B2B KYC checklist — what to collect and verify
What to collect from a business counterparty, how to verify each item against its source, and how long to keep it.
KYC has a reputation as compliance paperwork. Treated that way, it produces a folder of PDFs nobody looked at. Treated properly, it answers one question that matters commercially: if this goes wrong, who exactly do I pursue, and can I find them?
The distinction that matters: collected vs verified
A document a counterparty uploads is a claim. A document checked against its issuing source is a fact. Most B2B KYC failures are not missing documents — they are documents collected and never checked.
For each item below, the verification method matters more than the artefact.
Entity checklist
| Item | Why | How to verify |
|---|---|---|
| PAN | Tax identity, entity type | Format check; 4th character indicates entity type |
| GSTIN | GST registration, state | GST portal taxpayer search: status must be Active, name must match |
| CIN / LLPIN | Legal existence | MCA register: status and filing currency |
| Incorporation certificate | Constitution | Cross-check CIN, name and date against the register |
| Udyam | MSME status, your payment duties | Udyam portal verification |
| Registered address | Where notices go | Against MCA/GST records |
| Bank account | Where money goes | Account name must match the legal entity |
For non-incorporated entities the constitution document differs — partnership deed for a firm, and for a sole proprietorship there is none, so identity rests on PAN, GSTIN and business registrations.
Person checklist
The entity is usually real. Whether this person represents it is the open question.
| Item | Why |
|---|---|
| Identity of the authorised signatory | Who is binding the entity |
| Evidence of authority — board resolution, deed, PoA | That they can |
| Individual ID, verified not uploaded | DigiLocker or Aadhaar OKYC give signed documents from the issuer |
| Contact details on the company domain | A free mail account for a company signatory is worth a question |
The bank detail rule
Treat bank details as a separate, higher-risk category:
- The account name must match the legal entity name. Not the trade name. Not a director's name.
- Any change to bank details must be verified out of band — through a phone number you held before the request arrived.
- Never accept a change of account details in the same email thread that requests payment.
Invoice-redirection fraud is the most common B2B payment fraud, and it works by compromising or imitating an email account in an otherwise genuine relationship. Every control above exists because of it.
Collect the minimum
More data is not better KYC. Every field you store is a field you must secure, justify and eventually delete. Under India's DPDP framework, collecting personal data you do not need for a stated purpose is a liability, not diligence.
Prefer verification methods that give you less data: Aadhaar OKYC returns a masked Aadhaar number rather than the full one, which is sufficient for identity and safer to hold.
Refresh, do not archive
KYC done once is a snapshot of a moment:
- GSTIN registrations get suspended and cancelled
- Companies fall behind on filings and get struck off
- Authorised signatories leave
- MSME classification changes as a business grows
For any ongoing supplier relationship, re-check registration status annually, and re-check signatory authority whenever the person you deal with changes.
Common mistakes
Treating KYC as onboarding-only. The risk does not stop at onboarding.
Storing documents without a retention policy. Indefinite retention of identity documents is a breach waiting to have consequences.
Skipping KYC for small suppliers. Payment fraud does not scale with supplier size.
Accepting a screenshot. A screenshot of a verified document is an upload again.
How this works on Bidancer
Verification is a precondition of participation rather than a badge some profiles carry. Businesses complete entity KYC — PAN, GSTIN, incorporation documents, authorised-signatory evidence — and individuals verify through DigiLocker or Aadhaar-based flows, before they can transact at all.
Because it happens at the platform level, a buyer is not repeating this work for every supplier and a supplier is not submitting the same documents to every buyer.
See the verification guide.
All guides
Step-by-step guides to running B2B procurement in India — floating a tender, verifying a supplier, and getting a franchise or trade show off the ground.
Choose a marketplace
Nine questions that separate marketplaces by what they actually do — who verifies whom, who owns the lead, who takes a cut, and what happens when it fails.