Agentspay
All posts

Vendor Onboarding for AI Procurement Agents: The Checks to Run Before an Agent Can Buy

Agentspay · August 13, 2026 · 8 min read ·
Share
Agent Payments Console

Pick an agent

Payment intent

intent:

Policy evaluation

Human approval required

This spend is over your approval threshold. Approve it to issue a scoped card, or deny it.

Scoped virtual card issued

Agentspay

single-use

Wallet budget

spent of

Audit trail

Short answer: Before an AI procurement agent is allowed to place an order with a supplier, that supplier should clear six checks: legal identity (the entity exists and the name matches), tax documentation (a W-9 for US vendors, W-8 series for foreign ones), verified banking details (confirmed out of band, never from an emailed PDF), sanctions and denied-party screening against the OFAC list, insurance where the work warrants it, and agreed commercial terms (price, payment terms, who owns what). An agent can gather and pre-check all six. What it should not do is approve its own exceptions, and the finished onboarding should end in a payment allowlist entry rather than a row in a spreadsheet.

The reason this matters more with agents than it did with humans is a change in tempo. A buyer who found a new supplier used to spend a week getting them set up, and that week was, accidentally, a control. An agent can find a supplier, request a quote and be ready to transact in about ninety seconds. If nothing gates that path, the first time anyone reviews the vendor is when finance is trying to work out who received the money.

What is vendor onboarding?

Vendor onboarding is the process of collecting and verifying everything you need before you can legally, safely and payably do business with a new supplier. It ends with the supplier existing as an approved, payable record in your systems. In a traditional setup that record lives in an ERP or a vendor management system. In an agentic setup it needs to live somewhere the payment layer can read, because the whole point is to stop unapproved payments at authorization rather than in a review meeting.

Onboarding is not the same as sourcing. Sourcing is deciding this supplier is the right one commercially. Onboarding is proving they are who they claim to be and that paying them will not create a tax, sanctions or fraud problem. Agents are genuinely useful at the first, and useful but not trustworthy alone at the second.

What checks should you run before onboarding a vendor?

Six, in rough order of how much damage skipping them causes.

CheckWhat it provesCan an agent do it?
Legal identityThe entity exists and the trading name matches the registered oneYes, from registry lookups
Tax documentationYou can report payments correctly at year endCollect yes, validate yes, accept no
Banking detailsMoney reaches the supplier and not an impostorNo, verify out of band with a human
Sanctions screeningPaying them is not itself illegalYes to screen, no to clear a hit
InsuranceTheir liability does not become yoursYes, collect and check expiry dates
Commercial termsEveryone agrees what was bought and at what priceDraft yes, sign no

1. Legal identity

Confirm the business exists under the name on the invoice. For US suppliers that means a Secretary of State registration in the state of incorporation, an address that is not a mail drop, and a trading name that reconciles to the registered entity. Agents do this well because it is lookup work across public registries. The failure mode to watch for is an agent accepting a close match. "Acme Supply LLC" and "Acme Supplies LLC" are different companies, and one of them may not be the one you negotiated with.

2. Tax documentation

US vendors provide a Form W-9 with their legal name and taxpayer identification number. Foreign vendors provide the appropriate W-8 series form. You need this before the first payment, not at year end, because chasing a W-9 from a supplier who has already been paid is one of the least productive conversations in accounts payable. Validate that the name and TIN combination is internally consistent and matches the entity you verified in step one. An agent can collect the form, extract the fields and flag mismatches. A person should accept it.

3. Banking details

This is the one to never automate end to end. Business email compromise works precisely because a convincing message asking to update bank details arrives at the moment a payment is expected. Verify account details through a channel you established independently, such as a phone number from the supplier's registered record rather than from the email signature. Then lock the details so changing them requires the same verification again. An agent that can update a payee's bank account from an inbound message is a fraud pipeline with good intentions.

4. Sanctions and denied-party screening

Screen the entity and its principals against the US Treasury's OFAC Specially Designated Nationals list, plus any denied-party lists relevant to your industry. This is not optional and it is not risk-based in the way the other checks are: paying a sanctioned party is a violation regardless of intent. Screening is well suited to automation, and re-screening on a schedule matters as much as the initial check, since a supplier onboarded clean in March can be listed in September. What an agent must not do is dismiss a partial name match on its own judgment.

5. Insurance

Where a supplier will be on your premises, handling your data, or doing work that could injure someone, collect a certificate of insurance showing current general liability, and workers' compensation or professional liability as the engagement warrants. The practical difficulty is that certificates expire, usually quietly, and a supplier with lapsed cover looks identical to a covered one in a vendor master. Teams that track this properly tend to run a system that tracks certificates of insurance and chases renewals before they lapse rather than relying on a folder of PDFs and someone's calendar reminder. An agent is good at reading the expiry date off a certificate. It is not the right thing to decide whether coverage is adequate.

6. Commercial terms

Agree price, payment terms, delivery, and what happens when something is wrong, in writing, before the first order. For low-value repeat purchases this can be a standing agreement the agent orders against. For anything material it is a contract a person signs. The relevant question for agent-driven buying is narrower than general contract review: does this agreement let an agent place orders, and up to what value? If your terms are silent on that, your legal exposure is ambiguous in a way you will not enjoy discovering during a dispute.

Can an AI agent onboard a vendor by itself?

It can do most of the work and should not make the final call. The sensible division is that the agent gathers, extracts, screens and pre-fills, then presents a completed file with exceptions flagged. A person clears the exceptions and approves the vendor. This is not a hedge about agent capability. It is that four of the six checks above have a failure mode where a plausible-looking wrong answer costs real money, and an agent optimizing to complete the task is precisely the wrong reviewer for its own work.

The pattern that works is the same one that works for AI procurement agents placing orders: the agent moves fast on everything reversible and stops at the things that are not. Onboarding a fraudulent payee is not reversible. Neither is a sanctions violation.

How does vendor onboarding connect to what the agent can actually buy?

This is the step most teams miss, and it is what separates onboarding that works from onboarding that is theater. An approved vendor record has to become an allowlist entry the payment layer enforces. If approval lives only in a vendor management system, and your agent pays by card, nothing stops that agent from buying from a supplier who was never onboarded at all. The check happened; it just was not connected to anything.

Wired properly, the flow is: vendor clears onboarding, vendor is added to the allowlist for a specific category and spend ceiling, and the agent's wallet declines any authorization to a merchant outside that list. The agent does not need to be trusted to remember the policy, because it cannot execute outside it. That is the difference between a prompt that says "only buy from approved suppliers" and a control. Prompts can be argued with. A declined authorization cannot. We go deeper on the enforcement side in agent spend controls, and on how the platforms in this space compare in AI procurement agent platforms.

What about agents buying from merchants you did not onboard?

Increasingly agents buy through assistant surfaces rather than through your supplier relationships, which is a different problem wearing similar clothes. When an agent completes a purchase through agentic checkout, there is no onboarding step at all: the merchant is whoever the assistant selected, and the human confirmation screen that used to exist has been deliberately removed. For consumer-style purchases that may be fine. For company spend it means the allowlist is doing all the work, so it needs to be a real ceiling rather than a preference. Decide in advance which categories your agents may buy openly and which require a named, onboarded supplier.

How long should vendor onboarding take?

For a low-risk supplier with clean documentation, hours rather than weeks, and agents genuinely compress this. Most of the historical delay was queueing rather than work: a form sat in an inbox for three days, then a person spent twenty minutes on it. Removing the queue is a legitimate win. What should not compress is the out-of-band bank verification and the review of any screening hit, because those are the steps where speed is the risk rather than the cost.

What are the risks of onboarding vendors too quickly?

Three, in descending order of frequency. Payment fraud, where an impostor is set up as a payee or a real supplier's bank details are altered, which is the most common and most expensive. Tax reporting gaps, where you paid vendors you cannot properly report on because nobody collected the documentation. Sanctions exposure, which is rarer but carries penalties that do not care how it happened. Notice that none of these are caught by asking the agent to be more careful. They are caught by a verification step the agent cannot skip and a payment rail that will not settle to an unapproved account.

The short version

Let agents do the gathering, the extraction, the registry lookups and the screening, and let them do it in minutes instead of days. Keep human judgment on bank details, screening hits, contract signature and final approval. Then connect the approved vendor list to the payment instrument, so the onboarding decision actually constrains what gets bought. Onboarding that ends in a database row is documentation. Onboarding that ends in an allowlist is a control.

Try it in the sandbox

Give an agent a wallet, write a policy, and issue a scoped virtual card in an afternoon. Never moves money without policy.