Vendor Onboarding Checklist
Legal and Compliance
Tag the vendor as supplier, 3PL/fulfillment, SaaS/data processor, marketing agency, or marketplace service. Risk tier drives downstream depth — a 3PL that touches inventory and customer addresses needs a deeper review than a Canva-style design tool.
Get the W-9 for US vendors or W-8BEN/W-8BEN-E for foreign vendors before the first payment, not at year-end. Missing TINs cause 1099 filing scrambles in January and 24% backup withholding exposure.
For 3PLs, manufacturers, and any vendor handling inventory: confirm general liability ($1M / $2M minimum), workers' comp, and product liability where applicable. Verify your company is named as additional insured and the certificate is current.
Route the master services agreement and mutual NDA through DocuSign or Ironclad. For suppliers, include MAP language, IP ownership of custom tooling, and exclusivity terms if relevant. Counter-signed copies live in the vendor folder, not just an inbox.
If the vendor produces or handles supplements, cosmetics, children's products, CBD, alcohol, or food: collect FDA registration, GCC/CPC certificates, MoCRA registration, lab test reports, or state shipping permits as applicable. Skipping this is how Amazon listings get suppressed at scale.
Financial Setup
Target Net 30 minimum for domestic suppliers; Net 60 for established factory relationships. Overseas suppliers typically require 30% deposit / 70% on BL copy or against shipping documents. Document early-pay discounts (2/10 Net 30) in the AP system.
Call the vendor at a number from the signed contract — not a number in the wire-instructions email — to confirm ACH/wire details. Vendor email compromise (BEC) attacks redirecting first payments are common; a 5-minute callback prevents a five-figure loss.
Create the vendor record in QuickBooks, NetSuite, Bill.com, or Ramp. Attach the W-9, COI, and signed MSA. Set the GL account, default expense category, and 1099 flag now — fixing 1099 flags in December for the prior tax year is painful.
Confirm where invoices are sent (AP email, Bill.com inbox, portal upload), required PO reference format, and three-way match expectations for inventory POs. For 3PLs, agree on monthly statement cadence so storage and pick-pack fees reconcile cleanly.
Operational Integration
3PLs and suppliers usually need a Shopify / NetSuite / Cin7 / SkuVault connection for inventory sync, order push, and tracking writeback. SaaS vendors may just need SSO. Marketing agencies often need ad-account access and analytics permissions only.
Use a Shopify dev store or NetSuite sandbox. Test order push, inventory sync, shipment writeback, and cancellation handling. Confirm SKU-to-vendor-SKU mapping; mismatches here cause overselling across channels on day one.
Map vendor SKU ↔ internal SKU ↔ Shopify variant ↔ Amazon ASIN/FNSKU. Set per-channel low-stock buffers so a single warehouse unit doesn't get sold simultaneously on Shopify and Amazon. Confirm sync cadence (real-time webhook vs. 15-minute poll).
Capture day-to-day contact, escalation contact, and after-hours contact for stockouts, shipping holds, or outages. Agree on response SLAs (4 hours for P1, next business day for P2) and the channel — Slack Connect, shared email alias, or vendor portal.
Walk through pick-pack standards, branded packaging inserts, gift-message handling, and the cutoff time for same-day ship. For Amazon SFP or Seller-Fulfilled orders, confirm carrier-rate shopping logic and on-time-shipment expectations.
Lock targets: on-time shipment rate (≥98%), order accuracy (≥99.5%), inbound receive turnaround (≤48 hrs for 3PLs), defect rate (≤1%). Set a monthly review on the calendar; KPIs without a recurring review get ignored.
Product and Quality Assurance
Tech pack for product, dieline for packaging, FNSKU label placement, polybag suffocation warning, tracking labels for children's products, and expiration formatting for consumables. Suppliers will follow whatever you document — and infer whatever you don't.
Receive and inspect the golden sample against the tech pack before authorizing bulk production. Approve in writing; this sample becomes the QC reference for every future PO.
Set AQL (commonly 2.5 major / 4.0 minor for general consumer goods) and decide who inspects — vendor self-inspection, third party (QIMA, AsiaInspection), or your own QC. Specify whether inspection is during production (DUPRO) or pre-shipment (PSI).
Document who pays for return freight, defect-rate threshold for chargebacks, replacement-vs-credit policy, and the RMA process for B-stock. For Amazon FBA-bound inventory, agree on prep responsibility for returns sent back as unfulfillable.
Data Security and Privacy
3PLs see names and shipping addresses; CX tools see emails and order history; subscription tools see card tokens. If the vendor never touches customer PII, the rest of this section is light. If they do, treat them as a sub-processor under GDPR/CCPA.
Request the current SOC 2 Type II report (under NDA) or ISO 27001 certificate. Skim exceptions and the bridge letter if the report is older than 6 months. For high-risk vendors, also request a recent pen-test summary.
If neither attestation exists, complete a security questionnaire (SIG Lite or your own) before granting production access.
Sign the data processing addendum with SCCs for any EU/UK data transfers. Add the vendor to your public sub-processor page (Klaviyo, Yotpo, Recharge, etc., expect this from you too) so customer disclosures stay current under GDPR Article 28.
Contract should require notification within 24-48 hours of confirmed incident — well inside the GDPR 72-hour window so you have time to prepare your own notification. Capture the vendor's security contact email and after-hours phone for incident response.
Activation and Sign-Off
For 3PLs: ship 5-10 live orders before flipping the full channel. For SaaS: enable for one team / one store before company-wide. Catches integration bugs, packing-slip typos, and tracking-writeback gaps while the blast radius is small.
Operations, finance, and (if applicable) security each confirm their sections are complete. The vendor record moves from Onboarding to Active in the AP and OMS systems. Schedule the first quarterly business review on the calendar.
Use this template in Manifestly
- Delivery Tracking Checklist
- Product Discontinuation Checklist
- E-commerce Fraud Prevention Checklist
- E-commerce Risk Management Checklist
- Social Media Marketing Checklist
- E-commerce Backup and Recovery Checklist
- E-commerce Legal Compliance Checklist
- E-commerce Sales Funnel Audit
- E-commerce Annual Budget Planning Checklist
- Inventory Replenishment Checklist
- Website Usability Audit Checklist
- Website Analytics Checklist
- Employee Onboarding Checklist
- Monthly Lead Generation Checklist
- Data Privacy Checklist
- Website Launch Checklist
- GDPR Compliance Checklist for E-commerce
- Ecommerce Customer Onboarding Checklist
- PPC Campaign Checklist
- E-commerce IT Security Checklist
- E-commerce Website Maintenance Checklist
- Sales Reporting Checklist
- Product Listing Update Checklist
- Security and Privacy Review Checklist
- International Shipping Checklist
- Payment Reconciliation Checklist
- PCI DSS Compliance Checklist
- Inventory Management Checklist
- Returns and Refunds Checklist
- Returns Processing Checklist
- Weekly Review Checklist for E-commerce Founders
- Order Fulfillment Checklist
- Payment Processing Checklist
- Return Authorization Checklist
- CRM Setup Checklist
- E-commerce Expense Management Checklist
- Live Chat Operations Checklist
- Daily Operations Checklist
- Website Security Checklist
- Product Launch Checklist
- Order Processing Checklist
- CRM Audit Checklist
- Email Marketing Campaign Checklist
- E-commerce Site Quality Assurance Checklist
- Affiliate Marketing Program Checklist
- Employee Exit Checklist
- Website Maintenance Checklist
- Payment Gateway Integration Checklist
- Warehouse Operations Checklist
- E-commerce Platform Update Checklist
- Customer Behavior Analysis Checklist
- E-commerce Financial Audit Checklist
- Shipping Carrier Selection Checklist
- Order Packaging Checklist
- E-commerce SEO Monthly Audit
- Monthly E-commerce Marketing Checklist
- Stock Level Monitoring Checklist
- Content Marketing Checklist
- Shipping and Delivery Checklist
- Employee Performance Review Checklist
- Customer Feedback Review Cycle
- E-commerce Sales Tax Reporting Checklist
- Customer Service Ticket Triage Checklist
- Vendor Contract Negotiation Checklist
- Vendor Setup and Maintenance Checklist
- Vendor Performance Evaluation Checklist
- Service Contract Renewal Checklist
- Vendor Onboarding Checklist
- Contractor Management Checklist
- New Vendor Onboarding Checklist
- Vendor Management Checklist
- Contract Review Checklist
- Contract Review Checklist
- IT Vendor Management Checklist
- Vendor Management Checklist
- Vendor Contract Review Checklist
- Supplier and Vendor Evaluation Checklist
- Supplier Onboarding Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
