Vendor Onboarding Process: Steps, Owners, Controls

Vendor Onboarding Process: Steps, Owners, Controls

2026-09-28 · Tommaso Maria Ricci

In 2025, business email compromise cost American victims $3.05 billion, from fewer than 25,000 complaints, according to the FBI's 2025 Internet Crime Report. That is an average above $120,000 per complaint, and one of the most common routes is painfully simple: someone emails accounts payable, claims to be a supplier, and asks to change the bank details. Whether that email becomes a loss depends almost entirely on one process most companies never designed on purpose: the vendor onboarding process. It decides who gets into your vendor master, with what data, verified by whom, and what it takes to change any of it later.

Most companies treat vendor onboarding as paperwork. A buyer finds a supplier, sends a form, someone in finance types the details into the ERP, and the first invoice gets paid. That works until one of three things happens. A fraudster changes a bank account through a convincing email. An auditor finds hundreds of vendors with missing tax forms, duplicate records or no owner. Or the business discovers, after a supplier fails, that nobody ever checked whether it was financially sound, sanctioned or even insured.

This guide is not a list of tools. It is the method I use when I help a company rebuild the process: what vendor onboarding actually covers, the stages and who owns each one, the controls that stop fraud without slowing the business down, the tax and compliance checks for US companies, what to automate first, and a 30, 60 and 90 day plan to get there.

What the vendor onboarding process actually covers

Vendor onboarding is the set of steps between the decision to buy from a new supplier and the moment that supplier can be paid safely. It sits inside the wider procurement cycle. Upstream, sourcing decides which supplier to use. Downstream, purchasing, receiving and accounts payable handle each transaction. Onboarding is the gate between the two.

A useful definition has three parts.

  1. Identity. Confirm the supplier is a real, legally existing business and that the person you are dealing with is authorized to represent it.
  2. Data. Collect and validate the information every downstream process depends on: legal name, tax identification, remit-to address, bank details, payment terms, contacts, categories.
  3. Risk. Decide how much scrutiny this supplier deserves based on what it will do for you, and apply it before the first payment, not after.

When those three are done, the supplier gets an active record in the vendor master. Everything after that, from purchase orders to 1099 reporting, inherits the quality of that record.

Where onboarding ends and vendor management begins

Onboarding is a one-time gate with a clear end state. Ongoing vendor management is the continuous work of monitoring performance, risk and contracts over the life of the relationship. If you are building that wider discipline, the method is in the guide on how to build a vendor management program. This article stays on the gate.

Vendor onboarding versus supplier onboarding

The terms are used interchangeably. In some companies "supplier" means goods and "vendor" means any payee, including service providers, contractors and landlords. For onboarding purposes the distinction does not matter much: any entity that will receive money from you needs the same identity, data and risk checks, scaled to the risk.

Why vendor onboarding became a finance risk

For years onboarding was owned by whoever needed the supplier, with finance entering data at the end. Three shifts turned it into a control that belongs on the CFO's list.

Payments fraud targets the vendor master

The 2025 AFP Payments Fraud and Control Survey, which looks back at 2024, found that 79% of organizations experienced attempted or actual payments fraud. Business email compromise was reported by 63%. Among organizations hit by payments fraud, 45% reported vendor imposter fraud, and among BEC attempts, vendor impersonation was cited by 60% of respondents. One in five organizations did not recover any of the funds stolen.

The 2026 edition of the survey, based on 465 corporate practitioners, found 76% of organizations experienced attempted or actual fraud in 2025, and for the first time looked at AI-enabled fraud and deepfake impersonation of executives and vendors. The FBI report points the same way: in 2025 businesses reported more than $30 million in losses to BEC scams involving AI.

The common thread is that most vendor fraud does not break into systems. It walks through the process: a change request that nobody verifies, a new vendor that nobody checks, a duplicate record that nobody notices.

Tax reporting rules changed

For payments made after December 31, 2025, the reporting threshold for Forms 1099-NEC and 1099-MISC rose from $600 to $2,000, per the IRS instructions for Forms 1099-MISC and 1099-NEC. That reduces the number of forms many companies file, but it does not remove the need to collect a Form W-9 at onboarding. Without a correct taxpayer identification number, the payer may be required to apply backup withholding at 24 percent on reportable payments. A W-9 collected at onboarding is far cheaper than one chased in January.

Third parties became a larger share of what companies do

Outsourced services, cloud providers, contractors and logistics partners now touch data, customers and operations. A weak onboarding gate is no longer only a payments risk. It is a data, compliance and continuity risk too.

The vendor onboarding process steps, stage by stage

This is the process I recommend for a mid-sized company, with the owner and the failure mode for each stage. Adapt the depth, not the sequence.

Stage 1: Request and business justification

Owner: the requesting business unit, usually through procurement.

A new vendor starts with a request: who the supplier is, what it will provide, estimated annual spend, whether it will access systems or data, and why an existing vendor cannot do the job. The last question matters more than it looks. Every vendor you add is a record to maintain, a risk to monitor and a door for fraud. A short justification kills a surprising number of unnecessary vendors.

Failure mode: vendors created directly by accounts payable to pay an invoice that already arrived. That is onboarding in reverse, and it is where most bad records come from.

Stage 2: Duplicate check

Owner: vendor master data team or accounts payable.

Before anything else, search the existing vendor master by legal name, tax ID, address, bank account and phone number. Duplicates are not just clutter. They enable duplicate payments, split spend analytics and hide fraud, because a fake record that shares an address or bank account with a real one is easy to miss.

Failure mode: checking by name only. "ABC Supply Inc" and "A.B.C. Supply" pass a name check and fail a tax ID check.

Stage 3: Risk tiering

Owner: procurement, with input from security, legal and finance.

Not every vendor deserves the same scrutiny. Tier them on a few questions: annual spend, whether they will access your systems or personal data, whether they are critical to operations, whether they operate in regulated activities or high-risk countries, and whether they are a single source. A simple three-tier model works for most companies.

  • Tier 1, critical: high spend, data access, single source or regulated. Full due diligence.
  • Tier 2, standard: moderate spend, no sensitive access. Core checks plus targeted questions.
  • Tier 3, low: low spend, one-off or commodity purchases. Core checks only.

Failure mode: sending every vendor the same 200-question security questionnaire. Low-risk vendors abandon it, business units bypass it, and the questionnaire stops protecting anything.

Stage 4: Data collection through a controlled channel

Owner: procurement or the vendor master team.

The vendor submits its own data through a portal or a controlled form, not through email attachments retyped by a clerk. The core data set: legal name and any DBA, tax ID with a Form W-9 for US vendors or W-8BEN or W-8BEN-E for foreign ones, registered and remit-to addresses, bank details on company letterhead or through a verified channel, contacts for orders, invoices and remittance, and insurance certificates where relevant.

Failure mode: bank details received by email and entered without verification. This is the single most exploited gap in the process.

Stage 5: Verification

Owner: vendor master team, with finance for bank details.

Everything collected gets checked against an independent source.

  • Legal existence: state business registry or equivalent.
  • Tax ID: IRS TIN matching for US vendors, where you are eligible to use it.
  • Sanctions: screening against the OFAC Specially Designated Nationals list and other applicable lists, for the company and, for higher tiers, its owners.
  • Bank account: confirm ownership through a bank account validation service or a callback to a phone number obtained independently, never the one on the form or in the email.
  • Insurance and licenses: where the work requires them.

Failure mode: calling back the number printed on the same document that contains the new bank details. If the document is fake, so is the number.

Stage 6: Due diligence for higher tiers

Owner: security, legal, compliance and finance, depending on the risk.

Tier 1 and some Tier 2 vendors get deeper checks: financial health, security posture through a questionnaire or a SOC 2 report, data protection terms, business continuity, conflicts of interest with your own employees, and references. Ask only what changes a decision. A question whose answer would not change whether or how you use the vendor is a question to drop.

Failure mode: due diligence completed after the contract is signed and work has started. At that point the findings have no leverage.

Stage 7: Contract and terms

Owner: legal and procurement.

The contract, or at least the standard terms, must be in place before the first purchase order: payment terms, pricing, liability, data protection, audit rights, termination. For many companies this is where onboarding connects to the contract lifecycle management process.

Failure mode: payment terms entered in the vendor master that differ from the contract. The ERP pays on the master, not the contract.

Stage 8: Approval and activation

Owner: someone independent from the requester and from whoever entered the data.

The vendor record is reviewed and activated by a person who did not request the vendor and did not key the data. This segregation of duties is the core anti-fraud control of the whole process. Activation should be logged, with the approver's name and date.

Failure mode: the same person creating, approving and paying a vendor. In small finance teams this happens by default unless someone designs it out.

Stage 9: First payment and hypercare

Owner: accounts payable.

The first payment to a new vendor, or the first after a bank change, gets extra attention: a confirmation with the vendor through a verified contact, or a small test payment where the relationship justifies it. The first ninety days are when onboarding errors surface: wrong remit-to address, missing PO references, unclear contacts.

Failure mode: treating the first payment like any other, which is exactly what a fraudster relies on.

The control that matters most: changes to vendor data

Onboarding a new vendor gets attention. Changing an existing vendor rarely does, and that is where most vendor fraud happens. A fraudster does not need to create a fake supplier. It is easier to impersonate a real one and ask for new bank details.

A strong change control has five rules.

  1. Every change goes through the same channel as onboarding. No bank changes by email, phone or chat, ever.
  2. Bank changes are verified independently. Call back a contact already on file from before the request, or validate account ownership through a service. Never use contact details supplied with the change request.
  3. Changes are approved by someone other than who entered them.
  4. Changes trigger a notification to the vendor's existing contact. If the vendor did not request it, they will say so.
  5. Payments to recently changed accounts get a hold or a second review for a defined period.

The AFP data explains why this matters: vendor impersonation now sits among the most frequent BEC tactics, and a meaningful share of stolen funds is never recovered. The best recovery plan is a payment that never goes out.

Tax and compliance checks for US companies

These are the checks a US company should build into onboarding, not bolt on at year end. Confirm specifics with your tax adviser, since rules depend on your situation.

Form W-9 and TIN matching

Collect a Form W-9 from every US payee before the first payment. It gives you the legal name, entity type and taxpayer identification number, and determines whether the vendor is exempt from 1099 reporting, as many corporations are. Match the name and TIN against IRS records through TIN Matching where available. A mismatch caught at onboarding costs an email; caught later, it can mean penalty notices and backup withholding at 24 percent.

The new 1099 threshold

For payments made after December 31, 2025, the 1099-NEC and 1099-MISC reporting threshold is $2,000 for most payment types, up from $600, and it will be indexed for inflation from 2027. Onboarding should still classify every vendor correctly, because you will not know at onboarding whether annual payments will cross the threshold.

Foreign vendors

Foreign vendors provide Form W-8BEN (individuals) or W-8BEN-E (entities) instead of a W-9. The form supports treaty claims and determines whether US withholding applies. Payments to foreign persons can trigger withholding and Form 1042-S reporting, so the form needs to be on file and current before payment.

Sanctions screening

US persons are prohibited from dealing with parties on the OFAC sanctions lists, and liability can apply even without intent. Screen every vendor at onboarding and rescreen periodically, since lists change. Higher-tier vendors warrant screening of beneficial owners too.

Insurance, licenses and certifications

Contractors working on your premises need certificates of insurance with the right coverage and your company named where required. Regulated work needs valid licenses. Track expiry dates, because a certificate that was valid at onboarding may lapse mid-contract.

Self-assessment: twelve questions before you redesign anything

Answer yes or no. Every no is a point where the process leaks value or risk.

  1. Can a vendor be created only through a request, never directly in the ERP by accounts payable?
  2. Is there a duplicate check on tax ID and bank account, not just name?
  3. Do vendors have risk tiers with different levels of scrutiny?
  4. Do vendors submit their own data through a portal or controlled form?
  5. Is bank account ownership verified independently before activation?
  6. Is every vendor screened against sanctions lists at onboarding?
  7. Do you hold a valid W-9 or W-8 for every active vendor?
  8. Is the person who approves a vendor different from the one who requested it and the one who entered it?
  9. Are bank detail changes verified through a contact already on file?
  10. Do payments to recently changed accounts get a second review?
  11. Is there a named owner for every active vendor?
  12. Are inactive vendors deactivated automatically after a defined period?

0 to 2 no answers. Your process is solid. Focus on speed and vendor experience.

3 to 6 no answers. You have specific gaps, usually bank verification and segregation of duties. Fix those first; they are the ones fraudsters use.

7 to 12 no answers. Onboarding is running on habit. The vendor master almost certainly contains duplicates, inactive records and missing tax forms. Clean-up comes before automation.

If you land in the top band and are not sure where to start, a conversation with someone who has rebuilt this process in similar companies saves months. You can request one through the consultation form on the site, with your vendor count, ERP and the problem that worries you most.

The metrics, in causal order

| Metric | What it tells you | Target direction |

|---|---|---|

| Vendors created outside the request process | Discipline at the gate | Zero |

| Duplicate vendor records found | Quality of the duplicate check | Down |

| Active vendors missing a valid tax form | Tax exposure | Zero |

| Bank changes verified independently | Fraud control coverage | 100% |

| Onboarding cycle time by tier | Speed for the business | Down, especially Tier 3 |

| Vendors abandoned during onboarding | Friction in the process | Down |

| First payment issues in 90 days | Quality of collected data | Down |

| Inactive vendors still active in the master | Hygiene of the vendor master | Down |

Read the table top to bottom. The first rows are causes: bypasses, duplicates, missing forms, unverified changes. The last rows are effects. If first payments go wrong, look first at who created the vendor and how the data came in.

Seven failure modes I see repeatedly

1. Onboarding in reverse. The invoice arrives, then someone creates the vendor to pay it. Every check becomes a formality because the money is already owed.

2. Email as a data channel. Bank details, tax forms and contact changes travel by email and get retyped. Email is the attack surface for vendor impersonation.

3. One questionnaire for everyone. The same heavy process for a one-off caterer and a cloud provider handling customer data. The business routes around it.

4. No owner for the vendor master. Procurement thinks finance owns it, finance thinks procurement does. Nobody cleans it.

5. Segregation of duties on paper only. The policy says three people; in practice one person covers when others are out, and the system allows it.

6. No offboarding. Vendors are never deactivated. A dormant record with valid bank details is an ideal target for a change request.

7. Speed ignored. Tier 1 checks applied to everyone make onboarding take weeks. Business units respond by pre-ordering, splitting purchases or using a card. The controls exist, but the spend goes around them.

What to automate first, and what not to

Automate first

Vendor self-service portal. Vendors enter their own data, upload forms and maintain contacts. It removes retyping and closes the email channel.

Validation at entry. Tax ID format, address normalization, duplicate detection on tax ID and bank account, sanctions screening. These are cheap, reliable and run in seconds.

Bank account validation. Services that confirm the account belongs to the named business. They do not replace a callback for high-risk changes, but they catch most errors and many frauds.

Workflow and approvals. Routing by risk tier, with segregation of duties enforced by the system, not by policy.

Tax form collection. Electronic W-9 and W-8 collection with TIN matching built in.

Automate carefully

Risk scoring. Useful to route vendors, dangerous if nobody understands why a vendor got its score.

AI document review. Reading insurance certificates, SOC 2 reports and contracts to extract dates and key terms works well with human review. It is a triage tool, not a decision maker.

Do not automate

The decision to trust a bank change. A person verifies it through a known contact. Deepfake voice and video impersonation, which the 2026 AFP survey examined for the first time, make this more important, not less. Use a contact already on file and, for large amounts, a second channel.

If you are extending automation to the rest of the payables cycle, the sequencing is covered in the guide to automating the accounts payable process.

Who should own vendor onboarding

There is no single right answer, but there must be a single owner of the process, usually one of three.

  • Procurement owns it where procurement is mature and controls most spend. Strong on risk tiering and supplier relationships.
  • Finance or the controller owns it where fraud and tax risk dominate and procurement is thin. Strong on controls and data quality.
  • A shared services or master data team owns it in larger companies, executing the process for both.

Whoever owns it, the responsibilities split cleanly: the business justifies the need, procurement tiers and manages the relationship, security and legal handle their parts of due diligence, finance verifies bank details and tax data, and an independent approver activates the record.

This is the same logic that makes the rest of the purchasing cycle work. If you want to see how onboarding connects upstream and downstream, the procure to pay process and the broader source to pay process cover the full chain.

Four maturity stages

Most companies can place themselves on this scale in a minute. The point is not to jump to the last stage, but to know which step comes next.

Stage 1: ad hoc. Vendors are created by whoever needs to pay them. Data arrives by email. There are no tiers, no independent verification and no owner. The vendor master grows every year and is never cleaned.

Stage 2: controlled. There is a request form and an approval step. Bank changes need a callback. Tax forms are collected, though not always before the first payment. Segregation of duties exists in policy, not yet in the system. Most mid-sized companies sit here.

Stage 3: tiered and system enforced. Vendors are tiered by risk, with checks matched to each tier. Vendors submit their own data through a portal. Duplicate checks, sanctions screening and tax ID validation run automatically. The ERP will not let the same person create and approve a vendor. Metrics are reviewed monthly.

Stage 4: continuous. Onboarding flows into ongoing monitoring: sanctions lists are rescreened automatically, insurance and certifications are tracked to expiry, dormant vendors are deactivated on schedule, and risk tiers are revisited when spend or access changes. The vendor master stays clean because the process keeps it clean.

Moving from Stage 1 to Stage 2 is mostly policy and discipline and costs little. Moving from Stage 2 to Stage 3 is where tooling earns its keep. Stage 4 is worth it for companies with large vendor bases or regulated activities.

Vendor onboarding for small finance teams

Segregation of duties sounds like a large company luxury. In a finance team of three people, one of whom is on vacation, who is the independent approver? The answer is to design the control around the people you have.

  • Split the steps across functions, not just finance. The requester is in the business, data entry is in accounts payable, activation is the controller or the CFO. Three people, only one of them in AP.
  • Use the system to enforce what people cannot. Most ERPs and accounting systems allow a vendor record to stay inactive until a second user approves it. Turn that on.
  • Make bank changes a two-person rule without exception. If only one person is available, the change waits. A delayed payment is recoverable; a diverted one often is not.
  • Review the vendor change log monthly. A short report of every vendor created or changed, reviewed by someone outside AP, catches most problems within weeks.
  • Outsource verification where it is cheap. Bank account validation, TIN matching and sanctions screening are available as services and cost little compared with the time of a small team.

A small team cannot run the full Tier 1 process for every vendor, and should not try. It can make sure that nobody gets paid without passing the gate and that no bank account changes without two people involved.

Offboarding: the step that closes the loop

Every onboarding process needs a matching exit. Vendors that are no longer used should be deactivated, not left dormant with valid bank details and open payment terms. A dormant record is the ideal target for a fraudulent change request: nobody at your company talks to that vendor anymore, so nobody notices when the bank account changes.

A simple rule works for most companies: deactivate any vendor with no transaction in 12 to 18 months, after confirming there are no open purchase orders, invoices, credits or contractual obligations. Reactivation goes through the same checks as a new vendor, scaled to the tier. Offboarding also means revoking any system access the vendor had, retrieving company assets and data, and closing the contract properly.

Twelve questions to ask vendor onboarding software providers

If you decide to buy a tool, test it against your process, not the demo script. Bring three real cases: a low-risk commodity supplier, a critical service provider with data access, and a bank change request for an existing vendor.

  1. How does the vendor submit its data, and how is it validated at entry?
  2. Which duplicate checks run automatically, and on which fields?
  3. How is bank account ownership verified, and in which countries?
  4. Which sanctions lists are screened, and how often are existing vendors rescreened?
  5. How are W-9 and W-8 forms collected, and is TIN matching built in?
  6. Can we configure different workflows by risk tier without custom code?
  7. How is segregation of duties enforced between requester, data entry and approver?
  8. How does a bank change request flow, and what verification is required?
  9. How does the tool integrate with our ERP, and in which direction does data sync?
  10. How are insurance certificates and other expiring documents tracked?
  11. What audit trail is kept for every creation and change?
  12. How do we export all vendor data and documents if we leave?

The last question tells you how easy it will be to leave. The bank change question tells you whether the tool was designed by people who understand vendor fraud.

What it costs to fix, and where the money comes back

The investment has four parts: cleaning the existing vendor master, redesigning the process and approvals, tooling such as a vendor portal and validation services, and the time of procurement and finance people during the transition.

The return comes from five places.

Fraud avoided. One prevented bank change fraud often pays for the whole project. The average BEC complaint in the FBI data runs above $120,000.

Duplicate payments avoided. Fewer duplicate vendor records mean fewer duplicate invoices paid.

Tax exposure reduced. Valid forms on file mean fewer penalty notices and less backup withholding cleanup.

Faster onboarding. Tiered checks let low-risk vendors through in days, not weeks, and reduce the bypasses that undermine every other control.

Better spend data. A clean vendor master is the basis for negotiating with suppliers and understanding where money goes.

Growth makes all of this more urgent. When a sports distribution company I worked with grew sales by 30% through AI-driven marketing, the pressure did not stay in the commercial team. Growth of that kind moves upstream to purchasing, logistics and suppliers, and every process that was held together by a few people who knew everyone starts to show gaps. Vendor onboarding is usually one of the first.

A 30, 60 and 90 day roadmap

Days 1 to 30: measure and stop the bleeding

  • Export the vendor master and count active vendors, vendors with no payment in 18 months, duplicates on tax ID and bank account, and vendors missing tax forms.
  • Map how vendors are created today, including every bypass.
  • Freeze bank changes by email with a simple rule and a communication to accounts payable.
  • Introduce independent callback verification for all bank changes, starting now.
  • Answer the twelve self-assessment questions with procurement, finance and IT.
  • Name a single owner for the process.

Days 31 to 60: redesign the gate

  • Define three risk tiers with the checks required for each.
  • Design the request form and the approval routing, with segregation of duties enforced in the ERP.
  • Deactivate dormant vendors after confirming no open items.
  • Merge duplicates and collect missing tax forms, starting with the highest spend vendors.
  • Choose tooling for self-service data collection, validation and sanctions screening, or configure what your ERP already provides.

Days 61 to 90: launch and hold

  • Launch the new process for all new vendors.
  • Move existing vendors to the portal for any data change.
  • Set up the metrics table and review it monthly.
  • Run a tabletop test: simulate a bank change request from a spoofed supplier and see where it is stopped.
  • Review cycle times by tier and remove any check that does not change a decision.

If halfway through you find that the hard decisions are about ownership and trade-offs between speed and control rather than about software, that is normal, and it is the point where an outside view saves the most time. You can ask for a conversation through the consultation form on the site, with a few lines on your vendor count, systems and the gap you worry about most.

Where vendor onboarding meets the rest of the business

Onboarding mirrors what companies do on the other side of the ledger. The same discipline that turns a new customer into a reliable, paying account applies to turning a new supplier into a safe, payable one. If you have already built the customer onboarding process, many of the same principles apply: clear stages, one owner per stage, and data collected once at the source rather than retyped downstream.

The companies that do this well are not the ones with the heaviest questionnaires. They are the ones where nobody can pay a vendor that did not come through the gate, and nobody can change a bank account without a second person confirming it with someone they already know.

FAQ

What are the vendor onboarding process steps and controls?

A sound vendor onboarding process has nine steps: request and business justification, duplicate check, risk tiering, data collection through a controlled channel, verification of identity, tax ID, sanctions and bank account, due diligence for higher-risk vendors, contract and terms, independent approval and activation, and extra review of the first payment. The most important controls are independent bank account verification, segregation of duties between requester, data entry and approver, and a strict process for any later change to vendor data.

How long should vendor onboarding take?

It should depend on the risk tier. Low-risk vendors with core checks only can be onboarded in one to three business days when vendors submit their own data through a portal and validation is automated. Critical vendors that need security, financial and legal due diligence often take two to four weeks. If every vendor takes weeks, the process is not tiered, and business units will find ways around it.

Who should own the vendor onboarding process?

One function must own the process end to end, usually procurement where it is mature, finance or the controller where fraud and tax risk dominate, or a master data team in larger companies. Ownership of the process is different from doing every step: the business justifies the need, procurement tiers the vendor, security and legal run their checks, finance verifies bank and tax data, and an independent approver activates the record.

How do you prevent vendor bank account fraud?

Never accept bank details or bank changes by email, phone or chat. Collect them through a controlled portal, verify account ownership through a validation service or a callback to a contact already on file from before the request, and require approval by someone other than the person who entered the change. Notify the vendor's existing contact of every change and add a second review for payments to recently changed accounts.

Do you still need a W-9 from vendors after the 1099 threshold increase?

Yes. For payments made after December 31, 2025, the reporting threshold for Forms 1099-NEC and 1099-MISC is $2,000 for most payment types, up from $600. But you rarely know at onboarding whether a vendor will cross the threshold, and without a correct taxpayer identification number you may be required to apply backup withholding at 24 percent. Collecting a W-9 before the first payment remains the simplest control.

What is the difference between vendor onboarding and vendor management?

Vendor onboarding is a one-time gate: it verifies a new supplier's identity, data and risk before it can be paid. Vendor management is the ongoing work over the life of the relationship: monitoring performance, risk, contracts and compliance, and eventually offboarding. Onboarding determines the quality of the data vendor management relies on, so weaknesses at the gate show up for years afterwards.