Third-Party Due Diligence: What the SEC Fake Court Order Case Shows About Vendor Risk
A recent investigation by the U.S. Securities and Exchange Commission's Office of Inspector General provides an unusual example of the risks that can arise when specialist work is outsourced to a third-party provider.
According to an investigative summary published by the SEC OIG on September 24, 2026, an entity previously involved in an SEC enforcement matter hired a reputation management firm to assist with search engine optimization and remove harmful internet links relating to its business.
The SEC OIG found that, without the entity's knowledge, the largely overseas-based firm created a fabricated U.S. District Court order and used it in efforts to have information concerning the SEC settlement removed from search results. The firm also sent requests to the SEC seeking removal of settlement information from SEC websites.
The case is unusual, but the wider issue is not.
Organizations routinely rely on outside consultants, agents, professional advisers, technology providers and other specialist vendors. In many circumstances, those third parties act publicly or operationally on the organization's behalf.
That makes understanding who they are, how they operate and whether their background raises material concerns an important part of third-party due diligence.
What Happened in the SEC Case?
The SEC's Division of Enforcement referred the matter to the Office of Inspector General after a reported U.S. District Court order was submitted to an internet search engine in support of a request to remove an SEC settlement from search results.
The OIG contacted the U.S. District Court for the District of Columbia and established that the court order had been fabricated.
Investigators subsequently obtained records connected with emails sent to both the search engine and the SEC and identified the internet protocol addresses associated with the communications.
The OIG then interviewed legal counsel for the entity concerned. According to the investigative summary, the entity had engaged a reputation management firm to assist with search engine optimization and the removal of damaging links.
Crucially, the OIG stated that the firm created the false court order without the entity's knowledge.
The OIG ultimately ensured that the Administrative Office of the U.S. Courts, the relevant District Court and the FBI's Internet Crime Complaint Center were aware of the matter before closing its investigation.
The case therefore should not be read as suggesting that the client instructed or approved the creation of the false document.
Instead, it illustrates a different risk: a third-party provider can take actions that the organization appointing it did not anticipate or authorize.
Why Third-Party Conduct Matters
Outsourcing work does not necessarily outsource the consequences of how that work is performed.
Companies appoint external providers for many legitimate reasons. A specialist vendor may have expertise, technology, local knowledge or capacity that is not available internally.
Those providers can include:
- Consultants.
- Agents and intermediaries.
- Marketing and reputation management firms.
- Professional advisers.
- Technology providers.
- Distributors.
- Overseas representatives.
- Specialist contractors.
Most operate legitimately.
However, the actions of an external provider can still affect the organization that hired it.
Improper conduct may create reputational questions, require internal investigation, attract regulatory attention or cause an organization to explain how a third party was selected and supervised.
The relevant due diligence question is therefore not simply whether a vendor exists and appears professional.
It is whether sufficient information is available to understand who the organization is entrusting with the work.
What Can Third-Party Due Diligence Examine?
The appropriate scope will depend on the nature of the relationship.
A company engaging a low-value domestic supplier will not necessarily require the same level of scrutiny as a business appointing an overseas intermediary with authority to communicate with regulators, customers or other third parties on its behalf.
For more significant relationships, Due Diligence Services can help examine matters such as:
- Corporate formation and operating history.
- Ownership and control.
- Key directors, managers and principals.
- Regulatory history.
- Significant litigation.
- Insolvency history.
- Sanctions exposure.
- Credible adverse media.
- Connected companies and business interests.
- Material inconsistencies between supplied information and independent records.
Due diligence cannot establish how a provider will behave in the future.
Its purpose is to improve the information available before an important commercial relationship begins.
Overseas Providers Can Add Complexity
The SEC case also involved a firm described by the OIG as being largely based overseas.
International outsourcing is routine and does not itself represent a concern. Businesses regularly appoint skilled providers in other jurisdictions.
Cross-border relationships can, however, make verification more complex.
Corporate information may be held differently from one country to another. Ownership records may be less transparent. Individuals may have business histories across several jurisdictions, while regulatory or litigation records may require local research.
Differences in business practices and legal frameworks may also matter depending on the service being provided.
Where an overseas third party will undertake sensitive, high-value or reputationally important work, the scope of due diligence may therefore need to reflect the jurisdictions involved.
Our guide to what due diligence involves for businesses and investors explains why the appropriate level of research should be proportionate to the decision being made.
Due Diligence Should Reflect the Provider's Role
Not every vendor represents the same level of exposure.
The degree of scrutiny should generally increase where a third party will:
- Represent the organization externally.
- Communicate with regulators or public authorities.
- Handle confidential or commercially sensitive information.
- Manage substantial payments.
- Operate in higher-risk jurisdictions.
- Make representations on the organization's behalf.
- Have significant discretion over how work is performed.
- Perform activities capable of creating regulatory or reputational consequences.
This is particularly important for specialist providers whose work may not be easily visible to the client on a day-to-day basis.
A professional-looking website, persuasive proposal or recommendation from another business may be useful information, but none necessarily provides a complete picture of the provider's ownership, background or previous conduct.
Independent verification can help test important representations before an appointment is made.
Due Diligence Is Only Part of Third-Party Risk Management
Pre-appointment checks should also be viewed as one component of a wider control framework.
Organizations may also consider clear contractual requirements, defined authority levels, approval procedures and appropriate oversight during the relationship.
That distinction matters because due diligence provides information about a third party at a particular point in time.
It cannot guarantee future behavior and should not be presented as doing so.
The objective is to identify information that may affect the decision to appoint a provider and allow any concerns to be examined before the organization becomes dependent on the relationship.
Where the work is particularly sensitive, changes in ownership, management, regulatory status or other material circumstances may also justify reconsidering the original risk assessment.
Know Who Is Acting on Your Behalf
The SEC OIG investigation is notable precisely because the entity concerned was reportedly unaware that its reputation management provider had created the fabricated court order.
That makes the case more relevant to third-party risk, not less.
Organizations can have legitimate objectives and still encounter problems if a provider chooses inappropriate methods to pursue them.
No due diligence process can prevent every instance of misconduct.
What it can do is help businesses understand the organizations and individuals they are appointing, verify important background information and identify matters that deserve closer examination before a third party is permitted to act on their behalf.
For significant vendor, consultant, agent or intermediary relationships, the question should therefore extend beyond what service is being purchased.
It should also include who is providing it, who controls the provider and what can independently be established about their background and business practices.