Today I am sharing techniques typically reserved for cybersecurity and intelligence analysis that can also be deployed to verify vendors, vet raw material sources, and ensure FAR compliance before a contract is even signed. In these modern times, old school standard validation tactics are no longer enough.
In the world of federal contracting, checking a box on SAM.gov is often treated as the ultimate vetting process. We assume that if an entity has an active CAGE code and isn't on an exclusion list, they are ready to do business. However, on the factory floor and deep within the tiers of a supply chain, reality is significantly more complicated.
Standard validation confirms a company exists on paper. It does not confirm that the company actually manufactures the components they claim to, nor does it guarantee those components aren't being sourced from prohibited entities masked by shell corporations.
The Limits of Traditional Vetting
Traditional procurement vetting relies heavily on self-attestation. Vendors fill out representations and certifications (Reps & Certs) affirming their compliance with the Federal Acquisition Regulation (FAR). While these are legally binding, they are fundamentally reactive. You often only discover a false attestation after an audit or, worse, a component failure in the field.
"We are trusting the paperwork of the entity we are trying to investigate. It’s a closed loop of trust that modern supply chain attacks actively exploit."
Consider a scenario where a prime contractor needs specialized aluminum extrusions. A lower-tier subcontractor provides documentation showing domestic sourcing. Traditional vetting stops there. But what if that subcontractor is merely a warehousing front, repacking extrusions manufactured overseas by an entity flagged for intellectual property theft?
Enter OSINT: Shifting from Reactive to Proactive
Open Source Intelligence (OSINT) involves collecting and analyzing publicly available data to answer a specific intelligence question. While commonly associated with cybersecurity (threat hunting) or journalism, these methodologies are highly adaptable to supply chain verification.
Instead of merely verifying documents, OSINT allows us to verify capability and relationships.
Key Techniques for Procurement
- Corporate Structure Analysis: Mapping out parent companies, subsidiaries, and joint ventures using international corporate registries (beyond just the US state level). We look for shared directors, overlapping addresses, or patterns of rapid name changes.
- Geospatial Intelligence (GEOINT): Using publicly available satellite imagery (like Google Earth or specialized commercial platforms) to verify physical infrastructure. If a vendor claims to manufacture heavy machinery but their registered address is a small residential storefront, that's an immediate red flag.
- Shipping and Customs Data: Analyzing bills of lading (BoL) and import/export records (available through commercial databases) to trace the actual movement of physical goods. This can reveal if a 'manufacturer' is actually just a heavy importer of finished goods.
- Digital Footprinting: Analyzing a company's web presence, job postings, and employee profiles (e.g., LinkedIn). Are they hiring engineers and machinists, or just sales and logistics staff? Does their website infrastructure share IP addresses or hosting providers with known prohibited entities?
A Hypothetical but Practical Example: The "Domestic" Switch
Last year, we encountered a vendor offering a highly specialized and difficult to source electronic switch at a surprisingly low price, claiming full domestic assembly to satisfy Buy American Act (BAA) requirements. Their SAM.gov profile was flawless.
Applying basic OSINT techniques, we looked past the SAM.gov profile:
- Geospatial check: We looked at the address listed for their manufacturing facility. The satellite imagery showed a small, generic warehouse bay, not a facility equipped for electronics assembly.
- Shipping records: A quick check of import records associated with their corporate name revealed regular, large shipments of "finished electronic switching components" from a region with known supply chain risks.
- Digital footprint: Their career page only listed openings for "Logistics Coordinators" and "Account Managers"—no assembly technicians or quality control engineers.
The conclusion was clear before a single dollar changed hands: they were likely importing finished goods, repackaging them, and falsely certifying them as domestic. By taking 45 minutes to apply these techniques, we avoided a potentially disastrous compliance violation.
Building an OSINT Capability
Implementing OSINT in procurement doesn't require hiring ex CIA and intelligence operatives. It requires a shift in mindset and equipping existing buyers and operations staff with new tools and training.
There are "CEOs" of government contracting businesses bragging on social media podcasts about winning contracts they never felt qualified for and were worried they would not be able to properly fulfill.
Many examples for my argument can be made. Ultimately this is why the financial threshold on what consitututes as a small business has been raised.
Don't make me rehash the recent reflecting pool debacle. What a mess. And yes, Mistakes do happen...
But... We need to stop asking, "Do they have the right paperwork?" and start asking, "Does the public footprint of this company align with the capabilities they claim to possess?"
Megan French
Operations Specialist
Megan specializes in bridging the gap between factory floor operations, digital systems research, and federal procurement logic. She writes regularly on supply chain friction and operational resilience.
View Full Profile