Vendor Verification

The Know Your Vendor Checklist: How to Authenticate Vendor Identity Before the First Payment

Ashley Poynter

Content Manager and Avid Traveler, Paymentworks

Most AP teams have some version of a vendor setup process. What most don't have is a vendor authentication process.

The difference matters more than it might seem. A setup process gets a vendor into the system. An authentication process confirms that the vendor is who they say they are, that their payment data is accurate, and that the person who submitted it was authorized to do so. The first is a workflow. The second is a control.

This checklist is built around the second. It's designed for finance and procurement teams that want to close the gap between collecting vendor data and actually knowing who they're paying, before the first payment goes out.

Work through each section. Where you find gaps, you've found risk.

Ready to close the gap?

Book a Demo

Before You Start: The Right Frame

A vendor authentication checklist isn't a one-time project. It's a standard that applies to every new vendor and, ideally, to periodic review of your existing vendor base.

The goal is not to create bureaucratic friction. It's to ensure that every vendor activated in your payment system has gone through a documented authentication process, one that can be reconstructed if a fraud event occurs or a compliance question arises.

With that in mind, here's what a complete vendor authentication process actually looks like.


This is the foundation. Before any payment data is collected or authenticated, confirm that the legal entity itself is legitimate.

Confirm the legal name matches IRS records. The name on the W-9 should match exactly what's registered with the IRS. Mismatches, even minor ones, can indicate data entry errors, operating name confusion, or fraud. Don't assume a close match is a clean match.

Run TIN matching before vendor activation. The IRS offers TIN matching tools, and most vendor identity authentication platforms automate this step. A TIN that doesn't match the legal name in IRS records is a hard stop, not a flag to review later.

Check for entity existence and status. For businesses, confirm the entity is registered and active in the relevant jurisdiction. Shell companies and dissolved entities can pass a basic data review. A quick check against state business registration records catches problems that a W-9 alone won't surface.

Identify beneficial ownership where appropriate. For higher-risk vendors or higher-value relationships, understanding who actually controls the entity matters. Ownership structures can obscure sanctions exposure that a direct name check wouldn't catch.

Document the authentication. Every step in legal entity authentication should be documented with a timestamp. If this authentication is ever challenged, "we checked" is not a sufficient record. "We ran TIN matching on [date], result [clean/mismatch], reviewed by [person]" is.

Section 2: Banking Information Authentication

Banking data is the most targeted information in any vendor record. It gets its own section because it deserves more rigorous treatment than most organizations currently give it.

Authenticate the banking details through an independent channel. Accepting banking information via email or a submitted form and entering it into the ERP is not authentication. Authentication means confirming the routing number and account number combination through an independent process, one that doesn't rely solely on trusting the submission.

Confirm the account belongs to the vendor. A routing number that resolves to a real financial institution doesn't mean the account belongs to the vendor. The account authentication process should confirm the relationship between the account and the entity, not just the validity of the numbers.

Document the banking authentication process. Who collected the banking information, through what channel, what authentication steps were taken, and when. This documentation is what distinguishes a defensible process from a vulnerable one when fraud is investigated.

Do not activate a vendor for payment without completed banking authentication. This seems obvious. In practice, deadline pressure, incomplete submissions, and workflow shortcuts mean vendors routinely get activated before banking authentication is complete. Make completion of banking authentication a hard prerequisite for payment activation.

Treat banking information with elevated access controls. Who can view, enter, and modify banking information in your system? That list should be short, access should be logged, and changes should require secondary approval. Banking data is not general vendor data — it's the highest-risk field in the record.

Section 3: Sanctions and Watchlist Screening

Sanctions screening at onboarding is required. Ongoing sanctions screening is what a compliance program actually looks like.

Run OFAC screening before vendor activation. Screen the legal entity name, any doing-business-as names, and beneficial ownership against OFAC's Specially Designated Nationals list. Document the result with a timestamp.

Screen against additional relevant watchlists. Depending on your industry and vendor base, relevant watchlists may include the BIS Denied Persons List, state-level debarment lists, and sector-specific exclusion lists. Know which lists apply to your organization and screen against them.

Do not treat onboarding screening as a compliance program. A vendor that was clean at onboarding may not be clean six months later. Ongoing sanctions screening, running continuously against your active vendor base and flagging changes, is what distinguishes an active compliance program from a point-in-time check. The difference matters to regulators.

Document your screening cadence and results. If a compliance question arises, you need to show not just that you screened at onboarding, but that you maintained an active screening program. That requires records: what you screened, when, against which lists, and what the results were.

Section 4: Submission Legitimacy

This is the authentication step most organizations skip entirely, and it's the one that BEC attacks exploit.

Confirm that the person submitting vendor data is authorized to do so. Receiving a W-9 from an email address associated with the vendor is not confirmation of authorization. Someone with access to that email address, or a convincing spoofed version of it, can submit a W-9. Authorization confirmation means reaching the vendor through an independent channel to confirm that the submission is legitimate.

Use out-of-band confirmation for banking data specifically. For any banking information submission, confirm through a channel independent of the one used to submit it. Phone call to a number already on file, not a number provided in the email. Video call. A confirmation through the vendor's authenticated profile in your vendor identity platform.

Apply the same standard to updates as to initial submissions. A banking change request carries the same risk as an initial banking submission, and should go through the same authentication process. In many organizations, initial onboarding has more scrutiny than subsequent updates. That imbalance is a fraud invitation.

Flag and escalate unusual submission patterns. New vendor setup requests arriving just before a large payment is due. Banking change requests immediately following a new contact at the vendor. Submissions from slightly different email domains than the vendor's primary address. These patterns warrant additional scrutiny, not routine processing.

Section 5: Ongoing Monitoring

Authentication at onboarding is the starting point. Vendor knowledge requires maintaining it.

Monitor for banking data changes. Any change to a vendor's banking information should trigger re-authentication before the updated data is available to the payment system. The update workflow should be at least as rigorous as the initial authentication process.

Monitor for ownership and entity changes. Vendors get acquired, restructure, change beneficial ownership, and sometimes cease to exist as legal entities while remaining active in ERPs. Periodic review of active vendors against current entity records catches problems that onboarding authentication alone won't surface.

Maintain continuous sanctions screening. As discussed above: ongoing, documented, against relevant lists. Not just at onboarding.

Give vendors visibility into their own records. Vendors who can see what data you have on file for them, and who receive notifications when their data changes, are a detection mechanism for unauthorized modifications. If your current system doesn't provide this, vendor-owned profile infrastructure does.

Establish a periodic re-authentication cadence. For high-value or high-volume vendor relationships, periodic re-authentication of banking data and entity status, even without a specific triggering event, is good practice. Annual re-authentication for your top vendors is a reasonable baseline.

Section 6: Documentation and Audit Readiness

Everything above is more valuable when it's documented. Documentation is what turns a process into a defensible record.

Maintain authentication records outside the ERP. ERP data can be changed. An independent record of what was authenticated, when, and what the result was, maintained outside the system that manages vendor payments, creates a reference point that survives manipulation.

Ensure your audit trail captures the full authentication history. Not just the current state of vendor data, but every change, every authentication step, every approval, and every timestamp. When a fraud event occurs or a compliance question arises, this history is what investigators need.

Know your documentation retention requirements. IRS requirements, ACH rules, and OFAC regulations each have documentation retention standards. Know what they are and ensure your authentication records meet them.

Test your documentation regularly. Could you reconstruct the authentication history for your top 10 vendors right now? Walk through it. Find the gaps before an auditor or investigator does.


The Checklist at a Glance

For quick reference, here are the core authentication requirements across all six sections:

•       Legal name confirmed against IRS records

•       TIN matching completed and documented before vendor activation

•       Entity existence and status confirmed

•       Banking information authenticated through independent channels

•       Banking account ownership confirmed

•       OFAC and relevant watchlist screening completed and documented

•       Submission legitimacy confirmed through out-of-band authentication for banking data

•       Ongoing sanctions screening in place and documented

•       Banking change re-authentication process established

•       Vendor profile visibility available to the vendor

•       Authentication records maintained outside the ERP

•       Periodic re-authentication cadence established for high-value vendors

If any of these items doesn't have a clean "yes, documented, consistent" answer for your organization, you have a gap worth closing before the first payment to the next new vendor goes out.


Know Your Vendor Checklist in Practice

A vendor authentication checklist is not a bureaucratic exercise. It's the operational translation of what "know your vendor" actually means in practice.

The fraud patterns that most commonly hit AP teams, BEC targeting banking changes, fraudulent vendor setup, ghost vendor payments, all have documented authentication steps that would have caught them. The organizations that work through this checklist and close the gaps they find are the ones that don't learn what "know your vendor" means by having their payment security tested.


Get Ready For Vendor Management Appreciation Day

Vendor Management Appreciation Day (VMAD) returns this year—and we’d love to have you join the celebration. There’s never a wrong time to recognize one of the most essential yet often overlooked functions in every organization: vendor management.

We’re already preparing for this year's festivities, and we want the entire community to be part of it. VMAD was created to bring vendor management professionals together, spotlight the innovation happening in the field, and give this important work the recognition it deserves.

As a reminder, throughout the year, we’re rolling out monthly gifts and resources to help elevate your vendor management practice. We’re also planning a series of events designed to spark connection, learning, and celebration across the profession.

So, while you wait for the big day, explore what’s new—and grab some free vendor management goodies.


Want Help Aligning Teams?

Explore our blogs below. They’re filled with action items you can implement right away.

Why Supplier Verification Is the First Line of Defense Against Risk

What Is Business Identity? Why It Matters, and How to Get It Right

The Supplier Risk Assessment Process: A Step-by-Step Framework

Why Supplier Lifecycle Management Is the New Frontline of Cybersecurity


Interested in More Tips?

Subscribe to our blog


Want Personalized Guidance?

Contact Us–we’d love to help you

People Also Ask – Know Your Vendor Checklist FAQs

Are you interested in knowing more?

Contact Us

A complete know your vendor checklist should cover six areas: legal entity authentication (TIN matching, entity existence, beneficial ownership), banking information authentication (independent channel confirmation, account ownership confirmation), sanctions and watchlist screening (OFAC and relevant lists, both at onboarding and ongoing), submission legitimacy (out-of-band confirmation that the submitter is authorized), ongoing monitoring (banking change re-authentication, continuous sanctions screening, entity status monitoring), and documentation (independent audit trails, retention compliance, periodic re-authentication for high-value vendors).

Let us show you how we can help

We’d love to walk through your process with you and talk about security, compliance, efficiency and sleeping better at night.

See How it Works