Choosing a vendor, contractor, supplier, or business partner involves more than checking a website. A practical due diligence process helps a business confirm identity, understand risk, document evidence, and decide what additional verification is needed before money, data, access, or reputation is placed at risk.
Vendor due diligence checklist
- Confirm the legal business identity. Compare the company name, address, contact information, registration details, and the identity of the person you are dealing with.
- Check the website and domain. Look for a consistent business name, working contact information, clear services, privacy information, and signs that the domain actually belongs to the claimed organization.
- Verify licenses or certifications when relevant. Contractors, professional services, transportation providers, healthcare-related businesses, and other regulated activities may require specific credentials.
- Review insurance requirements. If the work creates property, vehicle, employee, professional, or liability exposure, request appropriate evidence of insurance and confirm what the policy actually covers.
- Check references and work history. Ask for recent customers, comparable projects, or other evidence that supports the vendor’s claimed experience.
- Compare claims across sources. Look for inconsistencies between the vendor’s proposal, website, business records, professional profiles, references, and supporting documents.
- Review payment terms carefully. Confirm who is being paid, what triggers payment, refund or cancellation terms, milestones, deposit requirements, and whether payment instructions match the contracting entity.
- Protect access and data. If a vendor will receive customer information, system credentials, financial data, or administrative access, define the minimum access required and how it will be removed when the work ends.
- Document unresolved risks. Not every uncertainty means a vendor should be rejected, but important unknowns should be recorded and resolved before commitment.
- Re-check important relationships. Vendors can change ownership, insurance, contact information, reputation, or operating status. Higher-value or higher-risk relationships may justify periodic review.
Red flags that deserve additional verification
- Pressure to pay immediately or outside the agreed process.
- Business names, email domains, invoices, and payment recipients that do not match.
- Claims that cannot be supported with documents or independent evidence.
- Unclear ownership, location, or contact information.
- Repeated changes to banking or payment instructions.
- Resistance to reasonable requests for credentials, references, contracts, or insurance evidence.
Verification should match the level of risk
A low-value office supply purchase does not require the same review as a contractor entering customer homes, a vendor receiving sensitive data, or a supplier receiving a large deposit. The amount at risk, type of access, regulatory exposure, and difficulty of reversing the decision should determine how much verification is appropriate.
Use evidence, not a single score
A useful due diligence process should show what was verified, which source supports each conclusion, what remains unknown, and which issues require human judgment. A risk indicator can help organize attention, but it should not replace the underlying evidence.
Source-backed verification from Tolux
Tolux Verify helps businesses review vendors, contractors, claims, links, messages, screenshots, and supporting evidence with source-backed analysis and risk indicators. For business workflow needs beyond verification, explore Tolux AI Automation or contact Tolux LLC.