Signing a contract with a new vendor can create financial, operational, cybersecurity, and reputational risk. A vendor may look credible on the surface and still have unresolved issues involving ownership, insurance, licensing, payment practices, data handling, or past performance.
The goal of vendor verification is not to eliminate all uncertainty. It is to make sure the important claims are supported and that unresolved questions are identified before the agreement becomes difficult or expensive to unwind.
1. Confirm the vendor’s legal identity
Start by confirming the business name, operating name, address, phone number, website, email domain, and the person authorized to sign the agreement.
Compare this information across the proposal, contract, invoice, public listings, official records, and the vendor’s website. Material inconsistencies should be resolved before signing.
2. Check registration, licenses, and required credentials
The records that matter depend on the vendor’s industry and location. Some vendors may require professional licenses, permits, certifications, registrations, or industry-specific credentials.
Verify important credentials through the appropriate issuing authority whenever possible instead of relying only on copies supplied by the vendor.
3. Understand who owns and controls the business
For higher-risk relationships, it can be useful to understand the vendor’s ownership, leadership, affiliated entities, and the identity of the person who will actually deliver the service.
This can help uncover situations where the contracting entity is different from the operating entity, where a business recently changed names, or where the vendor’s public claims do not align with available records.
4. Ask for relevant insurance
Insurance requirements should match the type of work being performed. Depending on the relationship, that may include general liability, professional liability, cyber coverage, commercial auto, or workers’ compensation.
For important contracts, verify certificates directly with the insurer or broker when appropriate and check whether the limits and dates satisfy your requirements.
5. Review references and past performance
Ask for references that resemble your organization, industry, or project size. General testimonials can be useful, but relevant references are much more informative.
Ask previous customers about reliability, communication, billing accuracy, missed deadlines, quality problems, dispute resolution, and whether they would use the vendor again.
6. Evaluate the vendor’s security and data access
If the vendor will access customer information, financial data, internal systems, credentials, employee records, or confidential business information, verification should extend beyond basic business legitimacy.
Understand what data the vendor will access, where it will be stored, which subcontractors may handle it, how incidents are reported, and what happens to your data when the relationship ends.
7. Review contract and payment terms carefully
Make sure the contract identifies the correct legal entity and clearly explains pricing, payment timing, renewal terms, cancellation rights, responsibilities, service levels, ownership of work product, confidentiality, and dispute procedures.
Be cautious of unexpected bank changes, unusual advance-payment demands, personal payment accounts, or pressure to sign before questions are answered.
8. Look for independent evidence
Do not rely only on information supplied by the vendor. Search for independent records, business profiles, regulatory information, customer experiences, news reports, professional listings, and other credible sources relevant to the relationship.
The goal is to see whether the vendor’s claims are reasonably consistent with the broader evidence.
9. Document unresolved questions
A vendor does not have to be perfect to be acceptable. What matters is knowing what remains uncertain and deciding whether that uncertainty is appropriate for the level of risk.
Document missing documents, contradictory information, unresolved ownership questions, security concerns, insurance gaps, or unclear contract terms before approval.
10. Recheck important vendors over time
Vendor risk can change after onboarding. Ownership can change, licenses can expire, insurance can lapse, websites and contact information can change, and new complaints or regulatory issues can appear.
For important vendors, periodic review can be more useful than treating due diligence as a one-time event.
For a broader checklist, see the Vendor Due Diligence Checklist for Small Businesses.
Use Tolux Verify before signing with a new vendor
Tolux Verify helps organize source-backed evidence about businesses, vendors, contractors, claims, URLs, messages, screenshots, and other supported verification subjects.
It can help surface supporting evidence, citations, risk indicators, and unresolved questions before you commit money, access, data, or reputation to a new vendor relationship.
Run a vendor verification with Tolux Verify before signing a new contract.
Tolux Verify provides decision support based on available evidence. It does not guarantee legitimacy, compliance, performance, security, or future behavior. Use qualified legal, financial, cybersecurity, or regulatory professionals when appropriate.