Vendor Onboarding Checklist: 10 Checks Before the First Payment
The first payment is the point of no return. Ten verification checks to run while a new vendor is still just paperwork — from registry lookups to banking callbacks.

In this list
- 1. Pull the registry record yourself
- 2. Match the tax ID to the legal name
- 3. Verify banking details by callback — before they enter the system
- 4. Ask for the certificate of insurance — then check it with the issuer
- 5. Screen against sanctions and watchlists
- 6. Look at the domain and email hygiene
- 7. Run every submitted document through forensic checks
- 8. Corroborate the physical footprint
- 9. Assign a risk tier, not just a green light
- 10. Re-verify on change, not on a calendar
- Frequently asked questions
Vendor fraud has a funny economics problem: almost all of the defense value is available before the first payment, and almost all of the actual checking happens after something goes wrong. Once money moves, you're in recovery territory — clawbacks, disputes, insurance claims, awkward calls. While the vendor is still paperwork, you hold every card.
So treat onboarding as the control point it is. Here are the ten checks, roughly in the order they pay off.
1. Pull the registry record yourself
Not the certificate the vendor sent — the live record, from the government registry. Confirm the exact legal name, active status, formation date, and registered officers. "Close enough" names are how lookalike vendors get in. The vendor's own paperwork tells you what they want you to see; the registry tells you what was filed. (Full sequence here: how to verify a company.)
2. Match the tax ID to the legal name
Whatever your jurisdiction's version is — W-9 and TIN matching in the US — run it. A tax ID that doesn't match the legal name is either sloppiness or a shell; both are worth knowing about before the relationship starts, not at 1099 season.
3. Verify banking details by callback — before they enter the system
Call the vendor on a number you found independently (registry, published directory — not the onboarding form) and confirm the account details verbally. Do it before the details are saved, because a banking record that enters the vendor master unverified becomes trusted by every downstream system forever. This is the same callback habit that protects against banking-change fraud later.
4. Ask for the certificate of insurance — then check it with the issuer
A COI is a one-page claim, not proof. Confirm with the issuing agency or carrier that the policy exists, is active, and actually covers the work you're hiring for. Fake and altered COIs are common enough that we wrote up what to look for separately.
5. Screen against sanctions and watchlists
Entity name, officers, and country. If you're in a regulated industry you already have to; if you're not, it's still ten minutes that prevents the worst headline your company can generate. Re-screen on a schedule, not just at onboarding — lists change.
6. Look at the domain and email hygiene
When was the vendor's domain registered, and does it predate their claimed history? Is the contact emailing you from that domain, or from a lookalike one letter off — or a free mailbox? A "procurement director" at meridian-supply.co when the company's site is meridiansupply.com is a flag with a documented history of costing money.
7. Run every submitted document through forensic checks
Registration certificates, COIs, bank letters, references — the onboarding packet is a stack of PDFs, and PDFs can be edited. An automated forensic pass catches files modified after creation, structures that don't match their claimed source, and the tells of template-built fakes — at intake, while declining is still cheap and painless.
8. Corroborate the physical footprint
Does the address resolve to real commercial premises? Does the phone line type match the business (a national distributor running entirely on a fresh VoIP number is a mismatch)? Does anything independent — map listings, business directories — agree this company operates where it says?
9. Assign a risk tier, not just a green light
Onboarding shouldn't end in "approved." It should end in "approved, tier 2" — because the vendor who'll invoice you $800 a quarter and the one who'll touch $2M a year don't deserve the same downstream treatment. Tier drives invoice thresholds, review frequency, and how much a banking change gets scrutinized later.
10. Re-verify on change, not on a calendar
The onboarding file is a snapshot; vendors drift. The events that should re-trigger checks: banking changes (always), legal name or ownership changes, a lapsed COI, and any sudden change in invoice pattern. Calendar-based re-reviews are fine as a backstop, but event-based re-verification is what actually catches things.
Frequently asked questions
How long should vendor onboarding take?
The checks themselves are fast — most of this list is minutes each, and several can run in parallel or as one automated pass. What takes days is chasing documents. A reasonable target: same-week onboarding for low-risk vendors, with the callback and insurance verification as the only genuinely serial steps.
Who should own vendor verification — procurement or AP?
Either works; both-and-neither fails. The pattern that breaks is procurement collecting documents nobody validates, while AP assumes procurement validated them. Name one owner for the checklist, give the other visibility, and make the banking callback a named person's job.
Do we need to re-run checks on existing vendors?
Run the cheap ones (registry status, sanctions, domain) across the existing master file once — you'll almost always find a few surprises — then switch to event-based re-verification. The vendor master file quietly accumulates risk precisely because everyone assumes it was checked on the way in.
Put it to the test
Scan a document and get a plain-English verdict in seconds. Free to start.
Keep reading
Purchase Order Fraud: Anatomy of a Fake PO
Invoice fraud targets the buyer; purchase order fraud targets the supplier. An illustrative look at how a fake PO ships goods on credit that will never be paid for — and where it breaks.
Reading the MRZ: How to Verify a Passport Like a Border Officer
Those two lines of angle brackets at the bottom of a passport are a built-in verification system. How the MRZ works, how to check its math, and where fakes get it wrong.
The Padlock Lies: What HTTPS Actually Proves
The padlock is the most misunderstood symbol on the internet. It certifies the pipe, not the shop — and almost every phishing page you will ever see has one.