Procurement & Spend Management3 min readUpdated September 2026

Vendor Onboarding Checklist: Vetting a New Supplier

Vendor onboarding is the set of checks you complete before a new supplier is approved and paid: rate the risk, collect tax, insurance and security documents that match that risk, verify payment details independently, sign the contract and record the vendor in one system. A low-risk office-supplies vendor needs far less than a payroll or cloud provider.

Tier first. Applying the full process to every vendor overloads whoever runs it, and applying none leaves the risky ones unchecked.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

How do you tier vendors by risk?

Ask four questions about each new vendor and count the yes answers:

  • Will they access our systems or customer data?
  • Would an outage or failure from them stop us delivering to customers?
  • Will we spend a large amount with them, or sign a multi-year commitment?
  • Are they handling money, regulated activities or our brand on our behalf?

Zero or one yes is low risk. Two is medium. Three or four is high. Write the tier in the vendor record. The tier decides which documents you request and how often you review the vendor. It also decides who approves, so a high-risk vendor might need finance and security sign-off, while a low-risk one needs only the budget owner.

What documents should you collect for each tier?

Ask for documents that match the risk:

  1. All vendors: a completed tax form, legal name and address, contact details and a signed agreement or terms.
  2. Medium and high: a certificate of insurance where relevant, and a description of how they'll deliver the service.
  3. Anyone with access to systems or data: a security questionnaire or their security documentation, and a data processing agreement where personal data is involved.
  4. High risk: references, financial stability checks, a review of their subcontractors and an exit plan for moving away from them.

Don't collect documents you won't read. Each item should have someone assigned to review it and a rule for what counts as a pass. Ask a lawyer to review contract terms on high-risk vendors, especially liability, data handling and termination.

How do you verify payment details safely?

This step stops the most common fraud. Never accept bank details from an email alone. Instead:

  1. Collect payment details through a standard form or the vendor portal, not a free-form email.
  2. Call the vendor at a phone number you've obtained independently, such as from the signed contract or their official site, and confirm the details verbally.
  3. Have someone other than the requester set up the vendor in your payment system.
  4. Make a first small payment or test where your bank supports it, or hold the first payment for a second review.
  5. Log who verified the details and when.

Apply the same callback to any later request to change bank details, which is a favorite method for fraudsters.

How do you set up the vendor record and kick off the relationship?

Enter the vendor once, in one place, with the tier, contract dates, renewal and notice deadlines, owner, contact list and payment terms. This record is what lets you find every contract expiring in the next quarter and see who uses which vendor. The contract lifecycle management guide covers renewals.

Hold a short kickoff with the business owner and the vendor to agree on how the service will run: main contacts, escalation, response times, reporting and how you'll judge performance. For important vendors, monitor delivery against those terms, following the operational SLA monitoring guidance. A task board, such as one in Monday.com, is a reasonable way to track each step across finance, legal and the business owner.

What should you review after 90 days?

At 90 days, meet with the business owner and check whether the vendor is delivering as agreed. Look at invoices against expectations, service issues, responsiveness and whether the original need is met. Adjust the tier if the vendor turned out to be more or less important than expected.

Then set a review cadence by tier: high-risk vendors every year, medium every year or two, low on renewal. Use a vendor scorecard to make those reviews consistent. Also update the process itself after each onboarding, adding a check that would have caught anything that went wrong. If you want to see how the same principle applies to new employees and customers, look at the employee onboarding checklist and client onboarding automation. For tools that manage procurement, see this spend management tool comparison.

Executive Capability Standard

What Good Looks Like

A good onboarding process tiers vendors by risk, collects only the documents that tier needs, verifies payment details by callback and records every vendor with renewal dates.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Learn which of your current vendors touch customer data or would stop delivery if they failed, and tier them.
2. Do Manually:Run the next new vendor through the tiering questions, document list and callback, and log the results.
3. Delegate:Assign one owner in finance or operations to run onboarding, with legal or security reviewing high-risk vendors.
4. Automate:Send each vendor a standard intake form, route approvals by tier and create renewal reminders from the contract dates.
5. Buy:Adopt a vendor management or procurement tool when the vendor count makes spreadsheets hard to keep current.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Monday.com

Fits as a shared tracker for onboarding steps that span finance, legal, security and the business owner.

Visit Monday.com→

Frequently Asked Questions

What is vendor onboarding?

It's the process of vetting, approving and setting up a new supplier before you pay them. It typically includes risk rating, collecting documents, verifying payment details, signing an agreement and recording the vendor in your systems.

What documents do you need from a new vendor?

At minimum a tax form, legal details and a signed agreement. Add insurance certificates for services with liability, and security and data processing documents if they'll touch your systems or personal data. Scale the list to the vendor's risk tier.

How do you verify a vendor's bank details?

Confirm them by calling a phone number you got independently, such as from the signed contract, and have someone other than the requester set up the vendor. Use the same callback for any later change.

How often should you review vendors?

Review high-risk vendors at least yearly, medium-risk vendors every year or two, and low-risk vendors at renewal. Also review after any incident, major change or price increase.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides