- Checklist
- US onboarding
US vendor onboarding: W-9, SAM.gov, OFAC, insurance and bank verification
Updated 5 min read
Onboarding a US supplier is mostly the same dozen checks whatever it sells: who the company legally is, how it is taxed, whether any government has barred it, where the money goes, what happens if it causes a loss, and whether it will behave. This guide lists each check, the record to keep, and the one control that stops the most expensive mistake: paying a fraudster who changed the bank details.
1. Legal identity and good standing
Record the exact legal name, entity type and state of formation, then look the company up on that state's Secretary of State business search. You want to see an active status (“active”, “good standing” or “existence”, depending on the state). A dissolved, forfeited or revoked company cannot validly contract, so treat anything other than active as a hard stop rather than a finding.
Record: a certificate of good standing, or a dated screenshot of the state record.
2. Form W-9 and the TIN
Collect a signed W-9 before the first payment. It gives you the taxpayer identification number (an EIN for most businesses) and tells you whether the vendor is subject to backup withholding and whether 1099 reporting applies. If you are enrolled in IRS e-Services, run a TIN/name match; a mismatch is the most common reason for a CP2100 notice later.
3. Sanctions and exclusions
| List | Who publishes it | What a hit means |
|---|---|---|
| OFAC SDN list | US Treasury | Paying them is illegal. Hard stop. |
| SAM.gov exclusions | General Services Administration | Barred from federal awards. Hard stop for federal work, strong red flag otherwise. |
| State debarment lists | Each state's procurement office | Barred from that state's contracts. Hard stop for public-sector work. |
Screen the company and its owners. A name match is a candidate, not a finding: record how each candidate was resolved (different address, different date of birth, different country) so the file shows a person looked. A lookup that failed is not a clear result.
4. Bank verification: the business email compromise control
Business email compromise is the single most expensive fraud most small companies will meet. It nearly always arrives the same way: an email that looks like it is from a real supplier, saying they have changed banks. The control is simple and non-negotiable:
- Verify the account at onboarding with a bank letter or voided check.
- Call the vendor to confirm it, on a number you already held: the contract, the vendor master, an invoice from before the request. Never a number in the request.
- Record who called, when, and who at the vendor confirmed.
- On any change request, block payment to the new account until the callback is redone.
5. Certificate of insurance
Ask for an ACORD 25 certificate of insurance showing general liability at the limits your contract requires (commonly $1M per occurrence and $2M aggregate), plus workers' compensation for anyone working on your premises, commercial auto if they drive for you, and cyber or professional liability if they handle your data or give advice. Check that your company is named as additional insured if the contract says so, and diary the expiry date: an expired certificate is the most common gap an auditor finds.
6. Compliance acknowledgements
- Code of conduct, signed by someone with authority.
- Anti-bribery (FCPA) certification, and a question about whether the vendor will deal with government officials on your behalf. That is where FCPA risk lives.
- Conflicts of interest: does anyone at your company, or their family, own or work for the vendor?
- Privacy: will the vendor handle personal information, and which state laws apply? If it will handle protected health information, a HIPAA business associate agreement is required before any PHI moves.
- Export control: are the goods or technical data controlled under the EAR or ITAR? ITAR work needs the vendor's DDTC registration confirmed.
- Diversity certifications (MBE, WBE, SDVOSB, HUBZone and others) if you report supplier diversity spend.
7. The decision, and why it is written down
End with one of three outcomes: approved, approved with conditions, or rejected, each with a sentence saying why and who decided. A conditional approval should name each condition, its owner and its due date. Hard stops (a sanctions match, an active exclusion, a company not in good standing, an unverified bank change) block even a conditional approval.
For the wider programme this checklist sits in, see Vendor onboarding checklist: the checks to finish before the contract is signed and how to tier vendors by risk.
Frequently asked questions
- What documents do you need to onboard a US vendor?
- At minimum: a signed IRS Form W-9, proof the business exists and is in good standing with its state of formation, a certificate of insurance for general liability, a bank letter or voided check for the payment account, and signed acknowledgements of your code of conduct and anti-bribery policy. Higher-risk vendors add financial statements, a security questionnaire and, where relevant, a HIPAA business associate agreement.
- Do I need to check SAM.gov for a commercial vendor?
- It is not a legal requirement for a purely commercial purchase, but it is a cheap and strong signal. An active federal exclusion means a US agency found the company not presently responsible, often for fraud or failure to perform. Federal contractors and grant recipients must check it; everyone else should.
- How do I stop bank detail change fraud?
- Treat every request to change a vendor's bank details as suspicious until verified by a phone call to a number you already held before the request arrived, never one supplied in the request. Block payment to the new account until that callback is recorded, and log who called, when, and who confirmed.
- Do US companies still have to report beneficial owners under the Corporate Transparency Act?
- No. FinCEN's interim final rule of March 2025 exempted companies formed in the United States from beneficial ownership reporting. Identifying a supplier's owners is still sensible buyer-side diligence, especially for sanctions screening, but it is your check, not the vendor's filing.
Related guides
- Fundamentals
- Checklist
Vendor due diligence: a practical guide for small and mid-sized businesses
The end-to-end process — scoping, questionnaires, evidence, scoring, review cadence — sized for a team of one.
9 min read
- Checklist
- Onboarding
Vendor onboarding checklist: the checks to finish before the contract is signed
Twelve checks, grouped by who owns them, with the one record to keep for each so the file is audit-ready from day one.
7 min read
- Questionnaires
- Scoring
Vendor risk assessment questionnaire: what to ask, and how to score the answers
The questions that matter by risk tier, mapped to the controls auditors recognise, with a scoring method you can explain.
8 min read