Florida Man InnovationsFarsight IntelligenceFederalServicesInsightsAboutBook a MeetingOpen an Inquiry
← Back To Main Blog

Due Diligence Has an Expiration Date

The vendor file you cleared eighteen months ago describes a company that no longer exists. The report was accurate the day it was written. It has been decaying every day since.

Corporate diligence gets treated as a gate. Run the checks, clear the counterparty, sign the agreement, close the file. A gate measures one thing well: the moment someone walked through it. It says nothing about who is standing inside the building now.

Ownership changes. Officers resign and get replaced by people who would have failed the original screen. A judgment gets entered in a county nobody thought to check. A UCC-1 appears against equipment the company swore it owned free and clear. None of it reaches you, because nobody is looking, because the file says cleared.

Every diligence report starts decaying the day it is issued

The aggregator databases behind most commercial background reports, TLO, IRB, Tracers, do not query courts in real time. They buy or harvest record sets and refresh them on their own schedule. In counties with mature e-filing the lag runs days. In counties still processing paper it runs weeks, and in a few it runs into months. A civil judgment entered in July can be genuinely invisible to a commercial report pulled in September, and the report will not warn you that it might be.

That gap is why a court-of-record pull and a database query are different products sold under the same name. One is a clerk confirming what is on the docket today. The other is a copy of what a vendor collected on some earlier date it usually will not disclose. Both are useful. Only one of them is current, and the price difference between them is the reason most programs quietly buy the wrong one.

Different fields also decay at different rates, which almost no program accounts for. Corporate registration status turns over on an annual cycle. Officers and registered agents change episodically, often quietly, often shortly before something else goes wrong. Liens, judgments, and new litigation accumulate continuously. Professional license status flips on a renewal date that has nothing to do with your contract date.

A single report captures all of that at one instant and presents every line with the same confidence. Twelve months later, part of it is still true and part of it is fiction. The document gives you no way to tell which is which.

The changes that matter happen after the contract is signed

During diligence a counterparty is on its best behavior and knows it is being watched. That is the least informative window in the entire relationship. The conduct that actually costs money comes from someone who already has access to your systems, your premises, your customer list, or your payments.

Consider what a stale file hides. A vendor pledges its receivables to a factoring company, your outstanding invoices included, and the only public evidence is a UCC-1 financing statement nobody went back to look for. Liens surface financial pressure well before the statements admit to it, and they keep doing that long after closing. Or the company misses the Florida annual report deadline on May 1, gets administratively dissolved that September, and keeps invoicing on an entity that no longer legally exists. Your contract now runs to a counterparty a court would have to reconstruct.

A signed agreement with a stale file behind it is not a managed relationship. It is an open position.

New litigation is the cheapest early warning available anywhere in the process. When three other customers sue the same vendor inside one quarter, they are telling you what is coming for you. That signal costs one docket check and expires quickly.

Most monitoring subscriptions watch the wrong things

Continuous monitoring, as the large screening vendors sell it, means adverse media alerts and sanctions name-matching. Both are tuned to fire. Name-only matching against a watchlist with no date of birth and no secondary identifier produces homonym hits all day, and adverse media screening finds the headline while missing the pattern underneath it. An analyst clears a hundred false positives, then clears the hundred and first without reading it.

Sanctions screening earns its keep when you have foreign counterparties, cross-border payments, or a regulator who will ask. For a domestic services firm buying from domestic vendors, it mostly generates work and a false sense of coverage.

The signals that actually predict loss are duller and structured. Registration status. Officer and registered agent changes. New UCC filings. Civil judgments and state tax warrants. License lapses. A principal address that quietly becomes a residence or a mail drop. Each has a specific source, a low false positive rate, and an unambiguous meaning when it moves. The standard corporate checklist already skips most of them at onboarding, and nobody goes back for them afterward.

Set the refresh interval by exposure, not by the calendar

Re-screening every counterparty on one annual cycle is how monitoring programs die. The cost lands all at once, the yield is mostly confirmation of nothing, and the first budget review kills it.

Tier by what the counterparty can do to you. Four questions settle it: how much you pay them, whether they hold or route funds, whether they hold credentialed system access or unescorted access to premises, and whether replacing them within 30 days is realistic. A vendor that fails one of those four belongs in the top tier no matter how small the invoice is.

Run the arithmetic before concluding it is unaffordable. A firm with 140 active vendors re-screening all of them at $350 a file spends $49,000 a year, and most of that money buys confirmation that the office cleaning company is still an office cleaning company.

Tier the same 140 and the shape changes. Twelve critical vendors on a quarterly refresh: 48 files, $16,800. Thirty important vendors annually: $10,500. The remaining 98 sit on automated registration and lien watch at a few dollars each per year, escalated to a full file only when something moves. Call it $28,000 for a program that concentrates attention where the exposure is instead of spreading it evenly across a list. The numbers are illustrative and your per-file cost will differ. The ratio holds.

Trigger events beat intervals

Scheduled refreshes catch drift. Triggers catch intent.

Six events should pull a file regardless of where it sits on the calendar. A change in payment instructions. A request for prepayment, accelerated terms, or a deposit outside the contract. The departure of your main contact. A change of registered agent or principal address. A renewal or scope expansion. A material price increase with no market explanation behind it.

Payment instruction changes outrank the other five by a wide margin, because that is where business email compromise lands. A vendor emailing new banking details is either a routine change or an attacker sitting in the vendor’s mailbox, and the only reliable way to separate the two is a callback to a number you already had on file, never the one in the new signature block. Occasionally it is neither, and the vendor has sold its receivables to a party you have never heard of and forgot to mention it.

Physical verification belongs on that list too. An address nobody has ever laid eyes on is an assumption wearing the costume of a fact, and addresses change without anyone sending notice.

The test to run this week

Pick your five largest vendors by annual spend. Open each file and find the date on the most recent diligence document in it. Then spend ten minutes pulling the current corporate record for each one from the Secretary of State, which costs nothing, and compare the status line, the officers, and the registered agent against what your file claims. If even one of the five disagrees, onboarding is the only diligence you have.

The exercise takes under an hour. What it turns up is rarely a fraud. It is a file that stopped being maintained the day the contract was signed, and now and then a vendor that was administratively dissolved before its last invoice cleared.

Farsight Intelligence runs counterparty diligence and ongoing monitoring for attorneys, executives, and compliance officers who need to know what the record says today rather than what it said at signing. Background at brettfl.com, scheduling at meet.brettfl.com, or write to [email protected].

Cleared once is not cleared.

Ready to move?

Explore our services or book a 30-minute call.

View Services & Pricing Book a Call
← Back to Main Blog