procurement

Vendor onboarding

PROFESSIONALEstimated read: 11 min· Updated 2026-06-05

Vendor onboarding

ProfessionalAdmin

Vendor onboarding is the gate every supplier passes through before the workspace can transact with them. Skip it and the cost is real: fraudulent banking details, double payments to colluding suppliers, regulatory violations on sanctioned-party transactions, or simply a tax filing the workspace can't reconcile because the W-9 was never collected. The onboarding flow stages the supplier through identity → qualification → tax + banking → sanctions → approval, with each step's evidence attached so the supplier file is audit-ready from day one.

TL;DR — Open Procurement → Vendors → New vendor. Capture identity, send the vendor self-service intake to the supplier (they fill in tax + banking themselves), run sanctions screening, approve. The vendor is now active for POs.

Before you start

  • Confirm why you need this vendor — a single-purchase exception or an ongoing relationship. Single-purchase one-offs may use a lightweight onboarding path (with restrictions on total spend).
  • Have the supplier's business name, tax ID, primary contact, remit-to address. The vendor-self-service form will collect banking + tax docs from the supplier directly so the workspace doesn't hold the data in an email thread.
  • Plan for a sanctions screening failure to be the most common gate. Names match across the global lists more often than people expect; manual review usually clears them, but budget the time.

Stage 1 — Identity

  1. Open Procurement → Vendors → New vendor

    The intake form opens.

  2. Capture business identity

    Legal name, DBA, business type (corp / LLC / partnership / sole prop / non-profit / government), state of formation, primary contact name + email + phone.

  3. Run a duplicate-vendor check

    The platform searches for matching names + tax IDs across active + inactive vendors. Duplicates are a major fraud vector and a finance headache; reuse the existing record when match is real.

  4. Pick the vendor type

    Standard supplier / one-time / employee reimbursement (for employees paid as vendors for documented purposes) / intercompany / government. Each carries different defaults

    • approval thresholds.
  5. Save as Draft

    The vendor enters Draft status. You can now send the self-service invite to the supplier.

Stage 2 — Qualification

Qualification asks "is this supplier suitable to deal with for this category of spend?" The workspace decides which categories require what level of qualification — minimum bar is usually financial stability + insurance + relevant certifications.

FieldWhat it doesAccepted values / default
Financial stabilityCan the supplier deliver on commitments?D&B / Equifax report / financial statements (for material spend); summary attached, full report retained.
Insurance certificatesGeneral liability, workers' comp, professional liability where applicable.Captured at onboarding; expiry-tracked with automatic renewal reminders.
Relevant certificationsIndustry-specific (ISO 9001, SOC 2, GMP, FSC, etc.).Captured per category; the platform alerts when expiring.
Diversity classificationMWBE / SBE / veteran-owned / disability-owned status.Self-certified by supplier with documentation; drives diversity-spend reporting.
Conflict of interestWorkspace employees with an interest in the supplier.Required disclosure; reviewed by Ethics if a relationship exists. See [Ethics → Welcome](/ethics/welcome).

Stage 3 — Tax and banking (vendor self-service)

The workspace does not collect or hold the supplier's tax + banking data through email. The supplier fills in a secure self-service form; the workspace receives the structured data + the signed documents.

  1. From the vendor draft → "Send self-service invite"

    The supplier's primary contact receives a tokenized link to the intake form.

  2. Supplier completes the form

    Tax: W-9 (US domestic), W-8BEN/BEN-E (foreign), local equivalents elsewhere. Banking: bank name, routing/IBAN/BIC, account, account holder name. Remit-to: where invoices should send.

  3. Supplier signs the tax form digitally

    The W-9 / W-8 is generated from the supplier's input and e-signed on submission. The signed PDF is stored on the vendor record.

  4. Banking is validated

    A penny verification (for US ACH) or a bank-letter confirmation (international) is the second leg of validation. Banking details aren't activated until verified.

  5. The vendor draft returns to the workspace

    Marked Self-service complete, ready for sanctions screening.

Stage 4 — Sanctions screening

Every vendor + every banking-detail change runs through sanctions screening before activation.

FieldWhat it doesAccepted values / default
OFAC SDN list (US)Treasury's list of sanctioned parties.Required for any US-based workspace; transacting with a hit is a federal violation.
Consolidated Sanctions ListOFAC's full set including SSI / FSE / SDN.Broader than SDN alone; covers sectoral + other lists.
EU consolidated listEU + UN listings.Required for EU workspaces.
UK HM Treasury listUK financial sanctions list.Required for UK workspaces.
Politically Exposed Persons (PEP)Heightened-risk individuals.Not always a deal-breaker; triggers enhanced due diligence + documented rationale.
Denied Persons ListBIS export-control denied parties.Required for export-controlled goods.

A name match doesn't always mean a real match — manual review clears most. When a hit is real, the vendor is rejected and the rejection is documented.

Stage 5 — Approval + activation

  1. Procurement reviews the full file

    Identity + qualification + tax/banking + sanctions all present

    • clean.
  2. Workspace-policy approver signs off

    Often the procurement director for standard vendors; treasurer or CFO for vendors above an annual spend threshold.

  3. Vendor moves to Active

    The vendor is now available for requisitions + POs. The supplier receives a welcome notification with their vendor ID + the workspace's supplier portal link.

Every field, explained

FieldWhat it doesAccepted values / default
Legal nameName on the tax form + the bank account.Required; must match across documents. Mismatches are the most common 1099 reconciliation issue.
DBATrade name the supplier operates under.Optional; useful for matching on invoices.
Tax IDEIN / SSN / VAT / equivalent.Captured via signed tax form; never re-keyed from email.
Vendor typeStandard / one-time / employee / intercompany / government.Drives approval defaults + reporting buckets.
Remit-to addressWhere invoices are mailed.May differ from business address; supplier-confirmed.
BankingRouting + account for ACH/wire.Encrypted at rest; access logged. Banking changes require re-verification.
Insurance certificatesRequired coverage + expiry.Auto-reminder ~60 days before expiry.
Sanctions screening resultCleared / hit / cleared-with-rationale.Timestamped per screening; re-screened on banking change + periodically.
Conflict of interest disclosureWorkspace relationships with the supplier.Required; reviewed by Ethics.
StatusDraft / pending / active / suspended / inactive.Drives availability for new POs.

Common gotchas

  • "Supplier wants to change banking via email." Don't. Banking changes must go through the self-service flow + the re-screening. Email-driven banking changes are the canonical fraud vector ("hi, we changed banks, please redirect that $200k payment").
  • "The W-9 didn't return all fields." The form requires the legal name, address, tax classification, EIN/SSN, and signature. Missing fields block the e-sign; supplier must complete + resubmit.
  • "Sanctions screening returned a hit on a clearly different person." Document the basis for the clearance (different middle name, different date of birth, different country) and approve with rationale. The documented clearance is the audit defense.
  • "This vendor was inactive but I want to reactivate." Re-screen sanctions + re-confirm banking + tax docs (they may have changed). Don't reactivate without the refresh.
  • "Employee wants to be paid as a vendor for a one-off service." Probably an employment-classification issue. Coordinate with HR/HCM before approving the employee-vendor path; misclassification has tax + benefits + statutory consequences.

Troubleshooting

Error codeWhat it meansFix
VENDOR_DUPLICATE_TAX_IDTax ID matches an existing vendor.Reuse the existing vendor or document the legitimate basis for a second record (e.g. different legal entity).
VENDOR_TAX_FORM_INCOMPLETESupplier's self-service form missing required fields.Resend the invite; supplier completes the missing fields.
VENDOR_BANKING_NOT_VERIFIEDPenny / letter verification hasn't completed.Wait for verification or re-initiate; banking inactive until verified.
VENDOR_SANCTIONS_HITScreening returned a match.Review the match; clear with documented rationale or reject.
VENDOR_CONFLICT_OF_INTEREST_UNRESOLVEDDisclosure pending Ethics review.Ethics signs off (or doesn't); the vendor cannot activate until resolved.

How this is recorded

Every onboarding step + every change to identity / banking / tax / sanctions / status writes to the vendor history ledger. The ledger is the artifact the auditor reads to confirm vendor master controls are operating + that high-risk changes (especially banking) went through the right approvals. Retention follows the audit-log retention FINANCE floor (default 7 years) at minimum; tax document retention follows the applicable tax-record rule.

Related