Due Diligence on an EU Project Partner Using Only Open Data: A Working Method

4 August 2026

You can verify most of what a prospective partner claims about their EU project history in under an hour, using three public sources: CORDIS for Horizon Europe and the earlier framework programmes, the Erasmus+ project results platform for Erasmus+ actions, and the participant register on the EU Funding and Tenders portal. Together they show whether the organisation exists as described, what it has taken part in, in what role, and alongside whom. What they cannot show is how well it delivered, which is why the method ends with first-call questions, not a database query.

The three sources and what each one covers

  • CORDIS covers the framework programmes: Horizon Europe, Horizon 2020 and their predecessors. Each project page lists the consortium, roles, dates, funding and reported results.
  • The Erasmus+ project results platform covers Erasmus+ actions, most of which never appear in CORDIS; project cards show coordinator, partners and uploaded results.
  • The participant register on the Funding and Tenders portal is the identity layer: it confirms a legal entity with a given Participant Identification Code (PIC) exists, where it is registered and in what form.

Three questions to answer before the mandate letter is signed

A mandate letter commits your consortium to this partner for the life of the proposal and usually the project. Before anyone signs, answer three questions from sources other than the partner's own slide deck.

  • Is this the legal entity I think it is? Registered name, country, legal form and a PIC that matches all three.
  • What has it actually done? Which programmes, how many projects, in which role: coordinator, beneficiary or associated partner.
  • Does its self-description match the record? That gap is where partner problems announce themselves early.

Open data answers the first two directly and the third by comparison.

Walkthrough: tracing one organisation across the records

Step 1. Ask the partner for their PIC and registered legal name, not the brand name on the website. Every organisation that has applied to a centrally managed EU programme has a PIC. Look it up in the participant register and confirm country, legal form and validation status. If the PIC does not exist, or belongs to a differently named entity, stop and ask why.

Step 2. Search CORDIS for the organisation: PIC where possible, then legal name, then variants. Names in the data rarely match names on websites: expect the legal name in the national language, an English translation, an acronym and sometimes a transliteration. A Greek university can appear under its Greek, romanised and English names in different projects.

Step 3. Search again for near-duplicates. Large institutions often hold several identifiers: departments registered separately, a PIC from before a merger, a new record after a rename. Building ingestion pipelines over this data, we found that treating each raw record as a distinct organisation splits one strong track record into several weak-looking ones. If your candidate looks thinner than expected, search by address and acronym before concluding anything.

Step 4. Repeat on the Erasmus+ project results platform, filtering by organisation, and read the project cards: role, dates, partners, results.

Step 5. Note the lag. Recently signed grants take time to surface; the platforms update on their own schedules, not in real time. An empty recent year is often a data artefact rather than a gap in activity.

Reading the pattern: roles, programmes, repeat partners

A raw project list tells you less than its shape. Three patterns matter.

Coordinator versus partner history. Coordinating is a different job from participating: consolidating budgets, filing consortium-level reports, chasing every partner for timesheets. An organisation with a long partner history and no coordinations is a solid partner and an unproven coordinator. If they propose to coordinate, the record should show they have done it before, at comparable scale.

Programme spread. A record built only from small-scale partnership actions says little about surviving a Horizon Europe reporting cycle. Participation across programmes and action types shows an organisation that has adapted to more than one rulebook.

Repeat collaborations. The strongest positive signal open data offers is being invited back. When the same coordinator includes the same partner in successive projects, someone with direct delivery experience keeps choosing them. For vetting purposes, re-invitation is the closest open data gets to a reference.

Red flags the data surfaces, and the false alarms it generates

Genuine red flags:

  • Claims the record contradicts: a partner presenting itself as an experienced coordinator whose name appears only as a beneficiary, or not at all.
  • An abrupt stop: steady participation that ends across all programmes at once. There are innocent explanations, but you want to hear one.
  • A trail of entities: the same team appearing behind several successive legal bodies, each with a short record.
  • A website project list that public data cannot corroborate at all.

False alarms, all of which we have hit in our own pipelines:

  • Renames and mergers: the record exists under the previous name.
  • Department versus parent: the work sits under the central university PIC while the institute you are talking to markets it.
  • Lag: recent projects are simply not published yet.
  • Nationally managed actions: some Erasmus+ actions are documented more thinly than centrally managed ones; thin is not absent.
  • Roles the data never records: subcontractors and third parties do real work and never appear in partner lists.

The rule that keeps you honest: a red flag found in open data is a question for the first call, not a verdict.

What open data cannot tell you, and what to ask instead

Open data records participation, not performance. It will not say whether deliverables arrived on time, whether reporting was clean, whether the people who earned the record still work there, or whether the organisation can carry costs between prefinancing instalments. Those gaps define the first call. Ask:

  • Who from your team worked on the projects we found, and who would work on this one?
  • How did your last periodic report go: any suspensions, recoveries or extended payment delays?
  • Which coordinator you have worked with can we call?
  • How do you bridge the financial gap between reporting periods?
  • Who inside your organisation owns timesheets and financial reporting?

An experienced partner answers these in minutes and usually volunteers the war stories; answers that redirect you to the slide deck tell you what the databases could not.

A vetting checklist to run in an afternoon

  • Collect the PIC and registered legal name from the partner.
  • Confirm both in the participant register, with country and validation status.
  • Pull the CORDIS participation list; search name variants and near-duplicates before judging the record's size.
  • Pull the Erasmus+ project results list the same way.
  • Tally roles per programme: coordinator, beneficiary, partner.
  • List repeat co-partners and note who keeps re-inviting them.
  • Compare everything against the partner's own bio and website; write down every mismatch.
  • Turn the mismatches into first-call questions and hold the call before circulating the mandate letter.

If the record and the call agree, sign. If they disagree, you have found out at the cheapest possible moment. This is the manual version of checks we run continuously in our own partner intelligence work.

FAQ: is a partner with no EU track record automatically a risk?

No. An empty record is absence of evidence, not evidence of a problem, and every experienced organisation in these databases started from zero. Track records also travel with people: a newcomer staffed by people who delivered EU projects elsewhere carries more real experience than its PIC suggests, so read CVs alongside the databases. Look for national funding, foundation grants or commercial delivery instead, and size the newcomer's role to its capacity, anchored by an experienced coordinator. The real risk case is the partner who claims a record the data contradicts. Honest inexperience is a design constraint; misrepresented experience is a reason to walk away.

Where this comes from

This method is distilled from building our consortium graph, which links 114,731 organisations across 83,490 projects using CORDIS and Erasmus+ open data from the 2014-2027 programming periods. Deduplicating name variants and reconciling identifiers at that scale is where we met every quirk described above. We also operate community platforms such as Impactful, so we see delivery from the operational side too.