Know Your Vendor (KYV): Third-Party Due Diligence for Compliance Teams
Know Your Vendor (KYV) is the due diligence a business runs on its suppliers, contractors, and other third parties before and during a commercial relationship. It verifies who actually owns and controls a vendor. It screens that vendor against sanctions and adverse-media sources, then tracks the risk profile over time. The discipline comes straight from the customer side. The same checks compliance teams already run on customers get pointed at the supply side, where hidden ownership and sanctions exposure do just as much damage.
For compliance and procurement leaders, whether a vendor delivers on time is rarely the hard question. The harder one is whether onboarding that vendor pulls sanctions exposure, concealed ownership, financial-crime risk, or reputational damage onto your organization. The sections below cover what KYV involves, how vendor risk gets assessed, and where it sits alongside your existing Know Your Customer program.
What Is Know Your Vendor (KYV)?
Know Your Vendor is a structured compliance framework for identifying, verifying, and risk-rating the third parties that supply goods or services to your business. The term is broad. A vendor can be a materials supplier, a logistics provider, an IT or SaaS partner, a contractor, or any external entity you pay. KYV establishes who the vendor really is, who stands behind it, and whether engaging it would breach your obligations under anti-money-laundering, sanctions, or anti-bribery rules.
At its core, KYV is about verification, not reputation. A vendor can have a strong delivery record and still carry a sanctioned ultimate beneficial owner, a director on a watchlist, or a parent entity in a high-risk jurisdiction. Surfacing those facts before a contract is signed, and continuing to surface them while the relationship is live, is the whole point.
Why Vendor and Third-Party Risk Matters
Third parties sit inside your risk perimeter even though they are outside your organization. Regulators increasingly treat vendor relationships as an extension of your own compliance posture, so a vendor's sanctions breach or bribery exposure can land as your enforcement problem. Supply chains have grown longer and more opaque too, and the entity you sign a contract with is frequently several steps removed from the people who actually control it.
Compliance teams track a handful of vendor-risk categories most closely:
- Sanctions and watchlist risk. A vendor, its owners, or its directors turn up on sanctions, PEP, or law-enforcement lists.
- Concealed ownership. Layered corporate structures hide the ultimate beneficial owner behind shell entities or nominees, so the name on the contract tells you nothing about who profits.
- Financial-crime and integrity risk: links to fraud, bribery, money laundering, or prior regulatory action.
- Operational and continuity risk. Financial instability or weak controls at a vendor can disrupt your own operations.
Onboard vendors with the same rigor you apply to customers and you close a gap that financial-crime networks actively exploit.
Vendor Onboarding Due Diligence
Vendor due diligence is the front-end check you complete before a third party is approved. It collects and verifies the vendor's legal identity, registration, and licensing, then layers risk screening on top. Match the depth of that check to the risk the vendor presents. A low-value office supplier and a cross-border payments partner should not get identical treatment.
A practical onboarding sequence runs four steps. First, confirm the vendor's legal entity, registration number, and licensing in its jurisdiction. Second, identify the ownership structure and the natural persons who ultimately control it. Third comes screening: check the entity and its key individuals against sanctions, PEP, and adverse-media sources. Fourth, assign a risk rating that drives whether enhanced checks are required and how often the vendor is reviewed. Write that workflow down once, run it across the supply side, and every vendor ends up with a consistent, auditable record.
If you onboard high-risk vendors, Enhanced Due Diligence extends the standard checks with deeper ownership mapping, source-of-funds questions where relevant, and closer review of any past legal or regulatory action.
Beneficial Ownership of Vendors
Identifying the ultimate beneficial owner is the part of KYV that catches the most serious risk. It is also the hardest to do by hand. Vendors are often structured through holding companies, intermediaries, or cross-border entities that obscure who ultimately profits and decides. Skip that chain and a sanctions or PEP screen on the visible entity alone can come back clean while a sanctioned individual sits one or two layers up.
Good ownership due diligence traces the corporate structure down to identifiable natural persons, records the percentage of ownership and control at each layer, and re-runs screening against those individuals. Concealed ownership gets exposed here. Unwind the layers and a vendor that looked unremarkable on the surface can turn out to have a beneficial owner tied to a sanctioned entity. Map ownership at onboarding, refresh it when structures change, and vendor screening stops being a checkbox and becomes a real control.
Sanctions and Adverse-Media Screening on Vendors
Screening is the engine of KYV. Every vendor entity and every individual surfaced through ownership analysis should be checked against current sanctions and watchlists, PEP databases, and adverse-media sources. Sanctions screening establishes whether engaging the vendor is legally prohibited. Adverse-media screening adds the context formal lists miss, flagging investigations, fraud allegations, or corruption reporting before they escalate into enforcement or headlines.
Currency is what matters here. Sanctions designations and negative news change constantly, so a screen run once at onboarding decays within weeks. Pair structured list screening with continuous adverse media intelligence and the vendor's risk picture tracks reality instead of freezing at the moment the contract was signed.
Ongoing Vendor Monitoring
Approval is not the end of KYV. A vendor that was clean at onboarding can pick up a sanction next quarter, change hands, or surface in adverse media long after the contract goes live. Point-in-time due diligence catches none of that. Ongoing monitoring is the difference between a one-time gate and a real control.
Continuous monitoring re-screens active vendors against updated sanctions, PEP, and adverse-media data, then raises an alert when a vendor's risk status changes. That lets compliance teams act on a new designation or investigation within days, instead of stumbling on it during an audit. Apply a perpetual KYC approach to vendors and periodic manual reviews give way to always-on screening, so risk events drive action when they happen instead of at the next scheduled review.
KYV vs KYC
KYV and KYC share the same toolkit but point in opposite directions. KYC verifies the customers and counterparties you take on. KYV verifies the suppliers and third parties you pay. Both rely on identity verification, beneficial-ownership analysis, sanctions and adverse-media screening, and ongoing monitoring. What changes is whose risk you are managing, the customer's under KYC and the vendor's under KYV.
Plenty of organizations run mature KYC programs and far weaker vendor controls. That leaves the supply side as the path of least resistance for sanctions evasion and illicit funds. Extending the verification standards you already apply to customers across to vendors is often the single highest-impact move in closing third-party risk.
How KYC Hub Supports Know Your Vendor
KYC Hub's Know Your Supplier solution brings vendor due diligence into the same platform compliance teams already use for screening and monitoring. Its core pillars map directly to the KYV requirements above:
- Vet suppliers continuously. Screen vendors against sanctions, PEP, and adverse-media data at onboarding and on an ongoing basis, with alerts when risk status changes.
- Catch concealed ownership: unwind layered corporate structures to find the ultimate beneficial owners behind a vendor, then re-screen those individuals.
- Centralise supplier records. Each vendor's verification, screening results, and risk rating sit in one auditable place rather than scattered across teams.
- Trade finance and investment management. The same supplier and counterparty checks extend across trade finance and investment-management relationships, where third-party exposure tends to concentrate.
The goal is a consistent, defensible vendor-risk record both procurement and compliance can rely on, without rebuilding the screening capability you already have for customers.



