Introduction
This Third-Party Due Diligence Policy establishes the framework and requirements for conducting due diligence on third parties, including vendors, resellers, agents and business partners. The objective is to ensure that all third-party relationships are compliant with legal and ethical standards and do not expose Engineering Plus FZE to reputational, legal or financial risks.
Scope
The Policy applies to all departments and individuals who engage, evaluate or manage third parties on behalf of Engineering Plus FZE. It covers new engagements, renewals and significant changes in third-party operations or ownership.
AML and CTF framework
With respect to anti-money laundering (AML) and counter-terrorist financing (CTF), Engineering Plus FZE complies with the applicable laws and regulations of the United Arab Emirates and other jurisdictions in which it operates, as well as relevant international standards and regulatory guidance.
Responsibilities
The Legal Department is responsible for overseeing the due diligence process and maintaining relevant records. Business units are responsible for initiating due diligence and ensuring its completion before engagement. All employees must report concerns or red flags related to third parties.
Due diligence process
The following steps must be followed for all relevant third-party engagements: completion of a third-party questionnaire; background checks including sanctions and watch list screening; evaluation of ownership structure and beneficial ownership; review of financial, legal and compliance history; risk classification and approval; and contractual obligations including compliance with anti-bribery, sanctions, AML and CTF requirements.
Identification and verification
For individuals, due diligence includes identification of full name, date of birth, nationality, identity document number and proof of address, verified against original or certified documents. For legal entities, due diligence includes identification of legal name, place and date of incorporation, registration number, registered address, business activity, and beneficial owners holding more than 25 percent of the entity.
Risk-based approach
Due diligence depth and frequency correspond to the risk level of the third party, based on factors including country of incorporation and operation, nature of goods or services, proximity to government entities, past compliance issues and negative media background.
Ongoing monitoring
Third-party relationships must be monitored regularly. High-risk third parties are reviewed at least annually, and any changes in ownership, business activities or negative news trigger a reassessment.
Documentation and record-keeping
Due diligence records must be retained for a minimum of five years after termination of the relationship and must be accessible to the Legal Department.
Violations
Failure to comply with this Policy may result in disciplinary action, up to and including termination. Third parties found in violation may be subject to contract termination and potential legal action.