
A vendor clears onboarding without a problem. Ten months later it sits at the center of a payment dispute, and someone finally pulls the file. The company was formed four months before the contract was signed, and the person who signed it had done the same thing twice before under different company names. None of that was hidden. It was never looked at, because fraud risk management in many organizations is pointed inward, at transactions and controls, while a good share of the loss walks in through the counterparty.
A well-run fraud program catches a lot. Approval thresholds, transaction analytics, vendor master file reviews, an ethics line someone actually reads. Those controls surface expense manipulation, procurement kickbacks, and the payment that does not fit the pattern.
What they answer is a question about behavior, which is whether this transaction is unusual for this relationship. They are not built to answer the question underneath it, which is whether the counterparty is what it claims to be. By the time an internal control fires on a fraudulent vendor, the invoices are already flowing and the recovery conversation has turned into a legal one.
Counterparty fraud risk sits earlier than that, and most of what makes it visible is public.
When fraud has already been adjudicated, the record says so plainly. A criminal conviction, a regulatory enforcement action, or a judgment that names fraud is not subtle, and a screen will surface it.
The harder case is the counterparty with none of that on file. There the record holds no verdict, only small checkable facts that either corroborate the story told during onboarding or quietly contradict it.
A formation date shows how long the company has actually existed, which is not always how long it has claimed to be operating. A registered agent shared with several dissolved entities says more about the person behind the company than about the company. Tax liens are often the earliest visible sign of financial strain, surfacing well before a counterparty would raise it. Uniform Commercial Code (UCC) filings can reveal that the equipment your contract depends on is already collateral for somebody else. Civil litigation shows whether the company is a frequent defendant, and in what.

A business background check pulls these into one place. None of them is a fraud finding on its own. They matter because they can disagree with each other.
Where they disagree most often is between the entity and the people behind it. Limited liability companies are cheap to form and easy to walk away from, so the company in front of you can be four months old with a clean record while the person signing has been through the cycle several times. A logistics company we worked with ran manual Secretary of State lookups, which is more than many companies do. It confirmed the entity existed, and it missed the web of related LLCs, dissolved companies, and registered agent changes behind one individual. The loss came to roughly fifty thousand dollars.
An associated business risk search closes that particular gap. It identifies the other companies where a person is listed as owner, operator, or executive, then checks those entities for bankruptcies, liens, and litigation. That is frequently the search that reframes a deal, and it is the reasoning behind screening principals alongside the entity rather than treating it as an escalation.
Fraud due diligence is largely the work of noticing when the picture these records form does not match the story told at onboarding. Entity verification does much of that, and it is worth knowing where it stops.
Screening works by matching names. You supply a subject, and the system returns records carrying that name, whether the record is a lien, a civil case, a criminal charge, a sanctions entry, or a news article. A match establishes that such a record exists. It does not establish that the record belongs to your subject, or that its contents are adverse.
Both halves of that gap show up in practice. A common business name pulls in filings against a similarly named company in another state. An entity operating under an assumed name may not connect to its own record at all. On the media side, a keyword category can attach to coverage that is neutral or even favorable, so a company can land under an environmental crime flag because a local article described a grant it received to cut emissions.
The discipline is to open the source before acting on the alert. A fraud screening service that returns a risk score without the record behind it has moved the interpretation problem rather than solved it. This is most visible on adverse media and sanctions screening, where the volume of source material is largest, but it applies to every category on a report, down to county civil filings. Confirming that a match belongs to your subject is what turns it into a finding, and on our reports an investigator does that before the report reaches you.
A database screen queries aggregated public-record data and returns what matches the name you entered. Nobody visits a courthouse, which is why it comes back in minutes and also where its limits begin. We compare the two approaches in depth in choosing between database screening and investigative due diligence.
Not every counterparty deserves the same depth, and a program that treats them as though they do spends its budget in the wrong places.
For routine, lower-risk onboarding at volume, a database screen is usually the right answer. Our Preliminary Report runs across public records with matching logic and comes back in minutes when it is clean, which clears the long tail of vendors where being wrong costs very little. Recommending anything heavier there is selling depth the deal does not need.
The escalation triggers are specific rather than atmospheric. A recently formed entity on a large contract. A principal whose name returns hits worth confirming. A counterparty controlling assets your deal depends on. A jurisdiction whose courts do not publish electronically, which is where database coverage thins fastest.

Past that point an investigator pulling from the source is doing something an aggregated database cannot. A database holds whatever its last feed contained, so a filing entered at the county in the last few weeks may not surface yet, and courts that still run on paper may never feed it at all. That is the distance between "no records found" and actually clean.
Whatever depth you pick describes the counterparty on the day it runs. Liens get filed and ownership changes hands without sending notice, which is why re-screen cadence belongs in the third-party risk management program rather than in the onboarding checklist. Point-in-time screening is genuinely the right call for plenty of counterparties.
Fraud risk management does not get solved with one purchase, and the counterparty layer is the piece many programs under-build, largely because it sits outside the org chart. The internal controls stay. What changes is the order of operations. Before money moves, look at the entity, look at the people behind it, and open the source behind a hit instead of reacting to the alert.
If you would like to talk through how this applies to your own counterparties, or you are considering moving some of this work off your team, fill out the form below and our team can help you determine the right approach.