Regulatory Compliance· 13 min read

Third-party due diligence: how to vet suppliers and partners under the Anti-Corruption Law

Law 12,846/2013 (the “Lei Anticorrupção,” Brazil’s Anti-Corruption Law) holds companies strictly liable for corrupt acts committed by third parties on their behalf — even if the company had no knowledge and gave no instructions. The third-party due diligence process is what turns that liability into a manageable risk.


1. The partner who compromised the company

A civil infrastructure company took part in a public bidding process for works commissioned by a municipal government in the interior of the country. To expand its regional presence, it hired a local commercial representative — an individual operating under a consulting-firm CNPJ (the Brazilian company/taxpayer registry number) — with authority to negotiate contracts and liaise with municipal public officials.

The representative offered an improper advantage to a member of the bidding committee. The conduct came to light during an investigation that originated with another company involved in the same process. The infrastructure company did not know. It had not authorized the conduct. There was no record that any instruction to that effect had ever been given.

Even so, it was held administratively liable under art. 2 of Law 12,846/2013, which establishes strict liability for the legal entity for acts committed by its representatives, officers, directors, or third parties acting on its behalf or in its interest. The result was an administrative fine and a period of debarment from contracting with government entities, for the term set out in the sanction.

The absence of a structured vetting process for the representative before engagement — and the absence of an anti-corruption clause in the contract with them — were factors that worsened the company’s position before the sanctioning authority.


2. Strict liability under the Anti-Corruption Law — and what it says about third parties

Law 12,846/2013 introduced a model of corporate liability for acts against the public administration that did not previously exist in Brazil in any systematized form.

The key provisions for third-party matters are two:

Art. 2: “Legal entities shall be held strictly liable, in the administrative and civil spheres, for the harmful acts set forth in this Law that are committed in their interest or for their benefit, whether exclusive or not.”

Art. 3, § 2: liability applies to acts committed by employees, representatives, officers, and directors. The well-established broad interpretation extends this to third parties acting on behalf of or in the interest of the company — even without a formal employment relationship.

Strict liability means it is not necessary to prove the company’s intent or negligence for it to be sanctioned. The act committed by the third party on the company’s behalf is enough on its own. The only meaningful mitigating factor under Law 12,846/2013 is the existence of an effective integrity/compliance program, which can reduce — but not eliminate — sanctions (art. 7, VIII).

Decree 11,129/2022, which regulates the administrative liability process under Law 12,846/2013, lists the elements an integrity program must have to be recognized as effective. Among them is explicitly the third-party due diligence process — covering suppliers, service providers, commercial representatives, and partners.

Relevant international legislation:

Brazilian companies with operations abroad or with international shareholders/investors may also be subject to the FCPA (Foreign Corrupt Practices Act, US) and the UK Bribery Act, both of which contain provisions on liability for acts of third parties (agents, distributors, representatives). Third-party due diligence that meets the standards set out in Decree 11,129/2022 is generally compatible with the standards required under these laws — but the specific alignment should be assessed on a case-by-case basis.


3. What third-party due diligence is, and why it isn’t optional

Third-party due diligence (“diligência prévia de terceiros” — pre-engagement vetting of third parties) is the process of structured assessment of suppliers, partners, representatives, agents, consultants, and any other third party acting on behalf of or in the interest of the company — particularly in relationships involving interaction with the public sector.

It isn’t optional, because:

  1. Law 12,846/2013 holds the company liable for the acts of the third party, regardless of the company’s knowledge or authorization.
  2. Decree 11,129/2022 includes third-party due diligence as an element of an effective integrity program — the main mitigating factor for sanctions provided for under the law.
  3. The absence of a documented process, in the event of an investigation, reinforces the case that the company failed to adopt reasonable measures to prevent the wrongdoing.

What sets third-party due diligence apart from a simple registry check is its focus on integrity risk: not just who the supplier is and whether it is duly incorporated, but whether there is a history of involvement in corrupt practices, connections to relevant PEPs (“Pessoas Expostas Politicamente” — Politically Exposed Persons), anti-corruption-related litigation, and relationships with public officials that could create a conflict of interest.


4. The four-stage process: screening, assessment, contracting, and monitoring

A structured third-party due diligence process has four phases. The depth of each phase varies according to the third party’s risk level, which is determined by factors such as the type of relationship (a commercial representative dealing with government has higher risk than an office-supplies vendor), the value and nature of the contract, and the jurisdiction of operation.

Stage 1 — Screening (risk triage)

Before deepening the assessment, the third party is classified by risk level:

  • High risk: commercial representatives, agents, consultants, and distributors with regular interaction with the public sector; partners in jurisdictions with high perceived corruption; large contracts with government entities.
  • Medium risk: service providers with some degree of public-facing interface; partners in regulated industries.
  • Low risk: suppliers of standardized goods with no public interaction; providers of administrative support services.

The screening should be documented and reviewed periodically — a third party’s risk level can change over time.

Stage 2 — Assessment (due diligence proper)

For medium- and high-risk third parties, the assessment includes:

  • Verification of corporate and tax standing (CNPJ, registration status, shareholders and controlling parties)
  • PEP screening: checking whether shareholders, officers, or beneficial owners are Politically Exposed Persons (per CVM (Comissão de Valores Mobiliários — Brazil’s Securities and Exchange Commission) Resolution 50/2021 and COAF (Conselho de Controle de Atividades Financeiras — Brazil’s Financial Intelligence Unit) Resolution 36/2021, for entities subject to these rules)
  • Screening against national and international restrictive/sanctions lists: OFAC (Office of Foreign Assets Control), UN sanctions lists, the debarred-entities registry of the TCU (Tribunal de Contas da União — Federal Court of Accounts), and the CEIS (Cadastro de Empresas Inidôneas e Suspensas — National Registry of Debarred and Suspended Companies)
  • Litigation search focused on corruption, money laundering, and public administrative misconduct (“improbidade administrativa”)
  • Structured adverse media search (news coverage of involvement in corruption, investigations, police operations)
  • An integrity declaration signed by the third party

For high-risk third parties with significant contracts, it may be necessary to go further with an on-site visit or a structured interview.

Stage 3 — Contracting (formalization with safeguards)

Third parties that have gone through due diligence should be contracted with anti-corruption clauses (detailed in section 5 below), and documentation should show that due diligence was performed and approved before signing.

Stage 4 — Ongoing monitoring

Due diligence does not end at signing. For medium- and high-risk third parties, it is advisable to have:

  • Periodic reassessment (at least annually) of the information collected
  • Updated PEP and sanctions-list screening
  • An open channel for reporting irregularities involving the third party
  • Review triggered by any material change: change in shareholders, relevant news, a new government contract

5. The anti-corruption clause in the contract: what it must contain

The anti-corruption clause in the contract with the third party serves two purposes: (a) formalizing the third party’s commitment to the integrity standards required by the company, and (b) creating a contractual basis for termination and liability in case of violation.

An effective anti-corruption clause should contain:

  1. Compliance representation: the third party represents that it knows and complies with Law 12,846/2013 and other anti-corruption rules applicable to the contract.
  2. Express prohibitions: a ban on offering, promising, paying, or authorizing any improper advantage to a public or private agent in connection with the contract or with services rendered on behalf of the contracting company.
  3. Reporting obligation: the third party must inform the company of any request for an improper advantage received in the course of the contracted activities.
  4. Recordkeeping obligation: the third party must keep adequate records of transactions related to the contract, accessible to the company for audit purposes.
  5. Audit rights: the contracting company reserves the right to audit the third party’s records related to the contract, upon reasonable prior notice.
  6. Termination for breach: violation of any anti-corruption obligation is grounds for immediate termination of the contract, without prejudice to damages.
  7. Indemnification: the third party agrees to indemnify the contracting company for any sanction, fine, or damage arising from corrupt acts committed within the scope of the contract.
  8. Subcontracting: if the third party subcontracts services, it must impose the same anti-corruption obligations on its subcontractors.

The clause should be proportionate to the risk level. A commercial representation contract involving dealings with government entities calls for a more detailed clause than a cleaning-services supply contract. This proportionality is recognized in the interpretive guidance issued for Decree 11,129/2022.


6. When the integrity program provides cover — and when it doesn’t

The effective integrity program, as defined under Decree 11,129/2022, is the main mitigating tool for sanctions under Law 12,846/2013. But there are clear limits on what it does and does not do.

What the program covers (can reduce sanctions):

  • Acts by third parties committed against the company’s will, where the company adopted reasonable, documented preventive measures
  • Situations where the company detected the irregularity internally and cooperated with authorities
  • Cases where the company has an active whistleblowing channel, regular training, documented third-party due diligence, and anti-corruption clauses in its contracts

What the program does not cover (does not eliminate liability):

  • Acts committed on the orders of, or with the knowledge of, the company’s own officers/directors — strict liability remains in place, and the officers/directors are personally liable under criminal law
  • Programs that exist only on paper, without effective implementation: Decree 11,129/2022 requires an assessment of actual implementation, not merely the existence of documents
  • Acts by third parties for whom the company failed to carry out due diligence appropriate to the risk level of the relationship

The distinction between an “effective program” and a “paper program” is made based on concrete evidence of implementation: training records, due diligence files, records of internal investigations into reports received, policies that were approved and communicated, and documented commitment from senior leadership.

Companies that implement integrity programs in response to an ongoing investigation receive a reduced benefit compared with companies that can demonstrate a pre-existing, functioning program.


7. Frequently asked questions

Which third parties need to go through anti-corruption due diligence?

The answer depends on the risk level of each relationship, but the starting point is: any third party acting on behalf of or in the interest of the company in relationships involving interaction with government or with high-impact decision-makers. This includes commercial representatives, business agents, government-relations consultants, distributors that negotiate with government entities, and partners in joint ventures in regulated industries or with government contracts. For suppliers with no public-facing interface — standardized goods, administrative support services — due diligence can be simplified. Risk classification should happen before engagement, not after an incident occurs. Companies structuring their integrity program for the first time typically begin by mapping existing third parties by risk level, and prioritize retroactive due diligence for high-risk ones that are still active.

This is general information and does not replace consultation with a lawyer regarding your specific situation.


Can the company be held liable if the third party acted on its own initiative, with no instruction at all?

Yes. This is exactly what the strict-liability model under art. 2 of Law 12,846/2013 is built for. The absence of instruction and knowledge does not eliminate the legal entity’s administrative liability — as long as the act was committed on behalf of or in the interest of the company. What the law offers as a counterweight is the possibility of reduced sanctions when the company demonstrates that it adopted effective preventive measures — an integrity program, third-party due diligence, training, a whistleblowing channel. This is not a defense that eliminates liability: it is a factor in setting the sanction. That’s why building the program and the third-party due diligence process in advance has direct value: it’s what the company presents to the sanctioning authority to show it did what was within its power to prevent the wrongdoing.

This is general information and does not replace consultation with a lawyer regarding your specific situation.


What is a Politically Exposed Person (PEP), and why does it matter in supplier due diligence?

PEP (“Pessoa Exposta Politicamente” — Politically Exposed Person) is the technical term for individuals who hold, or held within the past 5 years, a relevant public office or position — such as leadership roles in government agencies, the legislature, the judiciary, the armed forces, political parties, and state-owned companies. The concept is regulated in Brazil by Banco Central do Brasil (BCB, Brazil’s Central Bank) Resolution 4,753/2019 and by COAF regulations. Its relevance in supplier and partner due diligence is twofold: first, when the supplier itself or its shareholders are PEPs, there is heightened risk of conflicts of interest in government contracts. Second, when a hired commercial representative has close ties to PEPs relevant to the company’s industry, the risk of improper intermediation increases. Identifying PEPs among third parties does not automatically mean rejecting the engagement — it means applying enhanced diligence and, if the engagement proceeds, more frequent monitoring.

This is general information and does not replace consultation with a lawyer regarding your specific situation.


Conclusion

The strict liability imposed by Law 12,846/2013 for acts of third parties is not an abstract threat. It is triggered when a representative, agent, or partner commits a corrupt act on the company’s behalf — regardless of authorization or knowledge.

The third-party due diligence process is the mechanism that turns legal risk into manageable risk. Not because it eliminates the possibility of wrongdoing — no process does that — but because it documents that the company adopted measures that were reasonable and proportionate to the risk level of each relationship.

For companies growing quickly and building a network of partners and suppliers at speed, structuring this process from the outset — rather than retroactively — allows due diligence to keep pace with the rate of new engagements, especially when government contracts or expansion into new markets are on the horizon.

Speak with a lawyer


The information in this article is general and educational in nature. It does not constitute legal advice for any specific situation and does not replace an analysis of your particular case by a lawyer.


Alessandra De Paula Souza — OAB/PR 31.133 Corporate Law | Compliance and Integrity Programs

Talk to a specialist

Ready to protect your business?

Book an initial consultation and find out how we can help your business grow securely in Brazil. Professional confidentiality guaranteed.

What to expect from the consultation

  • Legal diagnosis of your company's situation
  • Identification of risks and opportunities
  • Tailored legal strategy proposal
  • Questions answered, no commitment
Professional confidentiality guaranteed under the Brazilian Bar Association (OAB) statute

Request a consultation

Fill in the details below to request a consultation.

Area of interest *(select one or more)
Regulatory Compliance