Know Your Supplier: A Practical Due Diligence Framework

In short
Banks have run a standardised KYC framework for two decades; procurement has never had an equivalent for suppliers. This piece lays out a five-check Know Your Supplier framework — identity, beneficial ownership, sanctions, financial health and operational capacity — plus risk-tiering and refresh cycles to apply it at scale.
Banks have worked to a standardised Know Your Customer framework for roughly two decades. Whatever the institution, whatever the country, a KYC file answers the same questions in the same order: who is this entity, who actually controls it, is it on any sanctions or watch list, and can it be trusted with the relationship. The framework is not optional, and it is not reinvented by every bank from scratch.
Procurement has no equivalent for suppliers. Every company that runs supplier due diligence has built its own version — a registration check here, a sanctions screen there, a financial questionnaire somewhere else — usually assembled department by department as new risks became visible. The result is programmes that check a great deal and prove comparatively little: a folder full of documents with no consistent logic behind what was collected, why, or what it was meant to demonstrate. This article sets out the structure that is missing.
KYS, KYC, KYB: what actually differs?
KYC is a banking term, built around anti-money-laundering regulation: verify the identity of the individual or entity opening an account, understand the source of funds, and screen against sanctions and politically exposed persons lists. It is codified in law, examined by regulators, and broadly comparable from one bank to the next.
Know Your Business (KYB) extends the same logic to corporate counterparties rather than individual customers — verifying that a company is what it claims to be, and who stands behind it, before doing business with it. KYB borrowed KYC’s discipline and adapted it to legal entities.
Know Your Supplier (KYS) is where that lineage runs out. Procurement and third-party risk teams have adopted pieces of the KYC and KYB toolkit — identity checks, sanctions screening, sometimes beneficial ownership — but there is no regulatory template that says a supplier due diligence file must contain X, Y and Z before onboarding, and no supervisor auditing whether it does. That absence of a common bar is precisely what makes supplier due diligence programmes incomparable from one company to the next. Two organisations can both claim to run “supplier due diligence” while one checks a company registration number and the other runs five layers of verification — and from the outside, there is no way to tell which is which. KYS needs the structure KYC already has, adapted to what a supplier relationship actually requires.
The five checks that make up a KYS programme via a TPRM solution
A complete KYS programme rests on five checks. Each proves something specific — and, just as importantly, each has a limit to what it proves.
Identity and legal existence. Confirming that the supplier is a real, legally registered entity — correct legal name, registration number, registered address, legal form — matching what it claims to be in its contract and invoices. This proves the entity exists and is who it says it is. It proves nothing about who controls it, whether it is solvent, or whether it can actually deliver. Marion Ami, who runs public-procurement compliance for the SDIS 34 fire and rescue service, described what this check delivers in practice:

We now have the certainty, in a single click, that a supplier’s file is complete and compliant. That strengthens the credibility of our processes.

Marion Ami
Public-procurement compliance | SDIS 34
Beneficial ownership. Who ultimately owns or controls the entity, beyond the registered company name. Covered in depth below.
Sanctions and integrity. Screening against sanctions lists, watch lists, adverse media and corruption indicators. This proves there is no known match today. It says nothing about tomorrow — a clean screening result is a snapshot, not a guarantee, which is exactly why refresh cycles matter later in this framework.
Financial health. Verifying solvency, payment history, and — increasingly relevant given the rise in payment fraud — the legitimacy of the bank details a supplier submits. This proves current financial standing and payment integrity, not future viability. Flavie Tremaudan, procurement counsel at Espacil Habitat, described the fraud dimension of this check directly:

The module lets us fully secure the creation or modification of bank details. Controlling the match between company registration number and IBAN, with a simple red/amber/green alert system, has significantly cut our fraud risk.

Flavie Tremaudan
Procurement counsel | Espacil Habitat
Operational capacity. Certifications, insurance, quality and safety credentials, and evidence the supplier can actually perform the work at the volume required. This proves current capability. It does not guarantee future performance, which is why it needs monitoring rather than a one-time check.
Beneficial ownership: the layer most programmes skip
Most KYS programmes stop at the first check. A registration number and a legal name feel like due diligence, and in a narrow sense they are — but they say nothing about who is actually behind the entity. A supplier can be perfectly registered, perfectly solvent on paper, and still be controlled by a sanctioned individual, a politically exposed person, or a structure designed specifically to obscure that fact.
Beneficial ownership is typically defined, across most anti-money-laundering regimes, as any individual who owns or controls more than 25% of an entity, directly or indirectly, or who otherwise exercises effective control regardless of formal shareholding. The 25% threshold is a convenient line, not a technical limit — control can sit below it through layered holding structures, nominee arrangements, or family relationships that a flat company search will never surface. This is why beneficial ownership is the layer that separates a KYS programme that genuinely screens risk from one that screens paperwork.
Antoine Beaume-Dessertaine, Director of Internal Control and Compliance at Antin+, described what changed once ownership and integrity screening were connected to an automated evaluation process across the organisation’s 2,000 third parties:

We have digitised and structured our entire third-party creation and evaluation process. Across our 2,000 third parties, we have been able to map risk levels, automate controls, and integrate integrity reports, a genuine step up in maturity for our organisation.

Antoine Beaume-Dessertaine
Director of Internal Control & Compliance | Antin+
Risk-tiering: not every supplier deserves the same depth
Running all five checks, at full depth, on every supplier is not rigour — it is a resourcing decision that fails twice over. It is too expensive to sustain against a supplier base of any real size, and because it is too expensive to sustain, it quietly gets diluted into something shallower everywhere. A uniform programme is usually both too costly and too superficial at the same time.
Three tiers are generally enough to fix this: a baseline tier for low-spend, low-criticality, low-risk-geography suppliers, covering identity and basic sanctions screening; a standard tier adding beneficial ownership and financial health for suppliers with meaningful spend or moderate exposure; and an enhanced tier — full five-check depth, with tighter refresh cycles — reserved for suppliers that are critical to operations, sit in higher-risk sectors or geographies, or handle sensitive data or payments. The classification criteria should be explicit and applied consistently: spend level, criticality to operations, sector risk, geography, and any prior red flags. Hervé Robert, who runs public procurement for the Département de la Vendée, described exactly this discipline when structuring a new supplier-evaluation programme:

The point for us was not to spread ourselves in every direction. We deliberately targeted a handful of major areas, with indicators that are simple, actionable, and genuinely usable by our teams.

Hervé Robert
Public Procurement | Département de la Vendée
Refresh cycles: due diligence has a shelf life
A due diligence check is a photograph, not a live feed. The moment it is completed, it starts going out of date — ownership changes, a sanctions list is updated, a certificate lapses, a company’s financial position shifts. Treating a completed check as permanent is one of the most common failures in supplier due diligence, and one of the easiest to miss until it matters.
Refresh cycles should be set by criticality, not by an arbitrary calendar. A baseline-tier supplier might reasonably be re-verified every two or three years. An enhanced-tier supplier — critical, high-risk, or handling payments — needs a much shorter cycle, and in some sectors this is already a formal requirement rather than a best practice: public procurement rules, for instance, can require certain regulatory checks to be repeated as often as every six months, regardless of how uneventful the relationship has been. The right model also builds in event-driven triggers alongside the calendar-based ones — an ownership change, a new sanctions hit, a missed certificate renewal — so that a review isn’t only prompted by the date, but by the event that actually matters.
From checklist to operating model
A checklist run once, by hand, against a spreadsheet does not survive contact with a real supplier base. What separates a genuine KYS operating model from a one-off compliance exercise is whether the five checks, the risk tiers and the refresh cycles run as a connected system rather than five disconnected tasks someone remembers to do.
That means the checks feeding a single supplier record rather than five separate files; the tiering rules triggering the right depth automatically at onboarding rather than being applied inconsistently by whoever happens to be reviewing the file; and the refresh cycle running on its own clock rather than depending on someone noticing a certificate has expired. This is the same discipline behind a complete methodology for third-party risk assessment and supplier due diligence as a risk-management pillar — KYS is the specific-checks layer that sits underneath both.
Alain Chenal, Procurement Methods and Performance Director at EGIS, described what this looks like once it is built into the systems a company already uses rather than bolted on beside them:

Connecting our supplier due diligence to our ERP lets us qualify our supplier base automatically and quickly. We now have several thousand active third parties in our system, and that streamlined onboarding is the foundation for finer-grained oversight of compliance going forward.

Alain Chenal
Procurement Methods & Performance Director | EGIS
That is the real difference between a checklist and a framework. A checklist proves someone looked, once. A framework proves the organisation can show, at any point in a supplier relationship, exactly what it knows, how recently it verified it, and why that level of scrutiny was the right one for that supplier. Banks built that discipline into KYC because regulators required it. Procurement has every reason to build the same discipline into KYS — because a supplier relationship carries the same categories of risk as a customer relationship, without anyone yet requiring the proof.
Book a meeting at our booth
Don’t miss this opportunity to connect with our team, see our solutions in action, and discuss how Aprovall can help you drive procurement excellence and stronger supplier risk management.
These articles might interest you
-
27 April 2026Risk indicators for third-party managementDue DiligenceRisk indicators for third-party management Risk indicators help procurement teams spot early warning signals in supplier relationships before disruption occurs. Des plateformes comme Aprovall centralisent les données fournisseurs et structurent le suivi des risques tiers, avec 1,800+ customer organisations using the platform. Procurement teams are under pressure to keep operations running while increasing oversight expectations […]Read more
-
15 May 2026The construction sector engages 88% of 11,000 suppliers via Ivalua and Aprovall: what this figure really reveals about the battle between platform pooling and specialisationDue DiligenceWhen Eiffage — the €23 billion French construction group with around 70,000 suppliers and subcontractors — reports an 88% activation rate on 11,000 third parties tracked through its TPRM platform, deployed in just 3 months, the natural reaction is to focus on the headline. But the more interesting story sits underneath: the figure quietly settles […]Read more
-
10 July 2026Supplier onboarding: why the first few weeks set the tone for the entire relationshipDue DiligenceThe Moment That Defines Everything That Follows Every supplier relationship has a founding moment. It is not the signing of the contract, nor the first invoice, nor the first delivery. It is the onboarding process, those first few weeks during which a new supplier discovers how your organisation works, what it expects, and whether it […]Read more
-
24 September 2026Sanctions Screening: Why Checking a Name Isn’t Checking a CompanyDue DiligenceIn short A clean sanctions screen only proves a supplier’s name isn’t on a list — it says nothing about who actually controls the entity behind it. Beneficial ownership, multi-jurisdiction list coverage, alert calibration and continuous rescreening are what separate a screening programme that holds up under scrutiny from one that only looks convincing on […]Read more