Written and maintained by CASRAI Editorial Board
Last updated
A new vendor doesn’t become eligible to invoice a hospital, health system, or research institution just because a buyer likes the quote. Before that vendor gets set up in the accounting system and a purchase order is cut, purchasing/accounts-payable (AP) and materials-management staff need a specific packet of documents on file — not because paperwork is an end in itself, but because each document closes a real risk: tax-reporting exposure, an uninsured claim, a recall nobody can trace back to a lot number, a vendor that turns out not to be who it claims to be.
This guide is a practical checklist for what to request, why each item exists, and who inside the institution typically owns collecting it. It’s written for purchasing/AP staff, materials management, and supply-chain coordinators standing up a new-vendor onboarding process (or auditing an existing one) for institutional medical-supply purchasing. It is not tied to any single supplier or product category — it’s the general document set that applies whenever a new company is about to start selling into the institution, whether that’s a distributor, a manufacturer selling direct, or a smaller specialty supplier.
Why documentation-first onboarding matters
Skipping or rushing vendor documentation doesn’t just create paperwork gaps — it creates specific, foreseeable failures:
- Tax exposure. Paying a vendor without a valid taxpayer identification number on file makes the institution responsible for backup withholding and creates 1099 reporting errors at year-end.
- Uninsured liability. If a vendor’s product or on-site work causes harm and the vendor carries no (or insufficient) insurance, the institution can be left absorbing a claim the vendor should have covered.
- Untraceable recalls. If a supplied product is later recalled and the vendor can’t confirm what lot went where, the institution can’t identify affected patients or locations quickly — the single biggest reason lot-traceability confirmation belongs in onboarding, not just in a crisis.
- Fraudulent or unverifiable vendors. A vendor set up on nothing but an emailed invoice and a bank account number is exactly the profile vendor-master-file fraud (fake vendor schemes, business-email-compromise redirected payments) relies on.
- Excluded-party exposure. Institutions billing Medicare/Medicaid can face civil penalties for knowingly doing business with an individual or entity excluded from federal healthcare programs — which onboarding-stage screening exists to catch before the first PO, not after.
None of this requires exotic process. It requires collecting a defined document set once, before the first purchase order, rather than reconstructing it under pressure after something has already gone wrong.
The core document checklist
1. Form W-9 (or W-8 series for a foreign vendor)
IRS Form W-9, Request for Taxpayer Identification Number and Certification, is the baseline: it captures the vendor’s legal name, business type, and Employer Identification Number (EIN) or Social Security Number, and the vendor’s certification that the number is correct. AP needs this on file before the first payment, not after, because it’s what makes accurate 1099-NEC/1099-MISC reporting possible and avoids backup withholding obligations. A foreign vendor with no U.S. tax presence completes the appropriate W-8 form instead (W-8BEN-E for a foreign entity) — don’t substitute a W-9 for an international supplier.
2. Business/legal entity information
Legal business name, DBA (if any), business address, entity type (corporation, LLC, sole proprietor, etc.), and a primary point of contact for both sales and AP inquiries. This sounds trivial but matters operationally: it’s what lets AP match an invoice to the correct vendor record instead of creating a duplicate, and it’s the starting point for confirming the entity is actually who it claims to be — state secretary-of-state business registration lookups are a quick, free way to confirm a legal entity is active and in good standing before it’s added to the vendor master.
3. Certificate of insurance (COI)
A current certificate of insurance, typically on the standard ACORD 25 form, naming coverage types and limits. For a medical-supply vendor, the coverages that matter most are commercial general liability and, critically, product liability/completed operations coverage — general liability alone often excludes claims arising from a defective product after it leaves the vendor’s control, which is exactly the scenario a supply vendor creates the most exposure for. Institutions with vendors performing on-site work (installation, service, delivery inside a facility) should also confirm workers’ compensation coverage. Request a COI that names the institution as a certificate holder (and, where the vendor’s contract calls for it, as an additional insured) so the institution is notified if coverage lapses or is cancelled — a stale COI collected once at onboarding and never refreshed is a common gap; track the expiration date and re-request before it lapses, not after.
4. EDI capability confirmation
For any vendor that will see recurring purchase-order volume, confirm upfront how the vendor actually transacts: full Electronic Data Interchange (EDI, typically ANSI X12 transaction sets — 850 purchase order, 855 PO acknowledgment, 856 advance ship notice, 810 invoice), a supplier portal, or manual fax/email order processing. This isn’t a nice-to-have question — it determines whether the vendor can integrate with the institution’s ERP/procure-to-pay system or whether every order will require manual re-keying, which is both a labor cost and an error source (wrong item, wrong quantity, wrong ship-to). If a vendor can’t support EDI today, get that in writing during onboarding rather than discovering it after the first order goes out manually and the discrepancy shows up as a receiving exception.
5. Lot-traceability and recall-response confirmation
This is the item most likely to get skipped in a fast onboarding — and the one with the highest downside if it’s missing. Ask the vendor, in writing, to confirm:
- Whether the products it supplies carry lot or batch numbers, and whether those numbers are captured on the packing slip/invoice (not just on the physical package) so receiving can log them against the purchase order.
- Whether the vendor maintains forward and backward lot traceability — i.e., can it identify which customers received a given lot, and can it identify what lot a given shipment came from, without a lengthy manual search.
- Whether the vendor has a documented recall/field-safety-notice process, and who the institution’s designated contact is for receiving a recall notice.
- For products that are FDA-regulated drugs or devices, whether the vendor’s traceability practice already aligns with the applicable federal framework — the Drug Supply Chain Security Act for prescription drugs, or device Unique Device Identification (UDI) requirements for devices — rather than something the institution has to verify only after a recall notice arrives.
Recall regulations for FDA-regulated products sit in 21 CFR Part 7; recalls are classified Class I (reasonable probability of serious injury or death), Class II, or Class III depending on severity. An institution can’t act on a Class I recall quickly if it can’t first determine, from its own receiving records and the vendor’s lot data, whether the recalled lot was ever received. Confirming traceability capability at onboarding — before the relationship is operating at volume — is far cheaper than discovering the gap mid-recall.
6. References
Two to three trade references, ideally from comparable institutions (similar size, similar purchasing volume) rather than the vendor’s largest or most favorable account. Useful reference questions go beyond “were they satisfied”: ask about on-time delivery rate, how the vendor handled a backorder or a quality issue, and how responsive the vendor was to a recall or corrective-action request. A vendor’s own sales materials won’t surface that; a peer institution’s AP or materials-management staff will.
7. Licensing and registration, where applicable
Not every medical-supply vendor needs a specialized license, but many do, and it’s onboarding’s job to check rather than assume: state wholesale drug distributor licensing for pharmaceutical distributors, DEA registration for any vendor handling controlled substances, and FDA establishment registration for device or drug manufacturers/repackagers. Verify these directly against the issuing authority’s own database rather than accepting a copy of a certificate at face value — licenses lapse, and a photocopy doesn’t show current status.
8. Exclusion and restricted-party screening
Before the vendor is added to the vendor master, screen the business (and, where relevant, its principals) against the HHS Office of Inspector General’s List of Excluded Individuals/Entities (LEIE) and the federal System for Award Management (SAM.gov) exclusions list — required diligence for any institution billing Medicare or Medicaid. For a vendor with any international sourcing or ownership, screening against the Treasury OFAC Specially Designated Nationals (SDN) list is the equivalent check on the trade-sanctions side. Re-screen periodically, not just once at onboarding — exclusions and designations are added continuously.
9. Banking/ACH setup and payment terms
Banking details for ACH payment, and agreement on payment terms (net-30 is standard institutional practice). Verify banking details through a callback to a known, independently-sourced phone number for the vendor — not a number provided in the same email that supplied the banking change — before entering new or changed account details into the vendor master; this single step is the standard defense against vendor-impersonation payment fraud, where a fraudster requests a “banking update” on an existing, otherwise-legitimate vendor record.
Who owns what: a practical division of labor
No single department should own the entire packet, and no single reviewer should be able to add a vendor to the system unassisted — segregation of duties here is a control, not a formality:
- Purchasing/materials management typically owns vendor qualification, references, and confirming the vendor can actually supply what’s being purchased — the sourcing side of the relationship.
- Accounts payable/finance typically owns the W-9, banking setup, and payment-terms agreement, and is the department with the strongest incentive to verify banking changes independently.
- Compliance, risk management, or legal typically owns the certificate of insurance, exclusion screening, and any licensing verification — the risk-transfer and regulatory side.
- Whoever owns the vendor master file should require sign-off from more than one of the above before a new vendor record goes live, and before any existing vendor’s banking details change.
For institutions purchasing off a Group Purchasing Organization (GPO) contract, some of this diligence — particularly insurance minimums and pricing terms — may already be handled at the GPO contracting level; confirm what the GPO agreement covers before duplicating work the contract already resolved.
Quick-reference checklist
| Document | Who typically collects it | What it protects against |
|---|---|---|
| W-9 (or W-8 series) | Accounts payable | Backup withholding, 1099 errors |
| Legal entity information | Purchasing / AP | Duplicate/incorrect vendor records, shell entities |
| Certificate of insurance | Compliance / risk management | Uninsured product-liability or on-site claims |
| EDI capability confirmation | Purchasing / IT-procurement | Manual-order errors, integration surprises |
| Lot-traceability / recall-response confirmation | Materials management / quality | Inability to act on a recall |
| References | Purchasing / materials management | Unreliable delivery, poor issue response |
| Licensing / registration | Compliance / legal | Purchasing from an unlicensed distributor |
| Exclusion / sanctions screening | Compliance | Federal healthcare program penalties, sanctions exposure |
| Banking / ACH setup | Accounts payable | Payment fraud, vendor impersonation |
Frequently asked questions
Do we need all of this for a small, one-time purchase?
Scale the rigor to the relationship. A one-time, low-dollar purchase from an established distributor already on the vendor master doesn’t need a fresh packet. A new vendor entering a recurring supply relationship — especially one supplying anything patient-contact or lot-tracked — is exactly the case this checklist is for. Many institutions set a dollar or recurrence threshold above which full onboarding documentation is mandatory.
What if a vendor can’t confirm lot traceability?
That’s a finding, not a formality to skip past. For a vendor supplying anything lot- or batch-numbered, inability to confirm traceability is a real qualification gap — document it and factor it into the sourcing decision rather than onboarding anyway and hoping a recall never happens.
How often should vendor documentation be refreshed?
Certificates of insurance expire on a fixed schedule and should be tracked and re-requested before lapse. Exclusion/sanctions screening should be re-run periodically (many institutions do this monthly against OIG/SAM updates). Licensing should be re-verified at renewal. Treat onboarding as the start of an ongoing file, not a one-time gate.
Is a signed vendor agreement part of this checklist?
A master supply or purchasing agreement is a related but separate document, usually owned by legal/contracting rather than AP, and it’s where insurance minimums, payment terms, and recall-cooperation obligations get made contractually binding rather than just confirmed informally. This checklist is the diligence that typically precedes and informs that agreement.
Related reading: hospital vendor credentialing covers the separate, individual-level requirements (facility access, training, background checks) for a vendor’s sales reps and technicians once the vendor itself is approved. Value analysis committee reviews cover how a hospital formally evaluates and approves a new product or vendor for use. See also Group Purchasing Organization (GPO), Electronic Data Interchange (EDI) in medical supply procurement, net-30 payment terms and vendor account verification, restricted-party screening software, and Request for Proposal (RFP).








