
When public or company money is at stake, the integrity of procurement depends on knowing exactly who you are contracting with. Vendor verification, the process of confirming a supplier’s identity, ownership, tax and company status, banking details and track record, is not an optional administrative nicety. It is a frontline fraud prevention control. South Africa’s recent procurement scandals and the findings of major public inquiries make this plain: where verification was weak or ignored, corrupt actors found opportunities to profit and public services suffered.
Why vendor verification matters
- Prevents impersonation and fronting: Verifying identity and beneficial ownership uncovers shell companies and fronting arrangements that mask the real beneficiaries of contracts.
- Ensures financial integrity: Bank account validation and tax compliance confirmation reduce the risk of payments to fraudulent/compromised accounts.
- Confirms capability: Checking past performance, references and capacity prevents contracts from being awarded to vendors unable to deliver.
- Meets legal and governance obligations: Due diligence supports auditability and compliance, as well as providing evidence for disciplinary or criminal action if needed.
South Africa’s public inquiries and special investigations over the past decade provide stark examples of what can go wrong when verification lapses.
- State Capture and the Zondo Commission: The Judicial Commission of Inquiry into Allegations of State Capture (the Zondo Commission) documented systemic procurement manipulation in which politically connected companies (including entities associated with Bosasa and Oakkbay/ Gupta interests) benefited from state contracts. A recurring theme in the findings was the deliberate use of front companies, opaque ownership structures and manipulated tender processes, situations that rigorous vendor verification would have exposed. The Commission’s reports repeatedly recommended strengthened due diligence and transparency in supplier records to prevent repeat abuses.
- COVID19 PPE procurement investigations (SIU and Auditor General reports): During the pandemic emergency, numerous public bodies awarded urgent PPE and health-related contracts. Subsequent Special Investigating Unit (SIU) probes and Auditor General reports identified inflated prices, non-delivery, payments to vendors with inadequate credentials, and instances where procurement rules were circumvented. The SIU’s investigations highlighted how the lack of thorough verification, fast-tracked awards without full checks on company status, tax clearance, bank accounts and supply histories, created openings for fraudulent suppliers to receive large public payments.
- More recently, the Madlanga Commission, the judicial inquiry into criminality, political interference and corruption in South Africa’s criminal justice system, has exposed extensive allegations of procurement manipulation and tender fraud, showing prima facie evidence that senior officials, politicians and private suppliers colluded to capture contracts and divert public funds. The hearings have detailed how tenders were allegedly rigged through front companies, manipulated evaluation records (including backdating minutes and recomputing score sheets), and the channelling of large security and service contracts to a network of linked firms, for example testimony outlining roughly R2.9 billion in Tshwane metro security contracts spread across some 22 companies and concerns about a R360 million police related healthcare contract linked to businessman Vusimuzi “Cat” Matlala. The commission’s interim material has prompted calls for criminal and disciplinary probes of implicated officials and has highlighted clear failures in supplier vetting and vendor verification processes that created the openings for these abuses.
These cases are not isolated audits; they routinely flag irregular supplier records, improper invoice verification, and ambiguous beneficial ownership as recurrent weaknesses. The pattern is clear: absent robust vendor verification, even well-designed procurement systems remain vulnerable.
To translate lessons into protection, procurement functions should adopt a layered, risk-based verification protocol:
- Identity and registration checks
- Verify the supplier’s legal name and registration number against CIPC (Companies and Intellectual Property Commission) records.
- Confirm directors and company status (active/deregistered).
- Verify identification details for company directors through the Department of Home Affairs and request proof of residential addresses for verification purposes
- Beneficial ownership and BEE verification
- Determine beneficial owners and ultimate controllers (individuals with significant shareholdings or control), not just listed directors.
- Verify Broad-Based Black Economic Empowerment (B-BBEE) certificates.
- Tax and banking validation
- Verify the SARS tax clearance, eFiling status and confirm VAT registration if applicable.
- Validate banking details independently to prevent diversion to third-party accounts.
- Capability and performance checks
- Request and independently verify recent references, evidence of completed similar contracts, proof of equipment/stock and CVs of key personnel.
- For high-risk or high-value contracts, include site visits or third-party performance audits.
- Conflict of interest and disclosure
- Require disclosure of any relationships with public officials, councillors or procurement decision-makers and check against municipal registers and declaration forms.
- Ongoing monitoring and payment controls
- Reverify key vendor data periodically (annually or at contract renewal).
- Use segmented controls for payments: supplier account changes require in-person verification and written confirmation from a senior official. Implement approval thresholds and dual-signature requirements for large payments.
- Digital and third-party tools
- Leverage database and screening services that flag politically exposed persons (PEPs), sanctions lists and litigation history. Use public procurement portals that centralise supplier information and historical performance.
Independent verification must be mandated in any procurement policy, backed by training and audited regularly. Tender evaluation committees should be required to document verification evidence as part of the award record. Auditors and anti-corruption units must have access to supplier due diligence files.
Vendor verification is not paperwork for its own sake, it is a practical, proven line of defence against fraud, corruption and operational failure. South Africa’s public inquiries and investigations show exactly how weak verification enabled serious abuse of procurement systems. By applying a systematic, risk-based verification regime, from identity and ownership checks through tax and banking validation to ongoing monitoring, procurement officials can make tenders resilient to manipulation and restore public trust in how the government or private companies buy goods and services.
For procurement teams and boards, the operational takeaway is simple: tighten verification now, or risk repeating expensive lessons later.
