Dispatch

Operations

Onboarding Paperwork for New Vendors: A Practical Checklist

8 min read
Organized manila folders and papers in a systematic arrangement

Vendor onboarding sits at the intersection of procurement, legal, and finance, which means it has three separate stakeholder groups with three separate sets of requirements, and any gap between them creates back-and-forth that delays the vendor start date. When the document set is incomplete or incorrect at the outset, each missing piece gets flagged separately, usually by a different person, on a different timeline. A vendor relationship that should be active within two weeks takes six.

Getting the document package right in the first submission is the highest-return intervention in vendor onboarding. The following checklist covers the documents that most professional services and operations teams require, the common gaps, and the sequencing considerations that reduce back-and-forth.

Category 1: Commercial Agreement and Scope

The commercial agreement is the foundational document. For a new vendor, this typically takes one of three forms: a master services agreement (MSA) with a separate statement of work, a purchase order with attached terms and conditions, or a service order under a pre-existing vendor framework.

The choice of structure should be determined before drafting, not after, because each structure has a different review path and a different signatory chain. An MSA requires legal review and executive sign-off in most organizations. A purchase order under existing T&Cs may only need procurement approval. Getting this wrong means routing the document through the wrong review path and restarting when the error is caught.

The statement of work or service order needs to specify at minimum: scope of work, deliverables and acceptance criteria, timeline, pricing structure (rate-based, milestone-based, or fixed fee), and invoicing schedule. Missing any of these creates ambiguity that finance or legal will flag during review. The scope specification should match the counterparty's understanding of the engagement, which requires that someone has confirmed alignment on scope before the document is drafted.

Category 2: Vendor Qualification and Due Diligence

Before any commercial document is executed, most procurement functions require a minimum set of vendor qualification documents. These vary by organization and by vendor risk tier, but the typical base set includes:

  • Proof of legal entity registration (certificate of incorporation or equivalent, depending on jurisdiction)
  • GST/HST registration number or equivalent tax identification
  • Certificate of insurance, including general liability and, where applicable, professional liability
  • Bank account details for payment setup, usually via a separate banking form rather than the commercial agreement itself

The sequencing issue here is common: procurement asks for qualification documents after the commercial agreement is drafted and circulated, rather than before. When qualification documents are missing or expired (an expired insurance certificate, for example), the onboarding stalls while the vendor obtains updated documents. Collecting qualification documents before drafting the commercial agreement avoids this stall. The checklist should be shared with the vendor at first contact, not after agreement terms have been exchanged.

Category 3: Information Protection and Data Handling

For vendors who will have access to any confidential information, client data, or internal systems, the information protection document set adds a second layer to the onboarding package.

A mutual or unilateral NDA is standard. The key variables to confirm before using a template: who is the disclosing party (unilateral vs. mutual), what categories of information are covered, what is the governing law, and what is the confidentiality term. Using a template that was drafted for a different relationship type without reviewing these variables is a common source of NDA defects. See our earlier article on NDA template problems for detail on the patterns that cause the most trouble.

Where vendors will process personal data on behalf of the organization, a data processing addendum (DPA) or equivalent may be required. Canadian organizations subject to PIPEDA considerations should confirm whether the vendor relationship triggers a third-party processing requirement. The DPA specifies the categories of personal data involved, the purpose and duration of processing, the vendor's security obligations, and the process for data return or destruction at relationship end. This document is often omitted from initial onboarding packages and added only when a compliance review flags the gap, which is the more expensive route.

Category 4: Tax and Payment Documentation

Finance will not set up a vendor in the payment system without a completed tax information form. For Canadian vendors, this typically means a completed W-8BEN-E or equivalent for cross-border situations, or a direct deposit authorization form for domestic payment setup. Non-residents may require additional forms depending on the nature of the services and applicable withholding rules.

Chasing tax documentation as a late-stage item is one of the most common causes of delayed vendor payment setup. The vendor is ready to start. The commercial agreement is signed. Finance discovers that the vendor was never added to the approved vendor list because the tax form is missing. Including the tax form requirement in the initial vendor onboarding package, alongside the qualification documents, avoids this sequencing failure.

Category 5: Access and System-Level Requirements

For vendors who need access to internal systems, project management tools, or client environments, the access provisioning process has its own document requirements. At minimum, this typically includes an acknowledgment of acceptable use policies and any specific security requirements applicable to the systems the vendor will access.

Access provisioning is often managed by IT separately from the procurement and legal processes, but the documentation requirement should be included in the vendor onboarding checklist so that IT is notified at the appropriate point in the process rather than after the commercial agreement is signed. Access provisioning that starts late delays the actual vendor start date even when all commercial and legal documentation is complete.

Sequencing the Checklist

The order of completion matters as much as the completeness of the document set. A practical sequencing for a typical vendor onboarding is:

Step 1: Share the qualification document request with the vendor at first contact. Collect certificates of insurance, entity registration, and tax identification before drafting any commercial documents.

Step 2: Confirm scope alignment before drafting the commercial agreement. The statement of work or service order should reflect a discussion that has already happened, not initiate that discussion.

Step 3: Draft and route the commercial agreement and NDA together. These two documents share signatories and will typically be reviewed together, so routing them separately creates unnecessary review rounds.

Step 4: Initiate tax and payment setup in parallel with commercial signature collection. Finance can prepare the vendor record while the agreement is under signature review.

Step 5: Notify IT of access provisioning requirements when the commercial agreement enters the signature stage, not after it is fully executed. Provisioning lead times vary, and starting late means the vendor is cleared to start contractually but not operationally.

Where Ops Teams Lose Time

The most common reason vendor onboarding runs long is not complexity. It is document fragmentation: each required document is requested separately, by a different person, on a different timeline, often after the vendor has already sent an earlier document to a different recipient. The vendor receives three separate requests in ten days. Each one requires a response and a follow-up cycle.

Consolidating the document request into a single structured intake, sent to the vendor once, with all required items listed and a defined deadline, is the operational fix. Most vendor onboarding delays are not caused by uncooperative vendors. They are caused by an onboarding process that requests documents piecemeal and lacks a single point of coordination.

For ops teams using a document generation tool, the vendor onboarding package is a candidate for automation: one intake form captures the variables for the MSA or service order, the NDA, and the tax form, generates all three documents from the current approved templates, and routes them to the appropriate reviewers simultaneously. The vendor receives one complete package. Review happens in one round. Onboarding completes faster.

Less document chasing, more getting things done

ZippedScript handles the routing and follow-up so your ops team can focus on what matters.

Try it free

More from Dispatch

Continue reading in the Dispatch archive.