RESOURCES AND PLAYBOOKS · GUIDEUPDATED 2026-08-20
    Resources and Playbooks

    Supplier Screening Checklist for Procurement Teams

    A supplier screening checklist for procurement: what to collect, how to screen suppliers for sanctions, PEP and ownership risk, and when to re-screen.

    Supplier screening works best when procurement collects the right legal-entity data before the request ever reaches compliance. Most failed supplier checks are not failures of the screening tool — they are failures of the intake form, where a trading name is captured instead of a registered legal name, or a country is left blank, and the resulting search returns either nothing or a queue of common-name false positives. This checklist sets out what to collect, how to tier suppliers by risk so the depth of the check matches the exposure, when to escalate to compliance, and when to screen again — without turning every low-risk purchase into a full investigation.

    What this workflow covers

    SCOPE
    • Record the supplier's legal name, registration number, country of incorporation, registered address, and trading names before screening starts.
    • Assign a risk tier — spend, jurisdiction, sector, and access to systems or data — and set the depth of supplier screening from that tier.
    • Identify beneficial owners, directors, and critical subcontractors where the supplier's risk warrants it.
    • Screen the supplier and relevant related parties against sanctions, PEP, and criminal watchlists in one pass.
    • Check government debarment and exclusion registers as well as sanctions lists if you sell into or buy from the public sector.
    • Cover ethical and supply-chain risk for higher tiers: labour practices, environmental enforcement, corruption cases, and other adverse media.
    • Search adverse media in the supplier's operating language, not only in English — local reporting often carries enforcement news first.
    • Assign a reviewer, record the decision and rationale, and retain the evidence used at the time.
    • Set the next review date and re-screen after ownership changes, risk events, renewals, or major scope expansion.

    Key statistics

    DATA
    Screening dimensions per supplier
    Sanctions, debarment, PEP, adverse media, UBO
    ScreenVeritAI supplier workflow model
    Public procurement exclusion grounds
    EU Directive 2014/24/EU, Article 57
    Official Journal of the European Union
    Corporate liability standard
    UK Bribery Act 2010, Section 7 — failure to prevent bribery
    UK legislation

    Compliance glossary

    TERMS
    Supplier screening
    The control that checks a supplier, its owners, and its critical subcontractors against sanctions lists, PEP data, criminal watchlists, debarment registers, and adverse media before onboarding, renewal, or a material scope change.
    Debarment list
    A government-maintained register of companies and individuals barred from public contracts, typically following fraud, corruption, non-performance, or sanctions breaches. Key registers include the US SAM exclusions, the EU early detection and exclusion system, and the World Bank list of debarred firms.
    Third-party risk management (TPRM)
    The framework for identifying, assessing, and mitigating risk introduced by external suppliers, subcontractors, and service providers across compliance, financial stability, security, operational resilience, and reputation.
    UBO (Ultimate Beneficial Owner)
    The natural person who ultimately owns or controls a legal entity, commonly defined as holding 25% or more of shares or voting rights. In supplier screening, UBO identification matters because a vendor can be clean on paper while being controlled by a sanctioned or politically exposed person.

    Expert perspective

    NOTE

    Most supplier screening gaps start at intake: a trading name and a blank country field cannot be screened well by any system.

    ScreenVeritAI Compliance Team · RegTech Research

    Frequently asked questions

    Q&A
    Q.01
    What is supplier screening?
    Supplier screening is the control that checks a prospective or existing vendor — and the people and companies behind it — against sanctions lists, PEP data, criminal watchlists, debarment registers, and adverse media before a contract is signed or renewed. It answers a narrower question than a full supplier qualification: not whether the supplier can deliver, but whether contracting with them creates legal, sanctions, or reputational exposure.
    Q.02
    How is supplier screening different from vendor due diligence?
    Supplier screening is one component of vendor due diligence. Screening is the list-and-media check against external sources; due diligence is the wider assessment that also covers financial stability, insurance, security posture, references, and delivery capability. Screening is repeatable and can run in minutes; the rest of due diligence is usually document-driven and slower, which is why the two are often separated in the intake workflow.
    Q.03
    Which lists should suppliers be screened against?
    At minimum the sanctions regimes that apply to your jurisdiction and trade footprint — commonly OFAC, EU consolidated, UN Security Council, and UK (OFSI) — plus PEP data for owners and directors. Organisations bidding for or awarding public contracts should also check debarment and exclusion registers such as the US SAM exclusions, the EU early detection and exclusion system, and the World Bank's list of debarred firms.
    Q.04
    Should procurement screen only direct suppliers?
    Direct suppliers are the baseline, but critical subcontractors and intermediaries should also be reviewed when risk warrants it. Second-tier exposure is where most sanctions surprises originate: the contracting entity is clean, while a subcontractor or an upstream owner sits on a list. Ask higher-tier suppliers to disclose critical subcontractors and screen those names as part of the same review.
    Q.05
    How do you screen suppliers without slowing down procurement?
    Tier the workflow. Low-value, low-risk purchases need a name and country check against sanctions and watchlists. Higher tiers add ownership tracing, PEP checks on directors, adverse media, and a documented compliance review. Running the check at requisition rather than at contract signature also removes most of the perceived delay, because screening happens while commercial terms are still being negotiated.
    Q.06
    When should supplier screening be repeated?
    At minimum before renewals and after major risk events, with periodic checks for high-risk supplier categories. Designations change constantly, so a supplier cleared eighteen months ago carries an unverified status today. Batch re-screening the full supplier master file on a fixed cycle — quarterly for high risk, annually for the long tail — is usually less work than tracking each anniversary individually.
    Q.07
    What is ethical supplier screening?
    Ethical supplier screening extends the check beyond legal designations to conduct: forced or child labour allegations, health and safety enforcement, environmental fines, corruption and bribery cases, and human rights reporting on the supplier or its ownership. It is generally driven by adverse media and enforcement records rather than by lists, and it is increasingly expected under supply-chain due diligence legislation in the EU and elsewhere.
    Q.08
    Can this checklist work with decentralized procurement teams?
    Yes. A shared checklist standard supports consistent controls across regions and business units, and it is the practical way to avoid each site inventing its own threshold for escalation. Keep the intake fields and risk tiers identical everywhere; let local teams differ only in who approves.
    Q.09
    What documentation is needed for approvals?
    Include screening evidence, ownership findings, analyst comments, and final approval rationale in the supplier record. The test is whether an auditor could reconstruct, from the record alone, what was screened, what was found, who decided, and on what basis.