Skip to main content

Due Diligence Framework

1. Purpose and Governance

This framework defines how {{company_name}} identifies, prevents, mitigates, tracks, remediates, and communicates actual and potential adverse impacts.

Framework owner: {{due_diligence_owner}}

2. Scope and Value-Chain Coverage

{{scope_description}}

The scope SHALL be reviewed when material changes occur in operations, products, sourcing, geography, business relationships, regulation, or risk evidence.

3. Risk Identification and Assessment

{{risk_methodology}}

Current salient risks or adverse impacts include: {{salient_risks}}

4. Prioritisation

Where all impacts cannot be addressed simultaneously, prioritisation SHALL be based on the governed methodology, including severity and relevant dimensions of irremediability, scale, scope, likelihood, and affected stakeholder context.

5. Prevention, Mitigation and Corrective Action

Priority actions: {{priority_actions}}

Actions SHALL identify owners, timelines, expected outcomes, evidence, dependencies, escalation conditions, and effectiveness measures.

6. Stakeholder Engagement

Relevant stakeholder groups include: {{stakeholder_groups}}

Engagement SHALL be meaningful, appropriately accessible, and proportionate to the nature and severity of the impacts under consideration.

7. Grievance and Remedy

Operational grievances may be raised through {{grievance_channel}}. The framework SHALL support access to appropriate remedy where the organisation caused or contributed to adverse impacts.

8. Monitoring and Effectiveness

Monitoring cadence: {{monitoring_cadence}}

The organisation SHALL track implementation, outcomes, recurring issues, evidence quality, and whether preventive or remedial measures are effective.

9. Communication, Evidence and Assurance

Due diligence conclusions and disclosures SHALL remain traceable to risk assessments, stakeholder inputs, actions, decisions, evidence, assurance activity, and subsequent revisions.

Audit Evidence Reference Bindings

The links below demonstrate document-local evidence requirements. At runtime, ZAYAZ resolves the requirement through the Evidence Registry and the current client/document context; the template does not contain CMIDs or E-C-O Numbers.

  • Due diligence risk assessment
  • Stakeholder consultation evidence
  • Corrective action evidence
  • Due diligence assurance evidence
GitHub RepoRequest for Change (RFC)