OSINT Due Diligence Services

OSINT due diligence tells you whether a relationship is safe to enter before you sign the agency agreement, wire the investment or close the deal. We review the company and its people together, test their claims against the open record, and size the work to your risk.

  • Agents, distributors and suppliers
  • Investment targets, founders and fund managers
  • Standard and enhanced levels
  • Focused reviews from 10 business days
Short answer

OSINT due diligence is a risk-based review of a counterparty, and the people behind it, using registries, court and insolvency records, sanctions and regulatory lists, media archives and online sources. It answers one question: should anything in the public record stop, delay or change this relationship? OSINT-S scales it from a focused review in 10 business days to enhanced work of about a month.

What Due Diligence Decides

Due diligence is not research for its own sake. It ends in one of four outcomes: proceed, proceed with conditions, ask more questions, or walk away.

Every review is tied to a decision with a deadline: appoint a sales agent, take a minority stake, approve a contract manufacturer or buy a business. The findings are written for the person who makes that call.

So the report says what to do with each finding. An undisclosed stake in a competitor may justify a contract clause; a family tie to the official who awards your license justifies stopping until counsel has reviewed it. Findings that change nothing are labeled as such.

Due Diligence, Background Checks or a Company Investigation?

A background check looks at one person, a company investigation goes deep into ownership and control, and due diligence combines both into a verdict on a relationship.

Background checkCompany investigationDue diligence
SubjectOne individualOne company and its structureA relationship: the entity, its owners and key people
Core questionIs this person who they say they are?Who really owns and controls this company?Should we enter this relationship, and on what terms?
OutputVerified profileOwnership chart and findingsRed-flag assessment with recommended actions

To vet one executive, a background check is enough. If opaque ownership is the whole question, commission a company investigation. Both plus a recommendation is due diligence.

Types of OSINT Due Diligence We Run

Five kinds of review cover most requests: one method, different risks.

Third parties

Agents, distributors and intermediaries

Anyone who will act or sell on your behalf, the relationships anti-bribery enforcers watch most.

Investors

Investor due diligence

Founders, management, co-investors and fund managers: track record, prior ventures, disputes and whether the story in the deck matches the record.

Financial services →
M&A

Pre-acquisition integrity review

The target, its owners, managers and agents, and the exposure you would inherit at closing.

Supply chain

Supplier due diligence

Whether a manufacturer exists as described, who owns it, and its sanctions, fraud or reputational exposure.

Partners

Joint ventures and licensees

The partner's owners, political connections, financial stress and record with previous partners.

Geopolitical risk →

Third-Party Due Diligence Under the FCPA, Bribery Act and ECCTA

US and UK enforcers expect risk-based due diligence on the third parties who act for you, and in the UK an adequate or reasonable prevention program is a defense to corporate liability.

  • FCPA (United States). The DOJ and SEC Resource Guide, second edition of July 2020, states that the FCPA expressly prohibits corrupt payments made through third parties or intermediaries, and that a bribe paid by a third party does not eliminate potential liability (FCPA Resource Guide). Its third-party red flags include excessive commissions, vaguely described consulting services, a consultant in a different line of business, and a third party closely associated with the foreign official.
  • UK Bribery Act 2010, section 7. A commercial organization commits an offense if a person associated with it bribes to win or keep business for it. It is a defense to prove it "had in place adequate procedures" to prevent this (legislation.gov.uk). Principle 4 of the Ministry of Justice guidance is due diligence, applied on "a proportionate and risk based approach"; an intermediary helping to establish a business in a foreign market typically needs a much higher level (MoJ guidance).
  • Failure to prevent fraud (UK). Under the Economic Crime and Corporate Transparency Act 2023, the offense came into effect on 1 September 2025 (GOV.UK). It applies to large organizations meeting two of three criteria: more than 250 employees, more than £36 million turnover, more than £18 million in total assets. Due diligence is again one of six principles, and the guidance says organizations should conduct it on associated persons, including new partners (Home Office guidance).

None of these frameworks prescribes a database. They ask whether you looked, in proportion to the risk, and acted on what you found.

How OSINT Tests the Classic Red Flags

Most red flags named by regulators can be tested in open sources. The table shows what we look at for each one.

Red flagWhat we check in open sources
Third party linked to a public officialOfficers and shareholders against public appointments, asset declarations, family names, wedding and obituary notices, local media
Consultant outside its stated line of businessRegistered activity codes, website history, past contracts, staff profiles and trade records
Requested payment to an offshore or third-country accountWhere the payee entity is registered, who owns it and how it connects to the contracting party
Recommended by the official awarding the contractLinks between the introducer, the official and the company: shared addresses, directors, events and media
History of prior misconductCourt records, debarment and enforcement lists, sanctions, regulatory notices and investigative journalism

A red flag is a question, not a verdict: we test it for an innocent explanation and state our confidence.

Standard or Enhanced OSINT Due Diligence?

Standard due diligence suits most third parties; enhanced due diligence is for high-risk countries, public-official exposure, large deals and anything a first review could not clear.

Standard

Focused review, from 10 business days

Existence and registration, owners and directors as filed, sanctions and watchlists, litigation and insolvency, adverse media and online footprint in the main jurisdictions, with a red-flag summary.

Enhanced

Enhanced due diligence, up to about a month

The standard review plus beneficial ownership through each layer, checks on key people, political exposure, related parties, operations on the ground and a written risk opinion.

How an OSINT Due Diligence Review Runs

Five steps, from the decision you face to a reviewed report with recommended actions.

  1. Define the relationship and the riskYou name the counterparty, its role, the countries and your deadline. We propose a level and a fixed quote in writing.
  2. Fix identitiesWe confirm the legal entity, owners and key people, so later records attach to the right company and individuals.
  3. Collect and screenRegistries, court and insolvency files, sanctions, enforcement and debarment lists, media archives and online sources in each country.
  4. Test red flags and claimsRed flags are checked for innocent explanations; claims are compared with independent records.
  5. Report with recommendationsA senior analyst reviews conclusions and recommended actions before the report reaches you.

Report, Timeline and Terms

A risk-rated report that opens with the recommendation, then the evidence and its sources. Focused reviews from 10 business days; enhanced work up to about a month.

  • Recommendation first. Proceed, proceed with conditions, clarify or stop, with the reasons in a few lines.
  • Red-flag table. Each issue, its source, what we did to test it and our confidence in the conclusion.
  • Questions to ask. Points the counterparty should explain before signing.
  • Audit trail. Sources, dates and captures you can keep on file to show what was checked and when.

The fee is fixed after written scoping. Urgent delivery is available for a 50% surcharge, and if we miss the agreed date, the fee goes down. Work is confidential, under NDA if needed. After signing, OSINT monitoring picks up new litigation, sanctions or media.

Limits of Open-Source Due Diligence

OSINT shows what the public record says. It does not audit accounts, read private data or replace your legal judgment.

We use lawful sources only: no hacking, no pretext calls, no fake profiles to see private content, no purchased leaked data. Personal data about owners and directors is processed for the stated purpose and kept proportionate, in line with the GDPR and UK GDPR (GDPR).

Open sources will not tell you whether the accounts are sound or the IP is owned; that is work for auditors, lawyers and the data room. Where registries are thin, we report a gap, not a clean result. Due diligence is one part of our wider OSINT services for companies, investors and law firms; when a finding needs a full inquiry, the same analysts can take it into OSINT investigations.

OSINT Due Diligence: Specialized Services

Focused versions of due diligence for specific subjects, deals and situations.

Due diligence

Third-party due diligence

Agents, distributors, resellers and consultants: anti-bribery checks, risk tiers for large third-party lists and scheduled refreshes.

Read more →
Due diligence

Enhanced due diligence

EDD reports for high-risk countries, layered ownership and PEP links: owners traced to people, wealth corroborated and a written risk opinion.

Read more →
Due diligence

Investor due diligence

For VCs, PE funds, angels and LPs: founders' records, traction and customer claims, cap-table parties and fund managers checked in open sources.

Read more →
Due diligence

M&A due diligence

Reputational and integrity review of the target, sellers, management and agents, alongside legal and financial diligence and timed to the deal.

Read more →
Due diligence

Supplier due diligence

Vendor vetting before onboarding: fake suppliers, capacity and certificate claims, owners, sanctions and forced-labor exposure.

Read more →

Tell Us Who You Are About to Work With

Send the counterparty's name, the role it will play, the countries involved and your deadline. We reply with a recommended level, a delivery date and a fixed quote.

OSINT Due Diligence FAQ

We're appointing a sales agent in a country with high corruption risk and our board wants OSINT due diligence on him and his company first — what would you check, and can it be done before our board meeting in three weeks?

Yes, three weeks fits a focused review and often an enhanced one. We confirm who owns the company, check the agent and co-owners for links to public officials, test whether the business matches the work you are hiring it for, and screen sanctions, litigation, debarment and media. You get a recommendation and questions to put to the agent.

Our UK company now falls under the failure to prevent fraud offence and our auditors asked how we vet new partners — would a documented OSINT review of each new partner count as reasonable procedures?

It can be part of them. The Home Office guidance lists due diligence on associated persons, including new partners, as one of six principles, applied in proportion to risk. Whether your procedures as a whole are reasonable is a legal judgment that also covers risk assessment, training, contracts and monitoring, so your counsel should confirm it.

I'm about to invest in a seed round led by a founder I've met twice — what would investor due diligence tell me that the pitch deck and reference calls wouldn't?

Whether the founder's history matches the story. We check prior companies and how they ended, disputes with earlier investors or co-founders, insolvency, regulatory actions and media, and whether claimed customers and credentials appear in independent records. Reference calls come from people the founder chose; the public record does not.

Our procurement team runs every new supplier through an automated risk database, so when is it worth paying for enhanced OSINT due diligence on top of that?

When the supplier is critical, sits in a high-risk country, has an opaque owner, or the database returns a hit or nothing at all for a company you cannot otherwise verify. Databases match names; enhanced due diligence explains the records, traces owners behind holding companies and checks that the factory exists.

We're acquiring a mid-sized company with distributors in several countries — should the pre-acquisition integrity review cover just the target, or its distributors and agents too?

Cover the highest-risk distributors and agents as well. The people selling on the target's behalf are where bribery and fraud exposure usually sits, and you inherit those relationships at closing. A practical split: a standard review of the target and owners, then enhanced checks on third parties with public-sector customers or unusual commissions.

If your due diligence finds that a director of our proposed partner is the cousin of a government minister, does that automatically mean we should walk away from the deal?

No. A family link to an official is a red flag, not a verdict. The question is whether the link touches your business: does the minister's office award your licenses or contracts, and is the director's role real? We report the record and our confidence; you and your counsel decide on conditions, disclosures or an exit.

Can you run due diligence on a competitor's supplier by calling them and pretending to be a customer, so we can find out their prices and capacity?

No. We do not use pretext calls, false identities or any method that misrepresents who we are or why we ask. Due diligence uses registries, court records, sanctions lists, media and other lawful sources; lawful competitor research is the job of our competitive intelligence service.