Supplier fraud is not a lightning strike; it is a pattern. The counterfeit factory, the hijacked email thread swapping bank details, the "trading company" that exists only as a website — each leaves fingerprints visible before any money moves. Supplier risk management is the practice of looking for them systematically instead of hopefully.
This guide gives the working framework: the verification stack, the red-flag catalogue, a simple scoring approach, and the control ladder that matches protection to exposure without strangling good relationships in process.
The verification stack
Layer one — existence: the supplier appears in its home jurisdiction’s official registry (SAMR in China, MCA in India, RGD in Ghana, CAC in Nigeria and peers), is active, of plausible age and capital, and registered for a scope that matches what it sells you. Layer two — account: the receiving bank account is in the exact legal name of that entity; near-matches, personal names and third-company accounts are where fraud lives. Layer three — screening: sanctions lists, adverse media and litigation signals on the entity and its principals.
Layer four — operational reality, scaled to exposure: business licences and product certifications for regulated goods; factory audits or third-party inspections for manufacturing claims; references from other buyers in your market. Layers one to three are cheap and fast through verification services and should be universal; layer four is proportionate to ticket size and category risk.
The red-flag catalogue
Certain signals predict trouble far above base rates. Treat any one as a caution and combinations as decisive.
- Account anomalies. Personal accounts for company invoices, accounts in third-party names, banks in unrelated jurisdictions, or bank detail changes communicated by email mid-transaction — the single most reliable fraud fingerprint.
- Price and pressure. Quotes far below the market for the category, expiring "today-only" discounts, and urgency engineered to rush you past verification. Fraud economics require both the lure and the deadline.
- Identity fog. Company names that shift between documents, registry records that do not match the website story, unverifiable addresses, refusal of video calls at the claimed premises.
- Documentation resistance. Reluctance to provide registration documents, licences or references a legitimate exporter produces routinely; pushback against escrow or staged terms without a commercial reason.
- Channel switching. Moving the conversation off-platform, invoices from domains that do not match the company, or "our accountant" appearing late in a thread with new instructions — the anatomy of business-email compromise.
Scoring risk so decisions are consistent
A simple score beats ad-hoc judgment because it is consistent across orders, staff and moods. Combine the dimensions: registry verification result, account-match result, screening result, company age and capitalisation, operational evidence, transaction history with you, and category risk (custom goods and prepayment-heavy categories carry more). Weight verification and account-match heaviest — they are the fraud gates — and let history earn points over time.
Bands then drive behaviour mechanically: high-trust suppliers qualify for lighter deposits and faster execution; mid-band suppliers get standard staged terms; low-band or unverified counterparties get escrow, inspection gates, or a polite pass. The point is not mathematical elegance — it is that the same evidence always produces the same controls, which is what protects you on the busy week when instinct would have cut corners.
Matching controls to exposure
Controls cost money and goodwill; spend them where the score says to. Low exposure with verified counterparties: standard 30/70 terms, references on file, periodic re-verification. Material exposure or thin history: escrowed balances, named-inspector release gates, tighter deposits. High exposure or any decisive red flag: full documentary structure or no deal — the discipline to walk away is itself a control, and the deals that punish its absence are exactly the ones engineered to look unmissable.
Close the loop with monitoring: re-verify on any detail change (especially banking), refresh registry and screening checks periodically for standing suppliers, and log every order’s outcome into the supplier’s file. Risk management is a flywheel — each cycle of evidence makes the next decision faster and safer, which is how good procurement gets both quicker and harder to defraud simultaneously.
Key terms
Counterparty risk
The risk that the party you pay fails to perform — through fraud, incapacity or insolvency.
Registry verification
Confirmation of legal existence, status and scope against official government company registries.
Account-name matching
Verifying the receiving account belongs to the verified legal entity — the primary fraud gate.
Business-email compromise
Fraud via hijacked or spoofed email threads, classically swapping bank details mid-transaction.
Risk banding
Translating a supplier’s score into predefined control levels — consistent evidence-to-controls mapping.
Re-verification triggers
Events (detail changes, long gaps, adverse signals) that mandate refreshing verification before further payment.
Frequently asked questions
What single check prevents the most fraud?
Account-name matching against the verified legal entity. Most supplier fraud does not fake an entire company — it diverts payment to a mismatched account. Verify the entity once; verify the account every time it changes.
How much due diligence is enough for a small first order?
The universal minimum is cheap: registry verification, account matching and screening — hours, not weeks. Scale factory audits and inspections with ticket size. Never scale the account check down; it is the gate regardless of size.
A supplier failed one check but seems otherwise fine — proceed?
Depends which check. Registry or account failures are decisive — resolve before any payment. Softer flags (young company, thin references) can be priced with tighter structure: escrowed balance, inspection gate, smaller first order.
How do I verify a Chinese supplier specifically?
Against SAMR records (legal name in Chinese characters, unified social credit code, registered scope and capital), with the bank account matching the registered entity — not a personal or third-party account. Verification services handle the registry access and translation gap.
How often should standing suppliers be re-checked?
On every banking detail change immediately; registry and screening refresh annually or on adverse signals; and after long order gaps. Companies change hands, licences lapse and accounts get compromised — verification has a shelf life.
Apply this in practice
Tools and services on KeyBS Pay that put this guide to work.
Keep learning
Move money with what you just learned
Get a corridor-specific quote — verification, FX and settlement in one workflow.