Exiger due-diligence escalation needs a scope-transition record
Exiger says a red flag can be escalated into deeper due diligence. The transition should preserve the trigger, prior evidence, new scope, authority, sources, owner, timing, outcome, and downstream decision instead of turning one click into an unexplained change of investigative purpose.
Third Party Current editorial graphic. Source material: Exiger Third-Party Risk Management; analysis and presentation by Third Party Current.
Treat escalation as a change in investigative scope
The direct answer is that a move from a red flag into deeper due diligence should create a versioned scope-transition record. Exiger's official page describes conditional workflows, risk assessments, monitoring, and escalation to deeper due diligence when red flags are raised. That workflow can accelerate review, but the click itself does not explain why the original work was insufficient, what the deeper review is authorized to examine, or which decision the additional evidence will support.
Preserve the third party and relevant legal entity, product, service, contract, relationship, jurisdiction, onboarding or monitoring stage, triggering signal, source and retrieval time, original screening scope, prior result, materiality assessment, escalation rule and version, initiator, approver, new questions, permitted data sources, geographic and language coverage, expected deliverable, owner, due date, cost authority where applicable, and stop conditions. A red flag should remain evidence to review rather than silently becoming a confirmed finding.
Keep the old and new evidence packages reproducible
The original evidence package should remain fixed and retrievable after escalation. Record each name, identifier, search term, ownership path, list or dataset, query time, match logic, result, analyst note, uncertainty, and disposition that existed before the scope changed. Then link the expanded work as a new package with its own sources, instructions, research period, translations, interviews or local-source work where used, quality checks, conflicts, and limitations. Later corrections should create another version rather than rewrite the package that caused the escalation.
This separation matters when one relationship generates several alerts or when several entities share similar names. The workflow should show which signal caused which question, which source addressed it, and whether the deeper work confirmed, contradicted, narrowed, or left the concern unresolved. If a source cannot be accessed, a jurisdiction is outside coverage, or an identity match remains uncertain, that condition belongs in the result rather than being converted into a clean conclusion.
Return a bounded result to an accountable decision
A completed diligence report is not the same record as onboarding approval, issue closure, risk acceptance, contract action, remediation, offboarding, or continued monitoring. Route the result to a named owner with the applicable policy, decision authority, alternatives considered, unresolved questions, conditions, review date, and downstream systems affected. If the result changes a risk rating or issue state, preserve the prior value, the new value, the evidence used, the person or body that approved the change, and the effective time.
Buyers should also test cancellation, duplication, and supersession. A later screening result may make an open escalation irrelevant, while a second alert may concern a different entity or risk domain. The operating model needs rules for merging or separating work, protecting sensitive research, handling conflicts, limiting access, retaining licensed material, notifying stakeholders, and restoring the earlier state when the escalation was opened against the wrong subject.
Test one red flag through confirmation, contradiction, and rollback
A representative evaluation should begin with one third party whose screening produces an ambiguous red flag. Escalate it under a defined rule, add a similarly named entity, expand the jurisdiction and source set, receive one contradictory source, correct an identifier, pause the work for an access restriction, and conclude with an unresolved limitation. Reviewers should reproduce the original evidence, scope decision, authorization, research instructions, source results, version history, analyst reasoning, final report, downstream disposition, and any rollback without relying on the current screen alone.
Exiger's page supports the attributed positioning about onboarding, conditional workflows, risk assessment, monitoring, issue remediation, escalation, and different due-diligence research approaches. It does not establish a customer's policy, source coverage, match quality, escalation authority, research completeness, factual conclusion, remediation, risk acceptance, contract decision, regulatory compliance, or outcome. Qualified third-party-risk, compliance, procurement, legal, privacy, security, investigations, and business owners retain those decisions.
What we will watch next
Third Party Current will watch for later primary-source evidence that changes the maintained company, capability, or standards record. The next useful evidence may include implementation documentation, release details, regulator findings, corrected methods, product packaging, customer-observable workflow, or a subsequent company statement. Until then, the dated source and its stated boundary remain attached to this analysis.
