How to See if a Company Is Legitimate Before You Pay

In 2023, people reported losing more than $1.1 billion to business and government impersonation scams, and those two categories accounted for 48% of fraud reports made directly to the FTC, excluding unspecified reports. The Federal Trade Commission's data changes the question you should ask before paying a supplier, contractor, lender, or online business. It isn't only “Does this company exist?” It's “Am I dealing with the company, and do the payment details belong to it?”
A government registry can confirm that an entity was formed and can show its current filing status. It can't, by itself, prove that the person emailing you works there, that the bank account is genuine, or that the company will perform as promised. The reliable approach is layered, risk-based, and documented.
Why a Registry Match Is Not the Same as Proof
A registry match establishes legal existence, not complete legitimacy. It tells you that an entity with a particular name was registered in a jurisdiction and that the registry assigns it a specific status. That's useful, but it answers only one part of the risk question.
Operational legitimacy requires more. You need to connect the entity record to the counterparty in front of you, reconcile names and addresses, confirm that the signatory has authority, and validate the contact and payment channels independently. A real company can be used as cover by an impostor who copies its branding, registration details, invoices, and employee names.

The scale of impersonation fraud shows why a simple search creates dangerous confidence. In 2025, the FTC reported nearly $1 billion in consumer losses to business impersonators, while impersonation scams overall generated $3.5 billion in reported losses. Those figures appear in the FTC's 2025 impersonation scam announcement, and they reinforce a practical point: criminals don't need to invent a company if they can borrow the identity of a real one.
Practical rule: A registry record is a starting point for verification, not a permission slip to pay.
The distinction matters most when the request arrives unexpectedly, the deal involves a large transfer, or the counterparty wants you to bypass normal procurement controls. A company can appear active while the contacting person has no relationship with it. Conversely, an incomplete public record isn't automatic proof of fraud because registries differ in their terminology, update cycles, privacy rules, and available filing detail.
A useful overview of business entity data can help explain what registries commonly provide, but your review should still move from existence to identity, authority, ownership, behavior, and payment validation. The next checks turn that principle into an auditable workflow.
The registry search is the first layer. The full answer comes from comparing official records with the documents, people, channels, and transaction details attached to the deal.
Here's a short visual explanation of why record retrieval needs to be separated from identity and payment checks:
Pulling the Official Registry Record the Right Way
Start with the jurisdiction where the company was formed or registered. In the United States, that usually means the relevant Secretary of State registry. A company may also be registered as a foreign entity in states where it operates, so search the formation jurisdiction and any important operating jurisdictions when the documents suggest more than one.
Don't rely on a company's website, a logo, or a search-engine result as your official source. Access the government registry independently, search the exact legal name, and use the entity identification number whenever the counterparty provides one. Common names create false matches, especially when several entities share similar words or abbreviations.
Capture the record rather than merely looking at it. Save the source, retrieval date, search terms, result identifier, and available filing documents. A timestamp matters because status, addresses, registered agents, and filings can change after onboarding.

The fields that answer different questions
Pull these fields into your case file:
- Legal entity name: Does the name on the contract and invoice identify the same entity as the registry?
- Entity identification number: Can you distinguish the counterparty from similarly named businesses?
- Jurisdiction: Was the entity formed or registered where the company claims?
- Formation or registration date: Does the age of the entity fit the company's stated history?
- Current status: Is it active, dissolved, suspended, inactive, or subject to another jurisdiction-specific status?
- Entity type: Is it a corporation, limited liability company, partnership, or another structure?
- Registered agent: Who receives formal legal notices, and does that information align with the company's records?
- Principal address: Does the official address match contracts, invoices, websites, and independently obtained contact information?
- Filing history: Are annual reports, amendments, mergers, reinstatements, or dissolution filings present?
A record in a database is only an initial signal. The U.S. Census Bureau's December 2024 Business Formation Statistics recorded 457,544 seasonally adjusted business applications and projected 28,834 of those applications would become employer businesses within four quarters. The difference illustrates why an application or name entry shouldn't be treated as evidence of an established operating business.
Make the search reproducible
For manual checks, a spreadsheet with one row per field is enough. For larger portfolios, an entity search API can normalize results across registry interfaces, but automation doesn't remove the need for review. It makes the collection and comparison more consistent.
Record what you found, not what you expected to find. If the legal name differs from the trading name, preserve both and document the relationship. If the registry doesn't display an officer or principal address, mark the field as unavailable rather than treating it as a negative result.
Reading Filings Officers and Status Like an Auditor
Collecting the registry record is mechanical. Interpreting it requires a timeline, context, and a documented explanation for anything that does not fit.
Review filings in chronological order rather than treating the latest status as the whole answer. Start with formation, then examine annual reports, amendments, mergers, reinstatements, address changes, registered-agent changes, and dissolution activity. The aim is to understand how the company developed and whether that history supports the business relationship being presented.
A recent filing is not automatically reassuring. An address or registered-agent change may reflect an ordinary relocation, a change in service provider, or routine administration. It deserves closer review when it appears alongside a new signatory, altered ownership-related information, changed payment instructions, or pressure to complete a transaction quickly. The timing may be coincidental, but the file should show that someone considered the connection.
Officer and management changes need the same treatment. A newly listed officer can be legitimate, yet the change may matter if the counterparty relies on that person's authority for a contract, account change, or high-value order. Compare the sequence of filings with the date of the relevant transaction and record whether the authority was current at that point. A registry may disclose only some officers, and jurisdictions differ in how much information they publish. Treat missing information as a reason to seek supporting evidence, not as proof of misconduct.
Status labels also require interpretation. “Active,” “good standing,” “in compliance,” and similar terms do not carry identical meanings in every registry. A company may be legally current while the record is incomplete, recently updated, or silent on issues that affect the transaction. The FinCEN customer due diligence framework supports a risk-based process that identifies and verifies the customer, beneficial owners, relationship purpose, and ongoing risk, rather than relying on a casual database match.
Escalate missing expected reports, administrative dissolution, inactive status, or an amendment that materially changes management or ownership-related information. None of these signals proves fraud by itself. The question is whether the full filing history supports the company's explanation and whether unresolved issues justify pausing the relationship.
An inconsistency is not always fraud. An unexplained inconsistency is always a reason to slow down.
Write the reasoning into the file. Identify the filing or status that raised the issue, state what evidence resolved it, name the reviewer, and record what remains uncertain. This creates an auditable decision trail and prevents a later reviewer from treating an unresolved discrepancy as cleared.
Red Flags That a Registry Search Will Never Show
A registry can't tell you whether the person contacting you controls the company. It can't authenticate an email thread, validate a new bank account, or detect that a criminal has cloned a legitimate supplier's website.
The most dangerous requests often use a real company identity. That's why the response to a matching registry record shouldn't be “safe to pay.” It should be “continue checking the person, channel, authority, and transaction.”
Watch for these behavioral signals:
- Contact details supplied only by the counterparty: Find the company's phone number, domain, or other contact channel independently. Don't use the number in the suspicious email to verify that same email.
- Sudden payment-account changes: Confirm the change through a separate channel already associated with the company. Replying to the message that requested the change doesn't provide independent verification.
- Urgent payment pressure: A demand to pay immediately, avoid normal approval, or keep the request confidential reduces your ability to investigate.
- Unusual payment methods: Requests for cryptocurrency, gift cards, or other methods that don't fit the commercial relationship deserve heightened scrutiny.
- Name mismatch: The seller, contracting party, invoice issuer, and beneficiary should have an explainable relationship. A mismatch between the registered entity and the party soliciting payment is a strong reason to pause.
- Resistance to ordinary questions: A genuine counterparty may need time to provide records, but refusal to identify the legal entity, authorized signatory, or payment owner is a material concern.
| Warning sign | Reassuring signal |
|---|---|
| Payment instructions changed by email alone | The change is confirmed through an independently sourced phone number or established contact |
| The sender uses a free or unrelated email address | The sender's identity and authority are confirmed through a trusted company channel |
| The request creates unusual urgency | The counterparty accepts normal approval and verification procedures |
| The legal name on the invoice differs without explanation | The relationship between trading name, legal entity, and beneficiary is documented |
| The seller avoids registry, ownership, or authorization questions | The seller provides consistent records and responds to reasonable due diligence |
The vendor due diligence software guide is relevant when these checks need to be applied consistently across a procurement team. Software can organize evidence and route exceptions, but it can't turn an unverified communication channel into a trusted one.
The practical rule is simple: verify payment changes separately, especially when the request is urgent. Don't let a familiar company name lower your scrutiny. Familiarity is exactly what impersonation relies on.
Building a Risk-Based Verification Workflow
A useful workflow doesn't force every company into a binary legitimate or illegitimate label. It assigns confidence to separate checks and sends exceptions to a person who can investigate them.
Begin by normalizing the submitted data. Standardize the legal name, jurisdiction, entity number, address, officers, registered agent, and ownership information before comparing it with the official record. Small formatting differences should be distinguished from substantive conflicts.
Then assess the file in sequence:
- Confirm the entity. Search the relevant official registry and verify the exact identifier where available.
- Reconcile the record. Compare the legal name, jurisdiction, status, formation date, address, agent, officers, and filings with the counterparty's documents.
- Review authority. Confirm that the person signing the contract can bind the entity. Use an authorization document or an independently verified corporate contact when the registry doesn't establish authority.
- Identify ownership and control. Determine the natural persons who own or control the business, then verify their identities using procedures comparable to customer identity verification.
- Validate the relationship. Confirm the business purpose, physical or operating presence where relevant, contact channels, and payment details independently.
- Document the decision. Preserve the source, retrieval timestamp, matched fields, evidence, reviewer, outcome, and unresolved issues.
Use confidence and exceptions
A high-confidence file generally has an exact or registry-confirmed entity identifier, an expected active status, a consistent jurisdiction and legal name, and no material contradiction in the filings. That doesn't prove performance or solvency. It means the identity evidence is coherent enough for the assigned risk level.
Escalate when the entity is inactive, administratively dissolved, newly formed, missing expected reports, or subject to conflicting addresses or officer data. Escalation is also necessary when you can't connect the contracting party to the registered entity, when the beneficial ownership structure is unclear, or when the counterparty refuses identifying information.
The FinCEN CDD FAQ emphasizes written procedures and risk-based verification. It also explains that beneficial-owner verification should use procedures comparable to those used for customer identity verification. In practice, that means your process should define acceptable evidence and escalation routes before a difficult case arrives.
For automated onboarding, assign independent outcomes for identity, status, address, management authority, filing continuity, ownership, and payment validation. A single “pass” field hides which part of the relationship remains unverified. Preserve filing PDFs or equivalent evidence for higher-risk files, and set a recheck requirement before payment when material changes occur.
Making Verification Continuous Instead of One-Time
A company that clears onboarding can change after approval. Its registered agent may change, its principal address may move, its status may shift, and ownership-related filings may change the risk profile. An impersonator can also appear later, using a genuine registry record to support a false request. A registry match proves the entity exists. It does not prove that a later contact, payment instruction, or signatory represents that entity.
The Identity Theft Resource Center's 2025 trends report reported that impersonation scams increased 148% year over year, with businesses representing 51% of impersonated organizations. A timestamped verification is evidence about a point in time, not a permanent verdict.
Set review triggers according to risk. A low-risk supplier may need periodic status checks. A financial, lending, marketplace, or high-value procurement relationship may justify event-driven monitoring before payments and after material account changes. Focus alerts on changes that can affect identity or authority, including status, registered agent, address, officers, and ownership-related filings. Record who reviews each alert, what evidence they inspect, and why they approve, restrict, or escalate the relationship.
Keep a reusable final checklist
Before approving a new counterparty, confirm:
- Registry record: Capture the official entity, identifier, jurisdiction, status, and formation details.
- Field reconciliation: Match the legal name, address, officers, agent, and entity type to the submitted documents, or record a written explanation for each difference.
- Filing review: Consider formation, annual-report, amendment, merger, reinstatement, and dissolution records where relevant.
- Authority check: Independently support the signatory's connection to the entity.
- Ownership check: Identify and verify the natural persons who own or control the business at the required risk level.
- Contact validation: Obtain contact information from an independent source, rather than relying only on the incoming message.
- Payment confirmation: Verify account details and changes through a separate channel.
- Audit trail: Preserve the source, retrieval time, evidence, reviewer decision, and open issues.
- Monitoring plan: Assign the next review and document which changes require escalation.
For teams applying this process across U.S. jurisdictions, compliance monitoring software can support recurring checks and change alerts. Use the tool to strengthen controls, while keeping judgment with the reviewer. The decision depends on the risk, the evidence, and whether unresolved questions affect the transaction.
SOSfinder provides normalized business entity records, filing histories, bulk verification, and monitoring for changes to status, registered agents, and addresses. Use SOSfinder to support an auditable company verification process before onboarding a vendor or approving payment.