Ten years ago, "vendor due diligence" mostly meant checking a trade license was current and a reference or two checked out. Today, especially for organizations operating in or from the GCC, it increasingly means something closer to what banks do for customers: screening the vendor and the people behind it against sanctions lists, politically exposed persons (PEP) registers, and adverse media. If that shift feels like it came out of nowhere for your procurement team, you're not alone — but it's not going away, and understanding what it actually involves makes it far less daunting.
Part of what makes this feel unfamiliar is that screening terminology arrived in procurement fully formed from the banking and compliance world, complete with its own acronyms and assumptions about what teams already know. Most procurement professionals didn't train in AML compliance, and reasonably expect a plain explanation of what's actually being checked, why, and what to do when something comes back flagged — which is exactly what this guide sets out to provide.
Why Vendors Get Screened Like Counterparties Now
Anti-money laundering obligations have traditionally sat with financial institutions and regulated businesses dealing directly with money movement. But regulators across the GCC and globally have steadily widened the net of who's expected to know their counterparties — and a vendor relationship is a counterparty relationship. Money flows to a supplier the same way it flows to a customer; the risk of it flowing to a sanctioned entity, a shell company, or someone using a legitimate-looking business as cover doesn't disappear just because the relationship is framed as "procurement" rather than "banking."
For enterprises operating in regulated sectors — real estate, construction, financial services, government-adjacent work — vendor screening has moved from "good practice" to something auditors and regulators actively expect to see evidence of.
What AML and Sanctions Screening Actually Checks
Sanctions list screening
This checks the vendor's legal name, and typically the names of its beneficial owners and directors, against government and international sanctions lists (such as those maintained by the UN, OFAC, and UAE authorities). A match doesn't automatically mean the vendor is sanctioned — common names produce false positives constantly — but every match needs a human review to confirm or dismiss it.
Politically Exposed Persons (PEP) screening
This flags whether a vendor's owners or senior officers hold or have held prominent public positions, or are closely associated with someone who does. A PEP match isn't disqualifying by itself — it usually just means the relationship gets enhanced due diligence rather than standard review.
Adverse media screening
This searches for negative news associated with the vendor or its principals — fraud allegations, regulatory action, litigation, criminal proceedings. It's inherently noisier than list-based screening (name collisions are common), which is why it's usually presented as a set of flags for a reviewer to triage rather than a pass/fail result. Good adverse media tooling also timestamps and sources each result, so a reviewer can quickly judge how recent and how credible a given finding is, rather than treating every headline with equal weight.
Building Screening Into Onboarding Without Stalling Procurement
The biggest practical risk with vendor screening isn't missing a real hit — it's building a process so slow or so manual that procurement teams route around it under deadline pressure. A few principles help:
Screen early, not at the end
Running screening as the very last step before approval means any issue discovered forces a restart of a process that's already consumed weeks. Running it early — ideally as part of initial vendor profile creation — means issues surface while there's still room to make a different decision.
Separate "flagged" from "blocked"
Most screening hits are false positives or require context, not automatic rejection. A workflow that routes every hit to a human reviewer with the context needed to make a fast decision works better than one that either blocks everything or, worse, gets silently ignored because it blocks too much.
Re-screen periodically, not just at onboarding
A vendor that cleared screening two years ago isn't guaranteed to still clear it today — ownership changes, new sanctions get issued, adverse media accumulates. Continuous or periodic re-screening (even quarterly) catches what a one-time check at onboarding misses.
Keep an audit trail of every decision
When a screening hit comes back, whatever decision gets made — cleared, escalated, rejected — should be recorded with who made it and why. This is both good governance and the difference between a five-minute audit and a week-long reconstruction exercise later.
What This Looks Like in Practice
Vendoreye runs AML, sanctions and adverse-media screening as part of the vendor qualification flow, so it happens automatically as vendors are onboarded rather than as a separate manual step someone has to remember to run. This also means the screening record — what was checked, when, and what came back — lives attached to the vendor's permanent profile rather than in a separate system that has to be reconciled with procurement records after the fact, which is usually where audit trails quietly fall apart. Flagged results surface directly on the vendor's review page alongside their documents and qualification score, so a reviewer has full context in one place rather than juggling a separate screening report. You can see how this fits into the broader review process in our vendor onboarding checklist, or read more about the platform's compliance posture on the security page.
Common Pitfalls
- Screening only the company, not the individuals behind it. Sanctions and PEP status attach to people, and beneficial ownership is often where the real risk hides.
- Treating every hit as a rejection. This trains teams to either over-block or, more dangerously, to stop taking the process seriously.
- One-time screening with no re-check. Risk isn't static; neither should your screening cadence be.
- No documented rationale for cleared hits. "We checked, it was fine" isn't an audit trail.
How Screening Results Should Change a Procurement Decision
Not every vendor decision is binary approve-or-reject, and screening results shouldn't force it to be. A useful way to think about outcomes:
- Clear across all checks — proceed through normal approval.
- Minor, resolved flag (a false-positive name match, dismissed with documentation) — proceed, with the review recorded.
- Genuine but low-severity flag (dated adverse media, a minor historical PEP connection) — proceed with enhanced monitoring, such as more frequent re-screening or a lower initial contract value.
- Serious or unresolved flag (an active sanctions match, an unexplained ownership link to a sanctioned entity) — escalate to compliance or legal before any further procurement action.
Building this kind of graduated response into policy — rather than leaving each reviewer to improvise — is what keeps screening from becoming either a rubber stamp or an unpredictable bottleneck depending on who's reviewing that day.
Who Should Own Vendor Screening?
In smaller organizations, procurement often ends up owning screening by default, simply because they're the ones onboarding vendors. In larger, more regulated organizations, it's more common for compliance or risk teams to own the screening policy and thresholds, while procurement executes the actual checks as part of onboarding. Neither model is inherently right, but the ownership needs to be explicit — screening that's "everyone's responsibility" in theory tends to be no one's responsibility in practice, and gaps only surface during an audit or, worse, after an incident.
Measuring Whether Your Screening Process Is Actually Working
It's worth periodically asking a few unglamorous questions about your own process, rather than assuming that having a screening step means the risk is handled: How long does screening typically take from initiation to a documented decision? What proportion of flagged results get resolved within a set number of business days versus sitting open indefinitely? Are re-screening cycles for existing vendors actually happening on schedule, or has that slipped once the initial rollout enthusiasm faded? None of these questions have a universally "right" answer, but a team that can't answer them at all likely has a screening process that exists on paper more than in practice.
Screening at Scale: What Changes as Your Vendor Base Grows
A team managing thirty vendors can plausibly run screening manually — a person, a screening tool's web interface, a spreadsheet to track outcomes. A team managing three hundred vendors, or one adding new vendors weekly through an active intake pipeline, hits a different problem: manual screening doesn't scale linearly. The review burden grows with the vendor count, but the number of people available to review flagged results usually doesn't grow at the same pace. This is typically the point at which organizations start looking for screening that's embedded directly into the onboarding workflow — triggered automatically when a vendor profile is created, rather than run as a separate manual step someone has to remember to initiate for every new vendor. It's less about any single check being hard to perform and more about consistency: a manual process run by busy people, under deadline pressure, tends to degrade quietly over time until an audit reveals how many vendors were actually never screened at all.
Vendor screening isn't about assuming the worst of your suppliers — most vendors clear without incident. It's about being able to demonstrate, quickly and with evidence, that you looked.