Home › Analytics › Counterparty: How sources are cited – supply risk

Counterparty: How sources are cited – supply risk

When assessing supply-side risk in a counterparty, the reliability of any conclusion depends entirely on how the underlying sources are identified, weighted, and disclosed. A rigorous counterparty review does not treat all data equally: it distinguishes between primary registry-sourced facts, secondary compiled datasets. Additionally. Inference drawn from patterns. and it flags each category explicitly so that the reader can calibrate confidence accordingly. Understanding this citation logic is not an administrative formality; it directly determines whether a risk signal is actionable or merely directional.

Why source citation matters in supply-risk analysis

Supply risk assessments of counterparties sit at the intersection of legal due diligence and commercial intelligence. Unlike a clean title search. where the question is binary and the register authoritative – supply risk is built from a mosaic of sources, each with its own refresh cycle, coverage gap, and jurisdictional bias. A finding described without its source provenance can mislead in two directions: it may be treated as more certain than the underlying data warrants. Alternatively. It may be discarded as speculative when it is in fact well-grounded.

The baseline principle applied at Ferraz & Whitmore is that every material fact cited in a counterparty supply-risk review carries an explicit source label, one of three tiers:

  • Primary (registry-grade): data extracted directly from an official public register, regulatory filing system, or court record. Examples include commercial registry extracts, insolvency court filings, official gazette publications, and regulatory sanction lists. These sources are cited by institution name and, where applicable, the specific register or bulletin number. Because access protocols and update frequencies differ by jurisdiction, the extraction date is always noted alongside the institution.
  • Secondary (compiled datasets): data aggregated from primary sources by a recognised third-party provider – credit bureaus, trade credit insurers' shared databases, industry association filings, or customs and trade statistics platforms. Secondary sources are cited by provider category rather than by commercial brand, because provider relationships vary by engagement. The key metadata disclosed is the dataset's stated coverage scope and the lag between primary-source events and dataset reflection.
  • Inferential (pattern-based): conclusions drawn by combining multiple data points where no single authoritative source directly establishes the finding. Supply concentration, sub-supplier dependency chains, and payment-behaviour trends inferred from invoice timing are typical inferential findings. These are always labelled as such, with the constituent inputs listed and the analytical logic stated.

How primary sources are accessed and cited for supply risk

The supply dimension of counterparty risk draws on primary sources that differ somewhat from those used in ownership or litigation checks. The core institutions consulted include the following.

Commercial and corporate registries establish the legal existence, registered capital, and statutory officers of the entity and, critically, of its disclosed suppliers where those relationships appear in contract annexes or public procurement filings. When a counterparty's supply chain includes entities registered in multiple jurisdictions, each jurisdiction's registry is consulted and cited separately. The citation format names the registry authority and the date of the extract; it does not reproduce authentication codes or access credentials.

Insolvency and restructuring registers are consulted to identify whether key suppliers or the counterparty itself has entered any formal insolvency procedure, moratorium, or court-supervised restructuring plan. In Portugal, the Citius judicial information platform surfaces insolvency proceedings; equivalent registers exist across EU member states under the interconnected insolvency register (IRI) framework. Citations reference the registry name and the search date, not the portal login path.

Regulatory and sanction lists relevant to supply risk include export control lists, sectoral regulatory blacklists, and anti-dumping measures that may restrict the counterparty's ability to import critical inputs or export finished goods. These are cited by issuing authority – for example, the European Commission's consolidated financial sanctions list, or the relevant national competent authority – with the version date of the list consulted.

Official gazette and procurement databases provide evidence of the counterparty's trading history, public contract awards, and, in some jurisdictions, mandatory disclosure of major supplier relationships. In Portugal, the Base public procurement portal and the Diário da República are the primary instruments. These are cited by publication reference where one exists.

Customs and trade statistics at the aggregate level – published by Eurostat, national statistics offices, or WTO data services – are used to contextualise sector-level supply concentration and import dependency. These are cited as statistical sources, not as evidence of the specific counterparty's transactions, which are generally not publicly accessible at individual entity level.

How secondary and compiled sources are handled

Secondary sources introduce a lag and a coverage assumption that must be disclosed. The two most common secondary source types in supply-risk work are trade credit data and logistics performance indicators.

Trade credit and payment behaviour data come from shared databases maintained by credit reference agencies or trade credit insurance pools. These datasets aggregate payment experience reported by suppliers. When used, the review discloses the dataset category, the stated geographic and sector coverage, and the reporting lag – typically the period between a payment event and its appearance in the dataset. If the dataset does not cover the counterparty's primary jurisdiction or sector, that gap is flagged explicitly rather than silently omitted.

Logistics and operational performance indicators. port congestion data, shipping lane reliability indices, and cross-border customs clearance statistics – contextualise whether supply disruption risk is structural to the counterparty's sourcing geography or idiosyncratic to the entity. These are cited as published indices with the issuing body named, and findings derived from them are always classified as inferential rather than primary.

News and media monitoring is used selectively and is always classified as secondary or inferential. A regulatory action first reported in trade press before appearing in an official register is cited as a media source with the caveat that official confirmation is pending. The review does not suppress media-sourced findings simply because they lack registry confirmation, but it labels them clearly so the reader can assign appropriate weight.

What the citation model does not cover – and why

Transparent citation also requires honest disclosure of what is structurally inaccessible. Several categories of supply-risk information are not available through public or compiled sources, regardless of diligence effort.

Sub-tier supplier relationships – the counterparty's own suppliers' suppliers – are generally not visible in public filings unless the counterparty has made voluntary disclosures under supply chain transparency legislation or sustainability reporting frameworks. Where such disclosures exist, they are cited; where they do not, the review states the visibility boundary explicitly rather than inferring sub-tier structure.

Proprietary contract terms governing supply exclusivity, minimum volume commitments, or force majeure triggers are not accessible through registries or public databases. A counterparty analysis can note the absence of visible long-term supply agreements in public procurement databases, but it cannot reconstruct confidential commercial terms. This boundary is stated as a scope limitation, not glossed over.

Real-time operational disruptions – a factory shutdown, a logistics bottleneck, or a sudden input shortage – may not yet have generated a registry-grade record at the time of analysis. Supply-risk analysis therefore distinguishes between the structural risk profile (visible through registries and compiled data) and the current operational state (which requires direct counterparty engagement or field intelligence to assess).

Practical implications: what to do with cited findings

Understanding the citation tier of each finding shapes how it should be used in commercial and legal decision-making.

Primary-sourced findings are suitable as a basis for contractual representations and warranties, for material adverse change clauses tied to registry-recorded events, and for regulatory compliance documentation. Their evidentiary weight is high, subject to the extract date.

Secondary-sourced findings are appropriate for negotiating credit terms, structuring payment security mechanisms, or calibrating the financial thresholds in supply disruption clauses. They are not, on their own, suitable for judicial proceedings without corroboration from primary sources.

Inferential findings should trigger further due diligence rather than immediate contractual action. They are most valuable as a prioritisation tool: they identify which aspects of a supply relationship warrant deeper investigation, direct engagement with the counterparty, or contractual protections against specifically identified risk vectors.

In cross-border supply chains – which increasingly define the risk landscape for transactions involving Portuguese-registered entities and their European partners – the citation model also serves a coordination function. When multiple advisers in different jurisdictions are each contributing registry extracts, the shared citation framework ensures that findings can be compared, gaps identified, and contradictions resolved without each party having to reconstruct the other's methodology.

How to engage Ferraz & Whitmore on counterparty source questions

If you are preparing for a significant commercial transaction, a supplier onboarding process. Alternatively, a dispute in which a counterparty's supply-side resilience is material. The citation logic underlying your due diligence package will be scrutinised. by your legal team, by your counterpart. Additionally, potentially by a court or regulator. Gaps in source provenance, unexplained inferential leaps, or undisclosed dataset limitations can undermine findings that are otherwise well-founded.

Ferraz & Whitmore advises clients on structuring counterparty due diligence to meet the evidentiary standards applicable to their specific transaction type and jurisdiction mix. Our legal analysts identify which source categories are available and authoritative for the relevant counterparty, map the gaps that require direct engagement or contractual mitigation. Additionally. Produce documented findings that distinguish clearly between what is registry-verified, what is compiled-data-supported, and what is inferred. Enquiries can be directed to info@ferrazwhitmore.com or through our contacts page.

For broader context on the legal framework governing counterparty risk in commercial relationships, the Analytics section of this site addresses related topics including cross-border due diligence methodology, sanctions screening protocols, and supply chain contractual structures.

Disclaimer: This article is provided for general informational purposes only and does not constitute legal advice. The sourcing practices and source categories described reflect general methodological principles and do not represent a commitment regarding the specific sources available for any particular counterparty, jurisdiction, or engagement. No attorney-client relationship is created by reading this material. For advice tailored to your specific situation, please contact Ferraz & Whitmore directly.

Reviewed by
Legal Analyst · Western Europe