Governance: Who Decides an Entity Is a Bad Actor¶
Principle 3 says the adopting company doesn't make this call itself. This document proposes a concrete mechanism for who does, and how. It is the piece of this framework adopters are most likely to want to tune to their own risk appetite — the defaults below are deliberately conservative starting points, not a claim that this is the only workable design.
1. The Reference Panel¶
Maintain a defined panel of independent human rights sources, split into two tiers:
Tier 1 — binding on their own. A finding from any one of these is sufficient for designation, because they already represent multilateral or judicial consensus: - UN Security Council sanctions list - UN Human Rights Council Commission of Inquiry findings (e.g., of genocide, crimes against humanity, war crimes) - International Criminal Court arrest warrants or convictions - Findings by UN treaty bodies or Special Rapporteurs naming a specific entity
Tier 2 — contributing sources. No single Tier 2 source triggers designation alone; they count toward the threshold in Section 2. Suggested starting panel (see reference/reference-organizations.md for detail):
- Business & Human Rights Resource Centre (allegation tracking)
- Amnesty International / Human Rights Watch (investigative reporting)
- Freedom House (Freedom in the World, Freedom on the Net)
- World Benchmarking Alliance — Corporate Human Rights Benchmark
- Ranking Digital Rights Corporate Accountability Index
- Global Network Initiative accountability assessments
- A reputable data aggregator (e.g., RepRisk) as a cross-check, not a primary source
Adopters should size this panel to their capacity to actually review it — a panel of 8–12 sources reviewed rigorously beats a panel of 30 reviewed superficially.
State-linked elevation (ICJ findings). The International Court of Justice doesn't appear in the Tier 1 list above because it has no jurisdiction to name individual or corporate entities — it only adjudicates disputes between states (contentious cases) and issues advisory opinions to UN organs. It therefore can't itself trigger a designation the way an ICC warrant or a UNSC listing can.
But an ICJ finding against a state — a contentious-case judgment or an advisory opinion addressing that state's conduct (e.g., a finding of genocide, or of an unlawful occupation) — is a Tier-1-strength signal about the state itself. When the ICJ has made such a finding, any entity substantially linked to the conduct addressed by that finding — the relevant government ministries and agencies, state-owned enterprises, and named officials — is automatically elevated to Tier 1 scrutiny for any transaction connected to that conduct, without needing separate Tier 2 corroboration.
This is a scoped elevation, not a blanket designation of the state's entire government: it applies only to entities and transactions substantially connected to the specific conduct the ICJ addressed, and it still passes through the notice-and-appeal process in Section 3 like any other non-Tier-1-sourced designation, since the ICJ finding is about the state, not the specific downstream entity.
2. Aggregation and threshold¶
An entity is designated a bad actor if any of the following is true:
- It is named by any Tier 1 source, or
- It is named by at least two Tier 2 sources, independently of each other (a single report syndicated across multiple outlets counts once), or
- It is named by one Tier 2 source where the underlying finding documents an egregious, well-evidenced violation (e.g., direct complicity in torture, mass surveillance of a protected group, forced disappearance) — routed through the fast-track review in Section 4 rather than the standard quarterly cycle.
This is an "N-of-M" design so that no single advocacy organization can unilaterally blacklist a counterparty, while a credible multilateral or judicial finding doesn't have to wait for corroboration.
3. Notice and appeal¶
Before a designation is finalized (Tier 1 findings excepted, since those already carry due process):
- The entity is notified and given a defined window (recommend 30 days) to respond with evidence.
- A response is reviewed by whoever the adopter designates as the appeals reviewer — ideally a function independent of the business relationship at stake (e.g., legal/compliance, not the deal team).
- Designations can be reversed on demonstrated remediation, not just on dispute of the underlying facts — an entity that stops the conduct and can show it has stopped should have a path back off the list.
4. Review cadence¶
- Quarterly: full refresh of the consolidated list against all panel sources.
- Ad hoc / fast-track: any Tier 1 finding, or a Section 2 egregious-violation trigger, is actioned within a defined short window (recommend 5 business days) rather than waiting for the quarterly cycle.
- Annual: review of the panel composition and thresholds themselves — sources merge, shut down, or lose credibility; thresholds that were right at launch may need adjusting.
5. Transparency¶
- Publish the designation criteria (this document) in full.
- Publish the current Reference Panel.
- Where legally and safely possible, publish the list of designated entities and the Tier 1/Tier 2 basis for each designation. Where publication would create safety risk (e.g., for the reporting sources), publish the aggregate count and category without naming underlying sources.
6. What this mechanism does not do¶
Designating an entity as a bad actor governs the relationship-level prohibitions in prohibited-actions/with-bad-actors.md. It does not replace an adopter's own product-level human rights due diligence under UNGP Pillar 2 — a "good actor" counterparty can still misuse a product in a way that causes harm. That residual risk is addressed separately in prohibited-actions/with-any-counterparty.md, which applies regardless of the counterparty's designation status.