
Evaluating Lead Vendors · October 4, 2026 · GrowthPros
How to verify a vendor?
Learn how to verify a lead vendor before you buy. This 5-point framework covers consent records, exclusivity, fraud checks, and pilot testing to cut TCP...

Key Facts
- Vendor fraud targeting jumped from 47% of companies in 2023 to 69% in 2024, per Trustpair's fraud research.
- A lead buyer faced $126M–$379M in potential TCPA exposure for 252,765 calls its vendor made, according to case analysis.
- The FTC's $45M MediaAlpha settlement made 'conscious avoidance' of a partner's unlawful conduct itself a violation, per FTC guidance.
- Roughly 70% of companies still validate vendors with manual callbacks, yet only 8% check credentials across all procurement stages, Trustpair found.
- A $50 lead closing at 5% costs $1,000 per job; a $150 lead at 25% costs $600, industry math shows.
- BEC and imposter email scams are the top fraud approach at 63%, up 103% year over year, according to Trustpair.
- 62% of network intrusions originate with a third party, making continuous vendor monitoring essential, per Bitsight's framework.
The Hidden Liability of Buying Leads: Why Verification Is Now Self-Defense
Most businesses treat vendor verification as paperwork. In 2025, it's self-defense — because when your lead vendor breaks the law, you pay the settlement.
The threat environment has shifted fast. According to Trustpair's 2025 fraud research, 69% of companies were targeted by vendor fraud in 2024, up sharply from 47% in 2023. More than half of US companies now face at least one vendor fraud attempt annually, and 12% see more than ten attempts a year, per Creditsafe survey data. Yet roughly 70% of companies still rely on manual callbacks and emails to validate vendors — methods one treasury expert bluntly says "don't work against such convincing schemes."
For lead buyers specifically, the stakes go beyond fraud. They extend to inherited legal liability for how every lead was generated.
Consider Braver v. NorthStar Alarm Systems. Over nine months, a lead vendor made 252,765 non-consensual soundboard calls on the buyer's behalf. NorthStar never placed a single call itself — yet courts found liability under agency, apparent authority, and ratification theories, exposing the company to $126M–$379M in potential TCPA statutory damages. The vendor's conduct became the buyer's balance-sheet problem.
Then in August 2025, the FTC removed any remaining ambiguity. Its $45M MediaAlpha settlement established that "conscious avoidance" of a partner's unlawful conduct is itself a violation. The FTC's language is worth reading twice: "A company can't avoid responsibility for deception it facilitates by intentionally burying its head in the sand." Not knowing is no longer a defense — it's the offense.
This creates an uncomfortable asymmetry for buyers:
- You cannot directly observe what the consumer saw, how consent was captured, or where the lead originated
- Even reputable vendors may unknowingly resell leads from deceptive upstream sources
- Regulatory protections are shrinking — the FCC's one-to-one consent rule was vacated in January 2025 and formally repealed that July
- The burden of proof sits with you when regulators come calling
That's why the practitioner's framing from the NorthStar analysis cuts so deep: when you ask whether a lead company is legit, you're asking whether you're comfortable being its co-defendant. Or, as the same source distills the prioritization: "Exclusivity determines your close rate, consent determines your liability."
The practical implication is that verification must happen before the first invoice, not after the first complaint. That means demanding a documented consent trail — timestamped records showing the disclosure text, IP address, and named contacting party for every individual lead — and treating any hesitation as disqualifying. A vendor running its own funnel can produce that certificate; a reseller marking up network leads cannot.
This is the standard GrowthPros builds into every lead it delivers: each one arrives with its consent record attached — disclosure text, timestamp, IP address, and named contacting party — because a lead you can't prove consent for is a liability you haven't been billed for yet.
The sections ahead walk through exactly how to run these checks, from registry searches to pilot testing. The FTC has made clear that unlawful lead generation is a priority enforcement area. The only question is whether your verification process reflects that reality.
Why Most Buyers Verify Wrong: Manual Checks Can't Catch Modern Lead Fraud
If your vendor verification process is a phone call, a quick email exchange, and a glance at a website, you are not verifying — you are hoping. And the data says hope is exactly what most buyers are running on.
According to Trustpair's 2025 fraud report, nearly 70% of companies still rely on manual methods like human callbacks and emails to validate vendors, while only 31% use an automated validation tool. Even more striking: only 8% of companies check supplier credentials across all procurement stages. That gap exists while vendor fraud targeting jumped from 47% of companies in 2023 to 69% in 2024.
Manual checks fail because modern fraud is built to survive them. A polished website, a friendly sales rep, and a plausible invoice are table stakes for a bad actor. Treasury expert Lee-Ann Perkins puts it bluntly in the Trustpair research: "These normal routines don't work against such convincing schemes and savvy fraudsters."
Lead generation fraud adds a second, harder problem: it is structurally invisible to the buyer. As ActiveProspect's analysis of lead generation fraud explains, buyers cannot directly verify what the consumer actually saw, how consent was obtained, when the lead was submitted, or where it originated. You receive a name and a phone number. Everything that matters about that lead happened upstream, out of your sight.
That means a callback to your vendor confirms nothing about the lead itself. The checks that actually matter are ones manual processes rarely touch:
- The exact time and location where each lead was collected
- The form and consent disclosures the consumer was shown
- The authenticity of the lead data itself
- Whether your vendor verifies its own upstream lead sources
That last point is the one most buyers miss entirely. Even a reputable vendor may unknowingly resell leads from deceptive upstream networks. Your partner can be honest while their supply chain is not — and the liability still lands on you.
The legal exposure is not theoretical. In Braver v. NorthStar Alarm Systems, a lead buyer faced potential TCPA exposure of $126M–$379M for more than 252,000 non-consensual calls it never made. And the FTC's $45M MediaAlpha settlement established that "conscious avoidance" of a partner's unlawful conduct is itself a violation. Not asking questions is no longer a defense — it is the offense.
This is why verification has to extend through the vendor's entire supply chain, not stop at the contract signature. At GrowthPros, every lead ships with its consent trail attached — disclosure text, timestamp, IP address, and the named contacting party — precisely because a buyer should never have to take consent on faith. If a vendor cannot produce a per-lead consent record, no amount of manual checking will protect you.
The uncomfortable conclusion: the way most buyers verify vendors was designed for a fraud landscape that no longer exists. Modern verification demands documented consent trails, automated validation, and scrutiny of everyone who touched the lead before it reached your CRM.
The Five-Point Vendor Verification Framework
Vendor fraud jumped from 47% of companies targeted in 2023 to 69% in 2024, yet only 8% of companies check supplier credentials across all procurement stages — a gap that costs buyers dearly when the vendor in question is a lead company. Because you inherit your vendor's legal liability, verification can't be a rubber stamp. It needs to be a structured, five-point process completed before the first invoice.
1. Confirm legal existence and enforcement history. Start with the public record: corporate registries (Secretary of State or Corporations Canada), WHOIS domain age, FTC case dockets, state attorney general press releases, and court records on PACER or CanLII. The FTC's $45M MediaAlpha settlement made clear that "conscious avoidance" of a partner's unlawful conduct is itself a violation — meaning you can't outsource your diligence to the vendor. A company with a two-week-old domain and no registry footprint deserves scrutiny before it earns your pipeline.
2. Demand a documented consent trail for every lead. This is the single most important check for a lead vendor. Ask for timestamped consent certificates showing the exact disclosure text, collection time, and IP address for individual leads — and treat refusal as disqualifying. A reseller marking up network leads will "promise to get that from the team," send a screenshot instead of a certificate, or claim certificates aren't needed in your niche. None of those is a yes. In Braver v. NorthStar Alarm, a lead buyer faced $126M–$379M in potential TCPA exposure for calls its vendor made. Every lead GrowthPros delivers carries its consent record attached — disclosure text, timestamp, IP, and the named contacting party — because that documentation is what separates a defensible pipeline from a liability.
3. Verify real exclusivity in writing. "Exclusivity determines your close rate, consent determines your liability." Distribution caps vary wildly across marketplaces — some platforms send leads to up to four buyers, and others specify no cap at all. If a vendor claims exclusivity or a low cap, get the number in the contract, not the sales deck.
4. Validate payment details and beneficial ownership before the first invoice. Nearly 70% of companies still rely on manual methods like callbacks for bank account validation, even though vendor impersonation and account takeover are among the most common fraud types. Confirm who actually owns the entity you're paying — and re-verify immediately if payment details ever "change."
5. Tier your diligence by risk. Verification should be proportional to vendor criticality: a lead vendor feeding your sales pipeline warrants deeper checks than a one-off software subscription. And it doesn't stop at onboarding — 62% of network intrusions originate with a third party, so continuous monitoring and periodic reverification are now part of the job.
Run all five checks before you sign, and you're no longer hoping your vendor is legit — you know whether you're comfortable being its co-defendant.
Pilot Before You Commit: Test ~20 Leads and Measure Unit Economics
Every verification framework in the world collapses if you skip the one step that actually tests performance: buying a small batch of leads and watching what happens. Paperwork tells you who a vendor claims to be — a 20-lead pilot tells you what they actually deliver.
According to practitioner guidance on vetting lead companies, the standard test is roughly 20 leads, measured on four metrics that reveal far more than any sales deck:
- Connect rate — how many leads answer or respond at all. A low connect rate signals aged, recycled, or fabricated data.
- Recall rate — how many contacts remember submitting the form. If they don't recall opting in, consent likely never happened — and that's your liability, not just the vendor's.
- Fit rate — how many leads actually match your niche, geography, and qualification criteria.
- Actual exclusivity — whether "exclusive" leads are also being worked by your competitors. Shared marketplaces distribute leads to as many as four or five buyers, so verify the cap, don't assume it.
The recall metric deserves special weight. You cannot independently verify what a consumer saw or when they submitted a form — lead generation fraud is structurally hard to detect for exactly this reason. Asking contacts directly whether they remember opting in is one of the few ground-truth checks available to you.
The most common buying mistake is optimizing for cost per lead. The math from industry analysis makes the point bluntly: a $50 lead closing at 5% costs you $1,000 per acquired job, while a $150 lead closing at 25% costs $600. The cheaper lead is the more expensive one — and the difference is exclusivity and speed.
Run your pilot numbers through the same formula: total pilot spend divided by jobs closed. That figure — cost per acquired job — is the only number that should drive your renewal decision. It's also the logic behind GrowthPros' model: exclusive and capped-shared leads (a hard maximum of two buyers, never five) with AI follow-up inside five minutes, because response speed and exclusivity are what move close rates, not sticker price.
Before your pilot converts to a contract, do the contract math. Vendor-vetting guidance warns that a 12-month term with a 90-day notice requirement is effectively a 15-month lock-in — you must decide to leave three months before you've seen a full year of performance. A generous refund clause means little if the term keeps you paying long after the leads stop performing.
This matters more than ever because the consequences of a bad vendor extend beyond wasted budget. The FTC's $45M MediaAlpha settlement established that "conscious avoidance" of a partner's unlawful conduct is itself a violation — and in Braver v. NorthStar Alarm, a lead buyer faced $126M–$379M in potential TCPA exposure for calls its vendor made. A pilot with clean consent records, verified exclusivity, and honest unit economics is your evidence that you looked before you signed.
Verification Never Stops: Ongoing Monitoring and the Questions to Ask on Day One
The biggest mistake in vendor verification is treating it as a gate you pass once. The vendors most likely to burn you are the ones you stopped checking after onboarding.
The research consensus is clear: verification is a lifecycle discipline. Multiple frameworks — from procurement security specialists to Thomson Reuters' "know your vendor" guidance — converge on the same two-phase model: initial verification before contracts, then continuous reverification after. KYV, as Thomson Reuters puts it, is now as crucial as KYC.
Three practices close the loop. First, re-verify on any payment-detail change. Vendor impersonation and account takeover rank among the most common fraud types, and a "we've updated our banking details" email is the classic attack vector — BEC and imposter email scams are the top fraud approach at 63%, up 103% year over year, according to Trustpair's 2025 fraud report. Manual callbacks alone won't save you; roughly 70% of companies still rely on them, and fraudsters count on it.
Second, verify the vendor's vendors. Fraud risk extends through the supply chain — even reputable partners may inadvertently buy leads from deceptive upstream sources, per ActiveProspect's analysis of lead generation fraud. Ask directly: does this vendor conduct due diligence on its own subcontractors and lead sources?
Third, tier your monitoring by risk. Bitsight's due diligence framework recommends continuous monitoring with more frequent reviews for critical vendors — those whose failure disrupts your operations or who touch your customer data. A vendor feeding leads into your CRM qualifies.
The day-one question set. Before the first invoice, ask:
- Can you produce a consent certificate for an individual lead — timestamp, disclosure text, IP address, named contacting party? A reseller that can't will stall, send a screenshot, or claim certificates aren't needed. None of those is a yes.
- What is the hard cap on lead sharing — in writing? "Shared" marketplaces distribute to four or more buyers; ask for the number.
- Are lists DNC-scrubbed before outbound contact, and how are opt-outs handled across channels?
- How fast does follow-up happen after a lead submits — and who does it?
The consent question carries the most weight. The FTC's position after its $45M MediaAlpha settlement is explicit: a company can't avoid responsibility by "intentionally burying its head in the sand" about a partner's conduct, per the FTC's own business guidance. Conscious avoidance is itself a violation — which makes documented consent your only real defense.
This is the standard GrowthPros holds itself to: every lead carries a consent record — disclosure text, timestamp, IP address, and the named contacting party — and capped-shared means a hard maximum of two buyers, never five. Lists are DNC-scrubbed before any contact, and every lead gets AI voice, SMS, and email follow-up inside five minutes.
If you're evaluating lead vendors — or questioning the one you have — book the 15-minute qualification call or submit the get-started funnel. It's free, honest about fit, and commits you to nothing. Ask us the day-one questions. We built the company to answer them.
Frequently Asked Questions
Why do I need to verify a lead vendor if they're the ones breaking the rules?
Because you inherit their liability. In Braver v. NorthStar Alarm, a lead buyer faced $126M–$379M in potential TCPA exposure for 252,765 calls its vendor made — and the FTC's $45M MediaAlpha settlement established that 'conscious avoidance' of a partner's unlawful conduct is itself a violation. Not knowing is no longer a defense.
What's the single most important thing to ask a lead vendor for?
A documented consent certificate for an individual lead — showing the disclosure text, timestamp, IP address, and named contacting party. A vendor running its own funnel can produce this; a reseller marking up network leads will stall, send a screenshot, or claim certificates aren't needed, and none of those is a yes.
Can't I just verify a vendor with a phone call and a look at their website?
No — manual checks are built for a fraud landscape that no longer exists. Roughly 70% of companies still rely on callbacks and emails, yet vendor fraud targeting jumped from 47% of companies in 2023 to 69% in 2024, per Trustpair's 2025 fraud report. A polished website and friendly rep are table stakes for a bad actor.
How can I tell if 'exclusive' leads are actually exclusive?
Get the distribution cap in writing — in the contract, not the sales deck. Shared marketplaces distribute leads to as many as four or five buyers, and some specify no cap at all, according to industry analysis of lead marketplace terms. During a pilot, ask contacts directly whether competitors have already called them.
Should I test a lead vendor before signing a contract?
Yes — buy roughly 20 leads and measure connect rate, recall rate (do contacts remember opting in?), fit rate, and actual exclusivity. Then judge cost per acquired job, not cost per lead: a $50 lead closing at 5% costs $1,000 per job, while a $150 lead closing at 25% costs $600, per practitioner vetting guidance.
Is vendor verification a one-time check before signing?
No — it's a lifecycle discipline. Experts recommend initial verification plus continuous reverification, since 62% of network intrusions originate with a third party. Re-verify immediately on any payment-detail change, and ask whether your vendor vets its own upstream lead sources — even honest partners can resell leads from deceptive networks.
Verify First, Buy Second: Your Pipeline Depends on It
The math is unforgiving: vendor fraud targeting jumped from 47% of companies in 2023 to 69% in 2024, and a lead buyer in Braver v. NorthStar Alarm faced up to $379M in potential TCPA exposure for calls it never placed. The five-point framework, the 20-lead pilot, and continuous reverification all serve one purpose — proving you looked before you signed, because the FTC has made it clear that burying your head in the sand is itself a violation. Start this week: run the registry and enforcement checks, demand a per-lead consent certificate from your current vendor, and treat any hesitation as your answer. When evaluating lead vendors, remember that exclusivity determines your close rate and consent determines your liability. GrowthPros was built around that standard — every lead arrives with its consent record attached, followed up by AI voice, SMS, and email inside five minutes. If you're questioning the vendor you have, book the 15-minute qualification call or submit the get-started funnel. It's free, honest about fit, and commits you to nothing — except asking the questions that protect your pipeline.
This article is general information, not legal or financial advice. Benchmark figures are directional industry data, not guarantees of results.