Guide · Supplier Verification
What Does Supplier Verification Software Actually Verify?
Short answer: supplier verification software establishes four separate things — that the company legally exists as described, that it operates from the site it gave you, that the documents it sent are genuine and cover the goods you actually buy, and that the practices those documents describe are performed by the people doing the work. Most tools sold under this name reach the first one well, the second one partly, and stop. The gap matters because a supplier can clear an entity check with room to spare and still be the reason a container sits at a border.
The word cleared means something different to everyone asking for it
Accounts Payable has a payment on hold because the banking details on an invoice changed, the request came by email from a name nobody in the building recognises, and they need someone to confirm that the company on the remittance is the company on the purchase order before they release the funds. Quality has a second-source supplier waiting on the approved vendor list, the production trial is booked, and they have done their part — the samples passed — so the only thing standing between them and the trial is you. And the insurance renewal came in with a schedule that has to name every facility where the goods are handled or stored, which sounds like an administrative question right up until you try to fill it in.
Not one of those people will use the word verification. Every one of them is asking for it, and each of them means something different by it — Accounts Payable wants to know the company on the remittance is the company you contracted with, Quality wants the site approved, and the insurer wants the address where the goods physically sit.
In thirty years I have been handed a great many supplier certificates, and I stopped reading them from the top a long time ago. The first thing I look at now is the address block and the scope line, because that is where a document stops being about the supplier in general and starts being about a specific building, doing specific work, on a specific date. Almost everything that goes wrong in supplier verification goes wrong in that part of the page, and it is the part everybody skims.
Two names, so you know which one this page is about. The checking itself — the sources, the site work, the documents, the interviews with the people who handle the goods — is XFACTOR VERIFIED, and that is the product a search for supplier verification software is looking for. Once those verifications exist they have to live somewhere every program can read them without anyone re-typing anything, and that place is XFACTOR COMMANDCENTER.
What is actually being verified — and against what
Verification has an object. Naming the object is most of the work, because the four objects in a supplier file need four different sources and fail in four different ways.
The entity. Does this company legally exist, under this name, with these owners? Company registers answer that in almost every country you buy from — Corporations Canada and the provincial registries here, a Secretary of State registry in the state of incorporation in the US, Companies House in the UK, the National Enterprise Credit Information Publicity System in China. A Legal Entity Identifier, if one has been issued, sits in the GLEIF index with the legal address and, at the second level of the record, the direct and ultimate parent. Running the entity and its named officers past the US Consolidated Screening List belongs at this layer as well, and it takes a search. Entity checks are cheap, fast, machine-readable, and they are what most products in this category mean when they use the word verification.
The site. Does the company operate from the place it named, and does that place do the thing the invoice implies? Satellite and street imagery settle more of this than people expect — whether there is a loading dock, whether there is anywhere for a container to turn, whether the footprint could plausibly hold the output you are buying. There is also a source you already own and almost never use: your own entry and bill of lading records name the shipper, the port of loading and the consignee, and they were created by the movement of the goods rather than by anyone filling in a form for you. When the shipper on the bill of lading and the company on the purchase order are not the same company, that discrepancy came from your own filing cabinet.
The paper. Is this certificate genuine, current, and about the goods you buy? Three questions, and the third one fails far more often than the first two.
The people. Do the humans who handle the cargo perform the procedure the document describes? Nothing in any register answers this. It is established by asking the people who do the work what they do, in the situations where it matters. A questionnaire that comes back clean cannot reach this layer at all, however well it is written.
The mechanism underneath all four is the same and it is not complicated: the party making the claim and the party confirming it have to be two different parties. What differs is how far each check reaches. Entity and site are largely settled by machine. Paper is settled by the issuer. Practice is settled by a person, in a conversation, with the people who perform it. Most supplier verification software automates the first two layers and stops, which is a real service honestly delivered — and it means the phrase verified supplier, coming out of that tool, is true about a much smaller subject than the one you asked about.
How do you tell a genuine certificate from a relevant one?
Take the document back to whoever issued it. An accredited ISO management-system certificate is published by the certification body in the IAF CertSearch database, so the certificate in your inbox can be checked against the issuer's own record rather than against the copy the supplier sent. Where the claim is C-TPAT membership, a Partner logs into the CTPAT Portal, opens the Status Verification Interface page, and searches for the company by name — CBP also lets you have a certification email sent from the Portal itself. Worth knowing if your process still asks a partner for their SVI number: CBP retired that mechanic more than ten years ago, and a form field still requesting one is collecting a string that identifies nothing. Criterion 3.4 asks both for evidence of a partner's certification and for continuous monitoring that they keep it, and a lookup you can run yourself, whenever you like, is what lets those two stop being separate pieces of admin. Where an approved AEO program under a mutual recognition arrangement is claimed instead, the principle holds: programs confirm their own members, and no supplier needs to be involved in the asking.
All of that establishes authenticity. It says nothing about relevance, and relevance is the check almost nobody runs.
I was working through a file for a client whose supplier had sent everything asked of them, promptly, which should have been the first thing to slow me down. The certification was real. I confirmed it with the issuing body and the dates were current. The corporate registration was live, the ownership matched what we had been told, and nothing came back on the screening lists. On any dashboard that scores entity checks, that supplier was finished.
The address on the certificate was fifty kilometres from the facility that packed our client's product. Same corporate group, same legal entity, genuinely certified site — and it made something else entirely, for somebody else. The plant our goods actually moved through had never been assessed by anyone, was not named on any document in the file, and had a different security posture, different people and a different subcontracted trucking arrangement. Nobody had lied. Somebody had sent the certificate the company had, and everyone who received it read the logo, the accreditation mark and the expiry date, and never read the address line underneath.
That is the shape of most document failures I see. Outright forgery turns up rarely and is the easiest of them to catch, because the issuing body will simply tell you the certificate is not theirs. The failure that gets through is an authentic document about the wrong building, and the only defence against it is knowing which building your cargo goes through before you open the certificate. That is step one of the 5-step risk assessment, mapping cargo flow and identifying business partners, doing work nobody expects it to do: it tells you what the paperwork is supposed to be about.
What should verified mean before it goes on a supplier record?
The word is doing something specific in your system. It is a claim you are making to your own colleagues, and it should carry the same four elements every time: the attribute being asserted, the source it was confirmed against, the date it was confirmed, and the name of whoever confirmed it. Verified with nothing behind it is a colour on a dashboard.
A record built that way answers the questions that actually get asked later, because each one reduces to a lookup rather than an investigation:
What was verified — the entity, the site, a named certificate, an observed practice — never the supplier as a whole
Against what source, named specifically: the registry, the issuing body, the program portal, the site visit, the person interviewed
On what date, and when it expires, taken from the source rather than from a review cycle
By whom, so the check has an owner and not just a timestamp
What came back short — a refusal, a missing document, an unanswered request — recorded as a finding with an owner, rather than left as a blank field
That last line is the one that separates a verification record from a marketing badge. A validator does not expect a clean sheet. Criterion 3.6 assumes weaknesses will be found in a business partner's security assessment and asks what you did about them — whether deficiencies were mitigated, confirmed with documentary evidence. A file showing twelve verified attributes and three open findings with owners and dates is a stronger file than one showing fifteen green ticks, and it is stronger precisely because somebody can tell it was worked on by a human being who was allowed to write down bad news.
Expiry belongs to the source, not to your calendar. A certificate expires on its own date. A screening-list result is stale the moment the list is republished. A registration changes when the company files a change, which nobody will tell you about. C-TPAT requires the risk assessment to be reviewed at least annually and business partner assessments to be updated as circumstances and risks dictate — the annual review is the floor of the obligation, and every attribute underneath it moves on its own clock.
Who is relying on your verification without re-checking it?
Here is the part that makes this expensive rather than merely untidy. The moment a supplier is marked verified in a system other people can see, the word starts travelling without the evidence attached to it. Procurement releases the PO because the supplier cleared. Quality shortens the qualification because the site is approved. Accounts Payable stops asking about the change of banking details because the vendor is a verified vendor. Legal signs a customer contract with a supply chain security clause in it on the strength of a list somebody exported from your system. None of those four people re-run your check. That is the entire value of the word, and it is also the exposure.
So when it comes apart, it does not come apart where the check was made. It comes apart at the point somebody relied on it — at the border, in a customer's audit, in an insurance claim where the facility that handled the goods is not on the schedule you filed. And the question in the room is never framed as a question about a source record. It is asked as: we were told this supplier was verified. What was verified, exactly?
The honest answer, in most of the files I have opened, is that the company was confirmed to exist. That is a true and useful thing to have established, and it is not what the person asking believed they were being told. The distance between those two sentences is where the cost sits, and it is not a distance anyone crossed carelessly. Nobody in that chain was being lax. They were reading one word that had been asked to carry four different meanings, and nothing in the tool told them which one it meant.
What can you verify this week without asking a single supplier?
More than most programs assume, and none of it needs a new headcount or another standing meeting. Take the suppliers you already have and settle the attributes that do not require anybody's cooperation: registration status in their own jurisdiction, ownership as filed, screening-list position, whether the address is a real commercial site, and whether the certifications they claim are current with the bodies that issued them. That work can start this afternoon and it costs you nothing but the looking.
Then do the one thing that reorders the rest. Put the shipper names from your last quarter of bills of lading beside your approved supplier list, and look at the rows that do not match. What surfaces there are parties who move your goods without appearing on anybody's list, and they are the ones whose verification is worth doing first, because nobody has ever done it at all.
XFACTOR VERIFIEDis built around the distinction this whole page turns on. Its scope is every party on the cargo map rather than every name in the vendor master, and each attribute it settles is stored as an attribute — what was checked, where it was checked, when, by whom — so nothing in the record has to be taken on anybody's word, including ours. The machine-settleable layer runs before a person is involved. The layer no register can answer is worked with the people who handle the goods, in scenarios, because that is the only place a practice exists. A supplier who will not open a door has that written down as a finding with an owner rather than a silence in a field.
All of it aggregates into the signed Master 5-Step Risk Assessment, and it aggregates once. C-TPAT, PIP and AEO each require a full five-step risk assessment behind their security profiles, and under Canadian statute a Bill S-211 executive summary report takes its evidence from the same foundation — so the verification work you do on a supplier is done for every program at once instead of three times in three formats. What happens to the resulting number, and how to make a vendor account for it, is the companion guide on supplier risk assessment software. Sitting across from a specialist afterwards and being asked the question you did not prepare for is what XFACTOR VALIDATED rehearses.
None of this arrives on the supplier as an unpaid errand. The Compliance Passport they receive under XFACTOR VERIFIED, funded by you and running four months, gives them in-depth training, scenario assessment, documentation verification and audits, and a recommendation report with an action plan written to their operation. That changes what comes back across the table, because for once the exercise leaves them holding something they can use with every other customer who asks.
I hold my own files to that standard because I have never seen the other kind survive contact with a specialist. A 100% success rate on C-TPAT, PIP and AEO — at Tier II, not the minimum.I was never someone who gave the bare minimum to my clients, and I would not write the word verified beside a supplier's name without being able to say what was verified, against what, and when.
Free guide
Free guide: How to Evaluate Supplier Risk
What you can confirm about a supplier without asking them — the registries, the issuing bodies and the records you already hold, and what a validator will want to see behind each one. We'll email you the link.
See what sits behind the word verified on a supplier record.
Look at how XFACTOR VERIFIED settles each attribute, and at what Operations sees when a site has never been established. Access is by request, and every request is reviewed personally.
The program this maps to: C-TPAT · The departments this maps to: Procurement · Operations · IT · Related reading: Supplier risk assessment software · What a C-TPAT security questionnaire proves · C-TPAT compliance software · Supplier due diligence · The Minimum Security Criteria · The C-TPAT 5-step risk assessment · Forced labour due diligence beyond tier 1