← CompanyProof Journal

KYB AND COMPLIANCE

Vendor due diligence after onboarding: evidence that stays current

The first UK prosecutions for Companies House identity-verification failures turn supplier identity into a monitored evidence problem, not a one-time checklist.

Vendor due diligence after onboarding: evidence that stays current — CompanyProof Research
READING VIEW

01

The decision: make vendor due diligence a monitored evidence record

Vendor due diligence now needs a live evidence rule for company identity, ownership and control changes after approval. The immediate trigger is UK-specific: on 17 September 2026 the Insolvency Service and Companies House announced the first prosecutions for failing to comply with Companies House identity-verification requirements. For US product, compliance, credit, procurement and data teams, the lesson is broader than the UK register. A supplier check is only defensible if it records what was retrieved, what was actually verified, and which later registry event should reopen the relationship.

Most current vendor due diligence pages answer the first-order procurement question: what should we ask before signing? That remains necessary. The unanswered enterprise question is different: when a company fact changes, which part of the vendor record should change with it? A supplier can remain incorporated while a director resigns, a PSC misses a verification deadline, a filed account becomes stale, or the entity on the contract turns out not to be the operating group company described in the questionnaire.

This article treats vendor due diligence in the procurement sense: evaluating a third party you buy from or rely on. It is not seller-side due diligence in an acquisition. The practical answer is to build an evidence record with four layers: resolved legal entity, observed source values, claim-level verification outcomes and monitoring triggers. A business verification result may support one layer, but it should not collapse the whole decision into a green badge.

02

What changed in the last 48 hours

The recent UK development is concrete. The public announcement says three directors were fined at City of London Magistrates’ Court on 16 September 2026 after failing to comply with identity-verification requirements. It also describes identity verification as part of the Economic Crime and Corporate Transparency Act reforms intended to improve the accuracy of the company register and deter misuse of UK companies.

That does not mean a procurement team can treat a verified director as proof that the supplier is safe. Companies House had already explained that mandatory identity verification for new directors and PSCs began on 18 November 2025, with transition arrangements for existing roles. The rollout information also explains that many people need to provide a Companies House personal code and a verification statement for each role they hold. In operational terms, the same individual can appear in several company roles, and each role can carry its own evidence and deadline.

The PSC guidance adds a second boundary. A PSC must verify identity and provide a personal code for the PSC role, but PSC information can also be incomplete, protected from publication or updated after a company identifies a change. The public API schema shows this becoming data, not just policy: PSC resources can contain identity-verification details such as due dates, statement dates, appointment verification start and end dates, verifying ACSP name and verification date where available.

The safe conclusion is narrow but useful. For a UK supplier, director and PSC identity-verification fields can become monitoring inputs. They help a reviewer distinguish a registered company with compliant role evidence from a registered company with unresolved role evidence. They do not prove beneficial ownership by themselves, and they do not replace sanctions screening, payment-control checks, financial review or contract authority review.

03

Where the current search results stop short

Current search results are useful but mostly checklist-led. Some use vendor due diligence for seller-commissioned M&A analysis; others use it for procurement review. Procurement guidance commonly covers corporate standing, beneficial ownership, filed accounts, sanctions, security, data protection, resilience, subcontracting and contract terms. Those are useful answers to the pre-signature question, provided the workflow first identifies which legal company is signing the contract.

Several guides also recommend recurring assessment, continuous monitoring or independent checks. The operational gap is the evidence state machine: how a later registry observation should be classified as unchanged, corrected, missing, contradicted, unavailable or stale. Supplier-provided information can age, and a monitoring alert needs to tell a reviewer which fact changed and which earlier decision depended on it.

That gap matters for product and data teams building a kyb api integration or an internal counterparty service. If the API only returns “approved” or “failed”, it cannot explain whether the supplier’s registration status changed, the source was unavailable, a PSC verification deadline arrived, a filed financial period aged out, or the system simply selected the wrong legal entity. The workflow needs evidence states, not just risk colours.

04

A field-level model for vendor due diligence evidence

Start by separating retrieval from verification. Retrieval asks what the source currently returns for a selected company. Verification asks whether that observed value supports a specific supplier assertion. Monitoring asks whether a later source event invalidates the evidence used in an earlier decision. These distinctions sound technical, but they are what keep a stale filing from being mistaken for a current approval.

The interagency third-party risk guidance for banking organisations is a useful anchor because it treats due diligence and ongoing monitoring as parts of the same lifecycle. It lists ownership structure, beneficial ownership, legal authority, sanctions exposure and compliance capability among possible due diligence considerations, and describes ongoing monitoring as a way to identify issues such as financial deterioration, security breaches, service interruptions and compliance lapses. NIST’s July 2026 supply-chain due diligence guide is similarly evidence-led, describing due diligence as research into available pertinent information about a supplier or product, with components including foreign ownership, control or influence, provenance, resilience, foundational cyber practices and supply-chain tiers.

For a company-identity workflow, that translates into a compact evidence receipt. Store the selected legal entity, jurisdiction, registration number, source, source record or link, observed value, retrieval time, source update or filing date where available, verification outcome and next review trigger. Where a tool such as CompanyProof is used, the useful implementation question is not whether the supplier received a single pass mark, but whether each material company fact keeps its source context and can be reopened when the underlying evidence changes.

  • Resolved entity: legal name, registration number, jurisdiction, source and match rationale.
  • Observed fields: status, legal form, incorporation date, director or PSC role, filed-financial period, ownership statement or parent link where available.
  • Verification outcome: supported, corrected, contradicted, unsupported, unavailable or stale.
  • Decision owner: procurement, finance, compliance, security, credit or legal reviewer responsible for the unresolved question.
  • Reopen trigger: source change, source age, renewal, contract expansion, ownership change, director or PSC event, payment change or material adverse event.
05

Worked example: a UK software supplier with a new PSC verification event

This example is hypothetical. The entity is “Northshire Analytics Ltd”, a fictional private company in England and Wales. The source model is based on Companies House public guidance and API field descriptions retrieved on 20 September 2026, not on a live lookup for a real company. The procurement scenario is a US financial-services firm approving the supplier for analytics support with access to sensitive operational data.

At onboarding, the supplier states that Northshire Analytics Ltd is active, incorporated in England and Wales, has two directors, has one PSC and has filed its latest accounts. The first review retrieves the company record, verifies the legal name and registration number, stores the selected jurisdiction and records the accounts period. That is business verification, not a complete compliance decision. Security still needs assurance evidence, finance still needs payment controls, and compliance still needs sanctions and policy checks.

Three months later, monitoring detects a PSC identity-verification statement due date or status change in the Companies House data model. The original approval should not be erased. Instead, the supplier record should show that the company identity remained the selected entity, the PSC evidence changed or became due, and the relationship moved to review because a control-person field now requires attention. If the source is unavailable on the review day, the record should say unavailable, not failed. If the returned PSC differs from the supplier’s questionnaire, the record should say contradicted and route to the owner who can request clarification.

The same logic applies to ubo verification outside the UK. FinCEN’s CDD materials preserve the distinction between identifying and verifying natural-person beneficial owners for legal-entity customers and performing risk-based due diligence. A supplier’s self-attested owner list, a registry PSC record, a private shareholder document and a bank CDD file may each support different claims. Treating them as interchangeable “ownership” fields creates false certainty.

06

How to implement the monitoring rule

A practical implementation starts with tiering, because not every vendor deserves the same depth. A stationery supplier with no data access may need identity and payment controls. A critical cloud, payments, logistics or data supplier may need legal-entity verification, ownership evidence, financial review, sanctions and adverse-media screening, security assurance, subcontractor visibility and explicit contract terms. The point of tiering is not to avoid evidence; it is to decide which evidence can change the decision.

Next, write field-specific ageing and trigger rules. Registration status may be checked at onboarding, renewal and when a registry change arrives. Director and PSC evidence may need event-based review where a jurisdiction supplies role-change or identity-verification fields. Filed financials need a period, currency, consolidation scope and filing date, not just a revenue figure. Ownership evidence needs the source, threshold, date and chain boundary; missing evidence is a gap, not proof that there is no owner.

Finally, design the failure handling before the first alert fires. A contradicted identifier should stop downstream reliance until the entity match is fixed. An unavailable source should pause or retry rather than imply misconduct. A missing owner field should route to enhanced review if the supplier tier requires ownership evidence. A stale financial period should trigger a request for updated accounts or a credit review, depending on the exposure. A changed director or PSC field should reopen the authority and control-person review, not automatically terminate the supplier.

  • For a low-risk supplier, collect legal identity, registration status, payment controls and a scheduled review date.
  • For a material supplier, add ownership and control evidence, financial-period context, sanctions and integrity screening, and named risk owners.
  • For a critical supplier, add continuous or event-based monitoring, contract rights to request updated evidence, exit planning and board or committee reporting where policy requires it.
  • For every tier, record missing, unavailable and contradictory evidence separately so analysts do not confuse absence of data with a clean result.
07

Decision table for supplier evidence changes

The operational goal is not to make every vendor due diligence decision automatic. It is to make the next action predictable. A procurement analyst, compliance officer or product workflow should be able to see why the supplier record changed and which owner must act. The table below is a compact rule set that teams can adapt to their policy.

The same structure supports a KYB API or internal company-data service. The API should expose the observed company fact and its evidence state. The business system should decide whether that state blocks onboarding, creates an exception, opens a review task, changes the supplier tier or simply updates the stored evidence.

  • Verified: keep the evidence receipt, approval owner and next review trigger.
  • Corrected: update the supplier record only after preserving the original assertion and observed value.
  • Contradicted: stop relying on the affected claim and route to the accountable reviewer.
  • Unsupported: request more evidence if the supplier tier requires that field.
  • Unavailable or stale: retry or use an approved fallback source, and reopen the earlier decision when the fact age exceeds policy; neither state proves a clean or non-compliant supplier.
INTERACTIVE TIMELINE

Timeline: why vendor due diligence now needs monitored company evidence

Key public milestones that move supplier identity from a one-time onboarding check toward field-level monitoring.

Interagency third-party guidance

US banking agencies describe planning, due diligence, contract negotiation, ongoing monitoring and termination as stages in third-party risk management.

Select a node to inspect its meaning. Nodes represent categories or stages, not measured quantities.

INTERACTIVE COMPARISON

Comparison: evidence states for supplier company facts

A practical classification that keeps retrieval, verification and monitoring separate in a vendor due diligence workflow.

A source returned a value

Useful for a profile, but not enough unless the system records which entity, field, source and retrieval time were used.

Select a node to inspect its meaning. Nodes represent categories or stages, not measured quantities.

NEXT STEP

Put the guidance to work.

FREQUENTLY ASKED QUESTIONS

vendor due diligence FAQs

What is vendor due diligence in a procurement workflow?

Vendor due diligence is the evidence-led review of a supplier or third party before, during and sometimes after a business relationship. It should establish the legal entity, relevant ownership or control facts, financial and operational resilience, security posture, compliance concerns and the decision owner for any exceptions.

Is vendor due diligence the same as supplier due diligence?

In procurement usage, vendor due diligence and supplier due diligence often describe the same review of a third party you may buy from. The phrase can also mean seller-side M&A diligence, so teams should define the procurement context in policy, workflow labels and search-intent content.

What did the September 2026 UK prosecutions change for supplier checks?

They made Companies House identity-verification compliance a more visible operational signal. For UK suppliers, director and PSC identity-verification evidence can now be monitored as a role-specific fact, while still remaining separate from ownership certainty, sanctions clearance and payment authority.

Does director identity verification prove that a supplier is safe?

No. Director identity verification can support the claim that a named person completed an identity process for a relevant registry role. It does not prove the supplier is solvent, authorised to receive a payment, free from sanctions issues, controlled by a particular UBO or suitable for a given contract.

What evidence should a business verification step keep?

A business verification step should keep the selected legal entity, jurisdiction, registration number, observed status, source, source record or link, retrieval time, source update or filing date where available, the verified claim and any limitation that affects the decision.

How should a kyb api handle missing supplier ownership data?

A kyb api should return missing ownership data as a separate evidence state, not as a failed supplier and not as proof that no owner exists. The workflow can then apply the organisation’s risk tier, request documents, use another approved source or escalate to enhanced review.

How is ubo verification different from a registry PSC record?

UBO verification usually asks which natural persons ultimately own or control the entity under a policy or legal threshold. A registry PSC record is one source that may support part of that answer, but it can have publication limits, protected details, timing issues and jurisdiction-specific definitions.

How often should vendor due diligence be refreshed?

Refresh frequency should follow risk and evidence type rather than a single annual rule. Critical suppliers may need event-based monitoring and scheduled reassessment; lower-risk suppliers may be reviewed at renewal or on material change, with source age and field criticality recorded in the supplier file.

What should happen when a registry source is unavailable?

Unavailable information should be recorded as unavailable, with retry or fallback steps defined by policy. It should not be silently converted into a pass, a fail or a clean ownership result, because the reviewer needs to know whether the source contradicted the supplier or simply could not be reached.

What is the next step for a team improving vendor due diligence?

Start with the supplier tiers that create the most exposure, then define the exact company facts, evidence states, source-age limits and review owners for each tier. After that, connect the workflow to implementation documentation so retrieval, verification, monitoring and exception handling use the same evidence model.