Industrialist Paper No. 16
Verification as Industrial Plumbing
By Andrew Kornuta • 9 min read
The promise of this series is to rebuild American manufacturing coordination by turning soft failure modes into hard control points that both generalists and builders can execute.
Picture the RFQ. It lands in the inbox, the drawing PDF looks clean, the STEP matches, the tolerance block is sane. Then the estimator pauses — and not because of anything in the package. The buyer is unknown, and the payment risk feels unpriced.
Claim (falsifiable): If supplier and buyer identity is captured as a verified, time stamped "identity packet" that is attached to every vendor master record and referenced by every RFQ and PO, then quote response rates to first time counterparties will rise and fraud driven vendor churn will fall, because "who are you" stops consuming the same cycle time as "can you make this part." By identity packet I mean a machine readable bundle of legal existence, location, sanctions screening, payment identity, and certification evidence, plus an audit trail showing when each check last passed. The vendor master record is the control point, and every RFQ and PO should link back to the same packet.
Move the trust checks out of the phone call
In custom work, trust starts as an identity problem long before it becomes a machining problem. When identity is uncertain, both sides reach for human conversation, because a call is the fastest way to test whether the details cohere: address, capability claims, payment expectations, who is actually going to sign the PO. That call is doing real work. It is an ad hoc risk model built out of tone, responsiveness, and institutional memory, and it exists because the system offers nothing durable in its place. You can see the failure in the artifact — an RFQ email thread that turns into a second work package, full of "who are you" questions that a vendor master record should have answered before anyone typed a word.
Verification becomes industrial plumbing when it gets boring, automatic, and hard to argue with. The inputs already exist in registries and documents: legal business name, physical address validation, taxpayer identity, bank account ownership, sanctions list screening, certification proofs. The output isn't a badge. It's a set of fields a buyer can rely on and a supplier can present without a sales pitch, each one tied to a timestamp and an evidence link. Government procurement runs this at scale by pushing vendors through structured identity requirements, including physical address validation and identifiers, and by treating entity data as a prerequisite to transact at all. SAM.gov's entity checklist is the shape of that plumbing: validated physical address, taxpayer identification, structured identifiers like CAGE or NCAGE.
What real procurement already demands
If you doubt that verification is already standard, look at what large buyers require before they will pay an invoice. A supplier onboarding form from a major industrial buyer is blunt about it — provide the required supplier setup information, keep the remit to name consistent, and get a W-9 or W-8 on file or payment will be delayed. That's not enterprise bureaucracy. It's a payment safety rail against vendor impersonation, misdirected funds, and AP disputes that never end. It is also why the vendor master record exists in ERP systems in the first place: a control surface for identity and payment, not a contact list. Skip it and the PO becomes the first moment anyone tries to reconcile who you are with where the money is going, which is the worst possible time to discover a mismatch.
Sanctions screening is the same kind of boring plumbing, and people still treat it like an optional checkbox. OFAC maintains multiple sanctions lists and warns explicitly that programs can change frequently, which is exactly why screening cannot be a one time event. I am not arguing that every job shop quote should turn into a compliance ceremony. I am arguing that the vendor master record needs an auditable "last screened" event that can be attached to an RFQ and later to a PO. In a weak identity environment, sanctions risk gets handled the way payment risk gets handled — relationships and familiarity — and familiarity is not a filter. The artifact is a sanctions list search record tied to the legal business name and address, time stamped, sitting alongside the supplier profile.
Fraud and risk are not edge cases
Fraud is not a rare anomaly that only catches the careless. The ACFE's 2024 Report to the Nations press release summarizes an estimate that organizations lose 5% of revenue to fraud each year, based on 1,921 investigated cases across 138 countries and territories. Procurement fraud and vendor impersonation are only one slice of that picture, but they matter out of proportion to their size because they poison the channel. One bad vendor event changes sourcing behavior for years. Burned buyers overfit — they narrow sourcing to a small circle and demand more manual gates. Burned suppliers stop quoting new logos after a nonpayment or a chargeback. And the record of it, after the fact, is a vendor change log in the ERP full of rushed "deactivate vendor" actions with almost no structured evidence about what actually failed.
PwC's 2024 Global Economic Crime Survey supplies the other half of the picture: procurement fraud is widely perceived as a serious concern, and many organizations still do not run mature third party risk programs or risk scoring. Their published key findings include that 55% report procurement fraud is a widespread concern in their country, and 42% either lack a third party risk management program or do not do any risk scoring within it. That gap is precisely where vibes and informal relationship gates expand to fill the vacuum, because people will always invent a verification layer when formal signals are absent. What should exist and usually doesn't is a third party risk record attached to the vendor master file, with a clear risk score, evidence links, and renewal dates.
The uncomfortable truth about relationship-driven commerce
In my experience, shops want to call and "get to know you." That isn't a cultural quirk. It's a rational response to asymmetric risk. A supplier can burn days quoting from a perfect RFQ package and still lose money if the buyer is slow pay, disputes quality opportunistically, or turns out to lack authority to issue the PO. A buyer can place a PO with a supplier whose website looks legitimate and get a no show, a bait and switch, or a capability mismatch that only surfaces at first article inspection and the CMM report. In that environment a phone call is a cheap probe for hidden variables, and the relationship stands in for the identity packet nobody built. The artifact that proves the point is the quiet "no quote" status in the RFQ system on jobs where the drawing package was complete. The missing input was counterparty confidence, not geometry.
And yet the data does not support the idea that B2B buyers universally want to live on the phone. Gartner reported in 2025 that 61% of B2B buyers prefer a representative-free buying experience, and that most prefer to carry out independent research through digital channels. McKinsey's survey work points the same way — strong willingness for remote and self-serve purchasing, including at large order values — while still acknowledging that buyers lean toward in person interaction when a purchase is high effort or when they are working with new suppliers. Both things are true at once, and the synthesis matters: relationships remain important at the moment of risk, and buyers also want systems that let them progress without friction until a human adds real value. So the flow to design around is the RFQ intake and supplier selection path, with a verified self-serve lane and an explicit "human handshake" lane for high risk work, and no requirement to schedule a call just to answer identity questions.
Industrial supply pricing opacity belongs to the same story. When prices are negotiated, availability is volatile, and credit matters, vendors protect themselves by keeping pricing behind a relationship — because the relationship also carries payment terms, returns behavior, and how disputes get resolved. McKinsey's work on industrial distribution describes how digital entrants increase pricing transparency and therefore negotiating power, while also noting that dedicated sales forces still play important roles for many customers. "Call for price" usually means "we are still doing verification and risk pricing in conversation." It rarely means "we hate the internet." What closes the loop is a quote history ledger tied to a verified buyer identity, so pricing and terms can stay contextual without staying opaque.
Implications
Make verification cheap and portable and markets widen without becoming reckless. More buyers will test new suppliers, because the first gate is factual instead of social. More suppliers will quote first time buyers, because payment identity and dispute history become legible at the RFQ stage instead of after the invoice. That fits what part buyer surveys report about trying new vendors and about caring for certifications and response speed, since experimentation requires confidence and fast feedback loops. Leave identity weak and you get the opposite: buyers hoarding work inside a small network, suppliers reserving attention for known accounts, and a public market that is a thin layer of marketing websites with little transactional truth underneath. If you want one number that tells you which way a network is heading, use the share of RFQs awarded to first time suppliers, tied to verified identity fields and quote response timestamps.
Verification also protects legitimate small shops, but only if it stays proportional. Demand the paperwork burden of a defense prime vendor onboarding process and you will exclude the long tail, and that exclusion will look like risk reduction while it quietly removes capacity and competition. The shape I would build is a ladder. Baseline identity, address validation, and sanctions screening run automatically. Deeper artifacts — ISO certs, special process approvals, on site audits — get pulled only when the RFQ requires them. Underneath sits a verification policy table that maps RFQ attributes to required evidence and logs every decision as an audit trail event the RFQ record can reference.
In practice, a coordination layer maintains the vendor master record that stores the identity packet, runs periodic re checks on address, sanctions, and certificate expiration, and attaches a compact evidence summary to every RFQ and PO — so humans spend their calls on exceptions instead of on basic legitimacy.
Outro
Industrial sovereignty depends on throughput, and throughput depends on trust that moves at machine speed. Leave identity ambiguous and the practical failure mode is distrust, and distrust becomes misallocation: fewer quotes, fewer new suppliers, more work trapped inside legacy relationships that stopped earning their premium years ago. Verification is not glamorous. It is the pipe that keeps the marketplace from filling with noise and fraud while keeping honest capacity visible.
Next I go past "are you real" and into "do you perform," where reputation, dispute closure codes, and inspection artifacts become the second layer of the same plumbing.
Questions to Ask
- Where, exactly, does identity live today — in the vendor master record, the RFQ system, email threads, or the memories of two people on the phone — and which artifact is treated as the source of truth?
- For every RFQ package, what identity fields are required before it is routed, and what percent of "no quote" outcomes are actually caused by missing counterparty confidence rather than missing technical data?
- Which checks are one time (legal existence) versus recurring (sanctions screening, address validity, certificate expiration), and where are the timestamps stored so an auditor can reconstruct the decision path from RFQ to PO?
- What is your minimum acceptable "identity packet" for a first transaction, and how many minutes of human time does it currently take to assemble it from W-9, COI, registry lookups, and email follow ups?
- When a vendor event goes wrong, what fields in the vendor master record change, what closure codes get written (fraud, nonpayment, misrepresentation), and how does that evidence propagate to future routing decisions?