Supplier Onboarding Checklist: Set Up Contacts, Orders, Invoices and Escalations
Use this supplier onboarding checklist to verify approvals, master data, contacts, ordering, delivery, quality, invoices, security and escalation routes.
On this page +
- Define scope, owner and approval path
- Copy this supplier onboarding checklist
- Verify identity and authorized contacts
- Complete proportionate due diligence
- Configure commercial and order data
- Set delivery, receiving and quality expectations
- Protect payment and invoice controls
- Approve data, system and site access
- Rehearse the first transaction
- Establish governance and escalation
- Capture onboarding meetings responsibly
- Approve readiness and preserve an audit trail
A supplier onboarding checklist should move an approved commercial need into a controlled working relationship. It connects due diligence, supplier master data, contacts, purchase orders, deliveries, quality, invoices, access and escalation.
It is not a universal compliance verdict. Apply the organization’s risk model and obtain qualified review for legal, tax, security, privacy, quality or regulated-product requirements.
Define scope, owner and approval path
Name the business sponsor, onboarding coordinator, procurement owner and required approvers. Classify the supplier by what it provides, spend or dependency, data and system access, operating geography, product criticality and substitution difficulty. This determines the depth of review.
Create one onboarding record and one source for status. The vendor due diligence checklist supports pre-approval evidence; onboarding begins only when the relevant decision is recorded.
Copy this supplier onboarding checklist
SUPPLIER ONBOARDING
IDENTITY AND APPROVAL
[ ] Legal name, registration, tax and address verified
[ ] Business sponsor and intended scope recorded
[ ] Risk tier and required reviews assigned
[ ] Commercial and specialist approvals evidenced
MASTER DATA AND PAYMENT
[ ] Supplier ID created without duplicate
[ ] Authorized contacts verified independently
[ ] Currency, tax, payment and remittance data approved
[ ] Bank details checked through the controlled process
ORDERING AND DELIVERY
[ ] Catalog, SKU, unit, price and lead-time sources agreed
[ ] Purchase-order and change routes tested
[ ] Ship-to, labeling, packaging and documentation confirmed
[ ] Returns, shortages, damage and escalation routes agreed
QUALITY, ACCESS AND GOVERNANCE
[ ] Acceptance and nonconformance process defined
[ ] Data, system and site access approved and least-privilege
[ ] Invoice channel and matching requirements tested
[ ] Owners, review date, offboarding and record retention set
READINESS
[ ] First order owner and checker named
[ ] Supplier received operating instructions
[ ] Readiness approved / conditions / expiry recorded
Mark “not applicable” only with a reason and authorized reviewer. A blank field is not evidence of completion.
Add fields for evidence location, reviewer, review date, expiry and condition. This makes the checklist maintainable after launch. Use statuses such as not started, pending supplier, pending internal review, conditionally approved and complete. Avoid a single percentage that hides one critical unfinished control. The coordinator tracks progress; each specialist remains accountable for their own conclusion.
Verify identity and authorized contacts
Record the legal entity, trading name, registered address, identifiers and approved contracting entity from reliable sources. Check for duplicates and parent-child relationships before creating a new master record. Keep the legal entity distinct from a local branch or sales contact.
Verify commercial, order, delivery, quality, invoice and emergency contacts through trusted routes. Record role-based addresses where possible. Do not grant authority because someone appears in an email thread; define who may accept orders, change bank data or approve deviations.
Complete proportionate due diligence
Route reviews based on actual risk. Relevant lanes may include financial resilience, beneficial ownership, sanctions controls, insurance, quality systems, product safety, modern slavery, environmental claims, privacy, cybersecurity and business continuity. Evidence needs an owner, source, review date and expiry where applicable.
Do not collect documents “just in case.” Minimize sensitive information and restrict access. If evidence is incomplete, record the condition, interim control, decision authority and deadline rather than silently treating the supplier as fully approved.
Check evidence authenticity and scope, not just presence. A certificate may apply to another entity, site, service or period. Record the covered legal entity and operation, issuing source and validity. When the organization accepts alternative evidence, preserve who accepted it, why it is proportionate and when the decision must be reviewed.
Configure commercial and order data
Confirm the catalog or statement of work, item identifiers, descriptions, units of measure, prices, currency, tax handling, lead times, minimum quantities and effective dates. Identify which contract, quote or price file is authoritative and who can approve changes.
Define the purchase-order channel, acknowledgment expectation, cancellation and amendment rules. A verbal request should not bypass required purchasing controls. Record how blanket orders, call-offs or emergency purchases are handled and reconciled.
Protect master data from uncontrolled spreadsheet copies. Name who maintains each field, how changes are requested and how effective dates are handled. Before launch, send the supplier a sample order and ask them to confirm item, quantity, unit, currency, destination and contact route. Correct mapping problems before a real commitment is placed.
Set delivery, receiving and quality expectations
Provide ship-to locations, operating hours, booking rules, packaging, labels, documentation and special handling. Confirm responsibility for transport, import or export tasks only from agreed terms and qualified guidance. Test location and item codes before the first shipment.
Define acceptance, inspection, quarantine, nonconformance, returns and corrective-action routes. Use the quality inspection report template to document received condition when relevant. Identify who the supplier contacts for delays, shortages or damage and what evidence is needed.
Protect payment and invoice controls
Capture bank and payment data through the approved secure route. Independently verify new or changed details using a trusted contact method; do not use contact information contained only in the change request. Preserve evidence of verification without exposing bank data broadly.
Confirm invoice address or portal, mandatory fields, purchase-order reference, tax requirements, matching rules, dispute route, payment terms and remittance advice. Keep invoice approval separate from supplier-master changes where policy requires separation of duties.
Approve data, system and site access
Identify what personal, confidential or operational data the supplier will receive and why. Complete required privacy and security reviews before transfer. Define permitted use, secure channels, retention, deletion, incident contacts and subcontractor constraints from approved agreements.
Grant system and site access by named role, least privilege, owner and expiry. Test accounts without sharing credentials. The GDPR by design guide provides useful design questions, but accountable privacy and legal owners must decide applicable requirements.
Plan access removal at the same time as access creation. Record devices, badges, integrations, shared folders, API credentials and data exports that require review when the relationship changes. A contract end date does not automatically revoke technical access. Test the incident contact and escalation channel before relying on it during a real event.
Rehearse the first transaction
Walk through one representative order from request to payment: purchase order, acknowledgment, delivery booking, receipt, inspection, invoice, match and query. Include exceptions such as a changed quantity, delayed shipment or disputed invoice. A dry run exposes ambiguous contacts and codes before they affect service.
Name the first-order owner and checker. Define enhanced monitoring for the initial period, the evidence required to graduate to routine operation and the route if readiness conditions are not met.
Establish governance and escalation
Give both organizations a clear contact map for commercial, operational, quality, invoice, security and emergency matters. Define response expectations, decision authority and escalation levels. Keep individual contact changes maintainable without rewriting the whole agreement.
Set review frequency according to risk and change. Trigger review for ownership, bank, product, location, access, incident or material performance changes. Use the decision log template for conditional approvals and material exceptions.
Capture onboarding meetings responsibly
Onboarding sessions can expose pricing, bank routes, personal data, security controls and contract positions. Record only when authorized and necessary, with clear notice and agreement where required. Exclude or restrict sensitive segments and apply approved retention.
For an authorized supplier onboarding meeting with visible, consented capture, Kuno can help draft notes and actions for human verification. It does not approve suppliers, validate bank details or replace specialist review. Explore Kuno
Verify every identifier, payment instruction, commitment and approval against controlled evidence before use.
Approve readiness and preserve an audit trail
Readiness approval should state scope, conditions, expiry, approved entities and first-order controls. Distribute operating instructions to the supplier and internal teams. Archive superseded versions and make correction routes clear.
Final QA checklist:
- The business need, scope, risk tier and coordinator are explicit.
- Legal identity and authorized contacts were independently verified.
- Required due diligence has current evidence and owners.
- Commercial data uses an identified authoritative source.
- Ordering, delivery, receiving and exception routes are tested.
- Bank and invoice data followed controlled verification.
- Data, system and site access is approved and least-privilege.
- Conditions, expiries and review triggers are visible.
- The first transaction has an owner and checker.
- Readiness approval is documented before commitment.
Turn an authorized onboarding discussion into a reviewable action record, then verify it against source documents. Kuno supports consented capture; responsible teams retain approval and control. See Kuno