| Sanctions and watchlist screening |
Potential matches to sanctions lists, politically exposed person (PEP) records, or other relevant watchlists. |
Compares supplier names and associated people or entities against maintained screening lists; may support recurring rescreening. |
Assessing whether a supplier, owner, or intermediary presents a regulatory or restricted-party concern. |
Name matches can be ambiguous. Review identifiers such as location and date of birth, and confirm relevant legal requirements and list coverage. |
| Adverse media monitoring |
Publicly reported allegations or events involving fraud, corruption, labor issues, environmental harm, or other reputational concerns. |
Searches news and other published sources using entity names, people, and risk-related terms; alerts may flag new coverage. |
Adding context to a supplier review or tracking emerging public concerns. |
Coverage varies by language, region, and source. Reports may be incomplete, outdated, or unverified; findings need human review. |
| Corporate registry and ownership checks |
Unclear legal identity, inactive status, inconsistent company details, or potentially opaque ownership structures. |
Checks business registry records and available filings for legal names, registration status, directors, and ownership information. |
Confirming who the buyer is contracting with and identifying ownership details that warrant further diligence. |
Registry availability and filing detail differ across jurisdictions; records may not show every layer of ownership or reflect recent changes. |
| Financial health and credit monitoring |
Indicators of financial distress, such as deteriorating payment behavior, insolvency filings, or declining credit assessments. |
Reviews available financial statements, payment data, credit indicators, and public insolvency records over time. |
Evaluating supply continuity risk, payment terms, or exposure to a financially vulnerable supplier. |
Data can be delayed or unavailable for private companies. Credit indicators are estimates, not guarantees of future performance. |
| Cybersecurity and external attack-surface monitoring |
Exposed internet-facing systems, insecure configurations, leaked credentials, or reported security incidents. |
Monitors publicly observable assets and threat signals; some assessments also review security questionnaires or independent test evidence. |
Reviewing vendors that access buyer systems, handle sensitive data, or provide critical digital services. |
External observations do not prove a breach or reveal every internal weakness. Findings should be validated with the supplier and assessed in context. |
| Certifications and compliance evidence checks |
Missing, expired, or out-of-scope evidence of a supplier’s security, quality, or management controls. |
Reviews certificates, audit reports, scope statements, issue and expiry dates, and supporting evidence where available. |
Comparing documented controls against procurement requirements and identifying gaps for follow-up. |
A certificate or audit report covers a defined scope and period; it does not establish that every process or product is risk-free. |
| Payment and invoice fraud controls |
Unexpected bank-account changes, suspicious payment instructions, duplicate invoices, or mismatched supplier details. |
Validates payment changes through an independently verified channel and checks invoice and account details against approved records. |
Reducing exposure to impersonation, business email compromise, and payment diversion. |
Automated alerts can produce false positives. Account changes should be confirmed using a trusted contact method, not details in the change request. |
| Product safety and recall monitoring |
Product recalls, safety alerts, restricted substances, or reported hazards relevant to goods being purchased. |
Tracks notices from regulators and other authoritative sources, then compares product identifiers and categories with purchasing records. |
Buying consumer goods, components, equipment, or products subject to safety requirements. |
Notices may be jurisdiction-specific and product identifiers may be incomplete; buyers should verify applicability with authoritative sources. |