Compliance Programs & Controls
What Is Due Diligence?
A practical explanation of due diligence as a structured review process used before transactions, partnerships, hiring, investments, onboarding, or major decisions.
Quick answer
Due diligence is a structured review performed before entering a relationship, transaction, investment, or decision. It helps identify facts, risks, obligations, and unanswered questions.
Where the term appears
- vendor onboarding
- business acquisitions
- investment review
- customer risk review
- employment or partnership checks
How this fits into a control system
Governance and control terms are easiest to understand as parts of a larger compliance system. A policy sets expectations, a procedure explains the steps, a record shows what happened, and review or audit activity checks whether the process works in practice.
Organizational relevance
Organizations use this concept within governance, customer or vendor due diligence, policy management, evidence collection, monitoring or assurance. The key question is how the term connects to a named obligation, operating process, control owner and retained record.
What it does not establish by itself
- It is not a guarantee that no risk exists.
- It is not always a legal investigation.
- The right level of review depends on the context and risk.
Key records and decision points
- Purpose and risk of the decision
- Information requested and sources checked
- Red flags, unresolved gaps and approvals
- Refresh triggers and ongoing monitoring
Common confusion
Due diligence should be proportionate to the decision. Collecting a standard document pack without evaluating risk is not meaningful diligence.
Official-source check
For current rules, forms, deadlines, eligibility, or filing instructions, always check official sources. This article is an educational overview, not a substitute for official guidance.