The most-repeated supplier onboarding best practice is the one that quietly does the most damage: standardize one rigorous intake, collect every document up front, and run every vendor through the same gate. It reads like discipline. In a real procurement team it is the reason business owners stop calling procurement at all. When the office-furniture vendor has to clear the same gauntlet as the SaaS vendor with access to production data, someone in the business decides the gauntlet is the problem and routes around it. The best practice created the bypass.
This article exists to argue that good supplier onboarding is not about collecting more, earlier. It is about scaling scrutiny to stakes, and building controls that survive contact with a busy team. The list of dos below is shaped by that distinction. If you want the underlying mechanics of the process itself, the supplier onboarding process and where it actually breaks covers the step-by-step arc. This piece is about what to do and what to stop doing inside that arc.

Best practice 1: tier the risk before you collect anything
The best practice says collect a complete document set from every vendor. The better practice is to decide, at intake, which lane a vendor belongs in, and let the lane decide the document set.
A low-risk, low-spend, no-data-access supplier needs a tax form, banking details, and a quick duplicate check. A strategic vendor that touches regulated data or carries six figures of annual spend needs the full treatment: sanctions screening, a security review, a negotiated contract, a data processing agreement, and ongoing monitoring. Forcing both down the same path does two bad things at once. It over-burdens the simple vendors, which trains the business to bypass you. And it under-serves the complex ones, because a process built to clear volume rarely has the patience for the cases that actually carry risk.
Tiering is the practice that makes onboarding faster and safer in the same move. You speed up the many and you concentrate attention on the few that earn it. The intake decision is the highest-leverage moment in the entire process, and most lists bury it under a document checklist.
Best practice 2: collect what the engagement needs, not everything you can name
Over-collection masquerades as diligence. A vendor that will never see a customer record does not need a SOC 2 report on file. A one-time supplier does not need a five-year financial history. Every document you require is a document someone has to chase, store, verify, and re-verify at renewal, and every unnecessary one slows the vendor down for no reduction in risk.
The defensible baseline for a US supplier is narrow:
- A W-9, or a W-8 series form for non-US suppliers, for tax reporting
- Banking details for remit-to, captured in a form rather than a free-text email
- A certificate of insurance with the coverage levels and additional-insured language your contracts require
Everything beyond that should be conditional on the tier. Diversity certifications when a customer or regulation requires reporting. Security certifications (SOC 2, ISO 27001, HIPAA) when the vendor handles data that makes them relevant. The rule is simple: a document earns its place on the checklist by mapping to a specific risk this vendor actually presents. If you cannot name the risk, drop the document.
Best practice 3: validate against the ERP before you create the record, not after
Here is where most duplicate-vendor messes are born. A business owner is impatient, a purchase order is waiting, so procurement creates the vendor record to unblock the PO with every intention of circling back to verify. The circling back does not happen. Three months later there are two records for the same legal entity with different tax IDs, and the AP team is paying invoices against both.
The control that prevents this is sequence, not effort. Validate the submission against the ERP’s existing vendor list at intake, before any record is written. Match on legal entity and tax ID rather than display name, because the same supplier reliably shows up as Acme Inc., Acme LLC, and Acme Industries across three half-finished records. The pattern of checking submitted vendor data against NetSuite before a record is created is documented end to end, and the same shape runs against Acumatica with the AP-side duplicate check before bill creation. The point is architectural: the duplicate check has to query the system of record, and it has to happen before the write, or it does not happen at all.
Best practice 4: make banking-change verification a step, not a policy
Banking detail changes on existing vendors are a known fraud vector. The standard advice is to “verify banking changes,” which everyone agrees with and which fails the moment a convincing email arrives during a busy week. A policy that asks a human to remember to verify is not a control. It is a hope.
The control is to make the verification a step the process will not skip. When a banking detail changes on an existing vendor, the request pauses. A callback to a known contact (not the contact on the change request) is required, and a named approver signs off before the ERP record updates. The verification is not optional and it is not dependent on whoever happened to open the email being suspicious that day. The difference between a policy and a control is whether the system enforces it when nobody is watching.

Best practice 5: make the request’s state visible to everyone who touches it
Onboarding stalls are almost never caused by one slow step. They are caused by nobody being able to see where the request is. Finance is waiting on legal. Legal thinks procurement is still collecting a document. Procurement assumed IT finished the security review last week. Three days evaporate before anyone notices nothing has moved, because the request’s state lives in five separate inboxes and no shared place.
The best practice that addresses this is written, too softly, as “communicate status.” The actual control has two parts. One is a single observable view of where every in-flight request sits and how long it has been there. The other is a defined service level for each review step, so a stalled request surfaces itself instead of waiting to be discovered. Visibility is not a nicety layered on top of the controls. For a multi-party handoff, visibility is half the control, because a handoff you cannot see is a handoff you cannot govern.
This is the point where the best-practice list runs into a wall that no single application solves, and it is worth naming plainly. The intake form lives in one tool. The duplicate check queries the ERP. The contract gets signed in DocuSign. The approvals happen in Slack or email. The renewal calendar lives somewhere else again. The “single source of truth” that every onboarding guide recommends does not exist as a product, because no one system holds all of those pieces. The truth is spread across the seams between systems, which is exactly where it goes missing.
That seam is the category the problem actually points to. An orchestration layer is a system that sits above the systems of record. It listens for what each one emits: a form submission, a signed agreement, an approval response, an ERP write. It carries the context across each handoff, and it pulls a human in only at the moments that need judgment instead of every moment by default. It is not a sixth system that becomes a sixth seam. It is the layer that makes the five existing systems agree on what is happening to which vendor at which step. FlowRunner is built for that layer, and the same coordination idea is described from the buyer’s angle on the supplier portal software and supplier relationship management software pages. The reason the “single source of truth” advice keeps failing is that teams keep looking for it inside a tool. It lives in the coordination across tools, and coordination is a layer, not an app.
The anti-patterns to retire
Several habits show up in nearly every team that has not reworked its onboarding, and each one is the shadow of a best practice done wrong.
- Documents collected by email and scattered across inboxes. The W-9 in one reply, the COI forwarded from a broker, the banking confirmation three threads later. When an auditor asks where the COI was on the date of the first purchase order, the answer becomes inbox archaeology. Collect into a structured place, attached to the vendor, from the start.
- Verification that depends on one specific person. Sanctions screening through one analyst, security review through one IT contact. When that person is out, the request sits, because the step was a habit, not a documented process with a defined backup.
- Records created before risk review finishes. The workaround that creates duplicates and orphaned vendors who get paid before anyone produced their insurance. Treat the ERP write as the reward for completing the checks, not the move that unblocks the PO.
- An audit trail made of Slack reactions and remembered approvals. A thumbs-up emoji is not a record of who approved a vendor at which payment term. If the answer to “who approved this” is a reconstruction from memory, you do not have an audit trail, you have a story.
- Treating onboarding and ongoing management as one program. Onboarding ends when a vendor can transact. Everything after (COI expiration tracking, banking-change verification, contract renewal surfacing, scorecard data) is supplier management, a different job. When the handoff between them is implicit, expiration dates and renewal clauses go missing.
The pattern under all five is the same one this article opened with. The work inside each step is rarely the problem. The continuity between steps is. Strengthen the handoffs and the anti-patterns disappear on their own, because most of them are just continuity failing somewhere along the chain.
Where to start when everything needs fixing

If two or more of those anti-patterns sound like your team, the question is not whether to rework onboarding. It is which seam to strengthen first, and the answer is almost always the intake-to-validation seam. Make it impossible to create a vendor record in the ERP until the documents are in, the approvals are captured, and the duplicate check has run. That single change pays compounding dividends. The audit trail gets easier because structured handoffs leave timestamps behind on their own. The renewal handoff gets easier because the documents now live where supplier management can see them. The bypass behavior fades because the formal path stops being slower than the workaround. A separate framework on how to decide which onboarding steps are worth automating first handles the financial side of sequencing that work.
The best practice worth adopting before any other is the one almost no list leads with: stop trying to make every vendor pass through the same rigorous front door, and start making the handoffs between your existing systems observable and enforced. Rigor applied uniformly creates bypass. Rigor applied to risk, with controls that hold when the team is busy, is the version that actually scales.
Quick answers
What is the most important supplier onboarding best practice?
Risk tiering. Decide at intake how much scrutiny a vendor needs, then run a fast path for low-risk suppliers and a slow path for strategic or regulated ones. A single one-size process is the practice that quietly drives business owners to bypass procurement, because the fast vendors get punished with the slow vendors’ controls.
What documents should you collect during supplier onboarding?
For US suppliers, a W-9 (or a W-8 series form for non-US suppliers), banking details for remit-to, and a certificate of insurance with the right coverage and additional-insured language. Add diversity certifications and security certifications (SOC 2, ISO 27001, HIPAA) only when the engagement actually requires them. Collecting every document from every vendor is over-collection, not diligence.
How do you prevent duplicate vendor records?
Run the duplicate check against the ERP at intake, before the vendor record is created, not after. Most duplicates come from creating the record early to unblock a purchase order, then never reconciling. Match on legal entity and tax ID rather than display name, because the same supplier shows up as Acme Inc., Acme LLC, and Acme Industries across three records.