Vendor onboarding
Vendor onboarding is the gate every supplier passes through before the workspace can transact with them. Skip it and the cost is real: fraudulent banking details, double payments to colluding suppliers, regulatory violations on sanctioned-party transactions, or simply a tax filing the workspace can't reconcile because the W-9 was never collected. The onboarding flow stages the supplier through identity → qualification → tax + banking → sanctions → approval, with each step's evidence attached so the supplier file is audit-ready from day one.
TL;DR — Open Procurement → Vendors → New vendor. Capture identity, send the vendor self-service intake to the supplier (they fill in tax + banking themselves), run sanctions screening, approve. The vendor is now active for POs.
Before you start
- Confirm why you need this vendor — a single-purchase exception or an ongoing relationship. Single-purchase one-offs may use a lightweight onboarding path (with restrictions on total spend).
- Have the supplier's business name, tax ID, primary contact, remit-to address. The vendor-self-service form will collect banking + tax docs from the supplier directly so the workspace doesn't hold the data in an email thread.
- Plan for a sanctions screening failure to be the most common gate. Names match across the global lists more often than people expect; manual review usually clears them, but budget the time.
Stage 1 — Identity
Open Procurement → Vendors → New vendor
The intake form opens.
Capture business identity
Legal name, DBA, business type (corp / LLC / partnership / sole prop / non-profit / government), state of formation, primary contact name + email + phone.
Run a duplicate-vendor check
The platform searches for matching names + tax IDs across active + inactive vendors. Duplicates are a major fraud vector and a finance headache; reuse the existing record when match is real.
Pick the vendor type
Standard supplier / one-time / employee reimbursement (for employees paid as vendors for documented purposes) / intercompany / government. Each carries different defaults
- approval thresholds.
Save as Draft
The vendor enters Draft status. You can now send the self-service invite to the supplier.
Stage 2 — Qualification
Qualification asks "is this supplier suitable to deal with for this category of spend?" The workspace decides which categories require what level of qualification — minimum bar is usually financial stability + insurance + relevant certifications.
| Field | What it does | Accepted values / default |
|---|---|---|
| Financial stability | Can the supplier deliver on commitments? | D&B / Equifax report / financial statements (for material spend); summary attached, full report retained. |
| Insurance certificates | General liability, workers' comp, professional liability where applicable. | Captured at onboarding; expiry-tracked with automatic renewal reminders. |
| Relevant certifications | Industry-specific (ISO 9001, SOC 2, GMP, FSC, etc.). | Captured per category; the platform alerts when expiring. |
| Diversity classification | MWBE / SBE / veteran-owned / disability-owned status. | Self-certified by supplier with documentation; drives diversity-spend reporting. |
| Conflict of interest | Workspace employees with an interest in the supplier. | Required disclosure; reviewed by Ethics if a relationship exists. See [Ethics → Welcome](/ethics/welcome). |
Stage 3 — Tax and banking (vendor self-service)
The workspace does not collect or hold the supplier's tax + banking data through email. The supplier fills in a secure self-service form; the workspace receives the structured data + the signed documents.
From the vendor draft → "Send self-service invite"
The supplier's primary contact receives a tokenized link to the intake form.
Supplier completes the form
Tax: W-9 (US domestic), W-8BEN/BEN-E (foreign), local equivalents elsewhere. Banking: bank name, routing/IBAN/BIC, account, account holder name. Remit-to: where invoices should send.
Supplier signs the tax form digitally
The W-9 / W-8 is generated from the supplier's input and e-signed on submission. The signed PDF is stored on the vendor record.
Banking is validated
A penny verification (for US ACH) or a bank-letter confirmation (international) is the second leg of validation. Banking details aren't activated until verified.
The vendor draft returns to the workspace
Marked Self-service complete, ready for sanctions screening.
Stage 4 — Sanctions screening
Every vendor + every banking-detail change runs through sanctions screening before activation.
| Field | What it does | Accepted values / default |
|---|---|---|
| OFAC SDN list (US) | Treasury's list of sanctioned parties. | Required for any US-based workspace; transacting with a hit is a federal violation. |
| Consolidated Sanctions List | OFAC's full set including SSI / FSE / SDN. | Broader than SDN alone; covers sectoral + other lists. |
| EU consolidated list | EU + UN listings. | Required for EU workspaces. |
| UK HM Treasury list | UK financial sanctions list. | Required for UK workspaces. |
| Politically Exposed Persons (PEP) | Heightened-risk individuals. | Not always a deal-breaker; triggers enhanced due diligence + documented rationale. |
| Denied Persons List | BIS export-control denied parties. | Required for export-controlled goods. |
A name match doesn't always mean a real match — manual review clears most. When a hit is real, the vendor is rejected and the rejection is documented.
Stage 5 — Approval + activation
Procurement reviews the full file
Identity + qualification + tax/banking + sanctions all present
- clean.
Workspace-policy approver signs off
Often the procurement director for standard vendors; treasurer or CFO for vendors above an annual spend threshold.
Vendor moves to Active
The vendor is now available for requisitions + POs. The supplier receives a welcome notification with their vendor ID + the workspace's supplier portal link.
Every field, explained
| Field | What it does | Accepted values / default |
|---|---|---|
| Legal name | Name on the tax form + the bank account. | Required; must match across documents. Mismatches are the most common 1099 reconciliation issue. |
| DBA | Trade name the supplier operates under. | Optional; useful for matching on invoices. |
| Tax ID | EIN / SSN / VAT / equivalent. | Captured via signed tax form; never re-keyed from email. |
| Vendor type | Standard / one-time / employee / intercompany / government. | Drives approval defaults + reporting buckets. |
| Remit-to address | Where invoices are mailed. | May differ from business address; supplier-confirmed. |
| Banking | Routing + account for ACH/wire. | Encrypted at rest; access logged. Banking changes require re-verification. |
| Insurance certificates | Required coverage + expiry. | Auto-reminder ~60 days before expiry. |
| Sanctions screening result | Cleared / hit / cleared-with-rationale. | Timestamped per screening; re-screened on banking change + periodically. |
| Conflict of interest disclosure | Workspace relationships with the supplier. | Required; reviewed by Ethics. |
| Status | Draft / pending / active / suspended / inactive. | Drives availability for new POs. |
Common gotchas
- "Supplier wants to change banking via email." Don't. Banking changes must go through the self-service flow + the re-screening. Email-driven banking changes are the canonical fraud vector ("hi, we changed banks, please redirect that $200k payment").
- "The W-9 didn't return all fields." The form requires the legal name, address, tax classification, EIN/SSN, and signature. Missing fields block the e-sign; supplier must complete + resubmit.
- "Sanctions screening returned a hit on a clearly different person." Document the basis for the clearance (different middle name, different date of birth, different country) and approve with rationale. The documented clearance is the audit defense.
- "This vendor was inactive but I want to reactivate." Re-screen sanctions + re-confirm banking + tax docs (they may have changed). Don't reactivate without the refresh.
- "Employee wants to be paid as a vendor for a one-off service." Probably an employment-classification issue. Coordinate with HR/HCM before approving the employee-vendor path; misclassification has tax + benefits + statutory consequences.
Troubleshooting
| Error code | What it means | Fix |
|---|---|---|
VENDOR_DUPLICATE_TAX_ID | Tax ID matches an existing vendor. | Reuse the existing vendor or document the legitimate basis for a second record (e.g. different legal entity). |
VENDOR_TAX_FORM_INCOMPLETE | Supplier's self-service form missing required fields. | Resend the invite; supplier completes the missing fields. |
VENDOR_BANKING_NOT_VERIFIED | Penny / letter verification hasn't completed. | Wait for verification or re-initiate; banking inactive until verified. |
VENDOR_SANCTIONS_HIT | Screening returned a match. | Review the match; clear with documented rationale or reject. |
VENDOR_CONFLICT_OF_INTEREST_UNRESOLVED | Disclosure pending Ethics review. | Ethics signs off (or doesn't); the vendor cannot activate until resolved. |
How this is recorded
Every onboarding step + every change to identity / banking / tax / sanctions / status writes to the vendor history ledger. The ledger is the artifact the auditor reads to confirm vendor master controls are operating + that high-risk changes (especially banking) went through the right approvals. Retention follows the audit-log retention FINANCE floor (default 7 years) at minimum; tax document retention follows the applicable tax-record rule.
Related