Essay · 2026
The Participation Gap in Third-Party Due Diligence
Why distance is not independence - and how the Confidence Layer can direct attention to the risks that remain
By Hugo Williamson, August 2026
The Participation Gap
When an experienced compliance leader is seriously concerned about a third party, they rarely seek greater distance. They get closer.
A former chief compliance officer who reviewed an earlier version of the Confidence Layer argument made this point forcefully. Where he could visit a high-risk agent, he did. Direct engagement helped him understand the organisation, test its controls and assess its response to concerns. It also made the resulting decision more defensible if something subsequently went wrong.
His challenge exposed an important nuance. Distance from third parties has not simply been a deliberate compliance choice. Often, it has been the unavoidable consequence of scale.
A multinational may have tens of thousands of suppliers, distributors and agents. Compliance teams cannot investigate or engage deeply with all of them. They have therefore done something rational: used inherent-risk indicators to identify the relationships that appear to warrant the greatest attention.
Those classified as high risk may receive enhanced diligence, interviews and site visits. The much larger remainder of the portfolio typically receives automated screening, a questionnaire or little direct engagement at all.
Risk-based prioritisation is necessary. But this model has created what I call the “Participation Gap”.
The third parties receiving the greatest scrutiny are often also given the greatest opportunity to explain themselves, provide evidence and demonstrate remediation. Across the rest of the portfolio, participation is generally confined to completing a standard questionnaire - if it happens at all.
What began as a practical response to cost and workload has become embedded in the architecture of due diligence. Distance is no longer always recognised as an operating constraint. At times, it is treated as if it were itself a source of independence.
It is not.
Questionnaire fatigue is a symptom
In 12 of 16 exploratory discovery interviews we conducted in 2025, participants described friction around questionnaires and information requests: repetition, delays, incomplete answers, requests reaching the wrong people and time-consuming follow-up.
Questionnaires are not inherently flawed. Organisations need information that only the third party may possess. The problem is that the questionnaire has become the principal scalable substitute for direct participation.
The same third party may be asked for similar evidence by multiple customers, through different systems and in slightly different formats. Previous answers are rarely portable. Supporting documents become detached from their original context. When something changes, the process begins again.
This creates work without necessarily creating confidence.
The relevant question is not whether information came from the third party. It is what happened to that information afterwards. Was its source clear? Was it current? Was it corroborated? Did it conflict with other evidence? Did it demonstrate that corrective action had actually occurred?
These are questions of verification and judgement - not distance.
Participation does not mean uncontrolled trust
In a structured market study we conducted in 2024, 16 of 17 corporate compliance interviewees expressed at least conditional openness to a reusable evidence model involving third-party contribution.
The conditions are as important as the headline result. Thirteen of the 17 explicitly raised quality, independence, credibility, defensibility or appropriate risk boundaries. Three senior external compliance lawyers interviewed separately saw no inherent regulatory objection, provided the process was robust, risk-based and appropriately bounded.
Later discovery interviews reinforced that distinction. In all 15 subsequent interviews where third-party participation was clearly present, it was accompanied by independent screening, corroboration, audit, verification or retained organisational judgement.
The message was not “trust the third party.” It was that the identity of the contributor did not, by itself, determine whether the process was credible.
Third parties can provide documents, explain discrepancies, correct factual errors and demonstrate controls or remediation. What they should not control is whether that evidence is accepted, how much weight it receives or whether the resulting risk is acceptable.
The third party can have a voice in the evidentiary process without having authority over the conclusion.
The problem is also one of attention allocation
The current model does not only limit participation. It can also allocate scarce compliance attention inefficiently.
Initial risk tiers are generally based on inherent-risk indicators: jurisdiction, industry, relationship type, government exposure, transaction value and similar factors. These are useful signals, but they do not show the quality of the third party’s controls, the relevance of a historical issue, the credibility of its explanation or whether remediation has reduced the risk.
As a result, considerable human effort may be directed towards entities that appear inherently risky but have strong controls and credible mitigation. Meanwhile, weaknesses in apparently lower-risk entities may remain hidden because those third parties receive limited attention and have little opportunity - or incentive - to contribute meaningful evidence.
This is the Missing Middle in third-party due diligence: the space between automated retrieval and screening on one side, and expensive human investigation and assurance on the other.
The Confidence Layer is intended to occupy that space.
It combines proportionate third-party participation with independent verification, contextual interpretation and residual-risk reasoning. Its purpose is not to give every third party the equivalent of a high-risk investigation. It is to identify where confidence can be established efficiently - and where uncertainty or residual risk remains high enough to require scarce human attention.
That changes the basis of attention allocation.
Instead of focusing primarily on who appears risky at the outset, organisations can focus their people and resources on the relationships where the evidence remains incomplete, contradictory or insufficient - and where risk remains genuinely elevated after controls and mitigation have been considered.
Evidence can travel; judgement cannot
Regulatory and industry developments increasingly support more proportionate and reusable evidence models.
Recent changes to the EU’s sustainability due-diligence rules state that information requests to business partners should be necessary, targeted, reasonable and proportionate. They also recognise independent reports, digital solutions and industry initiatives as ways to avoid duplicative requests. This is sustainability due diligence rather than a universal compliance rule, but the direction is significant.
The OECD has similarly highlighted joint supplier questionnaires, recognised templates and interoperable mechanisms as ways to reduce duplication and enable verifiable information exchange.
Neither development removes the organisation’s responsibility for its decision. Evidence may be reusable, but its meaning depends on the nature of the relationship, the organisation’s exposure and its risk appetite.
Evidence can travel. Accountability - and confidence - remain organisation-specific.
Closing the gap
The existing model concentrated its richest engagement on the smallest and apparently highest-risk part of the third-party population. That was not irrational. It reflected the economics and limitations of the available architecture.
But the resulting distance should not be confused with compliance independence.
Independent assurance does not come from excluding the third party. It comes from testing what the third party contributes, corroborating what matters and retaining control of the final judgement.
Closing the Participation Gap means making proportionate participation possible across a much wider ecosystem, while using the Confidence Layer to distinguish apparent risk from the residual risk that remains after evidence, controls and remediation have been considered.
By allowing verified evidence to be contributed once and reused where appropriate, participation can shorten onboarding, reduce repetitive requests and release compliance teams from low-value collection and reconciliation. It should therefore be a foundational capability of future due diligence - even when risk-based judgement determines that it is not required in every case.
The next generation of due diligence should not be defined by how effectively it keeps third parties at a distance.
It should be defined by how effectively it turns evidence into confidence - and confidence into better attention.
Research note: This research formed two analytically separate phases of the wider 30-plus interview programme referenced in the Confidence Layer paper. The 2024 phase comprised 17 corporate interviews and three external-lawyer interviews; the 2025 phase comprised 16 exploratory interview records. Some organisations participated in both phases, and the findings are reported separately because the methods differed.