The 2026 AFP Payments Fraud and Control Survey, released in April 2026, found that 76% of organizations experienced attempted or actual payments fraud in 2025, and 74% were hit through business email compromise, the vector that runs straight through the vendor master file.
Gigapay is the Merchant of Record for creator and micro-vendor payouts, which means the KYC and KYB file for every payee is built, validated, and refreshed before a single payment moves, and your ERP holds one vendor instead of hundreds.
Vendor onboarding KYC and KYB is the minimum due diligence file a company assembles before a person or a small entity can receive company money, and most AP teams are running it on a PDF and a hope.
This article breaks down exactly what that file should contain, who should collect it, how often it should be refreshed, and what it costs to get it wrong.
Key Takeaways
- 76% of organizations experienced payments fraud in 2025, mostly through vendor-facing channels.
- The minimum vendor file: identity, entity type, tax form, verified bank account, sanctions screen.
- A W-9 PDF and an IBAN in an email is not KYC.
- The party that pays the vendor should collect and validate the file at onboarding.
- With a Merchant of Record, you sample their file instead of rebuilding it.

Why Vendor Onboarding Became a Fraud Control in 2026
For most of AP's history, vendor onboarding was an administrative task. Someone in procurement negotiated a contract, someone in finance created a vendor record, and the master file grew quietly in the background. That era is over, and the numbers explain why.
The 2026 AFP survey data shows that spoofed emails hit 85% of organizations, and more than half of respondents received messages from lookalike domains that differed from the real one by a letter or two. The FBI's Internet Crime Complaint Center logged 24,768 business email compromise complaints in its 2025 report, with $3.05 billion in reported US losses, up from $2.77 billion the year before.
Vendor imposter fraud specifically hit 45% of US organizations in the most recent AFP data, an 11-point jump in a single year.
The attack pattern is consistent. A fraudster impersonates a payee your company already trusts, submits an invoice or a bank-detail change, and AP processes it because the record in the master file looks legitimate.
Under UCC Article 4A-207, a receiving bank can rely on the account number alone even when the beneficiary name does not match, so a fraudulent account number sitting under a genuine vendor name sails through.
Nacha's new ACH risk-management rules, phasing in during March and June 2026, require banks on both ends of a credit-push payment to monitor for fraud, but they require monitoring only. There is no payee name-matching mandate and no shift of liability away from the paying business.
The conclusion for finance leaders is uncomfortable but clear, the vendor master file is now a fraud surface, and every record you add without a verified due diligence file behind it widens that surface.
How Micro-Vendors and Creator Payees Changed the Vendor Master File
Twenty years ago, a mid-size company's vendor master held a few hundred suppliers, most of them established businesses with registration numbers, audited accounts, and long relationships. Today, the fastest-growing category of payee looks completely different: individuals, sole traders, and micro-entities.
Creator marketing is the clearest example. A brand running influencer campaigns at scale can generate hundreds of new payees per year, most of them individuals without a registered company. Gigapay's own analysis of a brand doing 600 creator collaborations annually found the manual process consumed roughly 840 admin hours per year and produced 300+ individual vendor records in the ERP, at a total cost of about €139,590 once vendor sprawl and error cycles were counted.
Each of those records carries the same fraud exposure as a traditional supplier, but with weaker verification behind it.
- An established supplier has a corporate registry entry, a bank relationship history, and repeat transactions that make anomalies visible.
- A one-off campaign payee has an email address and a bank account.
That asymmetry is exactly why one-off payees are the softest target in the file.
The Sumsub European KYB Benchmark Survey 2026, conducted in Q2 2026 among compliance and risk professionals, found that verifying a corporate client takes longer than a day for almost 60% of businesses, and 81% have lost clients to onboarding delays.
AP teams face the same tension from the other side: the business wants the payee active today, and the due diligence file takes days to assemble manually. Something gives, and it is usually the file.
What KYC and KYB Mean for Vendor Onboarding
- KYC, or Know Your Customer, is the verification of a natural person: confirming that the individual is who they claim to be, that their identity document is genuine, and that they are not on a sanctions or watchlist.
- KYB, or Know Your Business, is the verification of a legal entity: confirming the company exists, is properly registered, and identifying the real people who own or control it.
Vendor onboarding needs both, because your payee population contains both. An influencer paid as a private individual is a KYC case. A two-person production studio registered as a limited company is a KYB case. A sole trader sits somewhere in between, a person operating under a business registration, and needs elements of each.
This is worth stating plainly because the terms get blurred in practice. This article is about vendor due diligence, the minimum file before someone can receive company money. It is not about marketing-team "influencer vetting," brand safety checks, or audience audits. Those matter, but they answer a different question. Vendor due diligence answers one question only: is this payee real, legitimate, and safe to pay?

What AP Should Collect Before a Payee Hits the Master File
Here is the minimum file. If any element is missing, the payee should not be in the master file, and no payment should move.
Verified Identity
Identity verification means confirming a government-issued document is genuine and belongs to the person in front of you. A copy of a passport in an email attachment does neither. Modern verification checks the document's security features, matches it against the person through a liveness check or a national ID scheme, and validates the data against authoritative sources.
In Sweden, for example, Gigapay verifies individuals through BankID and/or passport or national ID, with residence and work permits checked for non-EU nationals, and an internal process that flags expiring permits so nobody with lapsed status can receive compensation.
Entity Type
Every payee is an individual, a sole trader, or a company, and the classification drives everything downstream: which tax form applies, whether invoices or self-billing documents are issued, whether VAT and reverse charge rules apply, and what gets reported to which authority. Collecting entity type as a self-declared dropdown is a start. Validating it against a business registry, or against the absence of one, is the actual control.
Tax Form
In the US, this means a W-9 for domestic payees and a W-8 series form for foreign ones. In the EU, platforms and intermediaries face DAC7, which requires collecting official name, primary address, tax identification number per issuing member state, VAT number, company registration number, and any permanent establishment in the Union. The form itself is not the control.
Validating the TIN against the format and, where available, the issuing authority's records is the control. A W-9 with a mistyped TIN is a future B-notice and potential backup withholding exposure, discovered months after the payment left.
Bank Account That Matches the Name
This is the element most AP teams skip, and it is the one invoice fraud depends on. Because banks can process on account number alone, the only party who will ever check that the account belongs to the verified payee is you.
Verification options include penny-drop or micro-deposit confirmation, account-name matching services where the local rail supports them, and instant bank verification through open banking.
Whatever the method, the rule is absolute: the name on the verified identity and the name on the bank account must reconcile before the first payment, and every subsequent bank-detail change must re-clear the same check through a controlled channel, never through email.
Sanctions and PEP Screening Appropriate to Your Policy
Screening depth is a policy decision, but zero screening is not a policy. At minimum, payees should be screened against the major sanctions lists (OFAC, EU, UN, UK) at onboarding, with rescreening on a defined cycle. Jurisdiction risk belongs in the same check.
As of the March 2026 FATF update, Iran, Myanmar, and North Korea sit on the black list, and 22 jurisdictions including Monaco, Vietnam, Lebanon, and the British Virgin Islands sit on the grey list of countries under increased monitoring.
FATF revises these lists three times a year, which is itself an argument for automated rescreening rather than a one-time check. PEP screening, identifying politically exposed persons, matters most where payment sizes are large or jurisdictions are higher risk, and your policy should say when it applies.
Beneficial Ownership for Entities
When the payee is a company, you need to know who is behind it. The US CDD framework identifies beneficial owners at 25% ownership or more, plus one individual with significant control. FATF Recommendation 24 pushes the same standard globally, and the EU's AMLD6 is harmonizing beneficial ownership registers across member states.
For AP, the practical version is proportionate: for a micro-entity receiving campaign payments, confirm the registered directors and owners against the corporate registry and screen those individuals.
Fraudsters increasingly build synthetic business identities that combine real registration data with nominee directors, which is precisely what a registry-plus-screening check catches and a self-declared form does not.
A Refresh Cycle
A vendor file is a snapshot, and snapshots age. Identity documents and permits expire. W-8 forms lapse. Sanctions lists change three times a year at FATF level and far more often at OFAC level. Ownership changes hands. A file without a refresh cycle is only as good as the day it was collected, which for many master files was years ago.
What AP Teams Usually Collect Instead
In most companies, "vendor onboarding" for a small payee means a PDF W-9 attached to an email, an IBAN pasted into the message body, and a 12-field form in the ERP filled in by whoever had time.
That is not KYC. That is how invoice fraud works.
Walk through the fraud pattern against that process:
- Nothing verified the identity behind the W-9, so a fraudster can submit one under any name.
- Nothing matched the bank account to the payee, so the IBAN can belong to anyone.
- Nothing screened the payee, so a sanctioned or fabricated counterparty passes.
- Nothing established a controlled channel for changes, so the follow-up email that says "we've changed banks, please update our details" gets processed by the same AP specialist who processed the original, with the same absence of checks.
The AFP data showing 45% of organizations facing vendor imposter fraud is the direct output of this process running at scale.
The gap is not effort. AP teams work hard, and the ones drowning in one-off payees work hardest of all. The gap is that email and PDF workflows cannot perform verification, only collection. Collection without validation produces a master file full of records that look complete and prove nothing.

Who Should Collect the Vendor Due Diligence File
The principle is simple: the party that pays the person collects the file, at onboarding, in a portal, with validation built in. Whoever moves the money owns the due diligence behind it.
That principle produces two very different operating models, and choosing between them is the real strategic decision.
If You Pay Payees Directly, You Own the Full Stack
If your company is the paying party for hundreds of individuals and micro-entities, you need the infrastructure of one: a self-service onboarding portal, document and identity verification, TIN validation, bank account verification, sanctions screening with rescreening, and a case-management process for the exceptions. You also need the staff.
Robert Half's 2026 Salary Guide puts the US midpoint at $56,500 for an AP specialist, $62,000 for an AP analyst, and $78,250 for an AP manager, before software licenses, and manual KYB verification runs 2 to 20 business days per entity depending on complexity.
For a payee population measured in hundreds, the math compounds quickly, which is how Gigapay's 600-collaboration model arrives at 840 admin hours and roughly €139,590 per year for the manual route.
If a Merchant of Record Pays, You Sample Their File
The alternative moves the paying-party role to a Merchant of Record. The MoR becomes the contractual counterparty to each payee, which means the MoR performs the KYC and KYB, owns the verification infrastructure, and carries the onboarding relationship. Your ERP holds one vendor: the MoR.
Your job then changes from building the file to assuring it. You do not rebuild the MoR's due diligence, and you should not try, because duplicating verification defeats the purpose of consolidating it.
Instead, you perform vendor assurance on the MoR itself: review their certifications (ISO 27001 is the relevant information-security baseline, and Gigapay holds it), understand their KYC methodology, and periodically sample their payee files to confirm the process runs as described. Sampling a file is an afternoon. Rebuilding one is a department.
The dividing line between the two models is volume and payee type. Ten established suppliers a year is a direct-payment problem. Three hundred individual creators a year is a Merchant of Record problem wearing a vendor-onboarding costume.
How to Set a Vendor Data Refresh Cycle
Refresh frequency is a policy decision, and a defensible policy recognizes that different elements of the file age on different clocks.
The tax form clock is the most concrete.
- A W-8BEN remains valid from the date it is signed through the last day of the third succeeding calendar year, so a form signed in September 2026 expires on December 31, 2029, and earlier if any information on it changes.
- A W-9 has no fixed expiry but must be recollected when the payee's circumstances change. If your file contains W-8 forms with no expiry tracking, some of them are already dead.
The sanctions clock runs faster. FATF updates its lists three times a year, and national lists like OFAC change far more frequently. Screening once at onboarding and never again means a payee sanctioned after onboarding stays payable in your system indefinitely. Automated rescreening of the full payee base, at minimum on each list update for higher-risk profiles, is the standard the screening industry has converged on.
The identity clock is event-driven. Passports, residence permits, and work permits expire on known dates, so the file should store those dates and block payment past them. Gigapay runs exactly this control: users with expired permits cannot work or receive compensation until the document is renewed and re-verified.
The bank detail clock is trigger-based rather than periodic. Details get re-verified on every change request, through the portal, with the same name-match check as onboarding. A calendar-based refresh adds little here; a controlled change channel adds everything.
Finally, a risk-based tier structure keeps the workload sane. Low-risk, low-value payees in low-risk jurisdictions can run on longer cycles. Payees in FATF grey-list jurisdictions, high-value payees, and entities with complex ownership run on shorter ones. Write the tiers down, because the policy you can show an auditor is the one that counts.

What Vendor Due Diligence Costs Compared to Skipping It
The cost of doing this properly is real, so it deserves honest numbers.
Running it in-house means software plus people. Verification platform costs vary widely with volume, and the people costs anchor around the salary data above: a single AP specialist at the $56,500 midpoint, fully loaded, plus the analyst time to handle exceptions, plus manager oversight.
For a few hundred micro-payees per year, Gigapay's cost model lands the manual route at roughly €139,590 annually, with 840 hours of admin time and a master file carrying 300+ individual records, every one of them a fraud surface and a data-protection liability under GDPR.
Routing the same population through a MoR lands at roughly €46,350 in the same model, with about 60 admin hours and one vendor record. The due diligence still happens for every payee. It happens once, inside the MoR's verification infrastructure, instead of being rebuilt inside yours.
The cost of skipping it is the third column, and it is the expensive one. The IC3's $3.05 billion in reported 2025 BEC losses is the aggregate; the individual version is a redirected payment your business generally cannot recover, because Regulation E protects consumer accounts only, and a business that authorizes a payment against fraudulent details typically bears the loss itself.
The main recovery mechanism is speed, with the FBI's Financial Fraud Kill Chain dependent on reporting within roughly 72 hours. Add tax exposure from unvalidated forms, and add the audit finding when someone asks to see the due diligence behind payee number 214 and the answer is a PDF in a shared inbox.
How Gigapay Handles KYC and KYB for Individuals, Sole Traders, and Companies
Gigapay operates as the Merchant of Record for creator and micro-vendor payouts, which makes Gigapay the paying party, and therefore the party that builds the file.
Every payee completes KYC and onboarding before receiving any compensation, with no exceptions: a payee who has not provided all requested information cannot be paid. Payees onboard as individuals, sole traders, or companies, and no registered business or VAT number is required for individuals, which removes the single biggest onboarding barrier for nano and micro creators.
- For international individuals, the file includes name, address, TIN, personal number where relevant, country of work, nationality, date of birth, ID copy, and bank account details, with an A1 form where relevant.
- For companies, the file extends to full company details and the DAC7 dataset: official name, primary address, tax registration number, VAT number, company registration number, and any permanent establishment in the EU.
Tax reporting runs on top of the verified file. Gigapay reports compensation to the Swedish tax authority, with international income statements exchanged to the payee's local authority, and handles DAC7 reporting for EU payees along with country-specific obligations such as KU14 for Denmark.
Gigapay tracks the FATF lists and applies extra due diligence to grey-list jurisdictions, and the whole operation runs under ISO 27001 certification and GDPR compliance.
For your AP team, the practical outcome is the one this article has been building toward: the master file holds one vendor, one contract, and one consolidated invoice per batch, while the per-payee due diligence lives where the payment obligation lives.
Brands like Boozt tripled creator collaborations without expanding the team, and WPPMedia's GOAT agency cut payment-management time significantly, because the file work moved to the party built to do it.

Conclusion
Gigapay is the Merchant of Record that keeps individuals and micro-entities off your vendor master file while making sure every one of them is verified, screened, and tax-documented before money moves.
The minimum vendor due diligence file is not complicated to describe: verified identity, entity type, validated tax form, a bank account that matches the name, sanctions screening, beneficial ownership for entities, and a refresh cycle that keeps it all true.
What is genuinely hard is running that file for hundreds of one-off payees with email, PDFs, and a 12-field ERP form, which is why 45% of organizations are eating vendor imposter fraud attempts.
If vendor onboarding at your company is a 12-field form, book a demo with Gigapay and see what it takes to keep those payees off your master file entirely.
Read Next:
- IR35 in 2026: What Finance Still Owns When You Pay UK Limited-Company Contractors at Scale
- E-Invoicing When the Payee Cannot Issue a Compliant Invoice
- Contingent Workforce Payouts: When You Need a Contractor Stack, Not an Employer of Record
FAQs:
1. What is the difference between KYC and KYB in vendor onboarding?
The difference between KYC and KYB in vendor onboarding is that KYC verifies natural persons while KYB verifies legal entities. KYC confirms an individual's identity, documents, and screening status. KYB confirms a company's registration, legitimacy, and beneficial owners. A mixed payee population of individuals, sole traders, and companies means AP will run both.
2. Is a copy of a passport enough to verify a vendor?
A copy of a passport is not enough to verify a vendor on its own. A passport copy proves a document exists, but it does not prove the document is genuine, that it belongs to the person submitting it, or that the linked bank account belongs to the same person. Proper verification checks document authenticity, matches the person to the document, and reconciles the bank account name.
3. How often should AP teams refresh vendor KYC and KYB data?
AP teams should refresh vendor KYC and KYB data on element-specific clocks defined in policy. W-8 forms expire at the end of the third calendar year after signing. Sanctions lists change at least three times a year at FATF level, so rescreening should be automated. Identity documents and permits should block payment past their expiry dates, and bank details should be re-verified on every change request.
4. What documents should AP collect before adding a payee to the vendor master file?
The documents AP should collect before adding a payee to the vendor master file are a verified identity document, an entity type declaration validated against a registry, a tax form with a validated TIN, bank account details verified against the payee's name, a sanctions and PEP screening result, and beneficial ownership information for companies.
5. Who is responsible for KYC when a Merchant of Record pays vendors?
When a Merchant of Record pays vendors, the Merchant of Record is responsible for KYC, because the paying party owns the due diligence behind its payments. The MoR builds and refreshes the per-payee file, and your AP team performs assurance instead: reviewing the MoR's certifications and methodology and sampling its files, rather than rebuilding verification that already exists.
.jpg)

.jpg)

.jpg)


