Most Indian SMEs learn vendor due diligence the hard way — after a supplier defaults, delivers substandard goods, or turns out to have a fraudulent GST registration. A systematic pre-onboarding check takes 30 minutes but can prevent months of financial and legal headaches. Here is a practical checklist built for Indian business realities.
Why Vendor Due Diligence Matters for Indian SMEs
Indian SME businesses face vendor-related risks beyond simple quality issues:
- GST ITC reversal: If your vendor's GST returns are invalid, cancelled, or fraudulent, your Input Tax Credit claim will be denied — you bear the tax burden
- Section 43B(h) payment compliance: If your vendor is an MSME and you don't pay within 45 days, your payment becomes disallowed as a deduction
- Legal liability: Undocumented or inadequately verified vendors create audit risks and compliance gaps
- Supply chain disruption: Financial distress in a key vendor can halt your operations overnight
Step 1: Legal Registration Verification
| Check | How to Verify | What to Look For |
| GST Registration | GST portal: gst.gov.in → Search Taxpayer → Enter GSTIN | Status: Active. Registration date. Address matches what vendor claims. |
| Company Registration | MCA21 portal: mca.gov.in → Company Search | Active status. Directors' names. Date of incorporation. Filed returns (AOC-4, MGT-7). |
| PAN Verification | Income Tax portal: e-filing.incometax.gov.in → Verify PAN | PAN is valid and matches entity name. |
| MSME/Udyam Registration | udyamregistration.gov.in → Verify Udyam | Confirms MSME status for Section 43B(h) compliance planning. Category: Micro/Small/Medium. |
| IEC (for import/export vendors) | DGFT portal: dgft.gov.in | Valid Import Export Code if vendor deals in imported goods. |
Step 2: GST Compliance Health Check
A vendor's GST filing track record directly affects your ITC claims. Verify:
- GSTR-3B filing status: Check if the vendor has been filing returns regularly. Vendors with multiple "Not Filed" periods are a red flag — their supplies may not appear in your GSTR-2B, blocking ITC.
- GSTR-1 uploads: Vendor must upload invoices in GSTR-1 for them to appear in your GSTR-2B auto-populated ITC. If a vendor consistently delays or misfiles GSTR-1, your ITC is at risk.
- E-invoicing compliance: For vendors with turnover above ₹5 crore, e-invoicing (IRN generation) is mandatory. Invoices without IRN from mandatory e-invoice taxpayers may not qualify for ITC.
⚠ GSTR-2B is your safety net: Only claim ITC that appears in your GSTR-2B (auto-populated from your vendors' GSTR-1 filings). If a purchase is not in GSTR-2B, do NOT claim ITC — regardless of whether you hold the physical invoice. See our
GST ITC reconciliation guide.
Step 3: Financial Health Signals
For key vendors (above ₹5 lakh annual business), check basic financial health:
- Request last 2 years' audited financial statements (for partnership firms and companies; proprietorships may not have audits)
- Bank account verification: Penny drop or bank account verification API services (Razorpay, Cashfree, etc.) confirm the account details match the business name
- Credit bureau check: For significant vendors, CIBIL MSME Rank or Equifax Business Credit Report provides a creditworthiness signal
- Debtors vs creditors aging: Ask for a summary — a vendor with all receivables overdue by 90+ days may be in cash flow distress
Step 4: Operational Verification
- Site visit (for manufacturing/production vendors): Physical infrastructure should match the claimed capacity. A vendor claiming ₹50 lakh monthly production from a 200 sq.ft shop is a red flag.
- Reference checks: Ask for 2–3 existing customer references; call them and ask about delivery reliability, quality consistency, and payment dispute history.
- Insurance: Product liability or professional indemnity insurance for vendors whose failure could expose you to claims.
- ISO / Quality certifications: Verify certificate validity directly with the issuing body — many certificates are forged or expired.
Step 5: Contractual Protection
Even after due diligence, protect yourself contractually:
- Purchase Order with clear specifications, delivery timelines, and quality parameters
- Payment terms explicitly stating conditions for deductions/deductions for short delivery or quality defects
- Representations and warranties clause: vendor represents their GST registration is valid and they will file returns on time
- ITC indemnification: vendor indemnifies you for any ITC reversal caused by their GST non-compliance
- Dispute resolution mechanism (arbitration clause preferable to civil court for speed)
For MSME payment compliance under Section 43B(h), see our MSME compliance guide. For related party transactions and disclosures, see our related party guide.
Red Flags: When to Walk Away
- GST registration cancelled or suspended
- Company has "Strike Off" or "Under Liquidation" status on MCA
- Director on MCA's disqualified directors list
- Multiple GSTR-3B filings "Not Filed" in recent months
- No physical presence matching claimed business address
- Reluctance to share PAN, GSTIN, or bank account details
- Pricing significantly below market with vague explanations ("we have special arrangements")
- Pressure to pay advance without proper documentation
Frequently Asked Questions
How do I verify if a vendor's GST registration is genuine? ▼
Go to gst.gov.in, click 'Search Taxpayer,' and enter the vendor's GSTIN. The portal shows: legal name, trade name, registration date, state of registration, GSTIN status (Active/Cancelled/Suspended), and the type of taxpayer (Regular, Composition, etc.). Verify that the name on the portal matches the entity you're dealing with, the address matches what the vendor provided, and the status is 'Active.' For any GSTIN showing 'Cancelled' or 'Suspended,' do not conduct business without the vendor first resolving the issue with the GST department.
Is it mandatory to do vendor due diligence for all vendors? ▼
Not legally mandatory for most SMEs, but practically essential for vendors above certain financial thresholds. A risk-based approach works: Tier 1 (annual spend > ₹5 lakh): full due diligence — legal verification, GST check, financial health, site visit. Tier 2 (₹1-5 lakh): basic legal and GST verification. Tier 3 (below ₹1 lakh): basic GST registration check and bank account verification before first payment. Concentrate due diligence effort on vendors who are critical to operations (single-source suppliers) or involve significant advance payments.
What is the risk to my business if a vendor has invalid GST registration? ▼
If you purchase from a vendor with invalid or cancelled GST registration and claim ITC on those invoices, the GST department can disallow your ITC claim during audit — requiring you to pay back the tax plus interest (18% per annum) and potentially penalty. Additionally, if the vendor's GSTIN was fraudulent (fake registration), you may face inquiry for collusion. The practical protection: always verify GSTIN before the first invoice, and reconcile your GSTR-2B monthly to confirm ITC is actually appearing from each vendor's filing.