Business: Compliance · Lesson N.comp.4

Choreography: third-party due diligence at scale

The choreography of using AI to sweep thousands of suppliers and partners in third-party due diligence: the machine flags risk signal (sanctions, PEPs, hidden business partners, adverse news) and you investigate each one, paying the cost of the false positive so you don't pay the much higher cost of the false negative.

Examples for

The company has three thousand two hundred active suppliers, and policy says all of them need annual due diligence against sanctions lists, politically exposed persons, and suspicious ownership structures. At manual pace you can review about fifteen a day, flat out, which would take almost a year to cover the base once. You upload all three thousand two hundred to AI and ask for something specific: don't conclude anything, just flag names that match (even partially) a sanctions list, business partners appearing in more than one company of the same economic group, and adverse news from the last two years. It sweeps everything in hours and returns one hundred ten suppliers flagged. Most are unrelated namesakes, false positives that cost only your time to dismiss. Three are serious: one has a partner on an international sanctions list for six months and nobody had noticed.

Let me hit you with a piece of math before any promise. You don't have a problem evaluating a supplier well; your compliance team knows how to do that better than any machine. The problem is volume and frequency: it's three thousand suppliers and policy says check every year, but the world changes every week, new sanction, new business partner, new news. The bottleneck was never the quality of the check, it was its coverage over time. And that's exactly where, in the volume and frequency nobody would sustain manually, AI comes in. It doesn't come to evaluate better than your analyst. It comes to sweep what nobody would have time to re-sweep every week.

The core idea of this lesson. In third-party due diligence, AI does one thing very well: it sweeps the entire base of suppliers and partners, continuously, and FLAGS risk signals (sanctions, politically exposed persons, hidden business partners, adverse news, violations). It flags, it doesn't conclude. The scrutiny stays yours: investigating every flagged signal, understanding the real impact, and deciding the action. The cost to name is the false positive and the false negative, and for a third party the false negative is the more expensive one: a sanctioned supplier that goes unnoticed becomes your company's joint liability. The machine is the detector; you're the one who decides what to do with what it found.

01The bottleneck was never the check, it was coverage over time

Take the scenario of the three thousand two hundred suppliers. At manual pace, checking covers a slice per year, usually at contract renewal, and hopes nothing changed between one renewal and the next. That's not continuous due diligence, it's a photograph taken once that goes stale the next day.

Notice where the squeeze is. It's not the quality of your analyst's assessment, which is high. It's the frequency your team can sustain. AI doesn't fix what you already do well; it attacks what your capacity can't sustain: re-sweeping the entire base every week against a sanctions list that changes, news that comes out, ownership structures that shift. What used to be an annual sample check becomes a continuous sweep of the whole base.

It's the difference between trusting a photo taken a year ago and having a camera running all the time. Fair?

02The choreography: AI flags, you investigate

Think of a metal detector sweeping a big beach every day, not once a year. It doesn't dig anything up and doesn't tell you what's underneath. It beeps. It beeped, you mark the spot and dig. Sometimes it's a coin, sometimes it's a bottle cap. But the detector covers the whole beach, every time, which nobody would do by hand with a shovel.

AI in third-party screening is that detector. It sweeps the registry and FLAGS points of attention: a name that matches a sanctions list, a business partner appearing in more than one company in the group, recent adverse news, a new violation. It flags "look here." It doesn't conclude "this supplier is corrupt" or "this partner needs to be cut off." The conclusion is yours.

And here's the part that stays entirely yours: investigating each flagged point, understanding the real impact on the business, and deciding the action, which can range from asking for clarification to suspending the contract. AI doesn't know whether that business partner on a sanctions list is grounds to end the relationship or a case the policy already handles differently. You know. It hands you the point; you hand it the judgment.

The third-party base swept: mostly clean, few flagged AI sweeps the whole base, every week, flags only the signals short list: 3 suppliers to investigate sanction, hidden partner, recent violation you dig into each flagged point

03The cost to name: false positives cost time, false negatives cost joint liability

Anti-hype time, because every tool has a cost and hiding the cost is selling an illusion. AI's sweep gets it wrong in two ways, and for a third party the two weigh differently than in almost any other context.

The false positive is when it flags a supplier that's nothing, a namesake, a name coincidence. It cost you the time to investigate something harmless. The false negative is the opposite and the more expensive one: it lets a genuinely sanctioned supplier or one with a risky business partner slip through, and it stays active, invisible in the base. For a third party, that's not just a problem you find out about later; the company can be held jointly liable for a relationship that should never have been maintained, before the regulator, the client, and public opinion.

That's why the screening design is intentionally asymmetric. You calibrate AI to flag generously, accepting false positives, because the false positive only costs the human's time filtering. The false negative costs the company's real exposure. It's cheaper to dismiss twenty false alarms than to let one sanctioned supplier slip through and turn into a headline and a lawsuit.

false positive flags a supplier that is nothing cost: human time acceptable false negative sanctioned supplier stays active, invisible cost: joint liability for the company

04How to build the screening without fooling yourself

Put it all together into a choreography that runs continuously on your third-party base. First, you define what AI should flag: the signals that matter for this specific base (sanctions list, politically exposed person, cross-referenced ownership structure, adverse news, regulatory violation). You give the target; AI doesn't guess what's relevant to your sector.

Second, AI sweeps the whole base at the frequency the risk demands (weekly for sanctions, which change fast; monthly for adverse news; continuous for ownership structure) and returns the short list with each flagged point and where it is. Third, and this never leaves your hands: you investigate point by point, dismiss the false positives, measure the real impact of each one that's left, and decide the action. Fourth, you close knowing you covered the entire base, at the right frequency, not an annual sample.

The mistake that sinks people here is confusing AI's alert with a ready-made conclusion. Whoever treats "this supplier has a partner on a list" as a verdict already given rushes to end the contract without checking whether it's the same name or a namesake, and ends up in a wrongful-termination lawsuit. Whoever treats it as noise without investigating runs the opposite risk. AI expands reach; the scrutiny is yours. Fair?

Do it now

Do it yourself

Take a real category of third parties your company monitors (your real task works well) and design the choreography before feeding anything into AI. Answer in four blocks:

  1. THE VOLUME: how many third parties are there, and how often does policy require checking? Name the bottleneck: is it the quality of the check or the frequency your team can sustain?
  1. THE SIGNALS: list 3 to 5 points of attention AI should FLAG for this specific base (sanctions list, politically exposed person, cross-referenced partner, adverse news, violation). This is the target only you can define.
  1. THE COST: for this base, what's worse, a false positive (it flags a supplier that's nothing) or a false negative (it lets one through)? Decide whether you calibrate the sweep to flag generously, and why.
  1. THE SCRUTINY: describe in one sentence what stays YOURS after the sweep, meaning what you investigate, measure, and decide, and who signs off on the action regarding the third party in the end.

If you can't fill in block 2, AI will flag noise. The target comes from you; the sweep comes from it.

Practice

1. In third-party due diligence with thousands of suppliers, what is the correct division of labor between AI and the compliance team?

2. Why is the false negative especially costly in third-party due diligence, more than in many other screenings?

3. Which phrase best describes the economic gain of using AI in continuous third-party screening?

For the board

On the bottleneckit was never the quality of the check. It was coverage over time: policy says check yearly and the world changes weekly.
On the splitthe AI is the detector that pings across the whole base. The team digs into each point and decides what matters.
On calibrationa false negative costs joint liability. That is why you flag generously, accepting more false alarms.
What did you think of this page?
Would you recommend this page to someone on your team?