Every new subcontractor and supplier is a chance to grow your capacity and a chance to let a fraudster into your accounts payable process. Fake vendors, impersonated companies and stolen identities are most easily caught at the beginning, before anyone has been paid. After the first payment, the relationship feels established, and attackers know it.
A consistent onboarding process, applied to every vendor, makes fraud harder without burdening honest businesses.
What attackers exploit
- Fictitious companies created to submit invoices for work never performed
- Impersonation of real subcontractors, using stolen details and lookalike email addresses
- Altered documents, such as forged insurance certificates, W-9 forms or licenses
- Insider collusion, where an employee sets up a vendor they control
- Rushed setups, where urgency is used to bypass checks
Build a vendor onboarding checklist
Collect the basics
Require a standard package from every new vendor:
- Completed tax form, such as a W-9, with legal name, address and taxpayer identification
- Certificates of insurance, issued directly by the insurer or broker
- Contractor licenses where applicable
- References or past project information
- Payment instructions on a standard form signed by an authorized representative
Verify independently
Do not rely solely on what the vendor sends you.
- Confirm the business exists. Check state business registrations and licensing boards.
- Verify taxpayer information using the approach your accountant recommends, such as the IRS TIN matching program where eligible.
- Contact the insurer or broker using contact information you look up yourself to confirm that coverage is real and current.
- Call the vendor using a number you find independently, to confirm banking details and key contacts.
- Check addresses. A mailing address that turns out to be a residence or an empty lot can be a signal, though not proof.
- Search for red flags such as complaints, litigation or news reports.
Review ownership and relationships
Ask who owns the company, and compare against your employee and vendor lists. Conflicts of interest are easier to manage when disclosed upfront. Rotate or add review for vendors connected to a single approver.
Control who sets up vendors
Separate duties wherever you can:
- The requesting project team identifies the need and provides documentation.
- Accounting or procurement verifies and sets up the vendor.
- A different person approves payments.
- A manager reviews a periodic report of newly added vendors.
Even in a small office, two sets of eyes are better than one.
Treat bank details with extra care
Banking information deserves a stricter process than other fields:
- Verify by phone with a known contact before saving
- Record who verified and when
- Alert on any later change, and require the same verification again
- Compare bank accounts across vendors to find duplicates, which can indicate fraud or error
Watch the first payments
New vendors are higher risk at first. Consider:
- A cap on initial payment amounts until a track record exists
- Extra review for first invoices, compared with contracts, purchase orders and proof of work
- Verification that work was actually performed, through a site visit, daily logs or photos
- Lien waiver requirements consistent with your contract practices
Protect the onboarding channel
Use a secure method to collect sensitive documents. Email attachments with tax IDs and bank details are a privacy and security risk. A secure portal or encrypted file transfer is better. Limit who can view the documents and delete copies you no longer need.
Train staff to resist pressure
Fraud attempts often come with urgency: a supposed emergency job, a pressing deadline, a project manager asking to pay a new vendor today. Make sure staff know they can pause and verify, and that leadership will back them.
A hypothetical example
Consider a hypothetical contractor that receives a request from a new "supplier" for rush payment on equipment rental. The documents look right, and a project manager vouches for the vendor after one phone call. A review finds the insurance certificate came from an email address unrelated to the insurer, and the phone number leads to a voicemail with no company name. The process caught what a single phone call would not.
A short policy outline
- All vendors complete the standard onboarding package
- Independent verification is documented in the vendor file
- Vendor setup and payment approval are separate duties
- Bank details are verified by phone with a known contact
- First payments to new vendors receive additional review
- Vendor lists are reviewed annually
Moving forward
Ironfield Cyber helps contractors and energy companies design vendor onboarding procedures, secure the tools that hold vendor data and train accounting teams to spot fraud. If your vendor setup process depends on trust and speed, we can help you add checks that work in the real world.