Loading
Updated September 23, 2026
Book a demo
Key takeaways
Vendor due diligence is the evidence a buyer gathers and verifies about a supplier before onboarding it for payment. It covers identity, ownership, sanctions screening, tax and insurance documents, and bank details, and the bank detail check is the one that prevents the most loss.
A new supplier is about to be set up in the payables system. Before any money can move, somebody has to establish that the supplier is a real business, that it is the business it claims to be, that paying it is lawful, and that the bank account on the form belongs to it.
That is vendor due diligence. It is the buy-side mirror of the credit checks a seller runs on a customer, and it asks a narrower question. A seller worries about whether a customer can pay. A buyer worries about whether the payee is who they say they are.
The term is borrowed from enterprise third-party risk management, where it carries a great deal of freight: questionnaires, control attestations, tiering models, annual reassessments. Most of that was designed for organisations with a risk function and thousands of suppliers. A finance team at a mid-market distributor onboarding forty vendors a quarter needs something a good deal shorter that still catches the things that actually cost money.
Step | What it produces |
|---|---|
Vendor due diligence | The verified evidence file. This page. |
Vendor risk assessment | A judgement about what that evidence means, a tier, and the controls that follow. |
Vendor onboarding | The whole process, including the approval, the master data setup and the payment terms. |
In a small team one person does all three in an afternoon and the distinction can feel like semantics. It stops being semantics after an incident, when the question is whether the evidence was gathered and verified, which is a different question from whether the risk was rated correctly.
Being clear about the threat model is what makes the rest of this page short.
The intuitive worry is that a vendor fails and cannot deliver. That happens, it is disruptive, and for most buyers it is not where the money goes. The money goes to payment diversion: a payment sent to an account that does not belong to the vendor.
The FBI's Internet Crime Complaint Center recorded 24,768 business email compromise complaints in its 2025 Internet Crime Report, with reported losses above $3.04 billion, inside a total of 1,008,597 complaints and $20.877 billion. Business email compromise is the category that covers a fraudulent instruction to change where a payment goes, and those are reported losses, so the real figure is higher.
Two structural features make this the dominant vector. The instruction usually arrives from a compromised or lookalike account belonging to a genuine supplier, so nothing about the vendor is fake. And the money moves before anyone notices, which makes recovery a matter of hours. Everything in the next section is ordered against that.
Four checks, none of them expensive, covering identity, legality, tax and the payment instruction. A buyer doing only these is in a materially better position than one with a forty-question survey and no callback procedure.
Beyond the four, what you collect should follow from what the vendor does for you.
The trap in this list is collecting all of it for every vendor. A landscaping contractor and a payroll processor do not need the same file, and a process that treats them identically will be abandoned within two quarters.
Formal tiering models assume a risk team. A workable substitute uses two questions.
First, how much will we pay this vendor in a year. Second, what happens to us if they stop or get it wrong. High on either puts the vendor in the smaller group that gets the full file and an annual review. Everything else gets the four checks and a light record.
That is cruder than a scoring matrix and it produces roughly the same sorting, because spend and dependency are what the matrices mostly measure anyway. The point is to have a defensible reason why one vendor got more scrutiny than another, which is what an auditor or an insurer will ask.
Diligence describes a vendor on the day it was done, and vendor records rot in ways customer records do not, because nobody is trading with the vendor daily.
Where a network of counterparties already holds verified vendor records, some of this becomes reusable rather than repeated; Nuvo's vendor network describes that model. The wider verification layer this sits inside is covered under KYB onboarding.
The check exists but nobody owns it. Bank verification written into a procedure and performed by whoever is free is performed inconsistently. Name the role.
Urgency defeats the process. Almost every diverted payment involves time pressure. A policy that allows no exception for urgency is easier to hold than one that allows a documented exception, because the documented exception is what gets requested.
Onboarding is treated as one-time. Most losses involve vendors who were onboarded correctly and changed later.
The file is collected but not read. A certificate that expired in March, filed in April, is worse than no certificate, because it creates the belief that the control is working.
Due diligence is gathering and verifying the evidence. Risk assessment is deciding what the evidence means and tiering the vendor accordingly. One produces a file, the other produces a rating and a set of controls. Small teams do both in one sitting, which is why the terms blur.
Verifying bank details by calling a number you already hold, confirming the legal entity exists and matches the name on the invoice, screening against sanctions lists, and collecting a signed W-9. Those four are cheap, fast and cover the failure modes that produce most of the money lost.
US persons are generally prohibited from dealing with blocked persons, and the obligation does not depend on company size or on having a compliance function. OFAC publishes the lists and a free search tool, so the check costs minutes. Take advice on how it applies to your business.
Sanctions screening on a schedule, because lists change and your file does not. Insurance certificates at expiry. Everything else on a cycle set by spend, with the highest-spend vendors reviewed annually. Any change of bank details triggers a full re-verification regardless of cycle.
For most vendors, no. A long questionnaire produces self-reported answers nobody verifies, which is documentation rather than diligence. Reserve them for vendors who will hold your data, have access to your systems, or whose failure would stop your operation.
Payment diversion. Someone changes the bank details on a real vendor's record, using an email that looks legitimate, and payments go to them instead. The FBI's 2025 report logged 24,768 business email compromise complaints and more than $3 billion in losses.