Incident Response Plan for GDPR and NIS2 Compliance
Build an incident response plan France teams can use to meet GDPR, CNIL and NIS2 reporting duties, manage cyber incidents and recover securely.
Build a third-party due diligence programme for France covering vendor compliance, supplier audits, corruption, AML, privacy and duty of vigilance risks.
Third-party relationships can expose a business to misconduct it did not directly commit. A distributor may pay bribes to obtain contracts, a supplier may conceal unsafe labour practices, or a technology provider may process personal data without adequate security. When these risks are ignored, the contracting company can still face regulatory investigations, financial loss and reputational damage.
Third-party due diligence is the process of identifying, assessing, approving and monitoring the external organisations and individuals with whom a business has a relationship.
It is what helps a company understand who a third party is, who owns it and how it conducts business. It is why organisations must assess vendors, suppliers, agents and intermediaries before allowing them to represent the company, receive payments or access sensitive information. It is also why due diligence must continue after onboarding rather than ending when a contract is signed.
In this guide, you will learn how to build a complete third-party due diligence programme for a business operating in France, from initial risk classification and integrity screening to supplier audits, contractual controls, ongoing monitoring and duty of vigilance responsibilities.
Third-party due diligence is a structured investigation used to determine whether an external business partner presents an acceptable legal, financial, operational, ethical or reputational risk.
The process generally begins before onboarding. The organisation collects information about the proposed third party, verifies its identity and ownership, screens it against relevant databases and assesses the risks associated with the proposed relationship.
The depth of the investigation should reflect the level of risk. A local office supplier delivering low-value stationery should not necessarily receive the same review as a commercial agent representing the company before public authorities in a high-risk market.
A complete programme should consider more than bribery and sanctions. Depending on the relationship, the organisation may need to assess money laundering, fraud, cybersecurity, data privacy, human rights, workplace safety, environmental performance, financial stability and conflicts of interest.
The final objective is not to guarantee that a third party will never cause a problem. No investigation can eliminate every risk. The objective is to make a reasonable, evidence-based decision and apply controls proportionate to the risks identified.
Modern organisations depend on extensive networks of suppliers, consultants, distributors, subcontractors, technology providers and logistics partners. These relationships provide expertise and operational flexibility, but they also extend the organisation’s risk beyond its direct employees and physical premises.
A third party may interact with customers, handle company funds, submit applications to government authorities or process confidential information. Its conduct may therefore be attributed to the organisation by regulators, customers or the public, even where the relationship is legally independent.
Third-party risk can affect companies of every size. A small business may rely heavily on one outsourced IT provider or overseas manufacturer. A larger organisation may have thousands of vendors operating across different countries and industries. The formality of the programme will differ, but the need to understand critical relationships remains.
For French businesses, due diligence also supports compliance with several overlapping legal frameworks. These include anticorruption controls under the Sapin II framework, sector-specific AML/CFT obligations, the GDPR, sanctions rules and the French duty of vigilance regime.
Third-party due diligence should therefore be treated as a business control rather than a questionnaire owned by the compliance department. Procurement, finance, legal, information security, sustainability and operational teams all contribute information needed to make a reliable decision.

Third-party due diligence in France is influenced by several legal frameworks. The exact obligations depend on the organisation’s size, sector, activities and the type of third party involved.
Article 17 of the Sapin II law requires qualifying large companies to assess customers, first-tier suppliers and intermediaries according to their corruption risk mapping.
In practice, businesses should apply stronger checks to agents, consultants and other third parties that interact with public officials, receive commissions or operate in higher-risk markets. The review should examine ownership, reputation, qualifications, compensation and potential conflicts of interest.
The French duty of vigilance law requires qualifying companies to identify and address serious human rights, health, safety and environmental risks connected to their operations, subsidiaries and certain suppliers or subcontractors.
For businesses within scope, supplier due diligence should include risk mapping, targeted assessments, corrective actions and ongoing monitoring. A questionnaire alone is unlikely to demonstrate effective vigilance where serious risks have been identified.
Regulated organisations must identify customers and beneficial owners, understand the purpose of business relationships and apply enhanced checks where money laundering or terrorist financing risks are higher.
Even where a commercial company is not directly subject to the full AML/CFT framework, these principles remain useful when reviewing opaque ownership structures, unexplained intermediaries, unusual payments or offshore accounts.
When a vendor processes personal data, the organisation must assess whether the provider offers sufficient privacy and security safeguards.
The review should cover the data processed, hosting locations, subprocessors, international transfers, security measures, breach reporting and deletion. Appropriate contractual protections must be in place before personal data is shared.
The developing EU sustainability due diligence framework will increase expectations around identifying and addressing adverse human rights and environmental impacts in corporate value chains.
French businesses should monitor its implementation and align supplier assessments with their existing duty of vigilance, sustainability and procurement controls. This can reduce duplication and make future compliance changes easier to manage.
A third party is any external organisation or individual that provides goods or services, represents the company, processes information or otherwise participates in its business activities.
This can include suppliers, subcontractors, consultants, commercial agents, distributors, resellers, brokers, joint-venture partners, customs representatives, logistics providers, recruitment agencies, technology vendors and professional advisers.
Not every party requires the same investigation. The organisation should first identify the relationship’s potential exposure.
An agent who negotiates with public officials presents a different risk from a domestic facilities provider. A cloud provider storing employee health data presents a different risk from a supplier of office furniture. A manufacturer in a high-risk supply chain may require labour and environmental checks that are irrelevant to a local accountant.
The organisation should therefore define the categories of third parties within its programme and identify the risk areas associated with each category.
Senior management should approve the third-party due diligence framework and appoint a responsible programme owner.
The owner may sit within compliance, legal, risk management or procurement. What matters is that the person has enough authority to request information, pause onboarding and escalate unresolved risks.
Responsibilities should be divided clearly. Business sponsors should explain why the third party is needed. Procurement should collect commercial and ownership information. Compliance should review integrity risks. Information security should assess technology access, while sustainability teams may assess labour and environmental exposure.
The decision-maker should be independent enough to challenge the employee proposing the relationship. A business sponsor who expects to earn commission or meet a sales target should not be the only person approving the third party.
Management should receive information on high-risk relationships, overdue reviews, unresolved red flags and programme performance.
A business cannot apply reliable due diligence without knowing which third parties it uses.
The organisation should create a central inventory showing the legal name, category, country, business owner, services provided, contract value, payment details, data access and risk status of each active party.
Information may currently be divided between procurement systems, finance records, local spreadsheets and department-specific applications. Duplicates and inconsistent names can make screening and monitoring unreliable.
The inventory should identify inactive or duplicate vendors and parties receiving payments without a current contract. It should also distinguish approved suppliers from parties that exist in a payment system but have never completed due diligence.
A clean third-party inventory supports vendor compliance, sanctions screening, supplier audits, payment controls and periodic reassessment.
The organisation should assign an initial risk level before deciding how much due diligence to perform.
Risk factors may include the country of operation, industry, type of service, interaction with government officials, payment structure, ownership complexity, access to personal data and dependence on subcontractors.
The value of the contract matters, but it should not be the only factor. A low-value agent with authority to obtain permits can present a higher corruption risk than a large but transparent domestic supplier.
A practical tiering model may use three levels:
|
Risk tier |
Typical profile |
Appropriate review |
|
Low |
Transparent domestic provider offering routine goods or services |
Basic identity verification and standard screening |
|
Medium |
Material supplier, data processor or overseas service provider |
Ownership review, compliance questionnaire and specialist checks |
|
High |
Agent, intermediary, high-risk country supplier or party with public-sector interaction |
Enhanced due diligence, senior approval and closer monitoring |
The methodology should be documented and applied consistently. Employees should not lower the risk rating simply to speed up onboarding.
Organisations developing their risk-scoring method may benefit from the French Compliance Institute’s Risk Management & Assessment course, particularly when connecting third-party ratings to wider enterprise risk governance.
The organisation should collect enough information to identify the party and understand the proposed relationship.
For a company, this normally includes the legal name, trading names, registration number, address, country of incorporation, directors and beneficial owners. The file should also explain the services to be provided, expected payment method, operating countries and use of subcontractors.
Additional information should reflect the risk. A distributor may need to disclose customers and territories. A commercial agent may need to explain government interactions and commission arrangements. A technology provider may need to identify hosting locations and subprocessors.
Questionnaires should be proportionate and written clearly. Sending a lengthy generic form to every supplier can create unnecessary work without producing meaningful information.
Documents should also be current. A registration certificate issued many years ago may not show the third party’s present ownership or directors.
The organisation should verify that the proposed third party legally exists and that the information provided matches reliable records.
This may involve reviewing company registry information, constitutional documents, annual reports, licences, tax information and official identification.
Beneficial ownership checks should identify the individuals who ultimately own or control the company. Complex chains, nominee shareholders, trusts and recently created holding companies may require enhanced review.
The purpose is not merely to collect a list of shareholders. The company needs to understand who benefits from the relationship and whether ownership creates sanctions, corruption, conflict-of-interest or money laundering risk.
Unexplained differences between the questionnaire and official records should be resolved before approval. The third party should also explain recent ownership changes where they appear connected to a regulatory, financial or reputational concern.
Screening should reflect the risks associated with the proposed relationship.
Common checks include sanctions designations, politically exposed persons, corruption allegations, fraud, enforcement actions, serious litigation, insolvency and adverse media.
A screening alert is not automatically evidence of misconduct. Common names, incomplete identifiers and old information can produce false positives. A qualified reviewer should compare dates, addresses, nationalities, registration numbers and other available details.
Politically exposed person status does not automatically prohibit a relationship. It indicates that the organisation may need deeper analysis of influence, source of wealth, conflicts and public-sector interactions.
Adverse-media research should distinguish credible reporting from rumours, duplicated stories and unsupported allegations. The reviewer should consider the seriousness, reliability, age and relevance of the information.
The investigation and conclusion should be documented. A simple note stating “screening passed” does not explain which databases were checked or how an alert was resolved.
Third parties that represent the organisation, obtain approvals or interact with public officials require particular attention.
The company should understand why the third party was selected, what qualifications it brings and whether its compensation is commercially reasonable.
Large success fees, cash payments, offshore accounts and vague consulting services can create significant risk. Payments should correspond to identifiable work and contractual deliverables.
The assessment should also identify personal relationships between the third party and company employees, customers or public officials. Employees involved in the selection process should disclose relevant financial or family interests.
Where a conflict exists, the organisation should determine whether it can be managed through independent approval, changed responsibilities or additional oversight. Some conflicts may make the relationship unsuitable.
Third-party due diligence should establish whether the proposed relationship makes commercial sense.
The organisation should review financial stability, operating history, staffing, facilities and experience. A company claiming to deliver specialised technical services should have employees or subcontractors capable of performing the work.
Bank information should be held in the third party’s legal name wherever possible. Payments to personal accounts, unrelated businesses or unexplained foreign jurisdictions require additional review.
Commission and pricing arrangements should be compared with market expectations. Unusually high fees may conceal improper payments or indicate that the contracting party does not understand the service being purchased.
Financial weakness does not always prevent approval. However, a critical supplier facing serious insolvency risk may threaten business continuity and require contingency planning.
Technology providers and outsourced service providers may have direct access to personal data, confidential information or company systems.
The due diligence process should identify the data involved, user access, hosting location, encryption, incident response, backup arrangements and subcontractors.
The organisation should determine whether the provider has experienced significant security incidents and how vulnerabilities are managed. Certifications and audit reports may support the review, but they should not replace an assessment of the particular service being purchased.
The contract should define permitted processing, security responsibilities, breach notification, deletion, audit rights and assistance with regulatory obligations.
Critical providers should be monitored after approval. A provider can change its hosting model, ownership or subprocessors during the contract, altering the original risk assessment.
Supplier due diligence should consider the potential impact of the goods and services being purchased.
Relevant risks may include forced labour, child labour, excessive working hours, unsafe workplaces, discrimination, pollution, illegal resource extraction and harm to local communities.
The assessment should focus on the parts of the supply chain where severe impacts are most likely. A uniform questionnaire sent to every supplier is less effective than targeted questions based on country, industry and product risk.
Evidence may include certifications, workforce information, environmental permits, accident records, sourcing policies and previous audit reports.
Where risks are identified, the organisation should distinguish between a problem that can be remediated and one requiring immediate rejection or suspension.
Duty of vigilance should not be treated as a paperwork exercise. The objective is to prevent or reduce serious impacts through practical actions, follow-up and meaningful engagement with affected parties.
Enhanced due diligence is appropriate when the initial review identifies elevated risk or unresolved inconsistencies.
It may include obtaining additional ownership documents, conducting interviews, commissioning specialist research or visiting business premises.
A high-risk supplier audit may examine employment records, safety conditions, environmental controls and subcontracting. For an agent or intermediary, the review may focus on qualifications, government connections, payment arrangements and previous clients.
Enhanced due diligence should have a defined objective. Requesting more documents without knowing what concern they are intended to resolve can delay onboarding without improving the decision.
The organisation should record the risk, the additional work performed and whether the concern was resolved.
The outcome should normally be approval, conditional approval, rejection or escalation.
Low-risk parties may be approved by procurement or the business owner under a standard process. Higher-risk parties should require review by compliance, legal or a senior committee.
Conditional approval may involve a reduced scope, additional contractual requirements, payment controls, training, remediation or more frequent monitoring.
The decision record should explain the evidence reviewed, identified risks, required conditions, responsible owner and next review date.
Approval should have an expiry or reassessment trigger. A third party should not remain permanently approved when ownership, activities and risk conditions may change.
Contracts should reflect the risks identified during due diligence.
Relevant provisions may address compliance with laws, anticorruption, sanctions, data protection, subcontracting, audit rights, recordkeeping and notification of ownership changes.
The agreement should allow the company to suspend payments or performance while investigating a serious concern. It should also provide termination rights where misconduct is confirmed or the third party refuses to provide required information.
For suppliers with correctable weaknesses, the organisation may agree on a remediation plan. This could include implementing safety controls, changing a subcontractor, improving data security or delivering compliance training.
The plan should contain specific actions and deadlines. A general promise to “improve compliance” is difficult to monitor or enforce.
No third party should be activated in procurement or payment systems until the required approval has been obtained.
The organisation should separate the responsibilities for requesting, approving and creating vendors. This reduces the risk of fictitious suppliers, duplicate records and unauthorised payments.
Changes to bank details should require independent verification through a trusted contact method. Fraudsters frequently impersonate suppliers and request urgent payment changes.
Invoices should match the contract, services and approved payment account. Unexplained descriptions, round-number invoices and repeated payments just below approval limits should receive closer review.
Where a relationship is conditionally approved, the system should record the restrictions so that employees do not exceed the agreed scope.
Third-party due diligence should continue throughout the business relationship. Ownership, directors, services, payment arrangements and regulatory exposure can change after onboarding, so higher-risk third parties should be rescreened and reassessed more frequently than routine vendors. Events such as a sanctions designation, data breach, regulatory investigation, ownership change or serious workplace incident should trigger an immediate review.
Risk-based supplier audits can provide deeper assurance where questionnaires and documents are insufficient. Depending on the identified risk, an audit may examine working conditions, environmental controls, cybersecurity, product quality or subcontractor management. Findings should be classified by severity, assigned to responsible owners and followed through to completion. Serious or unresolved concerns may require suspension or termination of the relationship.
The organisation should also retain enough evidence to reconstruct every significant due diligence decision. Records may include questionnaires, ownership documents, screening results, risk ratings, approvals, contracts, audit findings and remediation plans. Employees involved in selecting, approving, paying or managing third parties should receive training relevant to their responsibilities.
Finally, the programme should be tested through periodic compliance reviews, internal audits and sample checks. These reviews should assess whether risk ratings are consistent, required controls were completed and conditional approvals are being monitored. Findings should lead to documented improvements rather than remaining as unresolved observations.

Warning signs should be assessed in context rather than treated as automatic proof of misconduct.
A third party may present elevated risk where ownership is hidden, the legal entity was recently formed, or its capabilities do not match the proposed work. Unusual commissions, cash requests and payments to unrelated countries also require explanation.
Other red flags include government connections that were not disclosed, refusal to accept audit rights, repeated use of subcontractors and inconsistent company records.
In supply chains, concerns may include unexplained labour brokers, missing safety records, excessive working hours or environmental permits that cannot be verified.
For technology providers, warning signs may include unclear hosting locations, refusal to identify subprocessors and weak incident-notification commitments.
The presence of a red flag should cause the relationship to be paused or escalated until the organisation understands the issue.
A French manufacturer plans to appoint an agent to secure public-sector contracts in another country. The agent requests a high success fee and asks to be paid through a company registered in a different jurisdiction.
Before approval, the manufacturer should verify the agent’s ownership, qualifications, government connections and payment arrangements. The contract should define the services clearly, require supporting evidence for invoices and allow the relationship to be suspended if compliance concerns arise.
A cloud provider will store employee and customer information outside France and use several subprocessors.
The organisation should review the provider’s GDPR role, hosting locations, international transfer arrangements, security controls, breach notification process and data deletion procedures. A general cybersecurity certification may support the assessment, but it does not replace a review of the specific service and data involved.
A supplier operates in a region associated with labour, health and safety, or environmental concerns.
The business should assess recruitment practices, working conditions, subcontractors, sourcing methods and environmental controls. Depending on the risk, approval may require an on-site supplier audit, corrective action plan and closer ongoing monitoring.

Appoint the programme owner, map active third parties and identify critical relationships. Review current onboarding systems and determine where vendor information is incomplete or duplicated.
Create an initial risk methodology and identify urgent high-risk parties that require immediate review.
Develop questionnaires, screening procedures, approval levels and enhanced due diligence standards.
Align procurement, finance, legal, privacy and compliance responsibilities. Update contracts and introduce controls preventing unapproved vendors from receiving payments.
Train employees and review a sample of existing suppliers, distributors and service providers.
Test whether the organisation can detect a sanctions alert, ownership change, suspicious payment or serious supplier incident.
Report weaknesses to management, assign corrective actions and establish the ongoing reassessment schedule.
A business should be able to answer yes to the following questions:
Has management approved the programme and appointed a responsible owner?
Is there a complete inventory of suppliers, vendors, agents and other third parties?
Does the organisation apply a documented risk-tiering method?
Is identity, ownership and commercial-purpose information collected before approval?
Are legal existence and beneficial ownership verified?
Are sanctions, PEP, enforcement and adverse-media checks completed where relevant?
Are corruption risks, conflicts of interest and government interactions assessed?
Are financial stability and payment arrangements reviewed?
Are data privacy and cybersecurity controls assessed for technology providers?
Are human rights, safety and environmental risks considered in relevant supply chains?
Is enhanced due diligence applied to higher-risk relationships?
Are decisions documented and approved at the correct level?
Do contracts contain controls proportionate to identified risks?
Are vendor creation and bank-detail changes independently verified?
Are high-risk third parties monitored and rescreened?
Are supplier audits followed by documented corrective actions?
Are records retained and protected appropriately?
Are employees trained according to their roles?
Is the programme tested through compliance reviews or internal audits?
Can the organisation suspend or terminate a relationship when risk cannot be resolved?
A generic process can overwhelm low-risk suppliers while failing to ask the specialised questions needed for high-risk agents or technology providers.
Sanctions and adverse-media screening cannot establish whether compensation is reasonable, data is secure or working conditions are safe.
Once a contract has been signed or services have begun, the business may find it difficult to reject the relationship or impose necessary conditions.
A questionnaire completed by the third party is useful, but important facts such as legal identity, ownership and licences should be checked independently.
A programme focused only on new onboarding can leave long-standing high-risk relationships unassessed.
A large due diligence file has little value when no one evaluates the information, resolves inconsistencies or documents the approval rationale.
Conditional approval should lead to specific corrective actions. Without owners and deadlines, temporary exceptions can become permanent weaknesses.
Third-party due diligence is a complete business process covering risk classification, information collection, screening, verification, approval, contracting and monitoring.
French companies should connect the programme to the Sapin II framework, duty of vigilance, AML/CFT requirements, GDPR and relevant sector rules.
Due diligence must be proportionate. Higher-risk parties require deeper investigation, stronger approval and closer monitoring than routine low-risk vendors.
Vendor compliance depends on cooperation across procurement, compliance, legal, finance, privacy, cybersecurity and operational teams.
Supplier audits can provide important evidence, but they should be targeted, documented and followed by corrective action.
The programme should continue throughout the relationship because ownership, conduct, services and regulatory conditions can change.
Third-party relationships are essential to modern business, but they can also transfer legal, ethical and operational risk into the organisation.
A complete third-party due diligence programme allows a French business to understand who it is dealing with, identify the main risks and make a defensible decision before committing money, information or reputation.
The process should begin with a clear risk methodology and reliable third-party inventory. It should continue through identity verification, beneficial ownership checks, integrity screening, supplier assessment and specialist reviews.
Approval should be documented, contracts should reflect identified risks and payments should be controlled. High-risk relationships should remain subject to monitoring, rescreening and supplier audits.
The strongest programmes do not attempt to eliminate every possible risk. They apply proportionate controls, investigate warning signs and respond when a third party fails to meet the organisation’s standards.