All insights

Vendor compliance operations

Vendor Onboarding Checklist: The Evidence You Need Before Work Starts

Before a vendor starts work, collect the evidence your team needs, assign who owns the review, and record when each document expires. That simple control prevents avoidable delays, makes renewal follow-up visible, and leaves an audit-ready record instead of an inbox scavenger hunt.

8 min read

The vendor onboarding checklist, at a glance

A vendor onboarding checklist is a documented set of requirements that must be collected and reviewed before a supplier, contractor, or service provider begins work. It should cover identity and payment records, insurance and licensing evidence, requirements tied to the scope of work, expiration dates, exceptions, and the follow-up path for incomplete records.

  1. 01Classify the vendor and the work they will perform.
  2. 02Define the evidence required for that risk level.
  3. 03Collect legal, payment, and identity records.
  4. 04Request a current certificate of insurance (COI).
  5. 05Collect a current W-9 before payment setup.
  6. 06Confirm applicable business licenses are on file.
  7. 07Record document owners and expiration dates.
  8. 08Review gaps, exceptions, and next actions.
  9. 09Queue renewal follow-up before evidence expires.
  10. 10Keep the completed record ready for audit or client review.

Why this work belongs before the vendor starts

Vendor evidence is easiest to collect while access, a purchase order, payment setup, or project start is still conditional. Once the work is underway, missing documents become an urgent chase—and nobody can quickly tell which gap matters most. A repeatable intake process gives operations, finance, facilities, and compliance teams one shared record of what was required and what is still open.

It also creates a practical third-party risk control. Not every vendor carries the same exposure. A contractor entering a site, a supplier with a long-term service obligation, and a consultant handling sensitive operational information should not all receive the same evidence request. Start with the work and risk, then make the requirements visible.

The evidence to request—and what to record with it

Vendor profile and point of contact

Capture the legal business name, operating name, service category, primary contact, and the internal owner. This makes future requests and escalation traceable.

W-9 collection

Collect a completed W-9 before payment setup when your process requires it. Store it with a clear received status and restrict access appropriately. A W-9 is a tax record, not proof of insurance or licensing.

Certificate of insurance (COI) tracking

Request the current COI and record the coverage requirements you expect, the received date, expiration date, and review status. The COI is evidence to review against your requirements; it does not replace that review.

Business license verification

Request the license or registration that applies to the vendor’s work and operating location, then record its identifier, expiration date if applicable, and the person responsible for reviewing it. Confirm the exact requirement for your jurisdiction and scope rather than assuming one license fits every engagement.

Scope-specific evidence

Add the documents your organization requires for the actual work: safety records, trade qualifications, signed agreements, site access documents, or customer-mandated forms. Keep the requirement list explicit so vendors know what complete means.

A practical five-step onboarding process

01

Classify the vendor before requesting documents

Start with the service, location, spend, access, and operational impact. This determines whether your baseline request is enough or whether the vendor needs a higher-risk review path.

02

Set a clear evidence list

Translate the classification into a list the vendor can act on: W-9, COI, business license, and any scope-specific records. Include the requested format, expiration information, and a single point of contact for questions.

03

Collect and log the evidence

Keep each file connected to the vendor record—not scattered across mailbox threads. Mark documents received, missing, incomplete, or expired so the team can see the actual onboarding status.

04

Record expiration and renewal ownership

An accepted document can become a gap later. Record expiration dates at intake, assign who follows up, and review the renewal queue before insurance, licenses, or other time-bound evidence lapses.

05

Preserve the reviewable record

Document what was required, what was supplied, and how exceptions were handled. When a client, auditor, or internal reviewer asks for proof, your team should be able to produce the history without rebuilding it from scratch.

Common vendor onboarding gaps

  • Collecting documents without defining the requirement. A file in a folder does not prove that the correct evidence was requested or reviewed.
  • Treating intake as a one-time task. COIs, licenses, and other records can expire. Expiration tracking and renewal reminders need a visible operating cadence.
  • Using one generic list for every vendor. Match the request to the work and the risk. More documents are not automatically better controls.
  • Leaving exceptions in email. Record the decision, owner, and next action so the exception is visible during future review.

From onboarding checklist to audit readiness

Audit readiness is not a separate document project. It is the result of maintaining each vendor record as work changes: current evidence, visible expirations, clear ownership, and a documented exception trail. Teams using PermitPilot can organize evidence intake, use risk views to focus attention, work the renewal queue, and create an exportable audit pack from their operational record.

If you are already managing active vendors, begin with the highest-risk group. Create the evidence list, load what you have, identify missing or expiring records, and use the same workflow for every new vendor. You do not need a perfect archive to start building a controllable process.

Vendor onboarding checklist FAQ

What documents should be collected during vendor onboarding?

The requirements depend on the vendor and the work, but a practical starting set is a certificate of insurance, W-9, applicable business license, contact information, scope-specific safety or qualification records, and the relevant expiration dates. Define the exact requirement set before the vendor starts work.

How do you track certificates of insurance and other expiring vendor evidence?

Record the document, its expiration date, owner, and review status in the vendor record. Review the renewal queue on a regular cadence, request updated evidence before expiration, and preserve the replacement document with the original record.

Does a certificate of insurance prove a vendor is compliant?

No. A COI is evidence supplied for review; it should be checked against your organization’s stated requirements and the vendor’s scope of work. The same distinction applies to licenses, W-9s, and other records.

Why is vendor onboarding important for audit readiness?

A consistent onboarding record shows what was required, what was received, what was missing, and how follow-up was handled. That is much easier to review than reconstructing document history from inboxes and folders after an audit or client request arrives.

Build the evidence record before work begins.

Start a free PermitPilot workspace, add your first vendor, and make the next evidence request clear, trackable, and ready for review.

Start your free workspace
    Vendor Onboarding Checklist: The Evidence You Need Before Work Starts | PermitPilot