Third-party and supplier risk: screening your vendors for sanctions and forced labor

By Beady Team Aug 20, 2026

Procurement has always judged a vendor on price, on quality, and on whether it delivers when it says it will. Those measures still matter, but they no longer add up to the whole evaluation, because a fourth one has become just as important: whether a vendor exposes the organization buying from it to regulatory and reputational risk.

A supplier can be cheap, reliable, and punctual and still be a serious liability. Dealing with a sanctioned supplier can be a legal violation in its own right, and a supplier linked to forced labor can bring detained shipments, penalties, and a reputational hit that outlasts whatever its price ever saved. The awkward part is that none of this appears on a traditional vendor scorecard, and the exposure is growing rather than fading.

It is also a moving target. A vendor that is clean at onboarding can be sanctioned a quarter later, acquired by a sanctioned owner, or named in a report on labor conditions, so a single check at the start of the relationship cannot keep up. Screening vendors for sanctions and forced-labor exposure, and doing it continuously rather than once, is now part of basic supply-chain due diligence. What follows is what that screening involves for each risk, where it honestly stops, and how to fit it into procurement.

Why supplier risk outgrew price and delivery

The reason this became a fourth axis, rather than a footnote to the other three, is that several pressures have grown at once, and none of them is captured by a cost-and-delivery view of a vendor.

Sanctions have expanded in both volume and reach. The pace of designations has stayed high, and a supplier or its owners can be added to a list at any time, which turns a routine vendor relationship into direct legal exposure overnight. Because sanctions can reach through ownership, a supplier that looks entirely clean can carry exposure through who ultimately controls it.

Forced-labor law has hardened from an ethical concern into an enforcement one. Import bans tied to forced labor, most prominently the US Uyghur Forced Labor Prevention Act, along with supply-chain due-diligence and transparency laws in the EU and modern-slavery legislation in the UK and Australia, have put real legal and financial consequences behind forced-labor exposure. Shipments can be detained at the border, and penalties and mandatory disclosures now attach to getting it wrong.

Reputation raises the stakes further. A supplier scandal becomes the buyer’s scandal the moment it breaks, whether or not there is direct legal liability, because customers and the public do not draw fine distinctions about who in a supply chain was at fault. And all of this is made harder by the shape of modern supply chains, which are long and often opaque, so an organization is exposed not only to its direct suppliers but to their suppliers in turn, through connections it may not be able to see. Cost-and-delivery scorecards were never designed to catch any of this, which is why supplier risk has become its own discipline.

Screening vendors for sanctions

The sanctions side of vendor screening is the more clear-cut of the two, and it is worth being precise about what doing it properly actually means.

It starts with screening the vendor entity, and its beneficial owners, against global sanctions lists. The ownership point is not a detail, because a company that is itself clean can be owned or controlled by a sanctioned party, and that exposure is just as real as if the company were listed directly. Screening only the surface entity misses exactly the case that matters most.

It also has to be continuous rather than a one-time gate. A vendor screened clean at onboarding can be designated later, or can be acquired mid-relationship by a sanctioned entity, and a check performed once at the start of the relationship will never see either. The exposure begins the moment the designation or the acquisition happens, not the moment someone next gets around to re-screening, which for most organizations is far too late.

This is where continuous entity monitoring does the work, and it is squarely what Beady AI is built for. Rather than re-screening a supplier base by hand, the vendors and their owners are monitored continuously against global sanctions lists, so a designation or an ownership change surfaces when it happens, with every hit traced back to its source so it can be verified and defended. The sanctions monitoring page covers how that works in detail, and the case for why it has to be continuous rather than periodic is set out here.

Screening for forced labor, and its honest limits

Forced labour is where things get more complicated, and where being straight about what screening actually can and can’t do matters the most. Forced-labour risk shows up through two different kinds of signal, and those two signals call for two very different kinds of tool.

The entity and media signals

The first kind is entity and adverse-media signals. A supplier can appear on a forced-labor-related entity list, such as the entity list maintained under the US forced-labor import regime, or it can surface in adverse media, in reporting and investigations into labor conditions and abuses. Catching these is a matter of screening the supplier against the relevant lists and monitoring for negative coverage, which is the same continuous entity-and-media monitoring that sanctions screening relies on. This layer catches the supplier that is already listed or already in the news.

The supply-chain-tracing signals

The second kind is different in nature, and it is where entity monitoring stops. Full forced-labor due diligence also depends on tracing where inputs actually come from, analysing the risk of specific regions and commodities, auditing suppliers and their sites, and documenting the chain of custody back through the tiers of a supply chain. This is specialised supply-chain due-diligence work, and it is not something entity monitoring does. Mapping the origin of the cotton in a garment or auditing a factory floor is a different capability from screening an entity against a list.

So the honest framing is this. Continuous entity and adverse-media monitoring catches a real and important layer of forced-labor risk, the supplier that is listed or reported, and it catches it as it happens rather than at an annual review. But a complete forced-labor compliance program, of the kind laws like the US import regime demand, also requires supply-chain tracing that sits outside entity monitoring. Beady covers the entity-and-media layer. The tracing layer needs dedicated supply-chain due-diligence tooling, and a serious program uses both rather than pretending one tool does everything.

Why vendor screening has to be continuous

Whichever risk you happen to be focused on, the case for doing this continuously rather than as a one-off comes down to the same underlying fact: vendor risk isn’t static, and a supplier relationship usually runs for years.

Across the life of that relationship, sanctions designations land without warning, ownership changes hands, a supplier turns up in the news over its labour practices, and new entities are added to forced-labour lists. Every one of those is a moment the risk picture shifts, and none of them announces itself to the buyer. A check done at onboarding describes the vendor as it was the day you signed them up — not the vendor your organization is actually exposed to three years into the contract. The gap between the change happening and the buyer finding out about it is exactly where the exposure sits, and a one-time check leaves that gap wide open.

Scale drives the point home even harder. A real supplier base runs to hundreds or thousands of vendors, and re-screening every single one of them by hand every time a list updates just isn’t feasible — which means a manual program either misses changes or picks them up too late to be useful. Continuous monitoring is what turns coverage into something real at that scale, surfacing the vendors affected by a change automatically instead of relying on someone to re-check them all. It’s the same detection-latency problem that runs through any kind of ongoing risk: the thing that matters isn’t how quickly you can screen a single vendor, it’s how long a change sits unnoticed across the whole base.

Building vendor screening into procurement

The practical goal is to fold screening into how procurement already runs, rather than bolting it on as a separate exercise. A workable program comes down to a handful of steps.

  1. Screen at onboarding and continuously. A vendor should be checked before the relationship begins, and then kept under watch for as long as it lasts, since the onboarding gate only ever catches the risk that exists on day one.
  2. Screen the entity and its owners. Both the vendor and its beneficial owners need to be covered against sanctions lists. A company that is clean itself can still be exposed if a sanctioned party owns it.
  3. Cover both risks with the right tools. Continuous entity and adverse-media monitoring handles the sanctions and forced-labor signals it can catch, and supply-chain due-diligence tooling handles the origin-tracing layer that forced labor also requires. Neither covers the whole of forced-labor diligence on its own.
  4. Decide what happens when a vendor is flagged. Work out the response in advance, who gets notified, who makes the call, how quickly, and what the path to offboarding or remediation is. Without that, a flag lands and nothing moves.
  5. Match the depth of scrutiny to the risk. A critical strategic supplier earns deeper and more frequent checks than a one-off, low-value vendor, which keeps the effort focused where the real exposure is.

Frequently Asked Questions

What is third-party or supplier risk screening?
It is the practice of checking the vendors an organization works with for risks beyond price, quality, and delivery, specifically regulatory and reputational exposure such as sanctions and forced labor. A supplier can be reliable and well-priced and still be a legal or reputational liability, so screening for these risks, continuously rather than only at onboarding, has become part of basic supply-chain due diligence.
You screen the vendor entity along with its beneficial owners against global sanctions lists — and you do it on an ongoing basis, not just once. The ownership piece matters because a company that looks clean on the surface can still be controlled by a sanctioned party sitting behind it. The continuous piece matters because a vendor who was clear when you onboarded them can get designated later, or acquired by an entity that already is. Continuous entity monitoring is what surfaces those shifts as they happen, with every hit traceable back to its source.
It catches the supplier that is already listed or already in the news, and misses the one whose risk is buried in where its materials come from. That is the honest split. Entity and adverse-media screening surfaces a supplier on a forced-labor entity list or named in an investigation into labor conditions, which is a real and important layer. Tracing the origin of inputs and auditing supplier sites, the other layer forced-labor diligence depends on, is different work that screening does not do. A complete program needs both, not one standing in for the other.
Because vendor risk changes over the life of a relationship that runs for years. Sanctions designations happen without warning, ownership changes, and suppliers surface in the news, and none of these announce themselves to the buyer. A check at onboarding describes the vendor as it was then, not as it is now. Across a base of hundreds or thousands of vendors, continuous monitoring is the only realistic way to catch a change when it happens rather than at an annual review.
The main ones sit in a few jurisdictions. In the United States, forced-labor import bans do the work, above all the Uyghur Forced Labor Prevention Act. In the European Union, the obligations come through supply-chain due-diligence and transparency laws. In the UK and Australia, modern-slavery legislation applies. Each imposes different requirements, and those requirements keep moving, so the current rules for any market you operate in are worth confirming against primary sources.
Beady provides continuous, source-traceable monitoring of vendors and their owners against sanctions lists, and monitors for adverse media and forced-labor-related entity-list signals. That covers the entity-and-media layer of both risks. It does not perform supply-chain tracing, origin mapping, or site audits, which full forced-labor compliance also requires, so it works as the continuous entity-monitoring layer of a program alongside dedicated supply-chain due-diligence tools.

The short version

The thing to walk away with is that a good vendor isn’t just a cheap, reliable, on-time one anymore. Regulatory and reputational risk has become a fourth measure sitting alongside the other three, because a supplier that’s sanctioned or tied to forced labour is a liability regardless of how good their pricing looks, and that kind of risk moves continuously — which rules out the idea of a one-time check at onboarding. Sanctions screening has to keep watching the vendor and its owners against the lists on an ongoing basis. Forced-labour screening has to pick up on the entity and any adverse-media signals as they surface, with the honest caveat that a proper forced-labour program also has to include supply-chain tracing, which entity monitoring on its own doesn’t cover.

So the real answer is two tools, not one: continuous entity monitoring for the sanctions side and the listed-or-reported forced-labour risks, and dedicated supply-chain due-diligence tooling for tracing where the inputs actually come from. Assuming a single tool covers all of it is exactly how a blind spot forms without anyone noticing.

For the continuous entity-monitoring layer, screening vendors and their owners against sanctions lists and watching for adverse-media and forced-labor entity signals, all source-traceable, Beady AI is built for the job, and a session will show what it surfaces against a real supplier base. For the broader question of what an organization owes on its vendors, there is more here.

Beady Team

The team behind Beady, building risk intelligence and compliance software. We write about sanctions, due diligence, KYC, and screening — drawing on what we see across hundreds of millions of sources every day. Practical insight for compliance, risk, and investment teams.

Risk Intelligence, Straight to Your Inbox

Guides, regulatory updates, and lessons from real screening cases. Written for compliance, risk, and investment teams who need to know what's coming next.

    Follow Beady Where You Already Work

    Risk alerts, regulatory changes, and screening insight — posted where your team already spends its day. Join us on the most popular social networks.

    Ready to get started?

    Helping you go live in days, not weeks.