KYS · identity, ownership, evidence
You know the name on the invoice. Do you know the company behind it?
Know Your Supplier moves a principle from banking to the supply side: verified means checked. Merely recorded means typed in.
Know Your Customer has obliged banks for decades to establish the identity and beneficial owners of their customers. Know Your Supplier applies the same logic to suppliers – driven by sanctions regimes, fraud cases and regulatory demands on the supply chain.
The starting point is uncomfortable: many vendor masters hold details nobody ever verified. A company name from an old order, an address from an email signature, bank details from a PDF. Payment fraud lives in exactly that gap – and so does the sanctions check that quietly returns nothing because the name is wrong.
What identity includes
- The exact legal name and form as entered in the register.
- The company identification number or its equivalent in the country of domicile.
- Registered seat and the actual sites of performance, which may differ.
- Group affiliation and, where relevant, beneficial owners.
- Bank details verified through a second channel rather than lifted from an email.
The sequence
- Establish
- Check details against an independent source, not against the self-disclosure.
- Relate
- Link subsidiaries and branches to the parent company.
- Screen
- Check sanctions and watch lists, record the result with a date.
- Refresh
- Details age. A check date without repetition is an expiry date.
- Evidence
- Record the step, the source and the result, not only the outcome.
How SCRM covers it
Verified master data
Checked and unchecked details are distinguishable – the whole point of the exercise.
Group structure
Parent, subsidiaries and branches as relationships rather than a text field.
Check date with recall
What was verified gets verified again before it goes stale.
Evidence trail
The source and moment of every check is retained.
Frequently asked
Isn’t KYS excessive for an SME?
Depth can be graded; the principle cannot. Verifying legal name, company number and bank details for critical suppliers alone prevents the most common loss: payment fraud through a forged change of account.
Where does the data come from?
Public registers, sanctions lists and the supplier’s own disclosure – the last being the weakest source, and it should be marked as such.
How often should we re-check?
Immediately on triggering events, otherwise in fixed cycles by criticality. A change of bank account is always a trigger.