ServicesHow It WorksIndustriesResultsInsightsBuild My Plan
Vendor Trustworthiness Checklist

How to check if a vendor is legit?

Back to InsightsHow to check if a vendor is legit?

How to check if a vendor is legit?

Key Facts

  • American businesses lose an average of $300,000 annually to fake invoice fraud alone per fraud examiner data
  • The median loss per vendor fraud case is $100,000, with many schemes running undetected for 18 months according to fraud examiner data
  • Google and Facebook collectively paid out more than $100 million in false invoices to a non-existent vendor documented cases show
  • 62% of network intrusions originate with a third party, and 72% of organizations have suffered significant disruption from vendor relationships security research finds
  • More than two-thirds of businesses still rely on manual processes for third-party risk management, creating avoidable vulnerabilities Forrester data cited by Bitsight
  • Documented deepfake fraud losses reached $1.28 billion in 2025, with 46% in audio and 51% in video format per Resemble AI's Deepfake Threat Report
  • Business email compromise has generated over $55 billion in losses over a ten-year period ending in 2023 per FBI IC3 data

The Real Cost of Skipping Vendor Vetting

Skipping a vendor background check might feel like a time-saver, but it's one of the most expensive shortcuts a business can take. The numbers behind vendor fraud are sobering — and they catch even the biggest names off guard.

According to fraud examiner data, the median loss per vendor fraud case is $100,000, and American businesses lose an average of $300,000 every year to fake invoice fraud alone. Worse, many of these schemes run for 18 months before anyone detects them. By the time the fraud surfaces, the money is long gone.

If you think this only happens to small businesses with thin accounting teams, think again. Documented cases show that Google and Facebook collectively paid out more than $100 million in false invoices to a vendor that didn't exist. Save the Children, a global nonprofit with professional finance staff, wired roughly $1 million to a fake supplier who submitted invoices for work that was never done.

The damage isn't limited to fraudulent invoices, either. Vendor relationships are a front door for cyberattacks. Security research finds that 62% of network intrusions originate with a third party, and 72% of organizations have suffered at least one significant disruption because of a third-party relationship.

Here's what skipping vendor vetting typically costs a business:

  • Direct fraud losses — fake invoices, phantom suppliers, and redirected payments averaging $300,000 a year for US businesses.
  • Undetected schemes — fraud that quietly runs a year and a half before discovery, draining cash the whole time.
  • Breach exposure — a compromised vendor becomes your breach, since most intrusions now start with a third party.
  • Reputational fallout — customers and regulators don't accept "we didn't know" as a defense.

The pattern in nearly every case is the same: someone trusted a document, an email, or a voice that looked legitimate. As risk experts point out, your vendors are extensions of your business — if they're compromised or fake, you're exposed. That's why a structured vetting process matters more than instinct, no matter how busy your team is.

For service businesses that move fast — an HVAC company racing to answer leads, a dental office juggling vendors between appointments — the temptation to onboard a new supplier quickly is real. But a short checklist beats a fast signature every time. The sections below walk through exactly what to verify before you sign.

The 7-Point Legitimacy Checklist

The 7-Point Legitimacy Checklist

A single oversight in vendor verification can cost your business six figures, with median losses per fraud case reaching $100,000 and schemes often going undetected for 18 months. Industry research shows that 80% of organizations experience actual or attempted payment fraud, making proactive validation essential before signing any agreement.

Start by confirming the vendor’s legal registration and tax IDs through official government databases, then verify they maintain a legitimate physical address—PO boxes alone are a consistent red flag for fraudulent operations. Experts advise against relying on email for bank detail changes; instead, always confirm account information by phone using known, trusted contacts on file. Request clear, detailed service descriptions that avoid vague terminology, as ambiguity often masks illegitimate offerings.

Check references and online reviews across multiple platforms, paying attention to patterns in feedback about responsiveness and delivery quality. For vendors handling sensitive data—especially in healthcare or financial services—review their compliance practices, including HIPAA alignment and adherence to texting regulations under A2P 10DLC rules. Research indicates that 62% of network intrusions originate with a third party, underscoring the need for rigorous security scrutiny.

Finally, test responsiveness with a small inquiry or trial task before committing; delays or evasiveness during early engagement often predict future problems. As part of ongoing vigilance, implement the one-question audit: can you confirm proper validation was performed on your last 20 vendor bank account changes? If not, your verification process has a critical gap. Leading fraud prevention sources stress that this simple check exposes breakdowns in payment controls before they’re exploited.

For businesses like CallMyLeads managing lead response services across regulated industries, embedding these checks into vendor onboarding isn’t just prudent—it’s a operational necessity that protects both revenue and reputation. Automating where possible helps overcome the widespread reliance on manual processes, which more than two-thirds of businesses still use, creating avoidable vulnerabilities in an increasingly sophisticated threat landscape.

Red Flags That Should Stop You Cold

Some of the costliest vendor scams don't start with a stranger — they start with an email from someone you already trust. By the time the invoice looks suspicious, the money is often gone, and the median loss per vendor fraud case sits at $100,000, with many schemes running undetected for 18 months, according to fraud prevention research.

The number-one fraud vector is deceptively simple: a sudden bank detail change arriving via email. Fraudsters know that bank letterhead and voided checks no longer prove anything — both can be easily forged — so they exploit the channel where verification is weakest. The fix is basic: confirm any banking change by phone using contact information you already have on file, never a number included in the email itself.

Beyond that, research points to a consistent set of red flags that should stop any payment in its tracks:

  • Rounded invoice amounts — real work rarely produces bills that end in round numbers.
  • Vague service descriptions with no clear deliverables tied to the charge.
  • Urgent payment requests with a manufactured deadline or late-penalty threat.
  • Pressure to skip your normal approval process "just this once."
  • PO box-only addresses instead of a verifiable physical location.

One more deserves special attention: the "executive free pass." When a CEO or CFO emails asking you to wire funds immediately, process still applies. Security experts are blunt about this: no one, including executives, gets a free pass to break verification rules (PaymentWorks).

The tactics have evolved well beyond inflated invoices. Current fraud reporting documents fake vendor websites complete with customer service chatbots, hijacked legitimate vendor email threads, and deepfake impersonation. In one widely cited case, an employee wired $25 million after a video call in which every participant — including the CFO — was a deepfake.

The scale is staggering. Documented deepfake fraud losses reached $1.28 billion in 2025, with 46% of reported incidents in audio format and 51% in video. Meanwhile, business email compromise has generated over $55 billion in losses over a ten-year period ending in 2023, per FBI IC3 data. Even Google and Facebook fell for false invoices from a non-existent vendor, losing more than $100 million combined (Trustpair).

The lesson for any business vetting providers — whether it's a supplier, a contractor, or a service like CallMyLeads handling your inbound leads — is that trust must be earned through verifiable process, not assumed because the email looks right. When someone pressures you to move fast and skip steps, that urgency is the tell.

Make Verification Ongoing, Not One-Time

Verifying a vendor once at onboarding is like checking the weather in January and assuming it holds for the year. Vendor networks, security postures, and threat landscapes shift constantly, which is why security experts describe due diligence as a continuous discipline rather than a one-time gate.

The stakes justify the effort. A Bitsight analysis found that 62 percent of network intrusions originate with a third party, and 72 percent of organizations have suffered at least one significant disruption tied to a vendor relationship. A vendor that passed your checks last year may have changed ownership, suffered a breach, or quietly adopted weaker controls since.

Tier your effort by risk. Not every vendor needs the same scrutiny. Vendors that touch sensitive data, handle payments, or sit inside your core operations warrant deeper checks — think financial health reviews, cybersecurity questionnaires, and reference calls. Lower-risk vendors need less. This risk-based approach, recommended by vendor risk specialists, focuses your limited time where a failure would actually hurt.

Then build a rhythm of reassessment:

  • Reassess high-risk vendors at least annually, and immediately after any security incident or major change in the relationship.
  • Require multi-level payment approvals so no single person can create and pay a vendor.
  • Use three-way matching — purchase order, receipt, and invoice must agree — to block fraudulent payments, per fraud prevention guidance.
  • Re-verify bank details by phone using known contact information any time a vendor reports a change — never trust an email alone.

That last point deserves emphasis. Sudden bank detail changes are "red flag number one" in vendor fraud, and PaymentWorks warns that bank letterhead and voided checks no longer prove account ownership since both are easily forged. One useful self-audit: pull your last 20 vendor bank account changes and confirm proper validation occurred for each. If you can't, you have a gap.

Most businesses do have a gap. Per Forrester data cited by Bitsight, more than two-thirds of businesses still run third-party risk management manually with spreadsheets and email — a known weakness that creates blind spots as vendor portfolios grow. Even a service like CallMyLeads, which connects directly into a client's CRM and calendar, expects to be held to this standard: ongoing checks on compliance posture, data handling, and disclosure practices are reasonable asks for any vendor touching your lead flow.

Treat verification as maintenance, not a milestone. The vendor that earned your trust on day one has to keep earning it every quarter after.

Apply the Checklist to Your Own Vendors — Including AI Services

Applying the checklist to your own vendors — including AI services — turns abstract due diligence into concrete action. Start by verifying legal registration, physical address, and tax IDs; research shows that skipping these basics leaves organizations flying blind, with median losses per vendor fraud case reaching $100,000 and many schemes undetected for 18 months. Next, assess financial health and operational stability, watching for red flags like PO box-only addresses, rounded invoice amounts, or vague service descriptions that often signal deeper issues. For AI lead-response vendors like CallMyLeads, this means confirming transparent per-minute pricing quoted upfront, no contracts or hidden minimums, and clear AI disclosure to callers — features that align with both compliance needs and the promise of honest automation.

Ensure the vendor meets industry-specific requirements: A2P 10DLC-compliant texting for US carrier rules, HIPAA-aligned configuration for healthcare clients, and explicit consent collection in booking flows. CallMyLeads builds these safeguards into its core service, keeping your leads, your data, and your calendar yours while delivering 24/7/365 response in seconds. Finally, establish ongoing monitoring — not just a one-time check — since vendor networks and threat landscapes evolve constantly. Book a free ~15-minute scoping call to see how every lead gets answered in seconds, 24/7/365.

Frequently Asked Questions

How much does vendor fraud actually cost a business?
The median loss per vendor fraud case is $100,000, and American businesses lose an average of $300,000 every year to fake invoice fraud alone. Worse, fraud examiner data shows many schemes run for 18 months before anyone detects them. Even Google and Facebook collectively paid out more than $100 million in false invoices to a vendor that didn't exist.
What are the biggest red flags that a vendor might be fraudulent?
The number-one red flag is a sudden bank detail change arriving via email — bank letterhead and voided checks no longer prove anything since both are easily forged. Other warning signs include PO box-only addresses, rounded invoice amounts, vague service descriptions, urgent payment deadlines, and pressure to skip your normal approval process. Watch too for the "executive free pass": security experts are blunt that no one, including your CEO or CFO, gets to bypass verification rules.
How do I verify a vendor is legitimate before signing anything?
Start with the basics: confirm legal registration and tax IDs through official government databases, verify a physical address (PO boxes alone are a red flag), and check references across multiple review platforms. Then confirm bank details by phone using contact information you already have on file — never a number included in the email itself. Finally, test responsiveness with a small inquiry or trial task, since fraud prevention guidance shows evasiveness early on often predicts future problems.
Is a one-time vendor check at onboarding enough?
No — vendor networks, security postures, and threat landscapes shift constantly, so experts describe due diligence as a continuous discipline rather than a one-time gate. Reassess high-risk vendors at least annually, and immediately after any security incident or major change in the relationship. The stakes are real: Bitsight analysis found 62% of network intrusions originate with a third party, so a vendor that passed last year may have quietly become your biggest exposure.
Can vendor fraud really happen through deepfakes and AI?
Yes — documented deepfake fraud losses reached $1.28 billion in 2025, and in one widely cited case an employee wired $25 million after a video call where every participant, including the CFO, was a deepfake. Fraudsters also build fake vendor websites complete with customer service chatbots and hijack legitimate vendor email threads. Current fraud reporting shows business email compromise alone has generated over $55 billion in losses over a ten-year period ending 2023.
How do I know if my own payment verification process has gaps?
Run the one-question audit: pull your last 20 vendor bank account changes and confirm proper validation was performed on each one — if you can't, you have a critical gap. Also use multi-level payment approvals so no single person can create and pay a vendor, and three-way matching (purchase order, receipt, and invoice must agree) to block fraudulent payments. Be honest about your process: Forrester data shows more than two-thirds of businesses still run third-party risk management manually with spreadsheets and email, which creates blind spots as vendor portfolios grow.

Turn Vendor Vigilance into Your Competitive Edge

Skipping vendor verification isn’t just risky—it’s costly, with median fraud losses hitting $100,000 and schemes often running undetected for 18 months. As we’ve seen, even giants like Google and Facebook have fallen for sophisticated scams, proving that trust without validation is a liability. The good news? A structured, ongoing approach—starting with legal registration, physical address, and tax ID checks, layered with bank detail confirmation by phone, red flag awareness, and continuous monitoring—turns vulnerability into strength. For businesses relying on fast, accurate lead response, this means ensuring every vendor in your stack, including AI services like CallMyLeads, meets the same rigor you’d apply internally. Take one step today: pull your last 10 vendor bank changes and verify each was confirmed by phone using trusted contacts. If gaps appear, patch them now. When your vendor ecosystem is as reliable as your own team, you’re not just avoiding fraud—you’re building a foundation for faster growth and fewer surprises. See how verified, always-on lead response keeps your pipeline moving.

Build My Lead Response Plan

Get lead response tips that actually work