← Kelroy James
OSINT Supplier Verification
Method note Third-party due diligence Open sources only

Verifying a supplier who is telling you the truth about the wrong things

A seven-stage open-source verification sequence for the case where a supplier's paperwork is complete, its certifications are valid, and something about the relationship has stopped adding up.

Most third-party risk processes are built to catch a supplier who fails to produce evidence. They are much weaker against a supplier who produces all of it.

A completed questionnaire and a valid certificate each establish something real, within a defined scope. Neither establishes that the operation described in them exists in the place it claims to, is run by the people named on it, or is financially able to do the thing you are buying.

This sequence exists for the gap between those two positions. It runs in a deliberate order, because each stage narrows what the next one has to look for: corporate identity establishes who you are actually dealing with, geography tests whether the operation is where it says it is, and the financial and documentary stages test whether it can do what it has promised. Running them out of order produces a pile of findings rather than a line of reasoning.

Every stage below draws on publicly available sources. Roughly nine in ten useful facts in a corporate intelligence picture are already public; the discipline is in ordering them, not in obtaining them.

The sequence

Seven stages — order matters
01

Corporate structure

Establish baseline legitimacy before looking for discrepancies.

  • Confirm registration status and incorporation date against the statutory register
  • Identify every director and person of significant control
  • Read the filing history for lateness, resignations and recent restructuring
  • Cross-reference the registered office against the trading address given to you
  • Check that recorded activity codes match what the supplier says it does
Sources
Companies HouseOpenCorporatesCompany Check
Output

Registration verification with full filing and officer history. The authoritative baseline everything later is measured against.

02

Address and physical presence

Test whether the operation exists where it claims to exist.

  • Compare the registered office, the trading address and the address on correspondence
  • Assess physical existence through historical street imagery rather than current imagery alone
  • Check how many other businesses are registered at the same address
  • Verify business rates registration with the local authority
  • Examine property ownership records for the site
Sources
Land Registry192.comStreet imagery (historical)Rates register
Output

Location assessment recording what is verifiable, what is not, and the difference between the two.

03

Directors and officers

Establish that the people representing the company are the people who control it.

  • Map every director and controller against the contacts you have actually dealt with
  • Verify professional history and any claimed credentials or registrations
  • Map other directorships and company affiliations for concentration and conflict
  • Assess online presence for consistency with the professional history claimed
  • Record where claimed personnel and verified personnel do not overlap
Sources
Director searchOpenCorporatesProfessional registersLinkedIn
Output

Relationship map showing who controls the entity and how they connect to other interests.

04

Digital infrastructure

Where the systems actually sit, as distinct from where the letterhead says.

  • Registration records and name server distribution for every associated domain
  • Hosting geography, certificate detail and platform from technical infrastructure lookups
  • Historical site captures, to detect changes in claims over time
  • Message header routing and originating addresses across the correspondence you hold
  • Sender authentication records, and number type and carrier geography for stated contact numbers
Sources
WHOISDNS lookupsShodanWayback MachineHeader analysisNumber lookup
Output

Infrastructure picture mapping where systems, mail and telephony physically resolve, against the geography claimed.

05

Documentary authenticity

Test the documents themselves, not only the facts they assert.

  • Validate format and security features against the issuing authority's current template
  • Check temporal consistency across issue dates, expiry dates and stated history
  • Read file metadata on any digital copy for creation date and origin
  • Cross-reference document content against the corporate record already established
Sources
Issuing-authority templatesMetadata inspectionDocument verification services
Output

Authenticity assessment for each document received, with any inconsistency described rather than characterised.

06

Financial capability

Whether the supplier can sustain the obligation, not only whether it wants to.

  • Filed accounts, and whether filing has been timely and consistent
  • Credit history and payment behaviour toward other counterparties
  • County court judgments and other registered financial events
  • Indicators of stress: late payment, charges, changes in banking arrangements
  • Scale of the obligation you are placing against the balance sheet carrying it
Sources
Filed accountsCredit referenceCCJ registry
Output

Financial risk assessment stating capability and fragility separately. A solvent supplier can still be a single point of failure.

07

Synthesis

Build the hypothesis, then try to break it.

  • Consolidate findings across all six preceding stages onto one timeline
  • Identify correlations, and just as deliberately identify where stages agree
  • Form an explicit hypothesis about how the supplier actually operates
  • Test that hypothesis against the evidence that would disconfirm it
  • Grade each finding by confidence and record what would change the grade
Sources
Relationship mappingTimeline analysisOSINT Framework
Output

A graded assessment with a stated hypothesis, the evidence for it, and the evidence that would overturn it.

Grading a finding

Before it reaches a decision
Corroborated

Two independent sources

Confirmed against sources that do not derive from each other. Safe to carry into a recommendation, with the sources named.

Indicative

Single source, consistent

One reliable source, not contradicted elsewhere. Directs further enquiry. Does not on its own support an adverse conclusion.

Unresolved

Absence, or conflict

Sources disagree, or expected evidence is missing. Recorded as an open question. Absence of evidence is reported as absence, never as a finding.

The constraints this runs under

Set before collection begins

Purpose defined first

The question being answered is written down before any collection starts. Collection without a stated purpose becomes surveillance of a commercial counterparty, and produces findings nobody can act on.

Public sources only

Publicly available information, accessed as any member of the public would. No circumvention of access controls, consistent with the Computer Misuse Act.

Proportionate to the risk

Depth matched to the value and criticality of what is being bought. A commodity supplier does not warrant stage seven; a sole-source critical component supplier warrants all of it.

Personal data minimised

Individuals appear only where their role in the entity makes them relevant, under UK GDPR. The subject is the company. Directors are in scope because they control it, not because they are findable.

Sources and dates recorded

Every finding carries its source and the date it was retrieved. Company records change; an assessment without dates cannot be reviewed, defended or repeated.

It directs, it does not replace

This is the layer that tells formal due diligence where to look. It is not a substitute for contractual assurance, audit rights, financial verification or, where relevant, export control screening.