Insights

What a Vendor Due Diligence Report Should Actually Contain

Scrutinex · 22 August 2026

Start with the identifiers, not the story

Most bad vendor engagements do not start with fraud. They start with a company that cannot be found in any registry under the name on the invoice.

Before you look at anything else, collect three things: the legal name, the jurisdiction of registration, and the registration number. If a counterparty will not give you all three, that is your first finding.

The five checks that matter

  1. Registration status. Is the entity active, dissolved, or struck off? When was it incorporated? A company formed six weeks before a large tender deserves a second look.
  2. Ownership. Who are the shareholders and directors of record, and do those names match the people you have been dealing with?
  3. Sanctions and PEP exposure. Screen the entity and every named officer against OFAC, the UN Security Council Consolidated List, and the EU Consolidated List. One list is not enough.
  4. Offshore and beneficial ownership. Check the ICIJ Offshore Leaks Database for links between the entity, its officers, and offshore structures.
  5. Litigation and adverse media. Court records where available, and a structured media scan in the local language, not only in English.

Write down where each answer came from

A finding without a source is an opinion. Every line in a due diligence report should carry the database or registry it came from and the date it was checked. That is what lets you re-run the check yourself in six months, and what makes the report usable if a dispute ever reaches a lawyer.

When to escalate to a human

Automated screening produces name matches, not conclusions. A common surname will hit a sanctions list. A dissolved subsidiary will share a name with an active parent. Those are exactly the cases where an analyst has to read the underlying record and decide. If your process has no escalation step, your screening output is a list of maybes.