Diligent Logo
Diligent Logo
Products
arrow_drop_down
Solutions
arrow_drop_down
Resources
arrow_drop_down
Diligent AI

Know the risk. Own the record: What's new for third-party risk and compliance at Diligent

September 29, 2026
•
7 min read
Governance professionals reviewing organizational structures and planning activities during a board and compliance meeting.
Tracey Brady

Tracey Brady

Vice President, Corporate Services

A third-party risk assessment lands in your queue. The vendor has a medium rating. Senior leadership wants to know why. The auditor wants to know what evidence was reviewed and whether the documentation actually met your standards.

Elsewhere, a question comes in about an entity in the group structure. You need to understand who owns what and how it connects upward. The answer is somewhere across multiple charts, a few manual exports and a report that doesn't quite cover the right scope.

Two roles, one shared gap. The context you need to give a clear answer exists, it's just not visible in one place.

That's where the latest Diligent updates come in. For compliance and risk teams, there's a clearer, more defensible chain from vendor rating to decision. For governance and legal teams, there's broader visibility into entity ownership structures and a practical path for preparing for a significant change in UK filing requirements.

Evidence-backed third-party risk intelligence

Third-party risk decisions that need to stand up to scrutiny require more than a point-in-time score or a vendor's self-reported answers. They require an explainable chain: why the rating is what it is, whether the documentation holds up and what still needs to be resolved.

Third-Party Risk Intelligence works across that chain.

See what's driving the rating

Third-Party Risk Intelligence scores each third party across geography, relationship and vendor type and explains the specific factors behind each result.

Instead of a standalone number, risk teams get context: which elements influenced the rating, how they compare against the organisation's expectations and whether the score reflects the characteristics that matter in this particular relationship.

That context makes the difference when a decision needs to be explained to a senior leader, an auditor or a regulator. The rating doesn't just exist. It can show its work.

  • Understand the specific drivers behind every third-party rating
  • Assess whether a score reflects the factors that matter to the organisation
  • Create a clearer basis for review, escalation and documentation

Validate documentation against your standards

Questionnaires can provide useful starting information. But they can't confirm whether a vendor's actual documentation meets the standards your organisation has defined for the relationship.

Third-Party Risk Intelligence validates vendor documentation against those defined standards directly.

This gives compliance, procurement, legal and risk teams a reviewable workflow: see the standards relevant to the assessment, check the documentation the vendor has provided, identify what's missing or non-compliant and keep the review connected to the vendor profile.

Human judgement stays central. Reviewers have a clear evidence base to work from, rather than relying on what a vendor chose to report.

  • Compare vendor documentation against your organisation's defined standards
  • Identify missing or non-compliant evidence in the same workflow
  • Keep documentation review connected to the vendor profile and assessment

Follow up on evidence gaps

Identifying that evidence is missing is only the first step. Teams also need a practical way to pursue it.

Agentic follow-up tracks outstanding evidence gaps against the organisation's defined standards and supports a structured path from identifying an issue to resolving it.

Unresolved gaps stay visible rather than falling through the cracks between systems. Responsibility for the final decision stays with the relevant compliance, risk, procurement or legal stakeholders. The follow-up doesn't depend on someone manually chasing each item.

  • Make evidence gaps visible and trackable within the risk workflow
  • Pursue missing or non-compliant documentation through structured follow-up
  • Keep accountability for decisions with the right stakeholders throughout

Add context before ordering further investigation

A rating may indicate that deeper scrutiny is needed. But before ordering further due diligence, teams also need to understand what level of scrutiny is appropriate.

Benchmarked context and analyst-led due diligence ordering address that question. Findings are returned directly to the same vendor profile, so the initial assessment, the context and any subsequent investigation stay connected.

The aim isn't to produce another report sitting separately from everything else. It's to create a clear chain from rating to evidence, follow-up and decision, with everything visible in one place when that decision needs to be documented or defended.

  • Review benchmarked context alongside rating drivers
  • Order further due diligence and return findings directly to the vendor profile
  • Keep the full assessment chain visible and auditable in one place

Entity portfolio visibility and filing readiness

For governance and legal teams, portfolio-level decisions depend on having the right context about how entities connect, what the records actually show and who owns the work that keeps the portfolio compliant.

This month's Diligent Entities updates address three practical elements of that.

See more of the ownership structure around a selected entity

Understanding complex entity structures often requires piecing together relationships across multiple charts or reports, a time-consuming process that can still leave important connections out of view.

Ownership Map gives teams a broader view around a selected entity in one place. Rather than showing a single vertical ownership chain, it maps the entity's subsidiaries, parent entities and the subsidiaries of those parent entities together.

For governance, legal and compliance teams working with complex or interconnected structures like PE houses, funds and multinational groups, that means faster visibility into the relationships that matter without manually assembling separate views.

  • Visualise a broader ownership structure around a selected entity in one map
  • See subsidiaries, parents and parent-subsidiary relationships together for faster analysis
  • Improve understanding of complex ownership structures without piecing together multiple views
  • Support clearer internal reporting and governance review of entity relationships

Ownership Map is available to Diligent Entities customers where the Structure Store option in System Tools is active, and requires the Export Group Structure user role right.

Ask broader questions across your entity portfolio

Finding information across a complex entity portfolio can require repeated searches, careful navigation and manual reconciliation of results. The more entity types involved, the more time that takes.

Entities AI Assistant Insights supports more detailed natural-language questions across multiple entity types. Users can ask broader questions, export larger result sets to Excel, copy responses to the clipboard and rate Assistant responses to improve accuracy over time.

Results remain subject to existing access permissions, so broader queries stay within the relevant permission model.

  • Ask detailed natural-language questions across multiple entity types in one place
  • Export larger query results to Excel for further review or sharing
  • Keep broader record interrogation within existing access permissions

Prepare for software-only accounts filing before April 2028

From April 2028, Companies House will require all UK annual financial statement filings to be submitted through software. Paper filing and WebFiling uploads will no longer be accepted. Accounts will need to be iXBRL-tagged using accounting software before submission.

For governance teams, the transition creates a planning question worth addressing now rather than in 2027: who prepares the accounts, who confirms the required approvals and who controls the submission?

Diligent Entities supports submission of iXBRL-tagged accounts and provides the CoSec-controlled checkpoint in the new workflow. Finance or an external accountant prepares and tags the accounts in accounting software. The CoSec team confirms that Board, member, audit and CoSec approvals and consents are complete. The tagged accounts are submitted through Diligent Entities, with filing status and responsibilities visible to the relevant teams throughout.

Using the lead time before the deadline to define that handoff, confirming who prepares, reviews, approves and submits, is significantly less disruptive than addressing it when the requirement is already live.

  • Clarify the Finance-to-CoSec handoff for iXBRL-tagged accounts submission
  • Keep Board and CoSec approval requirements visible before filing
  • Submit tagged accounts through Diligent Entities and maintain filing visibility across the portfolio

When the evidence is ready, so are you

The evidence behind a vendor decision and the records behind a governance one have always existed. These updates make them visible, connected and ready, so CCOs, CoSecs, legal counsel and risk teams spend less time assembling context and more time acting on it.

Ready to explore?

Already a Diligent customer? Speak with your Customer Success Manager to confirm which capabilities are available for your account and how to activate them.

Not yet a customer? Request a demo to see how Diligent helps CCOs, CoSecs, legal counsel and risk teams make decisions with greater confidence and control.

Explore More

Error log analysis with alert warning sign

Blog

· Sep 25, 2026

· 6 min read

Your compliance program has more data than ever. Does it have more insight?

By Kristy Grant-Hart

Conflicts of interest, training, policy and speak-up data often live in silos. See why connecting them, not adding another tool, is the real fix.

AI action plan GRC

Guide

· Apr 22, 2026

· 1 min read

AI action plan worksheet for GRC leaders

Unlock the potential of AI in governance, risk, and compliance with this practical 90-day action plan worksheet designed for GRC leaders. This guide helps you assess AI maturity, prioritize use cases, and establish essential guardrails, ensuring a structured and accountable approach to AI implementation in your organization. Download now to transform AI discussions into a clear, actionable strategy.

Blog

· Sep 28, 2026

· 3 min read

A risk score isn't a decision: What third-party risk programs are missing

By Daniel Zmak

A "High" risk score doesn't explain itself. See why third-party risk programs need context, evidence and benchmarks — not just a color-coded rating.