Tools and providers
Part of Choosing grant research tools, application systems and advisers with 2027 in mind
Small business grants: vendor diligence before you sign a contract
Check a grant adviser, software provider or delivery supplier before contract, covering identity, competence, conflicts, security, fees and exit.
Due diligence should match the supplier's access, value and ability to disrupt the funded project. Verify evidence before contract, record exceptions and repeat material checks when circumstances change.
What to take away
- Match due diligence to the supplier's access, value and ability to disrupt the funded project.
- A live Companies House record does not prove financial strength, competence or honesty.
- Award value is not the same as client benefit or adviser success rate.
- Treat warning signs as reasons for further evidence or rejection, not proof of wrongdoing.
- Set triggers for fresh checks and confirm bank details separately before any changed payment.
Identity and ownership
- Confirm the contracting legal entity, registered address and company number where applicable.
- Check directors, people with significant control and recent filing status.
- Match payment details through a separate trusted channel.
- Record parent companies, key subcontractors and connected relationships.
The Companies House search service provides public company records. A live record does not prove financial strength, competence or honesty, so combine it with checks suited to the risk.
Competence and capacity
- Define the experience needed for the particular grant or delivery task.
- Verify named staff and who will perform the work.
- Ask for relevant, contactable references.
- Check delivery capacity against the funding timetable.
- Confirm professional qualifications only through the responsible body.
Do not accept a total value of grants "supported" without the period, adviser role, evidence and denominator. Award value is not the same as client benefit or adviser success rate.
Method and integrity
- Ask how the supplier checks eligibility and claims.
- Confirm that the applicant approves every declaration.
- Reject guaranteed funding or advice to change facts.
- Record conflicts, referral payments and success-fee incentives.
- Check complaint, correction and whistleblowing routes.
The CMA's reviews and endorsements guidance helps publishers and businesses assess review authenticity and concealed incentives.
Security and personal data
- Map data the supplier will access, store or share.
- Check authentication, administrator control, backups and incident notification.
- Identify hosting, subprocessors, retention and deletion.
- Put controller and processor terms in writing where required.
- Test how access ends at contract close.
Use the ICO guidance hub for data-protection duties and the NCSC small organisations guide for practical security controls.
Financial and insurance checks
- Assess financial resilience in proportion to dependency.
- Obtain the complete fee schedule, expenses and VAT position.
- Model no-award, reduced-award and delayed-payment charges where relevant.
- Verify required professional, cyber or public liability cover.
- Check who carries rework, delay and overrun cost.
Contract and grant fit
- Match supplier scope and dates to approved activities.
- Follow the award's procurement and conflict rules.
- Define deliverables, acceptance, changes, intellectual property and audit access.
- Preserve project evidence and export rights.
- Set termination, transition and data-return obligations.
The Cabinet Office Model Grant Funding Agreement illustrates recipient obligations that may need to flow into supplier arrangements. The live award and supplier contract need qualified review.
Warning signs to investigate
Pause the selection when a supplier refuses to name the contracting entity, pressures the business to sign before reviewing terms, guarantees an award or asks for false eligibility information. Investigate unexplained bank-detail changes, unverifiable qualifications, copied case studies and references that cannot be contacted.
A warning sign is a reason for further evidence or rejection, not proof of wrongdoing. Record the supplier's explanation and the review decision. Escalate suspected fraud or data incidents through the appropriate route rather than confronting an individual without a plan.
Recheck during delivery
Set triggers for fresh checks: ownership change, new subcontractor, key-person departure, insurance expiry, serious service failure, security event or material variation. Confirm bank details separately before a changed payment.
Review access lists and retained data at agreed intervals. Check that the supplier still meets grant deadlines and evidence duties. Document corrective action, suspension or exit where a condition fails.
Record the reviewer, date, sources, decision and unresolved risks. This draft has no live internal links and remains on hold for legal, finance and security review.
Before you act
- Confirm the contracting legal entity and company number.
- Match payment details through a separate trusted channel.
- Reject guaranteed funding or advice to change facts.
- Verify required professional, cyber or public liability cover.
- Define deliverables, acceptance, changes and audit access.
- Record the reviewer, date, sources, decision and unresolved risks.
Common questions
What should I check about a supplier's identity and ownership?
Confirm the contracting legal entity, registered address and company number where applicable. Check directors, people with significant control and recent filing status. Match payment details through a separate trusted channel. Record parent companies, key subcontractors and connected relationships. A live record does not prove financial strength, competence or honesty.
How should I handle security and personal data before signing?
Map data the supplier will access, store or share. Check authentication, administrator control, backups and incident notification. Identify hosting, subprocessors, retention and deletion. Put controller and processor terms in writing where required. Test how access ends at contract close, using ICO and NCSC guidance.
When should I repeat checks during delivery?
Set triggers for fresh checks: ownership change, new subcontractor, key-person departure, insurance expiry, serious service failure, security event or material variation. Confirm bank details separately before a changed payment. Review access lists and retained data at agreed intervals, and document corrective action, suspension or exit where a condition fails.