Skip to content
VetThisVendor

Knowing when a supplier’s status changes

By Published

Every check on this site — and every check anywhere else — answers a question about the day you asked it. A VAT number that was registered in March can be deregistered in September. A company that was trading last quarter can be in liquidation this one. Nothing about the first check tells you when that happened, and nobody sends you a letter.

For a supplier you pay once, that does not matter. For one you pay monthly on standing terms, the gap between “we checked them when we onboarded them” and “we know what they are today” can be years. Supplier Watch re-checks a supplier you have already checked and emails you only when something changes.

What actually changes, and which changes matter

Four things move often enough to be worth watching, and they are the four that change what you should do:

A VAT registration ends. The supplier deregistered, was struck off by the tax authority, or restructured into a different entity. Invoices carrying the old number are no longer valid for deduction, and continuing to pay them on the old terms is a problem that surfaces at audit rather than at payment.

A company enters liquidation, insolvency or is struck off. Where a national register publishes this, it is the clearest signal that payment terms are about to become somebody else’s problem. Prepaying a supplier in liquidation is money in the creditors’ pool.

A name reaches a sanctions list. Rare, and consequential in a way the others are not: paying a sanctioned party is a criminal matter in most jurisdictions, not a tax inconvenience. A designation can land overnight and applies immediately.

A Polish bank account leaves the white list. Poland is the only country in the EU that publishes which accounts a business has declared, and membership is a property of a particular day. An account listed in June and absent in July changes what happens if you pay it — see the Polish white list.

A fifth is worth mentioning and is weaker: a sending domain weakens its email authentication, or stops publishing mail servers. That does not mean anything is wrong. It means mail claiming to come from that domain is easier to forge than it was, which is context for the next payment request you receive from them.

The rule that makes monitoring useful: alert on change, not on state

This is the part most monitoring gets wrong, and it is the difference between a system you read and one you filter into a folder.

A supplier whose VAT number has been invalid for a year is not news. It was not news last month either, and it will not be news next month. If a monitor emails you about the current state on a schedule, you receive the same message about the same supplier indefinitely — and the entirely rational response is to stop reading messages from that sender. Then the one that mattered arrives, and goes with the rest.

So the thing worth being told is the transition: this was valid last time and is not now. Silence should mean “nothing moved”, and it should be the normal case.

Three consequences follow, and they are easy to get wrong:

Doing it without a tool

This is entirely possible by hand, and for a small supplier list it is reasonable.

  1. Keep the identifiers, not the verdict — the VAT number, the registered name, the sending domain, and for Polish suppliers the NIP and account number. A stored “passed” from eighteen months ago is worth nothing; the identifiers let you ask again.
  2. Re-run the checks on a schedule that matches your exposure. Quarterly is defensible for most trading relationships. Monthly is sensible above a threshold you set yourself.
  3. Record the previous answer, so you are comparing rather than re-reading. This is the step that makes it monitoring instead of repetition.
  4. Re-check on the events that actually predict trouble, whatever the schedule says: a change of bank details, a change of contact, an unexpected jump in invoice value, or a first invoice after a long quiet period.

Spread the work across the month rather than doing it all on the 1st. Public registries are free services with rate limits, and a burst is the thing most likely to be refused.

What monitoring cannot catch

The most common invoice fraud produces no change in any register at all.

The usual attack is a real supplier whose mailbox was compromised. Their VAT number is still valid, their company is still trading, their domain still authenticates, their name is on no list. Every check passes, before and after, because nothing about the supplier changed — only the bank details on one invoice did.

No monitoring service will tell you about that, and one that implies it will is selling something. The control that catches it is the same one every result page here ends with: a voice call to a number you already had, before you change how you pay somebody. There is a walkthrough in a supplier emailed asking to change their bank details, and if the request came by email, what “dkim=pass” really means covers why the message authenticating proves less than it looks like it does.

Monitoring is for the slower failures — the deregistration, the liquidation, the designation — that nobody tells you about and that are genuinely invisible until you look again.

Run a vendor check →Registry, IBAN, EU sanctions and sending domain, in one pass. Free, no signup.

Supplier Watch →Re-checks a supplier you have already checked, and emails you only when something changes — a VAT registration ending, a company entering liquidation, a name reaching a sanctions list, a Polish account leaving the white list. Nothing arrives while everything is unchanged.