Vendor Verification

What “Know Your Vendor” Compliance Actually Requires: Beyond the W-9

Ashley Poynter

Content Manager and Avid Traveler, Paymentworks

Ask most AP teams what vendor compliance looks like, and they'll point to the W-9.

It's collected at onboarding. It's filed. It gets pulled out at 1099 time. And for most organizations, that's roughly where vendor compliance lives — a tax documentation requirement, managed annually, with a form as the evidence.

That's not a compliance program. It's a paperwork collection habit.

The W-9 is one input into vendor compliance, not the entirety of it. What know your vendor compliance actually requires in 2026 goes well beyond a signed form — and the organizations that don't know this are carrying more liability than they realize.

Ready to close the gap?

Book a Demo

What W-9 Collection Actually Confirms

Before going further, it's worth being precise about what a W-9 does and doesn't tell you.

A W-9 collects a vendor's legal name, taxpayer identification number, tax classification, and certification that the information is accurate. The vendor signs it, certifying under penalty of perjury that what they've submitted is correct.

What a W-9 does not do: authenticate the legal name against IRS records, confirm that the TIN matches the name, confirm that the person signing it is authorized to act on the entity's behalf, confirm that the entity is real and active, or tell you anything about the vendor's sanctions status.

The W-9 is a self-reported document. It's accurate when the vendor is legitimate and honest. It's inaccurate or fraudulent when they aren't. And there is no authentication built into the form itself.

For 1099 purposes, the IRS provides TIN matching tools precisely because W-9s are self-reported and TIN mismatches are common. The form is the starting point, not the authentication.


The Compliance Obligations That Go Beyond the W-9

Know your vendor compliance draws from multiple regulatory frameworks, and the W-9 is relevant to only one of them.

IRS and 1099 compliance. The W-9 feeds 1099 reporting, and the IRS requires that 1099s be issued with accurate TIN information. When TINs are wrong or missing, backup withholding requirements kick in and penalty exposure begins. But the W-9 alone doesn't ensure TIN accuracy — TIN matching does. Organizations that collect W-9s without running TIN authentication are meeting the form-collection requirement while skipping the step that actually protects them from compliance errors.

OFAC sanctions compliance. The Office of Foreign Assets Control requires US organizations to screen against its Specially Designated Nationals and Blocked Persons list before doing business with or making payments to any entity. This requirement is not satisfied by the W-9. It requires an active screening program: screening at onboarding, ongoing screening throughout the vendor relationship, and documented records of both.

The consequences of OFAC violations are severe — civil penalties, criminal exposure, and reputational damage. The documentation bar is high. "We would have caught it if we'd looked" is not a defense. An active, documented screening program is.

ACH and payment network compliance. ACH network rules establish originator obligations that include maintaining accurate and authenticated vendor payment data. When a payment is originated using fraudulent banking information, the liability analysis traces back to the authentication quality of that data. Originators with documented authentication processes are in a materially stronger position than those that can point only to a form submission.

Industry-specific and contractual requirements. Healthcare organizations operating under HIPAA, organizations subject to FCPA requirements, and those doing business with government entities may have additional vendor due diligence obligations layered on top of the baseline requirements above. Contractual requirements from customers, partners, or insurers may add further obligations.


What an Active Compliance Program Looks Like vs. What Most Organizations Have

The gap between a genuine compliance program and a compliance-adjacent collection of practices is larger than most organizations realize — and it shows up most clearly in three areas.

Ongoing vs. point-in-time screening. A compliance program screens continuously. A common practice screens at onboarding and stops. The practical difference: a vendor that was clean when you added them two years ago may be on the SDN list today. If your program only checked at onboarding, you've been paying a sanctioned entity without knowing it.

Authenticated vs. collected data. A compliance program confirms that the data it relies on is accurate. A common practice collects what vendors submit and trusts it. The practical difference: a TIN mismatch that TIN matching would have caught at onboarding becomes a 1099 error, a backup withholding failure, and potentially an IRS inquiry.

Documented vs. undocumented process. A compliance program produces records. A common practice produces outcomes. The practical difference: when a compliance question arises, documented processes can be reconstructed and defended. Undocumented processes produce answers like "we always do a check" — which is not the same as evidence that the check was done.


The OFAC Compliance Gap Most AP Teams Don't Know They Have

OFAC compliance deserves specific attention because the gap between what most organizations think they're doing and what OFAC actually requires is significant.

Many organizations run an OFAC check during vendor onboarding. Some run it annually. Very few run it continuously, with documented records of each screening cycle.

OFAC's expectation is a risk-based compliance program — one proportionate to the organization's risk profile — with documented policies, procedures, and records of screening. The SDN list is updated regularly, sometimes multiple times in a week. An organization screening quarterly is not running a continuous compliance program by any reasonable interpretation of that standard.

For AP teams, the practical implication is this: the OFAC check at onboarding is a start, not a program. A defensible OFAC compliance posture requires ongoing screening, documentation, and a clear escalation process for potential matches. Manual quarterly reviews don't produce that posture. Automated continuous screening does.


TIN Matching: The Compliance Step Most Organizations Skip

TIN matching is one of the most consistently underutilized compliance tools in AP operations.

The IRS provides TIN matching through its e-Services platform, allowing organizations to confirm that a vendor's name and TIN combination matches IRS records before issuing 1099s. The purpose is to catch exactly the problems that W-9 collection misses: incorrect TINs, name mismatches, and missing information.

When TIN matching isn't run, the first indication of a problem is often a 1099 that comes back with a TIN error, or an IRS B-Notice requiring backup withholding on future payments to that vendor. At that point, the administrative remediation, the backup withholding obligation, and the potential penalty exposure are already in motion.

Running TIN matching as part of the onboarding authentication process, rather than as a Q4 cleanup exercise, catches these problems at the point of entry. The vendor's information is authenticated against IRS records before they're activated for payment, and the compliance record reflects that.


The Compliance Documentation Problem

Here's a scenario that plays out in organizations with some frequency: a compliance audit or a fraud investigation asks for documentation of the vendor authentication process for a specific vendor. And the organization discovers that the documentation either doesn't exist, is incomplete, or is scattered across email threads, spreadsheet notes, and ERP comments that no one can easily reconstruct.

This is a documentation problem, not a compliance practice problem. The organization may well have done the right things. But if it can't show that it did, the compliance record is thin.

A genuine know your vendor compliance program produces documentation as a byproduct of the process itself, not as a separate effort at audit time. Every TIN match has a timestamped record. Every OFAC screening has a result and a date. Every banking authentication has a documented confirmation. Every vendor activation has a checklist that was completed, not just a habit that was followed.

This documentation doesn't require a massive manual effort. It requires a platform that produces it automatically as part of the authentication workflow.


What Compliance Looks Like When It's Working

When know your vendor compliance is genuinely operating, a few things are true.

TIN matching runs at onboarding, catches mismatches before vendor activation, and produces a dated record of the result. No vendor gets activated for payment with a TIN that doesn't match IRS records.

OFAC screening runs at onboarding and continuously thereafter. Potential matches get escalated through a defined process. The screening record shows every cycle, every result, and every escalation.

Banking information is authenticated through an independent process before vendor activation, and re-authenticated when it changes. The authentication record exists outside the ERP.

The documentation for each of these steps is maintained with timestamps, retained for the required period, and accessible for audit without a reconstructive effort.

When something goes wrong — a fraud attempt, a compliance question, an IRS inquiry — the organization can answer the relevant questions with records, not recollections.

That's not a complex standard. But it's meaningfully different from collecting W-9s and checking a box.


Know Your Vendor Compliance Beyond the Form

Know your vendor compliance requires more than a W-9. It requires TIN matching, active OFAC screening, documented authentication processes, and records that can be reconstructed and defended.

The organizations that treat vendor compliance as a form collection exercise are carrying liability that their processes don't protect against. The IRS B-Notice that comes from an unmatched TIN, the OFAC exposure from a vendor added to the SDN list after onboarding, the fraud loss from unauthenticated banking data: these are the costs of a compliance program that stops at the form.

The good news is the bar, while higher than most organizations currently meet, is reachable. It requires the right platform and the right process — not more staff and more manual work.


Get Ready For Vendor Management Appreciation Day

Vendor Management Appreciation Day (VMAD) returns this year—and we’d love to have you join the celebration. There’s never a wrong time to recognize one of the most essential yet often overlooked functions in every organization: vendor management.

We’re already preparing for this year's festivities, and we want the entire community to be part of it. VMAD was created to bring vendor management professionals together, spotlight the innovation happening in the field, and give this important work the recognition it deserves.

As a reminder, throughout the year, we’re rolling out monthly gifts and resources to help elevate your vendor management practice. We’re also planning a series of events designed to spark connection, learning, and celebration across the profession.

So, while you wait for the big day, explore what’s new—and grab some free vendor management goodies.


Want Help Aligning Teams?

Explore our blogs below. They’re filled with action items you can implement right away.

Why Supplier Verification Is the First Line of Defense Against Risk

What Is Business Identity? Why It Matters, and How to Get It Right

The Supplier Risk Assessment Process: A Step-by-Step Framework

Why Supplier Lifecycle Management Is the New Frontline of Cybersecurity


Interested in More Tips?

Subscribe to our blog


Want Personalized Guidance?

Contact Us–we’d love to help you

People Also Ask – Know Your Vendor Compliance FAQs

Are you interested in knowing more?

Contact Us

Know your vendor compliance requires meeting obligations across multiple regulatory frameworks, not just collecting a W-9. At minimum, it includes: IRS TIN matching to support accurate 1099 reporting, active OFAC screening against the Specially Designated Nationals list at onboarding and on an ongoing basis, authenticated vendor banking data to meet ACH originator obligations, and documented records of all of the above that can be produced for audit or investigation. Industry-specific requirements, contractual obligations, and state-level regulations may layer additional requirements on top of this baseline.

Let us show you how we can help

We’d love to walk through your process with you and talk about security, compliance, efficiency and sleeping better at night.

See How it Works