Supplier Management

Supplier Onboarding: What to Check, and How Long It Should Take

Onboarding is where a supplier record is born, and where most bad procurement data and most payment fraud enter the business. It is usually done in a rush, by whoever is nearest, so an urgent invoice can be paid. This guide sets out what to collect, how to tier the checks so routine suppliers are not over-screened, what changed recently in UK rules, and how long it should reasonably take.

10 min read
A blank printed registration form and a pen on a plain office table

Supplier onboarding sounds administrative. It is actually the point where three things are decided at once.

Whether your supplier data will be usable. Whether you are about to pay a criminal. And whether you can answer a regulator, a customer or an auditor about who is in your supply chain.

All three are decided by a process that in most companies takes about ten minutes and is done by whoever received the invoice.

What onboarding is for

Three purposes, and it helps to keep them separate because they need different checks:

Can we pay them safely?
Are they who they say they are, and are these really their bank details? This is the fraud question, and it applies to every supplier.
Are we allowed to deal with them?
Sanctions, legal status, and any sector rules that apply to you. This is the compliance question.
Should we depend on them?
Financial health, capacity, insurance, continuity. This is the risk question, and it only matters for suppliers that matter.

Most onboarding processes fail by applying the third question to everyone, or the first question to nobody.

Tier the checks

Running enhanced due diligence on a company supplying £400 of stationery wastes everyone's time and teaches the business to route around you. Three tiers works for most mid-sized companies.

TierWho it applies toWhat you check
LightLow value, low risk, one-off or routine purchasesLegal identity, company number, address, verified bank details, tax registration
StandardRecurring suppliers or anything above a set valueAll of the above, plus insurance where relevant, agreed terms, named contacts, sanctions screening
EnhancedCritical suppliers, anyone touching your systems or data, anyone in a regulated areaAll of the above, plus financial health, security and data-protection review, continuity arrangements, subcontractor disclosure
Our suggested tiering. Set the value thresholds deliberately and write them down.

The tier should be decided by what you are buying and how much you will depend on it, not by how urgently someone wants it paid.

The core checklist

Identity

Legal entity name, company registration number, registered address, and trading address if different. Check the number against the public register rather than accepting what is on the invoice.

This got easier in the UK. Since 18 November 2025, identity verification has been a legal requirement for directors, people with significant control and others filing at Companies House. Anyone acting without verifying may be committing an offence. They may face prosecution or a financial penalty, and a note is placed against their name on the public register.

For a buyer, that means the register is a stronger check than it used to be — and that a company whose officers are flagged as unverified is worth a second look.

Bank details, verified independently

This is the single most important control in onboarding. Never take bank details from an email alone, even one that appears to come from the supplier.

Call the supplier on a number you obtained separately, speak to someone you can identify, and record who verified it and when. The same rule applies to any later change of details.

The scale of this is not theoretical. The FBI recorded $2.77 billion of business email compromise losses in 2024 across 21,442 complaints — second only to investment fraud by money lost.

Screening suppliers against sanctions lists is standard practice, and for many businesses a legal necessity.

Sector and regulatory checks

Two that catch mid-sized companies out:

  • If you are a financial entity in the EU, the Digital Operational Resilience Act has applied since 17 January 2025. It requires a register of contracts with technology suppliers and active management of the risks those suppliers create. Onboarding is where that register is populated or missed.
  • If you are a UK organisation above the turnover threshold, section 54 of the Modern Slavery Act 2015 requires an annual statement covering steps taken in your business and supply chains. Onboarding is the natural point to gather what that statement will need.

Even where a rule does not name you, larger customers increasingly pass their obligations down by contract. Assume you will eventually be asked.

Risk checks, for suppliers that matter

For critical suppliers, check financial health at onboarding and then annually. RapidRatings found that only 15% of enterprises fully use supplier financial health data when setting payment terms. Thirty per cent do not use it at all. Yet 82% had suffered a material supplier disruption in the previous year.

Onboarding is a fraud control

The person who creates a supplier record should not be the person who can pay it. If those two jobs sit with one person, a fake supplier is a short walk away.

The Association of Certified Fraud Examiners' 2024 study of 1,921 cases found billing schemes in 31% of cases at organisations with fewer than 100 employees. At larger ones it was 22%. Smaller teams struggle to separate duties. That is exactly why the supplier setup gate matters more, not less, when you are small.

A monthly review of newly created suppliers by someone outside the process takes about ten minutes and is one of the highest-value controls available to a small company.

How long should onboarding take?

APQC lists average cycle time to set up a supplier in the procurement system among its most popular procurement measures. That alone tells you it is worth tracking. We are not quoting a benchmark figure here, because the published values sit behind APQC membership and we have not read them.

Practical targets that work in mid-sized companies:

TierTarget turnaroundWhat usually causes delay
LightSame or next working dayWaiting on the supplier to return the form
Standard2–3 working daysBank verification call, insurance certificates
Enhanced5–10 working daysSecurity review, financial checks, legal review
Our suggested targets, not a published benchmark.

If onboarding routinely takes longer than this, people will start buying through suppliers that already exist, whether or not those are the right ones. Slow onboarding is a common and invisible cause of maverick spend.

Where onboarding goes wrong

It happens under pressure, at the end

The usual sequence is: work is already done, invoice arrives, someone needs the supplier set up today. Every check becomes an obstacle rather than a process.

The fix has two parts. Move onboarding earlier, starting it when a supplier is selected rather than when they invoice. And make the light tier genuinely fast, so there is no incentive to skip it.

Nobody controls how names are entered

"ABC Ltd", "A.B.C. Limited" and "ABC" become three suppliers. Then nobody can see total spend with them, risk scoring is wrong, and duplicate payments become possible. Agree a naming standard and check new entries against existing records before creating them.

Nothing is ever re-checked

Insurance expires. Companies change ownership. Financial health deteriorates. Set a re-verification cycle for standard and enhanced suppliers — annually is enough for most.

There is no offboarding

Suppliers you no longer use stay active in the system indefinitely. A dormant supplier record with live bank details is a standing risk. Mark suppliers inactive when they stop being used, and review the dormant list once a year.

A process that fits a mid-sized company

  1. One form, collecting everything the light tier needs, sent to the supplier by the person requesting them.
  2. One owner who creates supplier records, and who cannot release payments.
  3. One gate: no purchase order and no payment until the record exists and bank details are verified.
  4. A tier decision made at creation, recorded on the record, driving what else is required.
  5. A monthly ten-minute review of new suppliers by someone outside the process.
  6. An annual re-verification run and a dormant-supplier cleanup.

That is the whole thing. It does not need software beyond what you already own, and it prevents most of what goes wrong downstream.

Common questions

What is supplier onboarding?

The process of collecting and verifying the information needed to buy from and pay a company safely: legal identity, verified bank details, tax registration, insurance where relevant, compliance checks such as sanctions screening, and for important suppliers, financial health and continuity. It is also where the supplier record in your system is created.

What should a supplier onboarding checklist include?

At minimum: legal entity name, company registration number checked against the public register, registered and trading addresses, independently verified bank details, and tax registration. For recurring or higher-value suppliers add insurance, agreed terms, named contacts and sanctions screening. For critical suppliers add financial health, a security and data-protection review, continuity arrangements and subcontractor disclosure.

How long should supplier onboarding take?

As a practical target: same or next working day for low-risk suppliers, two to three days where insurance and bank verification are needed, and five to ten days where security or financial review applies. APQC tracks supplier setup cycle time as a standard measure, though the benchmark values sit behind membership. If onboarding is routinely slower, people start routing purchases through existing suppliers instead.

How do you verify a supplier's bank details?

Never from an email alone. Call the supplier on a number you obtained independently — not one provided in the email or on the invoice — speak to someone you can identify, and record who verified it and when. Apply the same rule to any later change. The FBI recorded $2.77 billion in business email compromise losses in 2024 across 21,442 complaints.

Has UK supplier identity checking changed?

Yes. Since 18 November 2025 identity verification has been a legal requirement for directors, people with significant control and others filing at Companies House. Those who act without verifying may be committing an offence and may face prosecution or a financial penalty, with a note placed against their name on the public register. That makes the register a stronger check for buyers than it used to be.

Where do I check UK sanctions when onboarding a supplier?

The UK Sanctions List is now the authoritative source. The government's older "Consolidated list of financial sanctions targets" page was withdrawn on 28 January 2026 and directs users to the UK Sanctions List instead. If your written screening procedure still names the consolidated list, it is pointing at a retired page and should be updated.

Should every supplier get the same checks?

No. Tier them. Running enhanced due diligence on a low-value stationery supplier wastes time and pushes people to work around procurement. Decide the tier by what you are buying and how much you will depend on it — never by how urgently someone wants the invoice paid.

Why is supplier onboarding a fraud control?

Because a supplier record is what makes payment possible. If the person who creates supplier records can also release payments, a fictitious supplier is straightforward. The ACFE found billing schemes in 31% of cases at organisations with fewer than 100 employees against 22% at larger ones, precisely because small teams struggle to separate duties. A monthly review of newly created suppliers by someone outside the process is a strong, cheap control.

Do we need to re-check suppliers after onboarding?

Yes. Insurance expires, ownership changes, and financial health moves. Set an annual re-verification for standard and enhanced suppliers. Also mark suppliers inactive when you stop using them and review the dormant list yearly — a dormant record with live bank details is a standing risk.

How do we stop duplicate supplier records at onboarding?

Agree a naming standard, make the required fields mandatory, and check new entries against existing records before creating them. Without this, the same company appears several times under trading name, legal name and abbreviations, which hides true spend, breaks risk scoring and makes duplicate payment possible.

Sources

  1. Companies House / GOV.UK, Verifying your identity for Companies House, Identity verification became a legal requirement on 18 November 2025; applies to directors, equivalents, PSCs and authorised corporate service providers; penalties and register annotation for non-compliance.
  2. GOV.UK, Financial sanctions: consolidated list of targets (withdrawn), Page withdrawn 28 January 2026; directs users to the UK Sanctions List as the source of current designations.
  3. FBI Internet Crime Complaint Center, 2024 Internet Crime Report, Business email compromise $2,770,151,146 across 21,442 complaints (p.10).
  4. Association of Certified Fraud Examiners, Occupational Fraud 2024: A Report to the Nations, Figure 24, p.34: billing schemes 31% of cases at organisations under 100 employees vs 22% at 100+.
  5. CSSF (Luxembourg financial regulator), Entry into application of DORA on 17 January 2025, DORA application date and the register of information covering ICT third-party contracts.
  6. UK Home Office, Transparency in supply chains: a practical guide, Section 54 of the Modern Slavery Act 2015 requires certain organisations to publish an annual statement covering their business and supply chains.
  7. RapidRatings, Annual Risk Report 2026, 2 March 2026. 15% fully integrate supplier financial health into payment-terms decisions, 30% not at all; 82% material supplier disruption in the previous year.
  8. APQC, How Do You Benchmark Procurement?, Average cycle time to set up a supplier in the procurement system listed among the most downloaded procurement measures.

Want this run for you?

We take on the transactional half of procurement — invoices, purchase orders, supplier data and indirect spend — inside your own systems and under your approval rules. Start with a free spend audit: we measure your volumes, cycle times and exception rates, and the report is yours whether or not you go further.

Book a free spend audit