How to verify a supplier in India
A practical checklist for confirming a supplier is real, registered, solvent enough, and represented by the person you are talking to.
Supplier verification answers a narrower question than most people think. It does not tell you whether a supplier is good. It tells you whether they are real, identifiable, and accountable — that there is a legal entity behind the conversation which can be held to a contract.
That is a floor, not a recommendation. But without it, nothing else you assess means anything.
Start with the entity, not the website
A website proves someone bought a domain. Start with registrations, which are harder to fake because they are checkable against public registers.
1. PAN
Ask for the PAN and read the fourth character. It tells you the entity
type: C company, F firm or LLP, P individual. A "company" whose PAN reads P is
an individual trading under a business name. That is not disqualifying — plenty of good
suppliers are proprietorships — but you should know it, because it changes who you are
contracting with and what recourse you have.
2. GSTIN
Check the GSTIN properly:
- The format is valid and positions 3–12 match the PAN they gave you
- Status is Active, not suspended or cancelled
- The legal name matches the entity you are contracting with
- The state code matches where they claim to operate
A supplier invoicing you from a state they are not registered in is a real problem, not a paperwork detail. See GSTIN verification.
3. Incorporation, for companies
For a company or LLP, check the CIN and the MCA register. The CIN itself tells you the state, the year of incorporation and whether it is private or public. The register tells you something more useful: whether annual filings are current. A company several years behind on filings is telling you about its administration, and often about its finances.
4. MSME status
Ask whether they are registered under Udyam. This matters for your obligations, not theirs — payments to MSME suppliers carry statutory timelines, interest on delay, and disclosure requirements for companies. Better to know at onboarding than at audit.
Then verify the person
This is the check most often skipped, and the one that catches the most common B2B fraud: a real company, and a person who does not represent it.
- Who is signing, and in what capacity?
- What evidence exists that they can bind the entity — board resolution, partnership deed, power of attorney?
- Does their email domain match the company's, or is it a free mail account?
- Do the bank details belong to the entity's own registered name?
That last one deserves emphasis. Bank details in a name that differs from the legal entity is the single highest-risk signal in B2B payments. Invoice-redirection fraud works precisely by changing account details late in an otherwise legitimate relationship. Confirm bank changes through a channel you already trust — a phone number you had before the request, not one in the email asking for the change.
Then assess capability, separately
Registration is not capability. Once you know who they are:
- Ask for reference contracts of similar size and scope, and actually call them
- Visit, or ask for a video walkthrough of the facility, for anything manufactured
- Ask what their capacity is and what else is on their order book
- For services, ask who specifically will do the work, not who sold it
What verification cannot tell you
It cannot tell you they are solvent tomorrow, that they will deliver, or that they are dealing in good faith. A fully verified business can still fail you. Verification narrows the field to counterparties who can be identified and pursued — it does not predict behaviour.
That is why post-engagement signals matter: whether a supplier actually responded after agreeing to, whether previous counterparties would work with them again. See response score.
A practical order of operations
- Before serious conversation — PAN, GSTIN status, entity type. Ten minutes.
- Before sharing anything confidential — incorporation and filing status, authorised signatory.
- Before the first purchase order — bank details in the entity name, references called, MSME status recorded.
- Before every payment change — re-verify bank details out of band. Every time.
- Annually, for ongoing suppliers — GSTIN status and filings, because both change.
Common mistakes
Collecting documents without verifying them. An uploaded PDF is a file, not a verified fact.
Verifying once and never again. Registrations lapse. Companies get struck off.
Verifying the entity but not the signatory. The entity is usually real. The question is whether this person speaks for it.
Treating a purchase order as verification. It is a commitment made after the question should have been answered.
How this works on Bidancer
Every business completes KYC before it can transact — PAN, GSTIN, incorporation documents and authorised-signatory evidence, checked against the issuing sources rather than filed on receipt. Individuals verify through DigiLocker or Aadhaar-based flows.
The practical difference is that this happens once, at the platform level, rather than being repeated by every counterparty who deals with that business. When an enquiry arrives, the identity question is already settled and you are assessing capability and fit.
See the verification guide.