ListMay 15, 2026by Docurensic Team4 min read

Vendor Onboarding Checklist: 10 Checks Before the First Payment

The first payment is the point of no return. Ten verification checks to run while a new vendor is still just paperwork — from registry lookups to banking callbacks.

Vendor Onboarding Checklist: 10 Checks Before the First Payment
In this list
  1. 1. Pull the registry record yourself
  2. 2. Match the tax ID to the legal name
  3. 3. Verify banking details by callback — before they enter the system
  4. 4. Ask for the certificate of insurance — then check it with the issuer
  5. 5. Screen against sanctions and watchlists
  6. 6. Look at the domain and email hygiene
  7. 7. Run every submitted document through forensic checks
  8. 8. Corroborate the physical footprint
  9. 9. Assign a risk tier, not just a green light
  10. 10. Re-verify on change, not on a calendar
  11. Frequently asked questions

Vendor fraud has a funny economics problem: almost all of the defense value is available before the first payment, and almost all of the actual checking happens after something goes wrong. Once money moves, you're in recovery territory — clawbacks, disputes, insurance claims, awkward calls. While the vendor is still paperwork, you hold every card.

So treat onboarding as the control point it is. Here are the ten checks, roughly in the order they pay off.

1. Pull the registry record yourself

Not the certificate the vendor sent — the live record, from the government registry. Confirm the exact legal name, active status, formation date, and registered officers. "Close enough" names are how lookalike vendors get in. The vendor's own paperwork tells you what they want you to see; the registry tells you what was filed. (Full sequence here: how to verify a company.)

Whatever your jurisdiction's version is — W-9 and TIN matching in the US — run it. A tax ID that doesn't match the legal name is either sloppiness or a shell; both are worth knowing about before the relationship starts, not at 1099 season.

3. Verify banking details by callback — before they enter the system

Call the vendor on a number you found independently (registry, published directory — not the onboarding form) and confirm the account details verbally. Do it before the details are saved, because a banking record that enters the vendor master unverified becomes trusted by every downstream system forever. This is the same callback habit that protects against banking-change fraud later.

4. Ask for the certificate of insurance — then check it with the issuer

A COI is a one-page claim, not proof. Confirm with the issuing agency or carrier that the policy exists, is active, and actually covers the work you're hiring for. Fake and altered COIs are common enough that we wrote up what to look for separately.

5. Screen against sanctions and watchlists

Entity name, officers, and country. If you're in a regulated industry you already have to; if you're not, it's still ten minutes that prevents the worst headline your company can generate. Re-screen on a schedule, not just at onboarding — lists change.

6. Look at the domain and email hygiene

When was the vendor's domain registered, and does it predate their claimed history? Is the contact emailing you from that domain, or from a lookalike one letter off — or a free mailbox? A "procurement director" at meridian-supply.co when the company's site is meridiansupply.com is a flag with a documented history of costing money.

7. Run every submitted document through forensic checks

Registration certificates, COIs, bank letters, references — the onboarding packet is a stack of PDFs, and PDFs can be edited. An automated forensic pass catches files modified after creation, structures that don't match their claimed source, and the tells of template-built fakes — at intake, while declining is still cheap and painless.

8. Corroborate the physical footprint

Does the address resolve to real commercial premises? Does the phone line type match the business (a national distributor running entirely on a fresh VoIP number is a mismatch)? Does anything independent — map listings, business directories — agree this company operates where it says?

9. Assign a risk tier, not just a green light

Onboarding shouldn't end in "approved." It should end in "approved, tier 2" — because the vendor who'll invoice you $800 a quarter and the one who'll touch $2M a year don't deserve the same downstream treatment. Tier drives invoice thresholds, review frequency, and how much a banking change gets scrutinized later.

10. Re-verify on change, not on a calendar

The onboarding file is a snapshot; vendors drift. The events that should re-trigger checks: banking changes (always), legal name or ownership changes, a lapsed COI, and any sudden change in invoice pattern. Calendar-based re-reviews are fine as a backstop, but event-based re-verification is what actually catches things.

Frequently asked questions

How long should vendor onboarding take?

The checks themselves are fast — most of this list is minutes each, and several can run in parallel or as one automated pass. What takes days is chasing documents. A reasonable target: same-week onboarding for low-risk vendors, with the callback and insurance verification as the only genuinely serial steps.

Who should own vendor verification — procurement or AP?

Either works; both-and-neither fails. The pattern that breaks is procurement collecting documents nobody validates, while AP assumes procurement validated them. Name one owner for the checklist, give the other visibility, and make the banking callback a named person's job.

Do we need to re-run checks on existing vendors?

Run the cheap ones (registry status, sanctions, domain) across the existing master file once — you'll almost always find a few surprises — then switch to event-based re-verification. The vendor master file quietly accumulates risk precisely because everyone assumes it was checked on the way in.

Put it to the test

Scan a document and get a plain-English verdict in seconds. Free to start.

Start scanning free

Keep reading

Case studyJul 01, 20264 min

Purchase Order Fraud: Anatomy of a Fake PO

Invoice fraud targets the buyer; purchase order fraud targets the supplier. An illustrative look at how a fake PO ships goods on credit that will never be paid for — and where it breaks.

ArticleJul 27, 20266 min

The Padlock Lies: What HTTPS Actually Proves

The padlock is the most misunderstood symbol on the internet. It certifies the pipe, not the shop — and almost every phishing page you will ever see has one.