
Why a Physical Document Custodian matters: not every Record is Digital
Some records must stay physical. Why a custodian; not just a folder keeps every original accountable across physical, digital and electronic records.

Manu Grover
Simplify vendor onboarding with structured approvals, compliance verification, document tracking, and audit-ready governance for Indian businesses.

Manu Grover
Editor

Picture the spreadsheet. It has a tab for approved vendors, a column for GST numbers, another for bank details, and a fill colour that means someone in finance has verified the paperwork. For a long time, it works. Then the business grows, three people leave, two new ones join, and one afternoon someone asks a simple question: is this vendor still valid, and who approved them?
Nobody can answer quickly. The spreadsheet is still there. The control it promised is not.
This is the quiet truth about vendor onboarding. It rarely fails in a dramatic way. It erodes. And because it erodes slowly, most organisations do not notice until the cost has already landed as a delayed payment, a failed audit, a compliance notice, or a vendor with access to sensitive data that nobody remembers approving.
This article is about that gap. We will look at what vendor onboarding really is, why the problem stays unsolved even in well-run companies, why most tools miss the point, and what a genuinely reliable system looks like. By the end you should be able to evaluate any onboarding approach, including your own, against a clear standard.
Ask ten teams to define vendor onboarding and you will hear ten versions of the same thing: collecting a vendor's details, checking a few documents, and adding them to the system so invoices can be paid. Procurement sees it as a purchasing step. Finance sees it as a payment prerequisite. Legal sees it as a contract trigger. IT sees it as an access request.
Each is partly right, and that fragmentation is exactly the issue.
Here is a more useful definition. Vendor onboarding is the process by which your organisation decides to trust an outside party, records the basis for that trust, and creates the conditions to hold them accountable later. In India this often runs alongside vendor empanelment, the formal approval of a vendor onto a panel before any work is awarded.
Read that definition again and notice what it contains. Trust. Evidence. Accountability. None of those are data-entry words. They are governance words. The vendor you onboard today may handle your customer data, invoice you for lakhs, sign a contract in your name, or fail an audit that becomes your problem. Onboarding is the front door through which all of that enters your business.
Treat the front door as admin, and you should not be surprised when the wrong things walk in.
The problem no one budgets for
The reason vendor onboarding stays broken is that its early symptoms are comfortable. A spreadsheet feels like control because you can see everything in one place. Email feels like a record because the thread is right there. Nothing is on fire. This is the illusion of control, and it lasts precisely until scale removes it.
Consider what actually happens as a company grows from twenty vendors to two hundred. Approvals move to whoever is available rather than whoever is accountable. The same vendor gets added twice under two spellings. A GST certificate expires and no one is watching the date. A compliance document is requested, promised over email, and never chased. The person who knew the history leaves. The spreadsheet survives, but the knowledge inside it does not.
None of these are catastrophic on their own. Together they produce an organisation that cannot answer basic questions with confidence: which vendors are active, what has been verified, who approved them, and what is due for review. When you cannot answer those questions, you do not have a vendor list. You have a liability you have not measured yet.
If vendor onboarding were only about convenience, it would deserve a convenient fix. It is not. Three costs make the case concrete, and two of them are specific to operating in India.
The security cost: Risk increasingly enters through the vendor. In its 2024 Data Breach Investigations Report, Verizon found that 15% of breaches involved a third party, a 68% increase over the previous period, including data custodians, third-party software, and other supply-chain routes. The cost of those breaches is not abstract in India. IBM's 2024 study put the average cost of a data breach in India at an all-time high of ₹195 million, up 9% in a single year. Every vendor you onboard without proper verification is a door you have opened without checking who holds the key.
The tax cost: This one surprises finance leaders. Since 1 April 2024, Section 43B(h) of the Income Tax Act allows a deduction for payments to micro and small enterprises only if you pay within the MSMED Act timeline: 15 days without a written agreement, and a maximum of 45 days with one. Pay late, and the deduction moves to the year you actually pay, raising your taxable profit in the meantime. Here is the connection people miss: you cannot comply with a rule you cannot see. If your onboarding does not capture whether a vendor is a registered micro or small enterprise through Udyam, your finance team is flying blind on a deadline that has real money attached. Governance that starts at onboarding is what makes that deadline visible.
The compliance cost: Under the Digital Personal Data Protection Act, 2023, a Data Fiduciary that shares personal data with a processor remains accountable for how that data is handled, and may engage a processor only under a valid contract. In plain terms, when a vendor touches your customers' data, their failure can become your penalty. Due diligence on that vendor does not begin when something goes wrong. It begins, or should begin, at onboarding.
Add the operational drag on top, the delayed payments, the approval that sits in an inbox for a week, the audit that turns into a document hunt, and vendor onboarding stops looking like admin. It looks like one of the highest-leverage control points in the business.
Why existing approaches keep missing
If the stakes are this clear, why has the market not solved it? Because most attempts fix the visible symptom and leave the real problem untouched.
Email and spreadsheets digitise nothing: They move paper into pixels while keeping every weakness of paper: no enforced sequence, no verification, no memory, no accountability. They feel efficient because they are familiar, which is the most expensive kind of familiar.
Point tools solve one slice and fragment the rest: A procurement tool captures the purchase. A separate form captures the documents. A shared drive holds the certificates. A compliance checklist lives in one person's head. Each tool is competent inside its own boundary, and the moment the vendor's information needs to cross a boundary, control is lost. This is the hidden tax of a category-first stack: every seam between tools is a place where governance leaks.
Most software automates the form, not the governance: This is the deepest reason, and it is worth sitting with. A digital onboarding form is still a form. It collects fields faster, but a faster way to collect unverified data is not progress. Real onboarding is not about the fields. It is about what happens around them: who is allowed to approve, what must be verified before approval, what evidence is retained, and what is scheduled for review. Almost every tool digitises the data. Very few digitise the accountability.
And automation projects fail for reasons that have nothing to do with software: This is the assumption most worth challenging. Buying a tool does not fix onboarding, and teams that believe it will are the ones most likely to be disappointed. Automation fails when no one owns the process, when the underlying process was never defined, when the people expected to use it were never brought along, and when the organisation is not mature enough to sustain it. Bolt automation onto a broken process and you get chaos, faster. The technology is the easy part. Governance, ownership, and adoption are the hard parts, and they are the parts that decide the outcome.
Strip away the branding and a reliable onboarding system, from any provider, does a small number of things well. Use the following as a checklist. It works whether you are evaluating a spreadsheet, a point tool, or a full platform.
A single, verified vendor record: One source of truth for each vendor, not a spreadsheet copied into three inboxes. Duplicate entries and conflicting details are designed out, not chased down.
Structured empanelment with real approval authority: The system knows who is allowed to approve a vendor and enforces it. Approval is a controlled decision with a name attached, not whoever happened to reply first.
Verification built into the flow: Identity and compliance checks such as GST, PAN, MCA, Udyam, and bank details are part of onboarding, not a separate favour asked later. A vendor is not simply added. A vendor is confirmed.
Document and expiry management: Certificates, registrations, and agreements are stored against the vendor with their validity dates tracked, so an expired document raises a flag instead of a future problem.
An audit trail by default: Every submission, verification, and approval is recorded automatically. When an auditor, a regulator, or your own board asks who approved this vendor and on what basis, the answer takes seconds, not a week.
Workflow and ownership, not just storage: Storing vendor files is not managing vendors. The system routes work, assigns responsibility, and moves each vendor through defined stages so nothing stalls in an inbox.
Scale without added headcount: The test of a real system is what happens at ten times the volume. If onboarding two hundred vendors needs ten times the effort of onboarding twenty, the system has not solved the problem. It has only relocated it.
Notice that not one of these points is a feature in the marketing sense. Each is an outcome: less risk, faster cycles, cleaner audits, and decisions you can defend. If a tool cannot demonstrate these outcomes, more buttons will not save it.
LegalBuddy built LB Onboard around exactly these outcomes, because vendor onboarding was one of the most conspicuously neglected parts of the legal and compliance stack.
The result is measured in outcomes, not screens.
As the COO of Tyresnmore put it, "what used to take days now takes minutes. No more endless email chains." That is the difference between digitising a form and fixing the governance around it.
There is a larger point here, and it is the reason onboarding matters so much. In most companies, the vendor you approve today will soon appear in a contract, a compliance obligation, a payment, and an audit. If each of those lives in a different tool, you are back to fragmentation.
LB Onboard is one module of an integrated system that also covers verification, compliance, contracts, document management, and secretarial workflows. Onboard a vendor once, and the same verified record governs everything downstream. Onboard once, govern everywhere.
This is what LegalBuddy means by treating legal and compliance as an operating system rather than a drawer full of separate tools. The goal is not to give you another application to run. It is to turn onboarding from a recurring source of risk into a repeatable, defensible business outcome.

Written by
Manu Grover
Editor at LegalBuddy

Some records must stay physical. Why a custodian; not just a folder keeps every original accountable across physical, digital and electronic records.

Manu Grover
A single document repository keeps institutional knowledge intact through growth, attrition, and role changes. See why accountability beats location tracking

Manu Grover
%20The%20Backbone%20of%20Smarter%20Business%20Operations.png&w=3840&q=75)
Explore how Contract Lifecycle Management (CLM) improves compliance, reduces risk, automates workflows, and strengthens smarter business operations.

Manu Grover