country may be less relevant, or governed differently, in another. Organisations shall use this matrix as a starting checklist to be tested against their own Applicable Obligations Register (Section 6.1) and risk assessment (Section 6.4), not as a determination that a module does not apply.
Subject type | 10.5 Anti-bribery | 10.6 AML/KYC | 10.7 Export control | 10.8 Supplier HREDD | 10.9 Forced labour/import | 10.10 Personnel | 10.11 JV/M&A | 10.12 Brand/reputational | 10.13 Environmental | 10.14 Health & safety | 10.15 Cyber/data privacy | 10.19 Deforestation/minerals | 10.20 Sanctions |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Natural person (employee/exec/board) | ○ | ○ | ○ | — | ○ | ● | — | ○ | ○ | ○ | ○ | — | ○ |
Agent/intermediary/consultant | ● | ○ | ○ | ○ | ○ | — | — | ○ | ○ | ○ | ○ | ○ | ○ |
Supplier | ○ | ○ | ○ | ● | ● | — | — | ○ | ○ | ○ | ○ | ● | ○ |
Channel partner/distributor | ● | ○ | ○ | ● | ○ | — | — | ○ | ○ | ○ | ○ | ○ | ○ |
Customer/reseller/end user | ○ | ● | ● | ○ | ○ | — | — | ● | ○ | ○ | ○ | ○ | ● |
Investor/financial counterparty | ○ | ● | ○ | ○ | ○ | — | — | ○ | ○ | ○ | ○ | ○ | ● |
Endorser/sponsorship partner | ○ | ○ | — | ○ | ○ | — | — | ● | ○ | ○ | ○ | — | ○ |
Vendor with data/system access | ○ | ○ | ○ | ○ | ○ | — | — | ○ | ○ | ○ | ● | — | ○ |
Contractor (on-site) | ○ | ○ | ○ | ○ | ○ | — | — | ○ | ○ | ● | ○ | — | ○ |
Site/facility/asset (M&A, real estate) | — | — | — | — | — | — | — | — | ● | ● | ○ | ○ | — |
JV/M&A target | ○ | ○ | ○ | ○ | ○ | — | ● | ○ | ● | ● | ● | ○ | ● |
Modules 10.16 (AI Governance), 10.17 (Vendor and Outsourced DD Provider Management), 10.18 (Remediation), 10.21 (Whistleblowing), 10.22 (Findings Assessment and Decisioning), 10.23 (Collaborative and Industry DD Initiatives), and 10.24 (Ongoing and Periodic Due Diligence) are cross-cutting and apply across all subject types where relevant, rather than being subject-type-specific — see the respective module scope statements.
● = primary module; ○ = applicable if risk factors present; — = not applicable.
This mapping is indicative and not exhaustive. A cell marked — (not applicable) reflects a considered judgement for the generic subject type shown, not a rule; organisations shall verify applicability for their own footprint, sector, and the specific countries in which they operate, and shall document any determination that a module does not apply, consistent with Section 5.2.3.
ANNEX C — Speeki Sentinel Implementation Guidance
Speeki Sentinel is Speeki's certification against SPK DDMS2000:2026 — it is not a platform, toolkit, or system that an organisation adopts or operates independently. An organisation builds and operates its own due diligence management system, using whatever internal processes, tools, or third-party providers it chooses; Speeki Sentinel is the name of the independent assessment and, where successful, the certificate confirming that system conforms to this standard. There is no pathway to Speeki Sentinel certification other than building a DDMS that genuinely conforms to SPK DDMS2000:2026 and having that conformance independently verified by Speeki. Certification is optional — an organisation may adopt and operate under this standard, on a self-assessed basis, without ever seeking Speeki Sentinel certification — but Speeki Sentinel itself has no existence or value apart from that certification process.
Speeki does not operate due diligence on behalf of any client. Speeki's role is limited to independently assessing a client's own DDMS against this standard as part of the Speeki Sentinel certification process. Speeki's internal AI tool, Nicole, supports Speeki's own auditors during that certification/assessment process only and has no role in a client's DD execution. This separation is what preserves Speeki's structural independence as a certification body: Speeki is never performing, or materially enabling, the activity it is independently assessing.
ANNEX D — Legal & Guidance Framework Crosswalk (Living Annex, Versioned and Dated)
D.1 OECD Six-Step Due Diligence Crosswalk
The OECD Due Diligence Guidance for Responsible Business Conduct (2018), carried forward into the 2023 updated OECD Guidelines for Multinational Enterprises and used as the template for CSDDD/CS3D, sets out six due diligence steps. SPK DDMS2000:2026 is designed so that full conformance with this standard necessarily satisfies all six steps. The crosswalk below is provided so organisations and assessors can trace each OECD step to its corresponding DDMS2000 clause(s), rather than treating OECD alignment as a separate exercise.
OECD Step | Corresponding SPK DDMS2000:2026 Clause(s) |
|---|---|
1. Embed responsible business conduct into policies and management systems | Section 5 (Business Context); Section 7 (Buy-in and Leadership Commitment, including 7.4 Due Diligence Culture and 7.5 Governing Body Governance); Section 10.1–10.2 (DD Policy; Principles and Guidelines) |
2. Identify and assess actual and potential adverse impacts in operations, supply chains, and business relationships | Section 6 (Understanding Risks, including 6.3 Subject and Risk Identification and 6.4 Risk Assessment); Section 10.8 (Supplier and Channel Partner HREDD, 10.8.1); Section 10.9 (Forced Labour and Import Compliance, 10.9.1) |
3. Cease, prevent, or mitigate adverse impacts | Section 10.4 (Controls); Section 10.8.4 (preventive and remedial action proportionate to severity and likelihood); Section 10.9.2–10.9.3 (traceability and independent verification); module-specific escalation and hold mechanisms throughout Section 10.5–10.24 |
4. Track implementation and results | Section 12 (Performance, Monitoring, and Audit, including 12.1 Monitoring, 12.1.6 detection-capability testing, and 12.1.7 outcome tracking); Section 10.8.5 (monitoring effectiveness of measures taken) |
5. Communicate how impacts are addressed | Section 11 (Awareness, Communication, and Training); Section 13.2 (Due Diligence Disclosure); Section 13.4 (Counterparty and Partner Disclosure) |
6. Provide for or cooperate in remediation when appropriate | Section 10.18 (Remediation and Access to Remedy — dedicated cross-cutting module); Section 10.8.3–10.8.4 (supplier-specific alert mechanism and remedial action); Section 14 (Improvement, including 14.2 Non-conformity and Corrective Action) |
This crosswalk shall be reviewed whenever the OECD Guidance or Guidelines are materially updated, and any resulting gap shall be addressed through the corrective action process at Section 14.2.
D.2 Legal and Guidance Framework Crosswalk
Maps DDMS2000 modules to specific laws and guides, each with a “last verified” date and review trigger.
Foundational guides: OECD Due Diligence Guidance for Responsible Business Conduct (see D.1 for full crosswalk); UN Guiding Principles on Business & Human Rights (UNGP); ISO 26000; IFC Performance Standards; ILO Combating Forced Labour Handbook; RBA Code of Conduct.
Human rights/environmental vigilance regimes: CSDDD (Directive (EU) 2026/470 — narrowed via Omnibus I, applies from 2029, EU threshold 5,000 employees/€1.5bn turnover); German LkSG (in force, reporting duty being repealed); French Duty of Vigilance Law (in force, actively enforced by courts); Norway Transparency Act (in force since 2022); Dutch Child Labour Due Diligence Act (dormant, pending — monitor).
Forced labour/import-enforcement regimes: US UFLPA (in force, rebuttable presumption); EU Forced Labour Regulation (EUFLR, Regulation (EU) 2024/3015) — in force since 13 December 2024, applies from 14 December 2027; prohibits placing, making available, or exporting products made wholly or partly with forced labour, regardless of operator size, sector, or origin; imposes no independent due diligence obligation (a strict-liability ban), but voluntary due diligence is explicitly taken into account by enforcing authorities and can help avoid or shorten an investigation; European Commission implementation guidelines published 26 June 2026, built on the OECD six-step framework (see Annex D.1); a public Forced Labour Risk Database and Single Portal are being established; enforcement is risk-based, considering scale/severity, product quantity, share of the affected part, operator size, and supply chain complexity; evidence-request deadlines as short as 30 working days; not affected by the EU Omnibus I package, unlike CSDDD; Canada Fighting Against Forced Labour and Child Labour in Supply Chains Act (in force since 2024); UK Modern Slavery Act 2015 (under review); Australia Modern Slavery Act 2018.
Deforestation and conflict minerals regimes: EU Deforestation Regulation (EUDR, Regulation (EU) 2023/1115, as amended by Regulation (EU) 2025/2650) — entered into force June 2023, application postponed twice, now applying 30 December 2026 for large/medium operators and 30 June 2027 for micro/small operators (confirmed as final by the European Commission’s May 2026 simplification package — no further postponement expected); covers cattle, cocoa, coffee, palm oil, rubber, soya, wood, and derived products; requires the product be deforestation-free since the regime’s reference date, legally produced, and covered by a due diligence statement filed through the EU Information System, with geolocation data required for production plots in most cases; core due diligence and traceability obligations remain intact despite simplification, though compliance costs have been reduced by an estimated 75% through scope and process simplification. EU Conflict Minerals Regulation (Regulation (EU) 2017/821) — in force, requires supply chain due diligence to the smelter/refiner level for tin, tantalum, tungsten, and gold importers above threshold volumes, consistent with the OECD minerals guidance. US Dodd-Frank Section 1502 (referenced by category) — the original conflict minerals disclosure regime for US-listed issuers, distinct in mechanism (SEC disclosure rather than an EU-style market ban).
(Content as compiled in prior research; to be maintained as a standalone, separately versioned document per the paper series plan.)
ANNEX E — Red Flag Response Library (Informative)
Annex E is informative (‘should’ language). It illustrates one defensible approach to standard response pathways for commonly encountered red flags, required to exist in some form under Section 10.22.2. Organisations shall build their own library calibrated to their risk appetite (Section 6.6) and Applicable Obligations Register (Section 6.1); this annex is a starting reference, not a mandated response.
Red flag category | Module | Typically remediable? | Illustrative standard response pathway |
|---|---|---|---|
Unresolved partial name match (sanctions/PEP) | 10.6, 10.7, 10.20 | Yes, if resolved | Enhanced identity verification to confirm true negative; document resolution evidence; proceed only once confirmed as a false positive |
Confirmed sanctions or denied-party match | 10.6, 10.7, 10.20 | No | Immediate hold; escalate per Section 10.20.5; do not proceed absent a licence or exemption under Section 10.20.4 |
Beneficial ownership cannot be fully verified | 10.6 | Sometimes | Apply enhanced due diligence; consider risk-based decision to proceed with enhanced monitoring (Conditional Go) or decline, per Section 10.6.1 |
Shell/nominee structure indicators | 10.5, 10.6 | Sometimes | Require additional documentation of beneficial ownership and business rationale; escalate to Tier 3+ per Section 10.5.2 |
Adverse media — unresolved, credible, material | Multiple | Sometimes | Corroborate per the evidence standard at Section 10.4.8; assess severity and recency; Conditional Go with enhanced monitoring, or escalate for No-Go if severity is high |
Reluctance to provide end-use information (export) | 10.7 | No | Do not proceed; treat as a primary red-flag indicator per Section 10.7.2 |
Confirmed prior data breach (vendor) | 10.15 | Sometimes | Require evidence of remediation and current certification status; Conditional Go with defined re-assessment date or decline for critical/unresolved findings per Section 10.15.3 |
Confirmed serious H&S incident history | 10.14 | Sometimes | Escalate per Section 10.14.3; Conditional Go only with evidenced corrective action at the subject; decline for fatality history without credible remediation evidence |
Supplier declines HREDD grievance mechanism access | 10.8 | Sometimes | Engage using leverage per Section 10.18.1(b); Conditional Go with a defined engagement timeline; escalate for exit consideration if engagement fails |
Missing supply chain traceability (rebuttable-presumption regime) | 10.9 | Sometimes | Do not treat as remediable by narrative alone; require traceability evidence per Section 10.9.2 before proceeding |
Product/geography match on public forced-labour risk database | 10.9 | Sometimes | Mandatory enhanced DD trigger per Section 10.9.4; Conditional Go only with satisfactory enhanced findings |
Missing geolocation/traceability data (deforestation) | 10.19 | Sometimes | Do not file a due diligence statement without required data; treat as a blocking gap, not a documentation formality |
Confirmed conflict-affected area sourcing (minerals) | 10.19 | Sometimes | Escalate to smelter/refiner-level due diligence per Section 10.19.3; Conditional Go only with satisfactory OECD-aligned findings |
Undisclosed conflict of interest (personnel/board) | 10.10 | Sometimes | Require formal disclosure and recusal from relevant decisions; escalate to governing body for board-level conflicts |
Whistleblowing report implicating a DD decision | 10.21 | Case-by-case | Route to investigation per Section 10.21.4; suspend reliance on the implicated DD file pending outcome |