Vendor Onboarding Checklist

Steps an e-commerce operations or finance lead runs to onboard a new vendor — supplier, 3PL, software/service provider, or marketplace partner — covering legal qualification, payment setup, systems integration, quality, and data security.

6 sections 25 steps Collects data
1

Legal and Compliance

  1. Classify the vendor type and risk tier
    • Tag the vendor as supplier, 3PL/fulfillment, SaaS/data processor, marketing agency, or marketplace service. Risk tier drives downstream depth — a 3PL that touches inventory and customer addresses needs a deeper review than a Canva-style design tool.

    Collects list Collects list
  2. Collect business license and W-9 / W-8
    • Get the W-9 for US vendors or W-8BEN/W-8BEN-E for foreign vendors before the first payment, not at year-end. Missing TINs cause 1099 filing scrambles in January and 24% backup withholding exposure.

    Collects file Collects text
  3. Verify Certificate of Insurance
    • For 3PLs, manufacturers, and any vendor handling inventory: confirm general liability ($1M / $2M minimum), workers' comp, and product liability where applicable. Verify your company is named as additional insured and the certificate is current.

    Collects file
  4. Execute MSA and NDA
    • Route the master services agreement and mutual NDA through DocuSign or Ironclad. For suppliers, include MAP language, IP ownership of custom tooling, and exclusivity terms if relevant. Counter-signed copies live in the vendor folder, not just an inbox.

  5. Confirm restricted-product compliance
    • If the vendor produces or handles supplements, cosmetics, children's products, CBD, alcohol, or food: collect FDA registration, GCC/CPC certificates, MoCRA registration, lab test reports, or state shipping permits as applicable. Skipping this is how Amazon listings get suppressed at scale.

2

Financial Setup

  1. Negotiate payment terms
    • Target Net 30 minimum for domestic suppliers; Net 60 for established factory relationships. Overseas suppliers typically require 30% deposit / 70% on BL copy or against shipping documents. Document early-pay discounts (2/10 Net 30) in the AP system.

    Collects list Collects list
  2. Verify bank details with a callback
    • Call the vendor at a number from the signed contract — not a number in the wire-instructions email — to confirm ACH/wire details. Vendor email compromise (BEC) attacks redirecting first payments are common; a 5-minute callback prevents a five-figure loss.

    Collects list
  3. Set up vendor in AP system
    • Create the vendor record in QuickBooks, NetSuite, Bill.com, or Ramp. Attach the W-9, COI, and signed MSA. Set the GL account, default expense category, and 1099 flag now — fixing 1099 flags in December for the prior tax year is painful.

  4. Document the invoicing process
    • Confirm where invoices are sent (AP email, Bill.com inbox, portal upload), required PO reference format, and three-way match expectations for inventory POs. For 3PLs, agree on monthly statement cadence so storage and pick-pack fees reconcile cleanly.

3

Operational Integration

  1. Decide whether systems integration is required
    • 3PLs and suppliers usually need a Shopify / NetSuite / Cin7 / SkuVault connection for inventory sync, order push, and tracking writeback. SaaS vendors may just need SSO. Marketing agencies often need ad-account access and analytics permissions only.

    Collects list
  2. Build and test the integration in sandbox
    • Use a Shopify dev store or NetSuite sandbox. Test order push, inventory sync, shipment writeback, and cancellation handling. Confirm SKU-to-vendor-SKU mapping; mismatches here cause overselling across channels on day one.

  3. Set up SKU mapping and inventory sync
    • Map vendor SKU ↔ internal SKU ↔ Shopify variant ↔ Amazon ASIN/FNSKU. Set per-channel low-stock buffers so a single warehouse unit doesn't get sold simultaneously on Shopify and Amazon. Confirm sync cadence (real-time webhook vs. 15-minute poll).

  4. Establish communication and escalation path
    • Capture day-to-day contact, escalation contact, and after-hours contact for stockouts, shipping holds, or outages. Agree on response SLAs (4 hours for P1, next business day for P2) and the channel — Slack Connect, shared email alias, or vendor portal.

  5. Train the vendor on order fulfillment SOP
    • Walk through pick-pack standards, branded packaging inserts, gift-message handling, and the cutoff time for same-day ship. For Amazon SFP or Seller-Fulfilled orders, confirm carrier-rate shopping logic and on-time-shipment expectations.

  6. Agree on KPIs and reporting cadence
    • Lock targets: on-time shipment rate (≥98%), order accuracy (≥99.5%), inbound receive turnaround (≤48 hrs for 3PLs), defect rate (≤1%). Set a monthly review on the calendar; KPIs without a recurring review get ignored.

4

Product and Quality Assurance

  1. Document product specs and packaging requirements
    • Tech pack for product, dieline for packaging, FNSKU label placement, polybag suffocation warning, tracking labels for children's products, and expiration formatting for consumables. Suppliers will follow whatever you document — and infer whatever you don't.

  2. Run pre-production sample inspection
    • Receive and inspect the golden sample against the tech pack before authorizing bulk production. Approve in writing; this sample becomes the QC reference for every future PO.

    Collects list
  3. Define QC and AQL standards for production runs
    • Set AQL (commonly 2.5 major / 4.0 minor for general consumer goods) and decide who inspects — vendor self-inspection, third party (QIMA, AsiaInspection), or your own QC. Specify whether inspection is during production (DUPRO) or pre-shipment (PSI).

  4. Set up returns and defect handling SOP
    • Document who pays for return freight, defect-rate threshold for chargebacks, replacement-vs-credit policy, and the RMA process for B-stock. For Amazon FBA-bound inventory, agree on prep responsibility for returns sent back as unfulfillable.

5

Data Security and Privacy

  1. Confirm whether the vendor processes customer data
    • 3PLs see names and shipping addresses; CX tools see emails and order history; subscription tools see card tokens. If the vendor never touches customer PII, the rest of this section is light. If they do, treat them as a sub-processor under GDPR/CCPA.

    Collects list
  2. Review SOC 2 / ISO 27001 attestation
    • Request the current SOC 2 Type II report (under NDA) or ISO 27001 certificate. Skim exceptions and the bridge letter if the report is older than 6 months. For high-risk vendors, also request a recent pen-test summary.

    • If neither attestation exists, complete a security questionnaire (SIG Lite or your own) before granting production access.

    Collects file
  3. Execute DPA and add to sub-processor list
    • Sign the data processing addendum with SCCs for any EU/UK data transfers. Add the vendor to your public sub-processor page (Klaviyo, Yotpo, Recharge, etc., expect this from you too) so customer disclosures stay current under GDPR Article 28.

  4. Confirm breach notification SLA
    • Contract should require notification within 24-48 hours of confirmed incident — well inside the GDPR 72-hour window so you have time to prepare your own notification. Capture the vendor's security contact email and after-hours phone for incident response.

6

Activation and Sign-Off

  1. Run a small pilot order or transaction
    • For 3PLs: ship 5-10 live orders before flipping the full channel. For SaaS: enable for one team / one store before company-wide. Catches integration bugs, packing-slip typos, and tracking-writeback gaps while the blast radius is small.

  2. Final onboarding sign-off
    • Operations, finance, and (if applicable) security each confirm their sections are complete. The vendor record moves from Onboarding to Active in the AP and OMS systems. Schedule the first quarterly business review on the calendar.

    Collects list Collects signature Collects paragraph

Use this template

Copy it to your account, customize the steps, and run it with your team in minutes.


Sections 6
Steps 25
Category E-commerce
Price Free to start
Need a different process

Browse hundreds of free templates across every team and industry.

Back to template library

Run Vendor Onboarding Checklist with your team

Customize the steps, assign roles, set a schedule, and keep a complete record for every run.