"We've always used this supplier" is one of the most reassuring sentences you'll hear in procurement, and simultaneously one of the most quietly dangerous, precisely because it sounds like a statement of confidence rather than a statement of accumulated, unexamined risk. It signals trust earned over years of reliable delivery — genuinely valuable, and not something to dismiss. But it also frequently signals a vendor relationship that predates whatever due diligence process the organization currently uses, one that's been grandfathered past every subsequent tightening of requirements simply because nobody ever went back and re-applied them.
Trust Is Real, and So Is the Blind Spot It Creates
None of this is an argument that long-tenured vendors are more likely to be problematic than new ones — in most cases, the opposite is probably true, since a vendor that's delivered reliably for years has demonstrated something a brand-new vendor simply hasn't had the chance to yet. The issue isn't the vendor's actual trustworthiness; it's that the evidence supporting that trust often predates the organization's current standards for what evidence should look like, and nobody has gone back to specifically close that particular, quietly accumulated gap.
How Legacy Vendors Escape Current Scrutiny
Due diligence requirements evolve — new document requirements get added, screening processes get introduced, approval workflows get more rigorous. Every one of these changes is typically applied to new vendors going forward. Existing vendors, especially long-standing ones already deeply embedded in day-to-day operations, are rarely retroactively subjected to the new standard once it's introduced. There's no single decision that causes this; it's simply that nobody's job is specifically "go back and re-verify all our existing vendors against current requirements," so it doesn't happen, indefinitely, until something forces the issue.
The result: a vendor onboarded eight years ago, under a process that required little more than a trade license copy and a handshake, can still be actively receiving purchase orders today without ever having been screened for sanctions, without a beneficial ownership declaration on file, without any of the due diligence a brand-new vendor in the same category would now be required to complete before their first invoice.
Why This Matters More Than It Might Seem
Long-standing, familiar vendors are very often among an organization's highest-spend relationships, precisely because tenure tends to correlate with expanded scope over time. This means the vendors most likely to be operating under outdated, minimal due diligence are frequently also the vendors where a problem would be most consequential — the opposite of where under-scrutiny should sit if risk were being managed deliberately rather than by historical accident.
Ownership can also change quietly over a long relationship without anyone on the customer side noticing. A vendor onboarded under one set of owners eight years ago may have been acquired, restructured, or changed hands since — and unless something specifically triggers a re-verification, that change can go entirely undetected by an organization that's continued paying invoices to what looks, on the surface, like the same familiar supplier.
Why Nobody Flags This Proactively
Raising the question "should we re-screen our long-standing vendors" tends to feel, internally, like questioning a relationship that's never given anyone a reason for concern — which makes it an easy conversation to avoid having. There's also a practical reality: re-verifying an entire existing vendor base is a real project, competing for time and attention against more urgent, more visible priorities. The combination of social awkwardness and competing priorities is exactly why this gap persists at most organizations indefinitely, rather than getting addressed in any single deliberate decision.
A Practical Approach to Closing the Gap
Start with a risk-based triage, not a blanket re-verification
Re-screening every existing vendor simultaneously is rarely realistic. Prioritizing by spend level, category risk, and time since last review turns an overwhelming project into a manageable, phased one — starting with the highest-spend, highest-risk legacy vendors first.
Frame the ask to vendors as routine, not exceptional
Vendors who've worked with an organization for years may reasonably wonder why they're suddenly being asked for documentation that was never required before. Framing this as a standard periodic review applied across the vendor base — not a signal of specific concern about them — reduces friction and avoids implying distrust where none is intended.
Build periodic re-verification into standard process going forward
The underlying fix isn't a one-time cleanup project; it's ensuring re-verification happens on a defined schedule for every vendor, including long-standing ones, so this gap doesn't simply reaccumulate over the next several years the same way it did the first time.
Make tenure visible as a data point, not just a feeling
Vendor records should make it easy to see how long a relationship has existed and when it was last actively reviewed — turning "we've always used them" from a vague institutional memory into a specific, checkable fact that can actually trigger a review when it's overdue.
How This Shows Up in Practice
Vendoreye tracks each vendor's onboarding date and last review date directly on their profile, and re-screening (AML, sanctions, adverse media, as covered in our guide to AML and sanctions screening) can be triggered for any vendor regardless of how long they've been active — meaning a legacy vendor onboarded years before the platform was even adopted goes through exactly the same current-standard screening as a vendor added yesterday. If your organization has vendors nobody can quite remember the original onboarding process for, that's usually a reliable sign they're overdue for a fresh look.
A Worked Example
Consider a logistics company that has used the same customs clearance agent for over a decade, onboarded long before any formal AML screening process existed at the organization. The relationship has been operationally flawless — on-time, responsive, never a quality complaint. When a new compliance lead eventually runs a standard screening pass across the full vendor base as part of a broader governance initiative, the agent's beneficial ownership structure reveals a shareholder who, unrelated to the customs business itself, was named in adverse media two years earlier connected to a separate venture under regulatory investigation. Nothing about the customs clearance relationship itself was ever a problem — but the organization had, unknowingly, been extending significant trust and payment to an entity connected to a genuinely relevant risk signal, simply because the relationship predated the screening process and was never retroactively subjected to it. This is precisely the scenario risk-based triage of legacy vendors exists to catch, and precisely the scenario "we've always used them" quietly allows to persist indefinitely.
The Cultural Dimension of This Problem
Beyond the practical mechanics of re-verification, there's a cultural dimension worth naming directly: long-tenured vendor relationships often develop genuine personal rapport between the vendor's team and the customer's procurement staff, built over years of working together. That rapport is valuable and shouldn't be treated as a liability — but it can make the people closest to a legacy vendor relationship the least inclined to raise the question of whether it's overdue for fresh scrutiny, precisely because doing so can feel like questioning a relationship they personally vouch for. This is one of the stronger arguments for making periodic re-verification a systematic, scheduled process rather than something that depends on any individual deciding, unprompted, to raise an uncomfortable question about a vendor they know well and like.
How to Prioritize a Legacy Vendor Review
When an organization decides to address this gap, the natural instinct is often to start with the vendors that feel most uncertain — the ones nobody quite remembers onboarding. That's a reasonable secondary signal, but the primary prioritization should be risk-weighted: total historical spend, category risk (physical site access, financial data access, regulated industries), and time elapsed since any documented review. A vendor that's been reviewed thoroughly within the last eighteen months, even if the relationship itself is old, is a lower priority than a vendor with no documented review at all, regardless of how comfortable and familiar that second relationship feels. Building this prioritization explicitly, rather than working through legacy vendors in whatever order feels intuitive, ensures the highest-risk gaps get closed first rather than last.
What a Reasonable Re-Verification Cadence Looks Like
Once the initial backlog of legacy vendors has been addressed, the ongoing question becomes how often re-verification should happen for every vendor, not just legacy ones. There's no single correct answer, but a tiered approach — annual review for high-spend or high-risk categories, a longer cycle (two to three years) for lower-risk, lower-spend relationships — is a reasonable default that most organizations can adapt to their own risk tolerance. The specific cadence matters less than the fact that one exists and is actually followed, rather than existing only as an aspiration nobody tracks against or holds anyone accountable to over time.
"We've always used this supplier" isn't a reason to distrust a vendor — it's a reason to make sure the trust is still resting on solid, current evidence that reflects your organization's actual present-day standards, not standards that quietly expired years ago.