
Before you sign a contract, share confidential data, extend credit, or add a partner to daily operations, you need a process for checking who they really are.
This guide walks through what to check, how to verify it, what red flags mean, and how to document a go/no-go decision that holds up later — whether you're bringing on a co-founder, a subcontractor, or a new supplier.
Key Takeaways
- Scale diligence depth to risk: money access, regulatory exposure, and ownership complexity.
- Verify identity, ownership, financials, and reputation through independent sources, not self-reports.
- Document every finding with a source, date, and clear statement of what wasn't checked.
- Monitor after onboarding; licenses, insurance, and ownership can change without notice.
What You Need to Check and Prepare
Start by locking four decisions before you collect a single document. Skipping this step is how companies end up gathering the wrong files for the wrong reasons.
Define up front:
- Business purpose of the relationship
- Your risk tolerance
- Who makes the final call
- What evidence you need before you accept the partner
Risk Scope and Review Plan
Identify the relationship type first — co-founder, investor, supplier, contractor, subcontractor, distributor, referral partner, or acquisition target. Each carries different stakes.
Build your scope around:
- Transaction value and payment terms
- Access to funds, systems, or sensitive data
- Regulated activities or government contact
- Subcontracting and geographic complexity
- How business-critical the relationship is to your operations
Business Identity, Ownership, and Authority
Confirm the basics on paper:
- Legal name and any assumed names
- Entity type, state registrations, and active status
- Principal address and registered agent
- Current leadership
Then verify that the person negotiating the deal can actually bind the company. A Secretary of State listing alone does not prove signing authority.
Cross-reference identity details across registries, licensing databases, contracts, and professional profiles. Flag unexplained inconsistencies in name, address, ownership, or leadership.
In one internal review of a fictional freight carrier, Larkspur Express Inc., authority had been granted only five months earlier. A continuity check tied it to a revoked predecessor through six dated matches: address, terminal, officer, insurance chain, and financed equipment.
None of that would have surfaced from a name search alone.
Financial, Legal, and Compliance Evidence
Request documents proportionate to the relationship: financial statements, credit information (with consent), insurance certificates, licenses, permits, and material contracts.
Research these independently:
- Litigation, liens, and bankruptcies
- Regulatory actions and sanctions or restricted-party matches
- Adverse media and unresolved complaints
- Intellectual property disputes
Distinguish verified proceedings from unsubstantiated allegations. A lawsuit filing is not the same as a judgment.
A review of fictional freight broker Tripeak Freight Solutions LLC turned up several signals at once:
- Current $75,000 bond, with a 19-day surety gap earlier that year
- Shared address with four other logistics entities (one with revoked authority)
- Two tagged slow-payment reports
Each finding alone might be explainable. Together, they form a pattern worth escalating.
Operational, Reputation, and Relationship Fit
Test whether the partner can actually deliver:
- Staffing and capacity
- Quality controls and cybersecurity practices
- Subcontractor use
- Customer references and service history versus what they claimed
Assess practical fit next:
- Communication style and decision rights
- Risk tolerance and reporting obligations
- How disputes get handled
Write down open questions that belong in the contract itself.
A specimen review of fictional mechanical subcontractor Cascade Comfort Mechanical LLC surfaced:
- Current $20,000 bond after a 26-day gap
- General-liability coverage expiring in 41 days
- Public reviews citing unfinished punch-list work on a prior job
None of that is automatically disqualifying. Each detail belongs in the contract's milestone and insurance clauses.

Methods to Conduct Due Diligence
No single document or database search proves a partner is trustworthy. Effective diligence combines independent source checks, direct questioning, and risk-based escalation, scaled to what's actually at stake.
Initial Public-Record and Open-Web Screening
This establishes a baseline: entity status, ownership, licenses, legal history, and public reputation.
Sources to use:
- Secretary of State or state entity registries
- Licensing boards relevant to the industry
- Federal and state court records
- Sanctions and restricted-party databases
- Trademark/patent databases where relevant
Process:
- Confirm the exact legal entity and search name variations, former names, and key executives.
- Compare registry data against the partner's questionnaire, website, and contract details.
- Save the source URL, capture date, search scope, and any unresolved limitation for every material conclusion.

Public records are efficient for initial screening, but they can be incomplete, outdated, or tied to the wrong entity entirely.
A structured research workflow helps close those gaps. Salvara's public-record and license-registry research pulls these sources together with capture dates attached, so a finding can be checked again months later instead of disappearing when a registry page updates.
Direct Verification Through Documents, Interviews, and References
Databases can't tell you if a partner will actually show up and do the work. Structured questionnaires, document requests, and reference calls can.
Ask focused questions about ownership, financial condition, compliance history, data security, subcontractors, and prior partnership failures. Then validate the answers against primary evidence:
- Cross-check claims against original certificates or filings
- Call independent references, not just the ones provided
- Review sample work or conduct a site visit when the stakes justify it
- Follow up on vague or inconsistent answers
Record who supplied each item, what it confirms, and what it doesn't establish. A reference call that confirms "they're reliable" doesn't confirm insurance is current.
Enhanced Due Diligence and Ongoing Monitoring
Some situations need a deeper look: complex ownership structures, high transaction values, sensitive data access, or unresolved red flags from initial screening.
The Department of Justice's 2024 guidance on corporate compliance programs asks whether companies understand a third party's business rationale, payment terms, and how red flags were resolved, not just whether a screen came back clean.
Triggers for enhanced review:
- Government contacts or regulated activities
- Overseas relationships or heavy subcontractor reliance
- Significant negative findings from initial screening
- High transaction value or ownership complexity
Diligence doesn't end at onboarding. Licenses expire, insurance lapses, and ownership changes without any announcement.
Salvara's Muster product tracks license standing, bond status, insurance expiry, and entity relationships across every state a partner operates in, flagging material changes monthly. In one case, a manufacturer's monthly dashboard caught an installer's license expiring in 21 days, plus an ownership transition the manufacturer hadn't been told about.
Set review intervals and event triggers: ownership changes, regulatory action, missed service levels, insurance lapses, or suspicious payment requests should all reopen the file.
How to Interpret the Results
Due diligence findings are evidence for a decision, not an automatic approval or denial. Weigh each result by source reliability, recency, materiality, and whether the partner will address concerns.
Clear or Acceptable Findings
A reasonably reassuring file typically shows consistent identity and ownership information, current licenses and insurance, explainable financial capacity, and credible references with no unresolved legal concerns.
A clean search result only means nothing turned up in the sources you checked. Record the search boundaries, sources, dates, and remaining unknowns before you approve the relationship—not after.
Concerning but Potentially Resolvable Findings
Outdated paperwork, isolated negative reviews, minor administrative violations, or old litigation with a credible explanation don't automatically disqualify a partner.
Proportionate responses:
- Request clarification or updated documents
- Narrow initial access until issues resolve
- Add representations, warranties, or indemnity provisions
- Set milestones tied to specific deliverables
- Delay onboarding until evidence is complete
Material Red Flags and Stop-or-Escalate Findings
Some findings warrant a pause regardless of how good the rest of the file looks: falsified documents, concealed ownership, refusal to provide basic verification, unexplained payment-account changes, invalid licenses, or sanctions matches.

A name match on a restricted-party list isn't proof by itself. The Office of Foreign Assets Control's own guidance calls for confirming potential matches against identifiers before acting on them, not just the name. Confirm context through reliable sources first, then pause, escalate, or decline if the issue is material and unexplained.
Decision, Documentation, and Contract Controls
Write down the decision. Include the business purpose, scope, evidence reviewed, findings, unresolved risks, approvals, and the reason for proceeding, pausing, or declining.
Connect findings to real contract terms:
- Payment limits or phased work
- Audit rights and confidentiality clauses
- Insurance requirements tied to renewal dates
- Subcontractor approval and termination rights
A source-linked research file, such as the kind Salvara's Deepread product produces, ties every claim to a date and source so the approval stays defensible months later when someone asks why the partner was cleared.
Common Errors and Best Practices
The most common mistakes create false confidence, not real protection:
- Searching only the company's name, missing related entities and former names
- Relying on a single database instead of cross-checking multiple sources
- Accepting screenshots without verifying the original source
- Treating unadjudicated allegations as proven fact
- Reviewing only at onboarding, then never again
Build these habits instead:
- Assign clear ownership of the diligence file
- Keep a central evidence record with dates and sources
- Set renewal and monitoring triggers tied to license and insurance expiration
- Revisit the relationship after ownership changes or performance problems
Collect only what's relevant to the business purpose. Secure sensitive documents and get consent where required.
Consult qualified U.S. counsel before running anything resembling a personal background check. Consumer-reporting rules apply differently to individuals than to business entities, and conflating the two creates legal exposure of its own.
Conclusion
Reliable partner diligence is a repeatable process, not a single search or filing. Strong diligence covers:
- Risk-based scoping
- Independent verification
- Direct questions
- Dated documentation
- Contract terms that match what you found
Use that work to understand the material risks, make a clear decision, write it down, and revisit it when the facts change.
Frequently Asked Questions
What are red flags in due diligence?
Red flags include concealed ownership, falsified or inconsistent information, refusal to verify basic claims, sanctions matches, invalid licenses, and unexplained financial pressure. A potential match still requires identity and context checks before you act on it.
What are the four main types of due diligence?
Common categories include financial, legal/regulatory, operational/commercial, and reputational/strategic due diligence. The exact framework should reflect the specific relationship's risk, not a fixed checklist.
What are the Four P's of due diligence?
One named framework (used mainly for evaluating investment managers) defines People, Philosophy, Process, and Performance. It's useful for organizing checks but isn't a universal legal standard for vetting business partners.
How do you perform due diligence on a business partner?
Define the relationship's risk level, verify identity and ownership through independent sources, review legal and financial records, check capabilities and references, and document every finding with sources and dates. Then monitor after onboarding.
What documents should you request from a potential business partner?
Request entity records, licenses, insurance certificates, financial information, ownership details, compliance policies, references, and relevant contracts, scaled to what the relationship actually requires. Avoid requesting more than the business purpose justifies.
How often should you repeat business partner due diligence?
Timing depends on risk level. Set scheduled reviews plus event-driven checks after ownership changes, regulatory action, litigation, insurance or license expiry, or unusual payment requests.


