Vendor onboarding and KYC documents between company agents
How company agents could exchange tax IDs, ownership details, sanctions checks and bank details for onboarding under IRS, CRA, FinCEN and FINTRAC rules.
How it works today
Onboarding a business counterparty means collecting documents, checking them against official sources, and keeping proof. Two versions of the job run on the same pattern.
A company onboarding a supplier
Before the first payment, accounts payable builds a vendor record:
- US tax identity. The supplier returns a Form W-9, the Request for Taxpayer Identification Number and Certification, which gives a payer the correct TIN for information returns. Payers that qualify can check name and TIN combinations against IRS records through the TIN Matching service in IRS e-Services, one at a time or in bulk.
- Canadian tax identity. A registrant can confirm a supplier’s GST/HST account number in the CRA’s GST/HST Registry using the number, the supplier’s business name and the transaction date, so that input tax credit claims only include tax charged by a registered supplier.
- Sanctions. OFAC’s Sanctions List Service publishes the Specially Designated Nationals (SDN) List and the Consolidated (non-SDN) List, and its Sanctions List Search uses fuzzy name matching. Global Affairs Canada publishes the Consolidated Canadian Autonomous Sanctions List for regulations under the Special Economic Measures Act and the Justice for Victims of Corrupt Foreign Officials Act, and notes that it is not exhaustive.
- Bank details. The supplier sends remittance instructions. This is the field fraudsters want. The FBI’s business email compromise guidance describes vendor messages with updated payment details and advises verifying any change in account number or payment procedure directly with the requester.
A financial institution onboarding a business customer
- United States. Under FinCEN’s Customer Due Diligence rule (31 CFR 1010.230), covered financial institutions identify and verify the beneficial owners of legal entity customers: each individual who owns 25 percent or more, and one individual with significant responsibility to control or manage the entity. They collect each person’s name, date of birth, address and an identification number, and may rely on the customer’s information unless they know facts that call it into question. Since FinCEN’s exceptive relief order of 13 February 2026, institutions may limit this to the customer’s first account, to later moments when they have reason to doubt the information, and to their risk-based ongoing due diligence. Separately, FinCEN’s final rule of 11 August 2026, effective 14 August, made permanent the exemption of US companies and US persons from beneficial ownership reporting under the Corporate Transparency Act. Foreign reporting companies still report.
- Canada. FINTRAC requires reporting entities, other than title insurers, to obtain beneficial ownership information for corporations, trusts and other entities. For a corporation that means the names of all directors, the names and addresses of everyone who directly or indirectly owns or controls 25 percent or more of the shares, and the ownership and control structure. Entities must take reasonable measures to confirm the accuracy of that information. Since 22 January 2024, corporations under the Canada Business Corporations Act file information on individuals with significant control with Corporations Canada, and some of it is public. Since 1 October 2025, reporting entities must check that database for federal corporations they assess as high risk, and report any material discrepancy to Corporations Canada within 30 days.
Today these documents move as email attachments and portal uploads, and someone retypes them into a vendor master or a customer file.
The agent-to-agent version
Illustrative. A buyer’s onboarding agent asks a new supplier’s agent for its vendor package, in A2A v1.0 shapes:
{
"jsonrpc": "2.0",
"id": "onb-2291",
"method": "SendMessage",
"params": {
"message": {
"messageId": "msg-onb-2291-01",
"role": "ROLE_USER",
"parts": [
{ "text": "Vendor onboarding for purchase agreement PA-2291. Please provide the items listed. Bank details will be confirmed by phone with your listed finance contact." },
{
"data": {
"onboardingId": "ONB-2291",
"requested": ["legal-name", "form-w9", "gst-hst-number", "remittance-bank-details", "certificate-of-insurance"],
"sanctionsScreening": "performed-by-requester",
"bankDetailVerification": "callback-to-known-contact"
},
"mediaType": "application/json"
}
]
}
}
}
Then:
- The supplier’s agent returns the W-9 and insurance certificate as file parts and the structured fields as a data part.
- The buyer’s agent runs TIN Matching, the GST/HST Registry lookup and sanctions screening as its own tool calls, never trusting the supplier’s word for the results.
- The buyer’s agent does not activate the bank details until a person confirms them through a callback to a contact already on file.
- Later changes, such as a new address or bank account, arrive as new tasks and go through the same checks.
What has to be true
Identity. Onboarding is where fake vendors and customers enter. The buyer must bind the supplier’s agent to the supplier’s real domain and legal entity before accepting anything, and a Signed Agent Card only proves who holds the key. The checks against the IRS, the CRA, OFAC and Global Affairs Canada lists must run on the buyer’s side.
Authority. A W-9 carries a certification by the payee, and beneficial ownership information comes from a person acting for the entity. An agent can deliver those documents. Someone at the company still has to stand behind them, and the receiving side should know who.
Record. Both the CDD rule and FINTRAC’s guidance turn on what was collected, when, and how it was confirmed. FINTRAC also requires keeping Corporations Canada’s acknowledgement when a discrepancy is reported. An exchange between agents should leave that trail automatically.
Data protection. Tax numbers, dates of birth and bank details are high-value data. Agents should send only what the recipient asked for, use short-lived links for documents, and never repeat those fields in logs or free text.
Where Emissar fits
- Verify (In development): checks that the agent asking for, or supplying, onboarding documents belongs to the company it claims, before sensitive data moves.
- Mandate (Spec in progress): a proposal for showing which person authorized an agent to certify or submit documents for a company.
- Ledger (Spec in progress): a signed record of which documents were exchanged and when, for audit.
- Handoff (In development): routes bank detail changes and screening hits to a person with the exchange attached.
Open questions
- Could registries and banks issue verifiable credentials, the W3C model of issuer, holder and verifier, for facts such as “this TIN matched” or “this account belongs to this company”, so agents exchange proofs instead of documents?
- With US companies now exempt from beneficial ownership reporting, how will institutions confirm ownership information that an agent submits?
- Should an agent ever be allowed to change remittance details, or only to propose a change that a person confirms?
- How should agents handle a sanctions near-match that needs human review without leaking the screening result to the counterparty?
Sources
- IRS: About Form W-9, Request for Taxpayer Identification Number and Certification (accessed )
- IRS: Taxpayer Identification Number (TIN) Matching (accessed )
- Canada Revenue Agency: Confirming a GST/HST account number (accessed )
- OFAC: Sanctions List Service (accessed )
- Global Affairs Canada: Consolidated Canadian Autonomous Sanctions List (accessed )
- 31 CFR 1010.230: Beneficial ownership requirements for legal entity customers (accessed )
- FinCEN: CDD Final Rule (accessed )
- FinCEN: CDD Rule FAQs (including the Account Opening Exceptive Relief Order of 13 February 2026) (accessed )
- FinCEN: Beneficial Ownership Information Reporting (final rule of 11 August 2026) (accessed )
- FINTRAC: Beneficial ownership requirements (accessed )
- Corporations Canada: Individuals with significant control (accessed )
- FBI: Business Email Compromise (accessed )
- W3C Verifiable Credentials Data Model v2.0 (accessed )
- A2A protocol definition (a2a.proto): Message, Part (accessed )