VERITAS
Commodity Advisory
Verifying Integrity
Framework

Supplier Verification Standard

20 min read24 pages

This is the internal standard our analysts apply to every supplier verification engagement. It is a 10-point framework that covers the full spectrum of supplier risk — from legal existence to operational capacity to reputation. Each point is a gate: if a supplier fails any one of them, the engagement report flags it and the client decides how to proceed.

Point 1: Legal company existence

We confirm the supplier's registered legal name, registration number, and status against the official national registry. A company that does not exist in the registry, or has been deregistered, is an immediate fail. We also check for typo-squatting — entities using names close to legitimate companies.

Point 2: Ownership verification

We verify the ownership structure disclosed by the supplier against registry records. Discrepancies between claimed and registered ownership are flagged. In jurisdictions where ownership is not fully disclosable, we note the limitation and verify what is available.

Point 3: Beneficial ownership review

Where disclosable under local law, we identify the beneficial owners — the individuals who ultimately control or benefit from the entity. Beneficial ownership that is obscured, inconsistent, or links to sanctioned individuals is a significant red flag.

Point 4: Physical office verification

We confirm that the supplier has a real physical office at the address they claim. Virtual offices, shared addresses with unrelated companies, and addresses that do not exist on the ground are flagged. Where feasible, a local analyst visits the address.

Point 5: Operational capability assessment

We assess whether the supplier has the operational capacity to deliver what they claim. A company registered to trade gold but with no visible infrastructure, staff, or operating history is unlikely to be a credible exporter. We look for evidence of real operations, not just a registered shell.

Point 6: Mining licence verification

Where the supplier claims to mine, we verify the mining licence against the issuing authority. We check validity, scope, expiry, and whether the licence is issued to the entity we are dealing with. Borrowed licences — genuine permits belonging to a different entity — are a common fraud pattern.

Point 7: Export capability assessment

We verify that the supplier is authorised to export the commodity in question. Export permits are separate from mining licences and are the document most commonly forged. We check the permit against the issuing authority, confirm its scope covers the proposed transaction, and verify it is issued to the correct entity.

Point 8: Reputation review

We conduct a structured reputation review — searching for adverse media, litigation, regulatory actions, and industry references. A clean online footprint is not proof of legitimacy, but adverse findings are meaningful. We also check whether the supplier has been referenced in fraud reports or blacklist databases.

Point 9: Compliance checks

We screen the supplier and its disclosed beneficial owners against sanctions lists, PEP databases, and adverse media databases. Compliance failures at this stage create regulatory exposure for the buyer, not just commercial risk.

Point 10: Risk scoring

Each of the nine points above is scored. The aggregate score produces a risk rating — low, moderate, elevated, or high. The rating is accompanied by a narrative explaining the score, the specific findings that drove it, and a recommendation. The client uses this to make their commercial decision.

Key Takeaway

The 10-point standard is a gate-based framework. Each point is a check that, if failed, flags risk for the client. The aggregate score produces a risk rating that supports the client's go or no-go decision before capital is committed.