Are they legally who they claim to be?
Confirm the registered name, registration number, tax ID, and address against the official company registry in the supplier's country, then find out who ultimately owns and controls the business. Many supplier onboarding tools automate these lookups, but bank details deserve a human check: verify them by calling a number you already hold, never one printed on an invoice or sent by email. Altered bank details are a common route for payment fraud.
Can they afford to stay in business?
A supplier that fails mid-contract can cost far more than one that charges a little extra. Ask for recent financial statements and look at cash position, debt, and dependence on a single large customer. If a small private supplier does not publish accounts, ask for bank or trade references instead. Direction matters more than any single figure: a modest supplier that is improving can be safer than a large one that is deteriorating.
Can they deliver at your volume, not just the sample?
A good pilot batch tells you little about steady production. Ask about real capacity, current utilization, and lead times at your forecast volumes. For critical items, visit the site or arrange a virtual walkthrough; it often shows how the operation really runs.
How do they control quality?
A certificate such as ISO 9001, the international quality management standard, shows that a documented system exists. It does not prove the system works. Ask how defects are caught, who signs off a shipment, and what happens to a rejected batch.
What legal and sanctions exposure comes with them?
Screen the supplier, its owners, and its directors against national and international sanctions lists. Ask about anti-bribery controls too, particularly if the supplier will act on your behalf or deal with officials. In many jurisdictions a company can be held liable for bribes that third parties pay for it, so a supplier's shortcut can become your legal problem, and evidence of careful checks at onboarding often counts in your favor.
What data will they touch, and how is it protected?
Even a packaging supplier may see your forecasts, designs, or pricing. Ask what data they will access and who can see it. ISO/IEC 27001, the international information security standard, is a useful signal, but check that the certificate's scope covers the sites and systems that will actually handle your information.
Who are their suppliers?
Your supplier's suppliers are your risk too. Ask which inputs come from a single source, where those sources are located, and what happens if one fails. A supplier that cannot answer is not necessarily hiding anything, but you will have little visibility when disruption hits.
What happens when something goes wrong?
Ask for the business continuity plan and when it was last tested; ISO 22301 is the international standard for business continuity management. Also ask how fast they will tell you about a problem and who you call. Late bad news often does more damage than the bad news itself.
Do the commercial terms hold up after the first order?
Compare quotes on total cost, not unit price. Clarify payment terms, triggers for price reviews, warranty and liability limits. Check insurance cover against a realistic loss. Terms left vague at the start get negotiated later from a weaker position.
How do we exit if it does not work?
Agree exit terms before signing: notice period, return of tooling and data, ownership of stock, and support during transition. Nobody plans for a failed relationship, but a contract without an exit route hands the supplier all the leverage.