
By the time a vendor reaches onboarding, you usually have a signed W-9, a certificate of insurance, and a questionnaire the vendor filled out about itself. What you do not have is a single piece of information that did not come from the vendor. A vendor background check is the part of the file that comes from somewhere else.
If your team has not run one before, the shape of it is simple. A vendor background check is independent verification on a company you are about to rely on, and on the people who control it. It draws on public records rather than on anything the vendor hands you: corporate filings, court records, liens and secured claims, licensing and regulatory records, sanctions lists, and press coverage.
The decision it supports is narrow and practical. Before you sign, before money moves, and before a vendor is operating inside your business, you want to know that the company is what it claims to be, that nobody has already sued it or filed a claim against its assets, and that the people behind it do not have a history that would change your mind.
In most organizations this sits with procurement, compliance, or whoever owns supplier onboarding, and it runs once at onboarding and then again on a schedule after that.
For teams that already have vendor screening in their workflow, it usually runs through a tool built for speed. LexisNexis, Dun & Bradstreet, and Experian all sell quick, broad searches against large public-record indexes, and they are good at it. You get a broad first pass in seconds, covering registration, some litigation, some liens, and a credit signal. At the volume a procurement team onboards, that efficiency is the whole point, and a lot of the time it works well.
Our Preliminary Report is our own database screen, and it behaves the same way on speed. Clean results come back in minutes. What differs is what happens when something does hit: our investigators review the alert to confirm the record actually belongs to your subject, so you are not handed a list of possible matches to sort out yourself.
When a deal matters more, or when something about it seems off, you can upgrade that same report in the same place. Same subject, same order, more depth, without starting a new request.
The trouble is only when a quick screen is the only thing standing behind a decision that deserved more.
A full vendor background check works on two levels. The entity layer looks at the company. The principal layer looks at the people who own and run it.

On the entity, that begins with corporate registration and standing, where you confirm the entity is real and matches the name on the contract. From there it should reach former and assumed names, civil court filings, liens and judgments and Uniform Commercial Code (UCC) filings, sanctions and politically exposed person screening, adverse media, and license and certificate verification.
Licensing repays a closer look than most files give it. Whether a vendor holds the right license today is the easy question. The more useful one is what its license history shows: whether it lapsed, whether the vendor kept operating during the gap, and whether a regulator ever placed it on probationary status. A license that was suspended and reinstated is still a valid license, and it is also a conversation worth having before you sign.
The principal layer is the half that gets skipped, and it is often where the answer lives. A background check for vendors that stops at the entity is checking the part that is easiest to replace, because an operating company is a legal wrapper that can be dissolved and re-formed cheaply. Criminal record searches and civil history on named principals, plus a search for other businesses those individuals are tied to, will sometimes surface a pattern no entity-level search would have caught. That is the reasoning behind our position that a business background check should cover the principals too.
An index is a copy of the record, assembled by someone else, and the gaps follow from that in four fairly predictable ways.
Names have to match. Index searches lean on the name you type. A vendor that filed under a former name, an abbreviation, a DBA ("doing business as"), or a slightly different spelling than the one on your contract can come back clean because the search never reached the record, not because the record is not there. Entities with common names produce the mirror problem, where results belong to a different company entirely.
Records arrive on a lag. A lien or judgment filed recently may not be indexed yet. The filing is real and public, and the search still returns nothing.
Some jurisdictions never feed an index at all. A number of county courts do not report electronically, so their filings stay where they were made regardless of how much time passes.
Coverage thins outside the United States. Foreign registries vary widely in what they publish and how, local-language and transliterated names multiply the matching problem, and a fair amount of what matters on a cross-border counterparty is not in any aggregated product. We handle international due diligence across 255+ countries and territories, and in this segment it comes up constantly, because supply chains rarely stop at the border.

What closes these gaps is not a better index. Our investigators go directly to the courts and registries, search under name variations rather than one string, and on our Deep Dive can search a county or state office in person. That is the difference between reading a copy of the record and going to where the record lives.
The gap is not theoretical. One private lender stepped away from a five hundred thousand dollar deal after our investigators identified more than one million dollars in recent tax liens that were too new to have been captured anywhere else. The filings were real, public, and entirely absent from the automated result.
Three things sit outside a background check no matter how deep it goes, and each one sends you somewhere else.
It is not a security assessment. A vendor background check says nothing about data security controls, access management, or incident response. Those come from a security review, and no volume of court records substitutes for one.
It is not a financial audit. Business credit data shows payment behavior and public signs of distress, which is genuinely useful for supplier continuity questions. It is not the same as audited financials, and it describes where a company has been more than where it is heading.
It is not employment screening of the vendor's workforce. Vetting a vendor as a counterparty is business diligence, and it does not require the subject's consent in the United States. Screening that vendor's individual employees is employment screening, it is regulated under the Fair Credit Reporting Act (FCRA), and it belongs to whoever employs those people. Running the two together is how a procurement process ends up with a compliance problem attached to it. We have written separately on whether a non-FCRA background check requires consent.
For many vendor programs, a large share of vendors do not need a deep investigation, and a few need considerably more. Running the quick screen on everyone and letting it separate the routine from the unclear is the sensible default.
Our Advanced report and our Deep Dive are the tiers where investigators work the records themselves rather than reading an index, and the Deep Dive reaches up to twenty years. Because the upgrade happens on the existing report, the depth is a decision you can make after you have seen the first result rather than before.

What justifies that step is usually the shape of the relationship rather than the size of the vendor: a counterparty that will handle money or goods on your behalf, one operating in a jurisdiction you cannot easily verify, a sole-source supplier you would struggle to replace, or an entity where the first screen returned something unresolved. We have set out the triggers in more detail in our piece on when to escalate a screen.
For everything else, the lighter check is the right answer, and we would rather say so than sell depth nobody needs.
A vendor background check describes a company on the day it was run. Lawsuits get filed, liens get recorded, sanctions lists change, and ownership shifts. A vendor that screened clean two years ago is an unscreened vendor today.
Monitoring re-checks previously screened subjects at whatever interval you set, from monthly through annually, with alerts by email, dashboard, or webhook. For a vendor base of any real size, that is what turns one-time vendor background screening into a program that stays current, and regulators increasingly expect ongoing oversight rather than a single review.
If you take one thing from this, let it be that a clean result and a verified result are different statements. Know which one you are holding when you approve a vendor, screen the principals alongside the entity, and set your default depth low with a written trigger for when a check gets escalated.
Our vendor and supply chain screening page covers how this works across a larger supplier base, including batch screening and monitoring. If you would rather talk it through, click Get Started below and our team will help you size it to your vendor base, including telling you where the lighter check is the right answer.