Identity and legal entity
The buyer establishes who they are contracting with and paying: registered legal name, registered address, company identifiers and tax registration. Consistency matters more than most suppliers expect. A name that differs slightly between the contract, the registration form and the invoice will be treated as a mismatch by an automated check, and the resulting hold is often communicated to nobody.
Bank verification
This is the most controlled step, and deliberately so. Payment fraud commonly takes the form of a plausible request to change bank details, so buyers verify through independent channels, sometimes by telephoning a number they sourced themselves, sometimes with a bank letter, sometimes with a test payment. Suppliers who press for speed here tend to slow the process, because pressure is a characteristic of the fraud the control is designed to detect.
Compliance documentation
The list varies by buyer and sector: insurance certificates, code of conduct acknowledgements, anti-bribery attestations, information security documentation, and sometimes financial statements. None of it is difficult to produce. Almost all of the delay comes from producing it one item at a time as each is requested.
Categorisation and terms
The supplier is assigned a category and payment terms in the vendor master. This is quietly important, because the category determines which approval path applies to future orders and which controls attach to them. A supplier miscategorised at registration will encounter friction on every subsequent transaction, and correcting it later is harder than getting it right once.