Skip to main content
Third Party Due Diligence | Arc

Trusted by leading organisations across 50+ countries

TATA SteelHilton HotelsAmulMJunctionitcCybageTTECPolarisIndiaFirst LifePlansee GroupGUSECKunvarjiTATA SteelHilton HotelsAmulMJunctionitcCybageTTECPolarisIndiaFirst LifePlansee GroupGUSECKunvarji

Due Diligence Solutions to Accelerate Your Business Growth

Identify hidden legal, financial, compliance, operational, and reputational risks before they impact your business decisions. Experience seamless scalability and unmatched efficiency tailored to your needs.

Vendor & Supplier

Assess the legal standing, financial stability, compliance posture, operational capability, and reputation of vendors and suppliers before onboarding to reduce business, financial, and supply chain risks.

ManufacturingRetailFMCG

Legal Risk

Assess legal, regulatory, and litigation risks through court records, tribunal filings, and defaulter database reviews.

Operational & Reputational Risk

Evaluate operational capabilities, business credibility, and reputational standing through site assessments and intelligence.

Financial Risk

Evaluate financial health, creditworthiness, and business stability through credit reports and financial analysis.

KYC & Company Vitals

Verify authenticity of company documents and gain insights into the legal structure, ownership, and corporate standing.

Compliance Risk

Evaluate regulatory compliance across statutory obligations, including tax, corporate filings, and labor laws.

Business License

Assess the validity, status, and compliance of business licenses, permits, and regulatory approvals.

Don't Let an Unverified Third Party Become Tomorrow's Crisis.

A vendor with hidden litigation, financial distress, sanctions exposure, or compliance violations can disrupt operations, trigger regulatory scrutiny, and expose your business to significant losses.

Verify Vendors Now
73%
of Fortune 500 fraud cases involve an external party
₹4.45Cr
average cost of a third‑party data breach in India
1 in 3
companies have onboarded a vendor later found fraudulent
68%
of third party risk incidents go undetected for over 6 months

Why Choose Us?

Portal Access + API Integration

Track every case in real time via your dedicated portal or plug directly into your HRMS/ATS via API.

Your Relationship Manager Handles It All.

A dedicated relationship manager oversees your account end-to-end, backed by two additional RMs to ensure uninterrupted support at every stage.

Tailored Packages & Processes

Packages and verification workflows built around your hiring volume, industry, and candidate types.

Intuitive Reports For Clear Insights

Our verification reports are structured for clarity, colour-coded risk flags, clear indicators, and audit-ready documentation that's easy to act on.

100% Data Security. Zero Incidents Reported

Data encryption, RBAC, MFA and GDPR, CCPA, DPDP compliant with zero incidents reported till date.

0
Comprehensive
Checks
0
Client Retention
Rate
0
Small to Enterprise
Clients Served
0
Countries
Served

See the Complete Third-Party Risk Picture.

Uncover what your third parties aren't telling you through verified findings, critical red flags, and actionable insights all consolidated into one structured report.

Colour-Coded Risk Indicators

Instant visual priority mapping.

Very high risk
3 Critical
High risk
11 Found
Medium risk
24 Flagged
Low risk
48 Notes
No risk
152 Passed

Evidence-Backed Insights

Each observation is backed with source references, supporting documents, database findings, or verification proofs for stronger decision confidence.

Litigation_Record.pdf
Verified Source Document
Attached
Global_Sanctions_DB
Database Match ID: 8942
Verified

Analyst Observation

Expert human intelligence decoding complex risks and providing actionable, context-driven recommendations beyond raw data.

ER
Lead Risk Analyst
Executive Summary • Confirmed Match
"While the entity cleared basic compliance checks, cross-referencing with local litigation databases revealed an active intellectual property dispute. The delayed tax filings noted in Q3 suggest underlying financial strain. We recommend holding the contract until the Q4 financials are verified."
Action RequiredIP Litigation
Confidential Dossier

See The Insights We Deliver

Access a sample assessment showcasing how verified records, compliance checks, corporate filings, and risk indicators are consolidated into a single, decision-ready report.

Unlock Sample Report Instant PDF Download
tpdd_sample_dossier.pdf1 / 15
CI2445XX9 | Company Due Diligence Report
AXXXR PXXXC AND HXXXXS
arc
Final Report
CASE INFO
Case-ID CI2445XX9 AnCoKALE1XXX
Company Name AXXXR PXXXC AND HXXXXS Date of Incorp.21 Jan, 2014
Client Name GXXXXT SXXXXP LIMITED Package TypeCustom
Report Date 18 Mar, 2024 Ref. No.NA
REPORT STATUS
RED
RISK ASSESSMENT SUMMARY
AXXXR PXXXC AND HXXXXS
PARAMETERS RISK INDICATOR ANNEXURE
KYCGREEN Annexure I
PAN Verification No Risk Annexure II
GST Verification No Risk Annexure III

Intuitive Report Structure

Every section is intelligently interconnected with clickable references, simplified redirections, and structured navigation paths.

report.pdfp. 4 / 15
→ See Litigation Records

Every Risk Parameter, Every Red Flag,
Every Layer Verified.

We run a 360° due diligence into every third party before they enter your ecosystem.
No red flag missed. No risk undocumented. No decision without proof.

Verification Modules

Smart Diligence

Not Sure Which Due Diligence Checks Your Business Actually Needs ?

Our specialists help you identify risks, select the right verification checks, and build a customized due diligence framework tailored to your business, industry, and risk exposure.

See what you're not seeing
RISK ASSESSMENT PREVIEW
High-Risk Vendor GapsUnverified supplier relationships
CRITICAL
Compliance ExposureRegulatory alignment check needed
HIGH
Tailored FrameworkCustom risk-based program built
READY

Case Studies / Real Scenarios.

Third-party failures don't announce themselves in advance. These are real scenarios where TPDD transformed hidden risks into documented proof.

BFSI

The “COMPLIANT” VENDOR WITH REGULATORY EXPOSURE

Problem

A leading BFSI firm shortlisted a fintech operations partner. Standard due diligence found no red flags. They were 72 hours from signing.

Risk Found

TPDD surfaced undisclosed risks across 3 critical checks:

  • Regulatory Status Check: Active regulatory scrutiny by financial authority — undisclosed
  • Adverse Compliance Check: Prior compliance violations and penalty records found
  • Directorial Association Check: Key directors linked to entities penalised by regulators
Outcome

The vendor was removed from the shortlist. The firm avoided audit escalations, regulatory liability, and reputational damage.

  • Audit escalation avoided
  • Regulatory liability prevented
  • Reputational damage contained
NBFC / Finance

The Fraud-Linked Processing Partner

Problem

An NBFC onboarded a processing agency based on stellar sector reputation. Standard checks did not reveal any underlying issues.

Risk Found

TPDD surfaced hidden risks from regional data sources:

  • Fraud Litigation: Hidden fraud litigation records discovered against the agency
  • Adverse Media: Negative coverage found in regional publications missed by standard checks
  • Reputation Discrepancy: Stated public reputation did not match the hidden legal realities
Outcome

Prevented regulatory scrutiny and potential legal/audit costs exceeding ₹50 Lakhs.

  • Regulatory scrutiny prevented
  • ₹50 Lakhs+ in potential costs avoided
  • Fraud exposure mitigated
IT Services

Real-Time Watchlist Exposure

Problem

IT firm engaged a dev vendor who was clean during onboarding but was added to an OFAC watchlist mid-project.

Risk Found

Real-time continuous monitoring triggered alerts:

  • Continuous Monitoring: System flagged a critical change in vendor status within 48 hours
  • Watchlist Match: Vendor added to official OFAC sanctions list
  • Mid-Project Exposure: Risk emerged dynamically during an active engagement
Outcome

Immediate termination saved the firm from an OFAC violation and account loss.

  • Immediate contract termination
  • OFAC violation avoided
  • Client accounts safeguarded
BPO / KPO

The Outsourcing Partner With Hidden Data Risks

Problem

A KPO company planned to onboard a third-party support vendor offering aggressive pricing and fast deployment.

Risk Found

TPDD identified multiple undisclosed operational risks:

  • Undisclosed Subcontracting: Vendor planned to use unapproved fourth-parties for processing
  • Weak Compliance: Substandard internal controls and data security policies
  • Confidentiality Disputes: History of prior data mishandling incidents found
Outcome

Prevented operational and reputational exposure tied to potential client data compromise.

  • Data compromise prevented
  • Operational risk mitigated
  • Reputational exposure avoided

Streamlined TPDD Process.

End-to-End Due Diligence — Initiated, Tracked, and Delivered in One Place

1
Initiation

New Case Request

Client creates a new case requests which trigger email to contact person with consent form link

2
Collection

Consent & Document Submission

Contact person fills consent form, attaches documents, and submits digitally.

3
Processing

Verification & Analysis

Data is validated, insufficiencies raised, and every risk parameters are tracked against defined SLAs with escalation-driven controls.

✦ Final Delivery

Intuitive Final Report Delivered

A clean, hyperlinked, audit-ready report delivered on email.

Do you still follow manual processes?
It's time to upgrade. Go Digital!

  • Zero manual work. 100% digital
  • Submit, track, receive — all in one portal

What Risk & Procurement Leaders Say

The decisions that matter most can't afford a gap in due diligence. Here's how we supported them.

"
★★★★★

"We were days away from signing a multi-year supplier agreement when Arc uncovered undisclosed litigation involving one of the promoter entities. The finding wasn't visible through standard onboarding checks. That single insight saved us from a potentially costly supplier relationship."

RM

R. Mehta

FMCG Conglomerate

"
★★★★★

"Our legal committee mandates TPDD before every strategic partnership agreement above a threshold. Arc provided us with comprehensive checks & found inconsistent information in promoter background litigation history, sanctions check, and a reputational risk narrative in a single structured report."

AS

A. Shukla

IT/ITES Enterprise

"
★★★★★

"Before finalising a minority stake acquisition, we approached Arc for a pre-deal background check on the investee's promoters. The PEP flag surfaced in the report and it completely changed our deal structuring approach. That level of intelligence is exactly what a serious investor needs."

NP

N. Patel

Private Equity Fund

Are Your Current Vendors Actually
Who They Say They Are?

Most procurement teams onboard vendors on trust and a GST certificate.
That's the gap that fraud exploits.

Your Next Vendor
Could Be Your Biggest Liability.

As third party ecosystems expand globally, the risks associated with them are escalating. Issues like undisclosed ownership structures, sanctions exposure, fraudulent entities, and regulatory non-compliance are becoming increasingly difficult to detect without in-depth due diligence processes.

Sanctions & Watchlist Exposure

Your vendor was clean at onboarding. That was six months ago. OFAC, UN, and EU watchlists update without warning. A flagged director. A blacklisted subsidiary. One hit and your bank freezes accounts before you finish reading the notice.


Penalties exceed ₹1Cr per undisclosed sanctions violation

Shell Company & Ownership Opacity

Behind every fraudulent supplier is a layered ownership structure designed to stay invisible. Shell entities divert payments, launder funds, and extract value while your procurement team approves the invoice. Without a UBO check, you don't know who you're actually paying.

68% of procurement fraud involves shell entity structures

M&A & Investment Due Diligence Gaps

Deals close on financials. Disasters emerge from the background. Undisclosed litigation, PEP-linked promoters, and buried reputational risk routinely surface after signing — when renegotiation is off the table and the liability is already yours.


40% of M&A failures trace back to overlooked third-party risk

Trusted Across Industries.

Every industry has different hiring risks. We tailor your process to what actually matters in your sector.

IT / ITES BFSI Manufacturing Investment & PE/VC Pharmaceuticals
Real Estate Insurance FinTech Venture Capital & Private Equity Startup Incubators & Accelerators
Technology & SaaS Steel & Metals Automotive & Auto Components Engineering & Industrial Services Logistics & Supply Chain

Choose the Right
Due Diligence Package.

What you don’t verify today can become tomorrow’s liability.
Each package is built to eliminate specific blind spots across different risk categories.

Foundation
Essential
For routine vendor and supplier onboarding — establishing baseline identity, legal standing, and compliance health before engagement.
  • KYC
  • Company Vitals - Basic
  • Compliance Risk
  • Legal Risk
  • Financial Risk - Basic

Board-Ready
Premium
For investment decisions, M&A transactions, and board-level counterparty relationships where full-spectrum intelligence is non-negotiable.
  • Everything in Global
  • Social Media Risk
  • Operational Risk
  • Reputational Risk
  • Company Vitals - Advanced
  • Financial Risk - Advanced
Tailored Solutions

Need a Custom Package For Your Industry?

Let our team analyze your requirement and suggest the exact combination of checks you need to hire with total confidence.

Queries?
We've Got You Covered.

Answers to what procurement, legal, and risk teams ask us most.

Risk & Monitoring
Scope & Coverage
Legal & Compliance
Process & TAT

What exactly does a TPDD report cover?

+
A TPDD report is a structured intelligence document covering the entity's legal standing, ownership structure (including UBO), financial health, sanctions and PEP status, litigation history, regulatory enforcement history, adverse media, and reputational risk — all with hyperlinked evidence. Scope varies by package and mandate.

Can you conduct TPDD on overseas entities?

+
Yes. Arc operates across 50+ countries via a global partner network and proprietary database infrastructure. We can verify legal registration, sanctions status, court records, and media coverage for entities in the US, UK, UAE, Singapore, and across Southeast Asia, Europe, and Africa.

Do you check individual directors as well as the entity?

+
Yes — and this is often where the most critical risk signals emerge. Our director and KMP profiling covers sanctions screening, criminal records, court cases, PEP status, adverse media, and disqualification orders on all key individuals, not just the entity as a corporate shell.

What is UBO verification and why does it matter?

+
UBO (Ultimate Beneficial Owner) verification maps the actual ownership chain of an entity to identify who truly controls it. This is critical for PMLA compliance, AML/KYB obligations, and detecting shell structures used to obscure fraudulent ownership or sanctions-linked individuals behind legitimate-looking companies.

Is a one-time TPDD check sufficient?

+
No. Third parties change — ownership transfers, financial conditions shift, key people leave, and new liabilities emerge. A one-time check only tells you what was true on that date.

How frequently should we re-verify an existing third party?

+
At minimum, annually for high-risk third parties. For lower-risk relationships, every 18 to 24 months is a reasonable baseline.

Do you offer ongoing monitoring beyond the initial check?

+
Yes. We offer periodic re-verification and monitoring arrangements for organisations that need continuous visibility over their third-party portfolio.

What triggers should prompt an immediate re-verification?

+
Change in ownership, leadership change, merger or acquisition, news of litigation, regulatory action, unusual financial behaviour, or any event that materially changes the third party's risk profile.

How do you help us prioritise which third parties carry the highest risk?

+
Through a risk-tiering framework based on factors like contract value, access to sensitive data, geographic exposure, and industry risk. We help you decide where to focus first.

Is TPDD legally mandated for Indian companies?

+
Yes, in various forms. RBI-regulated entities, NBFCs, and banks must conduct KYB and sanctions screening under PMLA. Listed companies under SEBI must demonstrate third-party risk management frameworks. In practice, procurement teams, legal departments, and audit committees increasingly mandate it for governance risk management regardless of regulatory requirement.

Can TPDD reports be used in legal proceedings?

+
Our reports are structured with hyperlinked, verifiable evidence specifically to support legal review, audit requirements, and regulatory submissions. While they are not legal opinions, they serve as structured intelligence documents that legal teams and compliance committees routinely rely on in proceedings and regulatory disclosures.

How do you handle data confidentiality for sensitive mandates?

+
All TPDD mandates are handled under strict confidentiality protocols with NDA-backed engagement terms, encrypted data handling, role-based access controls, and audit trails. For M&A and investment mandates, we operate under full information barrier protocols to protect deal confidentiality.

Do you screen against Indian regulatory databases?

+
Yes. We cover SEBI enforcement orders, RBI debarment lists, MCA director disqualification records, ROC filings, SFIO investigations, NCLT proceedings, ED and CBI publicly available records, and national court databases — in addition to global watchlists and sanctions lists.

How long does a standard TPDD report take?

+
Standard TPDD reports are delivered in 5–10 working days. Enhanced and Strategic packages typically take 10–15 working days depending on jurisdiction and scope complexity. Expedited processing is available for time-critical mandates — speak with your RM to confirm the track.

What happens if a red flag is found mid-process?

+
We flag critical findings immediately via your portal and RM — we don't wait for the final report. If a sanctions hit or material litigation is identified early in the process, your team is alerted within 24 hours so you can make time-sensitive decisions without waiting for report completion.

Can we run TPDD on multiple entities simultaneously?

+
Yes. Our platform is built for concurrent processing. Whether you're onboarding a new vendor panel or conducting pre-merger diligence on multiple investee entities, we handle parallel mandates with dedicated analyst teams and no compromise on TAT or quality.

How do we initiate a TPDD mandate with Arc?

+
Fill in the consultation form below and a TPDD specialist will reach out within 24 hours to discuss your mandate, scope requirements, and timeline. Existing clients can raise mandates directly through their dedicated portal. For urgent mandates, your RM can be reached directly.

Start Your Third Party
Due Diligence Today.

Tell us about the entity you need to verify — vendor, partner, investment, or counterparty. We'll scope the right due diligence framework within 24 hours.

Please enter your full name.
Please enter a valid phone number.
Please enter a valid business email. Personal emails are not accepted.
Privacy First. No Spam. Guaranteed Response Within 24 Hours.

Request Received — We'll Be in Touch.

Your TPDD specialist will reach out within 24 hours to discuss your mandate and scope requirements.

What You Walk Away With
Everything included in your free 30-minute TPDD consultation
Critical Risk DiagnosisA clear, contextual understanding of your third-party risks so every oversight decision is grounded in the specific impact each partner has on your business.
Strategic Transition RoadmapYou’ll have a structured plan, clear timelines for vendor onboarding, and a seamless path to integrating continuous monitoring into your existing workflows.
End-to-End Process ClarityFrom initiation to report delivery you'll know exactly how every check works, what to expect, and how to act on findings.
Cross-Border ComplianceFor partners operating outside of India, we provide a clear roadmap for aligning international data transfers and multi-jurisdictional laws with local mandates ensuring global operations remain seamless.
100% Confidential. Every consultation is covered by enterprise-grade NDA standards from the moment of first contact.

Ready to Get Started?

1000+ Companies Trust Us to Protect Their Workforce. Ready to Join Them?

CCPA GDPR DPDP NASSCOM