I have signed off on more facilities contracts than I can count. Sixteen years in procurement will do that. I started as a regional procurement manager, and today I run procurement as a VP for small and mid-sized companies that operate their own buildings, warehouses, and retail sites. One lesson has cost me time, budget, and a few uncomfortable conversations with ownership: a vendor that looks good on paper is not a vendor you can trust with your building, your staff, and your reputation. That gap is exactly why vendor vetting frameworks exist, and why so few small businesses build one before they need it.
What This Guide Covers, and Who It’s For
Small business owners and facilities leads rarely have a dedicated risk team. Usually one person, sometimes two, juggles lease renewals, HVAC contracts, janitorial bids, and security staffing all at once. Add a dozen other vendor relationships on top of that, and “vetting” often shrinks down to checking a website and asking for a quote. I get the time pressure. I have felt it myself, on both sides of the table. But I have also watched a poorly vetted vendor cause a six-figure liability claim. I have watched a mold remediation dispute drag on for eight months. And I once discovered that a “licensed” electrical contractor had let their license expire the entire time they worked on our properties.
This guide lays out the vendor vetting frameworks my team uses today. It breaks the process into eight steps, and I built it for procurement leaders and facilities managers at small and growing businesses. Most small businesses never write their vendor vetting frameworks down at all, which is exactly what gets them into trouble later. You do not need a theoretical model built for a Fortune 500 supply chain team with fifty analysts. You need something you can actually run. I will walk through what to check, in what order, why each step matters, and where most small businesses cut corners without realizing the cost.
Why Vendor Vetting Frameworks Matter More for Small Businesses, Not Less
Plenty of people assume formal vendor vetting only matters for large enterprises, since they carry more locations and more spend. I would argue the opposite for facilities-related vendors. A large company can absorb a bad vendor relationship at one site while the rest of the portfolio keeps running. A small business with three or four locations does not have that cushion. One bad janitorial contract, one HVAC vendor that disappears mid-winter, one landscaping company with an expired certificate of insurance, and the impact hits your entire operation at once. Strong vendor vetting frameworks catch these problems before they turn into a crisis, not after.
Facilities vendors also carry risks that other vendor categories simply don’t. They stand physically present on your property. Many of them hold keys, alarm codes, and after-hours access. They interact with your employees, and in retail or hospitality settings, sometimes your customers too. A software vendor that fails usually causes minimal disruption; you swap it out. A security vendor that fails can put people at risk. That difference alone drives me to push every small business client toward real vendor vetting frameworks. Gut instinct and a single reference call just don’t cut it.
Step One: Define What You Are Actually Vetting For
Before you request a single document from a vendor, sit down and write out what matters for this specific category of spend. A janitorial vendor and a fire suppression vendor should not face an identical checklist, even though both fall under facilities.
I ask three questions for every new category. What happens if this vendor fails to show up? What happens if this vendor does the work poorly? And what happens if this vendor causes property damage or injury? The answers shape how deep the vetting needs to go. Low-risk, easily replaceable services call for a lighter check. Anything touching life safety, structural work, or building access demands a much higher bar.
Write this down. I still see teams skip this step and jump straight to a generic vendor questionnaire. That approach wastes the vendor’s time and yours, and it still misses the risks that matter most for that category. The strongest vendor vetting frameworks I have built all start here, with this exact question, before a single form gets sent out.
Step Two: Verify Business Legitimacy and Licensing
This sounds obvious, yet teams handle it halfway more often than any other step. Confirming a business exists tells you nothing about whether it holds a proper license, registration, and good standing to do the work you need.
At minimum, I require the vendor’s legal business name and entity type, proof of state or local business registration, and any trade-specific licenses the work calls for. Electrical, plumbing, fire and life safety, and pest control trades usually carry a state license number, and you can verify it directly with the issuing board. I also check how long the business has operated under its current name. A pattern of frequent renaming is worth asking about directly.
Here is the mistake I see most often: a company reviews a license once at onboarding and never checks it again. Licenses lapse. Regulators suspend them. Mergers tie them to a different legal entity. I now build a recurring check into the calendar, typically annually, for any vendor whose work requires a license. Licensing comes up in almost every conversation I have with a new client about vendor vetting frameworks, and for good reason.
Step Three: Confirm Insurance Coverage and Request the Certificate Directly
A vendor telling you they carry insurance proves nothing. I require a current certificate of insurance, sent directly from the vendor’s insurance broker rather than forwarded by the vendor. I also confirm the coverage types and limits actually match the work performed.
For facilities vendors, general liability and workers’ compensation matter most. Depending on the work, add commercial auto and professional liability too. I also ask to appear as an additional insured on the general liability policy for any vendor doing ongoing work on our properties. Commercial contracting treats this as a standard request. A vendor who resists it, or can’t explain why, earns a closer look from me.
One habit has saved us real money: I set a calendar reminder tied to the certificate’s expiration date, not just the contract renewal date. Insurance certificates often expire mid-contract. An unnoticed lapse leaves you effectively uninsured for any incident that happens in that gap.
Step Four: Review Financial Stability
Small businesses skip this step constantly. It feels like something that only applies to large capital purchases. It doesn’t. A vendor in financial distress will cut corners on staffing, supplies, or safety equipment long before they tell you there is a problem, and a janitorial or maintenance contract carries that same risk.
I don’t expect small facilities vendors to hand over full financial statements, and most won’t. Instead, I look at how long the business has operated. I check for a pattern of legal judgments or liens on public record. I ask whether they can provide a bank or trade reference. For larger contracts, a simple credit report through a business credit bureau costs little and pays for itself. It costs far less than discovering mid-contract that a vendor can’t make payroll and walks off the job.
Step Five: Check References the Right Way
Reference checks usually fail because of how the questions get asked. If you call a reference and ask “were they good to work with,” you will get a positive, generic answer almost every time. Ask scenario-based questions instead. How did this vendor handle an emergency service request outside normal hours? What happened the one time something went wrong? Would you renew this contract today at the same price?
I also ask for at least one reference the vendor did not offer up front, when the relationship allows it. A property manager in the same building, or a shared vendor in an adjacent trade, both work well. Vendors naturally put their best references forward. A framework built only on hand-picked references doesn’t really vet anything; it just confirms what the vendor already wants you to believe.
Step Six: Assess Operational Capacity and Backup Coverage
A vendor can be legitimate, insured, financially sound, and well-referenced, and still be the wrong fit. Capacity matters just as much. I ask directly how many similar accounts a vendor currently services. Their staffing model matters too, so I ask about that directly. And I ask what happens if a key technician or crew leader gets sick or leaves the company.
This step matters enormously for facilities work, because so much of it rides on a small number of specific people. A janitorial company with one experienced site supervisor covering five accounts carries a very different risk profile than one with a documented backup rotation. I have learned to ask this question directly, because vendors rarely volunteer their staffing gaps on their own.
Step Seven: Confirm Compliance and Safety Practices
Any vendor whose work touches safety needs a closer look here. That includes a contractor on a ladder, a chemical-handling janitorial crew, or a security team carrying access credentials. I confirm their safety training program, their incident history, and how they document near misses or accidents. I also check for regulatory citations on record, which the trade and jurisdiction often make public.
This step is not about assuming the worst of every vendor. It is about making sure a documented process stands behind the vendor’s work. When something does go wrong, that documentation protects your business instead of leaving you exposed in a later claim or dispute.
Step Eight: Formalize the Agreement and Set a Review Cadence
The final step is where I see the most value lost. Many small businesses complete steps one through seven carefully, then let the paperwork lapse into something vague. A strong vendor agreement should spell out scope of work in concrete terms. It should set clear service level expectations. Insurance and licensing belong in there too, as ongoing conditions of the contract rather than just onboarding requirements. And it needs a clear termination clause and a schedule for performance review.
I recommend reviewing any vendor with ongoing facilities responsibilities at least twice a year. For higher-risk categories like security or life safety systems, review quarterly. This is also where I revisit the original questions from step one. Has the risk profile of this vendor relationship changed? Has the scope quietly expanded beyond what the contract covers? An eight-step framework only holds value when you apply it on a recurring basis, not as a one-time gate at onboarding.
Common Mistakes I Still See, Even at Companies That Think They Vet Vendors Well
The most common failure treats vendor vetting as a document collection exercise rather than a risk assessment. Collecting a certificate of insurance and a business license matters, but it means little if nobody actually checks whether the coverage limits or license type match the work being done.
Well-designed vendor vetting frameworks still fail sometimes. The reasons rarely have anything to do with the checklist itself. I see the same handful of causes repeat across almost every company I work with.
The second common failure is inconsistency across locations. I have walked into facilities portfolios where one site manager runs a thorough vetting process, while another site three miles away hires vendors off a flyer left on the door. A framework only works when you apply it consistently across every property and every category. In practice, that means writing it down and making it a required step, not a best practice that depends on who happens to handle the request that week.
The third failure, and the one I find most avoidable, is never revisiting a vendor after the initial onboarding. Businesses change. Ownership changes. Staffing changes. A vendor that passed every check three years ago may not run the same business today. A framework that only checks once amounts to a one-time screening, not an ongoing vetting practice.
What It Actually Costs to Skip a Step
I mentioned the electrical contractor with the expired license earlier. It’s worth walking through what that actually cost us, because the number surprised even me at the time. The contractor had sat on our approved list for two years. The license had lapsed eleven months before we found out. We nearly postponed the routine annual re-check that quarter, because the team was busy with a lease renegotiation. Had that check slipped another cycle, we would have run a full year of electrical work under an invalid license, and that would have voided our own liability coverage for any incident tied to that work.
Catching it cost us little: a few hours of staff time and an uncomfortable conversation with a vendor we otherwise liked. Not catching it would have cost far more. Our insurance broker estimated a rough number at the time, and it ran into six figures, the likely result if a claim had surfaced during that gap and the insurer had denied coverage because an unlicensed party performed the work. That single example is why I no longer treat the annual license and insurance recheck as optional busywork. It stands as the cheapest insurance policy in the entire framework, and it costs almost nothing next to what it prevents.
Choosing Tools That Support the Framework, Not Replace It
Small businesses sometimes ask me whether they need vendor management software to run a process like this. My honest answer: good tools support vendor vetting frameworks, but they don’t replace them. The discipline behind the process matters more than the software. I have seen companies with expensive vendor risk platforms still get burned, because nobody actually reviewed the alerts the software generated. I have also seen a facilities coordinator run this entire eight-step process out of a shared spreadsheet and a calendar app, and do it better than some enterprise deployments I have reviewed.
If you do want a tool, look for one that tracks license and insurance expiration dates automatically. It should store vendor documents in one place instead of scattered email threads. It should give you a simple way to score vendors side by side during a bid. Beyond that, extra features are usually nice to have rather than necessary. The framework itself, applied consistently, actually reduces risk. The software just makes it easier to stay consistent once you manage more than a handful of vendor relationships at once.
Building This Without a Large Procurement Team
Most small businesses reading this do not run a dedicated procurement department, and that’s fine. Effective vendor vetting frameworks do not require one. You need a written checklist tied to each vendor category. A shared calendar for tracking license and insurance expirations matters just as much. On top of that, a simple scoring approach helps you compare vendors during a bid process. And you need one designated person responsible for reviewing vendor files on a set schedule, even if that person also wears four other hats.
I have set this up for companies running a single facilities coordinator out of a spreadsheet, and it worked. It worked because the process stayed consistent, not because the tooling ran sophisticated. The framework matters more than the software behind it.
A Final Note From the Procurement Chair
Every vendor relationship I have watched go wrong carried a warning sign before the contract was ever signed. An insurance certificate that didn’t quite match the scope of work. A reference call that felt slightly too rehearsed. A license current for the wrong trade. None of these signs look dramatic on their own, and that’s exactly why teams miss them without a structured process behind the review.
Vendor vetting frameworks do not assume vendors are dishonest. Most aren’t. It protects your business, your employees, and your customers from the small percentage of vendor relationships that go wrong in preventable ways. If you take one thing from this guide, take this: build your vendor vetting frameworks once. Apply them every time, and revisit them on a schedule. That habit alone will save you more than any single price negotiation ever will.
Frequently Asked Questions
What is a vendor vetting framework? A vendor vetting framework is a structured, repeatable process for evaluating a supplier or contractor before and during a working relationship. It covers business legitimacy, licensing, insurance, financial stability, references, operational capacity, safety compliance, and contract terms. For a deeper look at how this applies specifically to facilities and supplier categories, see Certa’s guide to vendor vetting best practices.
How is vendor vetting different from vendor selection? Vendor selection is the decision of which vendor to hire. Vendor vetting is the due diligence process that informs that decision, and it continues after you sign the contract. Ivalua walks through the selection process itself in more detail in its vendor selection guide.
How often should facilities vendors be re-vetted after onboarding? Review most facilities vendors at least twice a year. Review higher-risk categories, such as security, fire safety, or structural contractors, quarterly, since licenses, insurance, and staffing can all change mid-contract. FacilitiesNet’s vendor selection guidance covers ongoing vendor management considerations for facility teams.
What documents should a small business always collect before hiring a facilities vendor? At minimum, collect proof of business registration, applicable trade licenses, a current certificate of insurance naming your business as an additional insured where appropriate, and at least one verifiable reference. Bitsight’s vendor risk assessment checklist offers a useful reference point for building out a fuller due diligence checklist.
Can a small business run an effective vendor vetting process without dedicated procurement staff? Yes. A written checklist, a shared calendar for tracking expirations, and one designated reviewer are enough to run a consistent process, even without a formal procurement department. JLL’s insights on vetting suppliers for facilities management speaks to how this scales across different organization sizes.
References
- Certa. “Best Practices for Vendor Vetting.” https://www.certa.ai/blogs/the-best-practices-for-vendor-vetting
- Ivalua. “Vendor Selection Process: Steps, Criteria & Checklist Guide.” https://www.ivalua.com/blog/vendor-selection-process/
- FacilitiesNet. “How to Select the Right Vendor for Your Facility.” https://www.facilitiesnet.com/facilitiesmanagement/article/How-to-Select-the-Right-Vendor-for-Your-Facility–20487
- Bitsight. “A Vendor Risk Assessment Checklist.” https://www.bitsight.com/learn/tprm/vendor-risk-assessment-checklist
- Bitsight. “The Vendor Due Diligence Checklist: A 5-Step Guide.” https://www.bitsight.com/blog/five-step-vendor-due-dilligence-checklist
- JLL. “Vetting Suppliers and Vendors for Facilities Management.” https://www.jll.com/en-us/insights/vetting-suppliers-and-vendors-for-facilities-management
- Art of Procurement. “Key Supplier Selection Criteria Every Procurement Executive Should Know.” https://artofprocurement.com/blog/key-supplier-selection-criteria-every-procurement-executive-should-know
- Zycus. “Supplier Vetting 101: Best Practices & Tools.” https://www.zycus.com/blog/supplier-management/supplier-vetting-101-best-practices-for-identifying-top-performers
