How do I securely onboard a new vendor (W-9, banking details, verification)?
Collect a Form W-9 before the first payment — the IRS requires 24% backup withholding if a payee's TIN is missing or incorrect. Then verify banking details through a channel the vendor didn't provide: call a number from your existing vendor file, never one in a change-request email, which is the FBI's core defense against business email compromise.
Part of the accounts payable and invoice processing guide.
| What to collect before payment 1 | Form W-9 (or W-8 series for foreign vendors), to establish the TIN |
|---|---|
| Consequence of a missing/incorrect TIN | 24% backup withholding on reportable payments until remedied |
| Core banking-change defense | Out-of-band verification — call a number you already had, not one in the request |
| Who verifies | Should not be the same person who processes the resulting payment (segregation of duties) |
| Where to report a suspected scam | ic3.gov, the FBI's Internet Crime Complaint Center |
Why W-9 collection is a timing problem, not a paperwork problem
The IRS's own instructions for requesters of Form W-9 describe backup withholding as a compliance safeguard that activates when a payee's tax information is missing, incorrect, or not properly certified — a payor must deduct, withhold, and deposit with the IRS 24% of reportable payments made to that payee until the cause is remedied. Collecting the W-9 during onboarding, before the first payment, is what avoids ever triggering that withholding in the first place; collecting it retroactively means a payment already went out without it.
Banking details are the highest-value target in the whole process
A vendor's banking details, collected at onboarding or changed later, are exactly what business email compromise (BEC) schemes target. The FBI's own guidance is specific about the defense: use secondary channels or two-factor authentication to verify requests for changes in account information, and verify the email address used to send such requests rather than trusting it at face value. In practice, that means a phone call to a number pulled from the vendor's existing file or public website — never a number supplied in the same email requesting the change.
Keeping verification separate from payment
The FBI's prevention guidance also names separating vendor setup from payment release as a control, not just a nice-to-have — the person who verifies a change to banking details shouldn't be the same person who then releases funds to that account. If those two functions collapse into one person, the out-of-band verification step is easy to skip under time pressure, and there's no second set of eyes to catch it.
Next step
Map the finance workflow with the most exposure and prove the automation path.
Bring the invoice, contract, payment reconciliation, or customer finance workflow you have to defend at audit. Loopfour can map the trigger, controls, integrations, and approval loop.
Checklist
Vendor onboarding: the two checks that actually stop fraud
- W-9/W-8 collected and TIN on file before the first payment is scheduled
- Initial banking details recorded from a source independently trusted, not just whatever the vendor emailed
- Any later change to banking details flagged for out-of-band verification before it's applied
- Verification call made to a number from the existing file, never one in the change request
- Verifier and payment-releaser are two different people
Frequently Asked Questions
Sources
Related
Topic
AP & Invoice Processing
Accounts payable and invoice processing is the set of steps a vendor bill goes through between arriving at a company and turning into a payment: capturing what the vendor sent, checking it against wha…
Read moreDiagnostic
What causes a three-way match failure between the PO, receipt, and invoice?
A three-way match compares the PO, the receipt (what was actually delivered), and the invoice on quantity, price, and charges. A failure means one of those three disagrees beyond tolerance — usually because the invoice bills a quantity that isn't fully receipted yet, the unit price differs from the PO, or the invoice adds a charge, like freight, the PO never included.
Read moreDiagnostic
Why did we pay the same vendor invoice twice?
Almost always one of two things: the vendor exists as two separate records in your vendor master, so a duplicate-invoice-number check that only compares within one vendor ID never sees the second copy — or the invoice was entered twice by different people, because it arrived through two channels and each assumed they had the only copy.
Read moreDiagnostic
Why does one vendor show two different balances in AP aging?
The vendor almost certainly exists as two separate records in your vendor master file — created under slightly different names (a typo, a rebrand, a merger, a re-onboarding) — so bills and credits are split across both. AP aging reports by vendor record, not by real-world vendor, so it shows two partial balances instead of one true balance.
Read more