1. Purpose
1.1 This Policy establishes a complete lifecycle framework for managing integrity and responsible-business risk arising from third parties and other external relationships.
1.2 It is designed to prevent TrustCome from becoming associated with concealed ownership, corruption, financial crime, sanctions exposure, exploitation, misuse of information, unqualified performance, improper influence or other conduct inconsistent with its constitutional values.
2. Policy Statement
2.1 TrustCome shall engage a third party only where the relationship has a legitimate purpose, the party has been identified and assessed to the required standard, material risks are understood and controlled, and an authorised decision has been recorded.
2.2 No commercial urgency, personal relationship, senior sponsorship, market custom or expected revenue shall displace the requirements of this Policy.
6. Risk-Based Approach
6.1 The depth, independence and frequency of due diligence shall be proportionate to the nature, geography, value, access, influence, sensitivity and potential consequences of the relationship.
6.2 A risk-based approach shall increase scrutiny where risk is higher; it shall not be used to justify the absence of basic identity, purpose, ownership and approval controls.
7. No Circumvention
7.1 No person shall divide, rename, route, prepay, reimburse, sponsor, subcontract or otherwise structure a relationship to avoid review, approval, contractual controls, screening, registration or monitoring.
7.2 Informal understandings, personal payments, side letters and work undertaken through an affiliated entity remain within scope where they support or benefit TrustCome activity.
11. Institutional Risk Appetite
11.1 TrustCome has no appetite for relationships that depend upon bribery, concealed influence, sanctions evasion, exploitation, falsified records, misrepresentation, unlawful surveillance, retaliation or deliberate concealment of ownership or purpose.
11.2 Risk acceptance may address controlled residual risk; it shall not convert prohibited conduct into acceptable conduct.
12. Legitimate Purpose
12.1 Every relationship shall have a documented institutional purpose, defined services or benefit, a credible need and a rational connection between the third party’s capability and the proposed engagement.
12.2 A relationship shall not be created merely to provide access, disguise a payment, reward influence, satisfy a private request or distance TrustCome from conduct it would not perform directly.
13. Transparency
13.1 TrustCome shall seek sufficient transparency to understand the party, ownership, control, key persons, compensation, subcontracting, relevant affiliations and intended flow of funds or information.
13.2 Unnecessary opacity is itself a risk factor and may justify enhanced diligence, conditions, suspension or refusal.
14. Beneficial Ownership
14.1 TrustCome shall identify the natural persons who ultimately own, control or benefit from a legal person or arrangement to the extent proportionate and lawful.
14.2 Nominee, trust, foundation, holding-company, family, state or layered structures shall be understood rather than accepted solely at face value.
15. Integrity and Reputation
15.1 The assessment shall consider conduct, enforcement history, allegations, public record, professional standing, ethical culture and the credibility of explanations.
15.2 Adverse information shall be evaluated for reliability, seriousness, recency, pattern, response and relevance; absence of adverse media shall not be treated as proof of integrity.
16. Capability and Suitability
16.1 A third party shall possess the competence, resources, licences, personnel, systems, insurance and operational capacity necessary to perform the approved role.
16.2 Selection shall not be based solely on relationships, status, access, low price, speed or the preferences of a senior sponsor.
17. Public-Sector and Politically Exposed Risk
17.1 Relationships involving public officials, politically exposed persons, state-owned enterprises, public procurement, licences, customs, taxation, state funds or government decision-making require heightened scrutiny.
17.2 The existence of a public or political connection is not itself misconduct; concealment, improper leverage, unexplained benefit and conflict require escalation.
18. Sanctions and Financial-Crime Risk
18.1 TrustCome shall assess applicable sanctions, asset-freeze, anti-money-laundering, counter-terrorist-financing, fraud, tax-crime and proliferation-financing exposure before and during relevant relationships.
18.2 Screening is one control among several and shall not replace understanding of ownership, control, geography, transaction purpose and payment behaviour.
19. Human Rights and Responsible Business Conduct
19.1 TrustCome shall seek to avoid causing, contributing to or being directly linked through a business relationship to serious adverse impacts on people, communities or lawful civic participation.
19.2 Diligence shall consider forced labour, child labour, trafficking, unsafe work, discrimination, harassment, unlawful displacement, violence, environmental harm and restrictions on effective remedy where relevant.
20. Information and Cybersecurity Risk
20.1 Third parties receiving access to confidential information, systems, facilities, identities, communications or personal data shall undergo proportionate privacy, information-security and resilience assessment.
20.2 No access shall be broader, earlier or longer than the approved purpose requires.
21. Unresolved Risk
21.1 Material unanswered questions, inconsistent explanations, unreliable documents, unexplained ownership, unusual payments or resistance to reasonable diligence shall be treated as unresolved risk rather than administrative inconvenience.
21.2 Where risk cannot be reduced to an acceptable and governable level, TrustCome shall decline, suspend or exit the relationship.
22. Approval Before Activity
22.1 A third party shall not begin work, contact a public body on TrustCome’s behalf, receive confidential access, make commitments, incur reimbursable cost or receive payment before the required approval and contract are complete.
22.2 Any exceptional urgent action shall follow the controlled emergency procedure and shall never authorise prohibited conduct.
48. Prohibited Relationships
48.1 TrustCome shall not approve a party where the relationship is unlawful, sanctions-prohibited, based on bribery or concealed influence, dependent on falsified identity or records, designed to evade controls, or presents serious unmitigable exploitation, security or integrity risk.
48.2 A prohibited classification cannot be overridden by commercial risk acceptance.
112. Suspension, Termination and Responsible Exit
112.1 TrustCome shall suspend or terminate where required by law, prohibited risk, serious breach, non-cooperation, unresolved red flags, ineffective remediation or loss of legitimate need.
112.2 Exit shall address continuity, safety, data and asset return, access revocation, payments, evidence, notification, surviving duties and potential remedy for affected persons.
145. Breach of Policy
145.1 Breach may result in stop-work, payment hold, access removal, investigation, disciplinary or contractual action, recovery, debarment, referral and remediation.
145.2 A leader who pressures others to bypass diligence or suppress red flags commits a separate governance failure.