Product

Upgrade Your MSME's Standards For Anchor Buyers With Vendor Readiness Assessment

A consent-first, evidence-based pre-screening for MSMEs positioning for anchor buyers. Here is what the intake asks, why every field is there, and what happens after you hit submit.

NA
Nitisagar Advisory
31 August 2026
VRAMSMEVendor Screening
Vendor Readiness Assessment intake and verification flow: nine-step consent form to independent registry checks to two-reviewer signed PDF report

Most Indian MSMEs still pitch anchor buyers with a self-declared PDF and a phone call. You send across a capability deck, a few certificate photocopies, an EPFO number that may or may not be current, and a signed cover letter. When a discrepancy shows up, it usually shows up six months in, on the shop floor.

We built the Vendor Readiness Assessment (VRA) as your alternative. It is a structured pre-screening where we check every declaration you make against an independent source before we issue a report. Our intake form is now live.

This post walks you through what we ask on the form, why we ask it, what we do after you hit submit, and how we handle your data under the DPDP Act.

What VRA is for

A VRA report is not a certification. It is an independently verified snapshot of your MSME’s readiness against a defined checklist. You choose whether we issue it to a named buyer or hold it for buyers generally. Every report we issue carries a two-reviewer sign-off, a SHA-256 fingerprint, and a public verification URL, so your buyer can confirm the copy they received is the copy we issued.

A chartered accountant’s certificate says “this figure is what the client told us.” Our VRA report says “here is what you declared, and here is what the independent registry actually shows.” A discrepancy is not the end of the process. We treat it as a category of finding, grade it by severity, and give you a chance to reconcile it before we finalise the report.

Sample Vendor Readiness Assessment report cover, Kamrup Precision Systems, Silver tier, composite score 83.1
Cover page of a sample VRA report. Tier, composite score, and per-axis scores stated up front.
VRA tier scale showing Platinum, Gold, Silver, Bronze bands and what each means for a procurement reader
The tier scale is our own four-level readiness heuristic. It is not a credit rating and not a certification level.

Your intake submission is where that whole verification chain starts.

The nine steps, and why we ask each one

We built the intake as a nine-step form. It is longer than a typical lead form on purpose. Every field you fill feeds a downstream gate check, a scoring input, or your consent audit trail. We don’t collect anything for marketing or funnel analytics.

VRA intake form step 1 of 9 showing itemised DPDP consent checkboxes for source verification against GSTN, MCA, EPFO
Step 1 of the intake. Itemised DPDP consent, nothing pre-ticked.

Step 0. Consent and contact. You tick four separate itemised checkboxes covering source verification, directors’ data, sharing with the buyer, and retention. Under DPDP §6, a general “I agree” will not cover the shape of processing we do here. We record your name and designation as the signatory of record for the consent version you agreed to.

Step 1. Entity and process family. You give us your legal name, entity type, CIN or LLPIN, PAN, and one of three process families: EMS/electronics, precision mechanical, or process/chemicals. The process family you pick decides which operational checklist we bring to the site visit.

Step 2. Related-party disclosure. List every entity where a director, partner, or proprietor of your business also holds a comparable role. If we surface an undisclosed relationship later, it becomes a Gate G9 finding, our disqualification gate for undeclared common control. That is the pattern anchor buyers most want us to catch.

Step 3. Promoters, directors, partners. Full name, role, PAN, and DIN for directors. We don’t collect this to display in your report (we don’t show it). We use it for two things: an MCA director-disqualification lookup, and a PAN-collision scan across every VRA applicant to date. Without that scan, Gate G9 is not enforceable.

Step 4. GST, Udyam, EPFO, turnover. Give us every GSTIN under your entity’s PAN, not only the principal one. We aggregate turnover verification across all of them.

Step 5. Certifications and insurance. ISO 9001, IATF 16949, ISO 14001, ISO 45001. We check every certificate you declare against its accreditation body’s public register. We do not accept it on the serial number alone. The certificate-mill problem is real, and the register lookup is how we filter it.

Step 6. Facility. Give us the address of your operating facility (which may or may not match your registered office), the built-up area, and a process-family-specific note on what we will check at the site visit.

Step 7. Workforce. Own-roll headcount, and separately, contract labour with the contractor’s own EPFO code. We verify contract labour against the contractor’s EPFO filings, not yours. Most self-declaration formats collapse that distinction.

Step 8. Documents and submit. Upload your redacted audited financials, lease deed, and certification copies, plus a free-text field for anything you want to flag to the analyst. Turnstile runs invisibly while you review the last step. As soon as you hit submit, we return your assessment reference number.

Start the Vendor Readiness Assessment intake  →

Or download the full sample report (PDF, 8 pages) first.

What happens after you hit submit

The moment we accept your submission, three things start in parallel.

You get a confirmation email in your signatory inbox with your assessment reference number. We start machine verification against every registry we can query without needing you online: GSTN through a GST Suvidha Provider, MCA director records, EPFO establishment lookups, certification accreditation registers. Any checkpoint that resolves against a live source, we score automatically. Anything that fails or comes back inconclusive, we queue for the analyst.

VRA readiness profile showing composite score dial and radar chart across Axis A and Axis B domain scores
Section 2 of the report. The composite dial with the tier band, plus a radar of all thirteen domain scores.
VRA domain findings for Axis A showing legal entity verification, tax registration, financial stability with evidence-confidence bars
Every domain score comes with a plain-English finding and a bar showing how much of it rests on machine-verified evidence.

We assign a Nitisagar analyst to your case within two business days. Your analyst reviews the machine-verification output, asks you for anything missing, and schedules the facility visit. We share discrepancies with you before the site visit, not after, so you get a chance to reconcile them. That covers cases like a self-declared headcount that does not match EPFO within tolerance, a certificate that is not on the accreditation register, or a related party we surfaced through the PAN scan.

VRA verification and discrepancy summary listing checkpoint, severity grade, finding, and reconciliation status for each source-checked item
Section 5. We list every check we ran against an independent source, whether it matched or not. An unresolved medium flag caps your tier at Silver. An unresolved high flag caps it at Bronze.
VRA hard-gate checks: ten disqualification gates covering GST, MCA, director conduct, Udyam, facility verification and court records
Section 6. Ten hard gates. Each one can disqualify you on its own, and your score cannot buy back a tripped gate.

We issue your report only after two reviewers sign off: the lead analyst who ran the fieldwork, and a second reviewer who did not. We register a SHA-256 fingerprint against the final PDF at issuance, and we publish it on a public verification URL. Your buyer can recompute the hash and confirm it matches. A forged or edited copy fails the check.

VRA assessment basis and sign-off page showing sources consulted, method limits, recheck schedule and two-reviewer integrity block
Section 7. Sources we consulted, our method and its limits, and the recheck schedule your downstream buyer relies on.

The DPDP posture

Because we collect director PAN, DIN, signatory identity, and your consent to independent verification, this form is DPDP-sensitive by design. Here are the concrete choices we made to reflect that.

Consent, itemised

We split consent into four separate checkboxes, each covering a distinct purpose (verification against sources, directors’ data processing, sharing with a named buyer, retention). We do not pre-tick any of them. We record the consent version identifier (VRA-CONSENT-1.0 today) against your submission, so you can always reproduce the exact wording you agreed to. Read the full Consent Notice at nitisagar.com/legal#vra-consent.

No analytics on the intake page. We do not load Google Tag Manager, Consent Mode, or any third-party tag on the form. Your data flows to Nitisagar and Cloudflare only.

Data minimisation on uploads. Step 8 spells out what you should redact before you upload. For audited financials, keep the summary schedules and strip out salary registers and bank account numbers. For your lease deed, keep the first page and the signature page and strip out witness Aadhaar. For certificate copies, keep the certificate face and strip out internal audit reports and auditor identity pages. If unredacted PII reaches us, the analyst returns it or scrubs it before it lands in our store.

Storage limitation, explicit. We retain your assessment working data for 24 months from issuance. We retain issued reports, consent records, and audit logs for 8 years under Income Tax and evidence-rule obligations. You can request erasure at any time. Where a legal retention obligation applies to a record, we retain the minimum the law requires and honour the balance of your request. Your canonical channel is our Data Rights page.

Signatory identity in the consent record. A consent decision without a signatory is a signature nobody can trace. We record your name, your designation, and the timestamp of your click alongside the four confirmations. That record is what proves, later, that a specific person authorised the processing on a specific version of the wording.

If you want the longer-form treatment of how we move client data through Nitisagar generally, our earlier post How Nitisagar Handles Your Data walks you through the eight-stage engagement flow, device controls, banned channels, and offboarding.

Who should apply now

We built VRA for MSMEs positioning for anchor procurement pipelines where the buyer already has, or is about to have, a formal supplier-qualification bar. Concretely, that means you if you are:

We price the report flat, disclose it up front, and do not vary it with the outcome. You will see our fee-independence statement on the cover page of every report we issue.

Start the intake

Our form is at nitisagar.com/vra/intake. Budget about 25 minutes if you have your GSTIN list, PAN details, and one recent audited financial to hand. We do not offer save-and-resume in this beta. The form runs in memory only, so please complete it in one sitting.

If you want to see the deliverable before you commit to the intake, grab our full sample report (PDF, 8 pages). Kamrup Precision Systems, all names and figures fictitious.

If a question in the intake does not apply cleanly to your entity type (proprietorship, LLP, partnership), or if you want to talk to us about the report before you start, write to [email protected].


Nitisagar Advisory (OPC) Private Limited is a DPIIT-recognised policy advisory and MSME facilitation firm focused on Northeast India’s electronics and manufacturing ecosystem. The Vendor Readiness Assessment is our supplier pre-screening product. Our Assam MSME subsidy calculator covers live incentive schemes.

The moves that matter, before they cost you

Northeast India's industrial policy shifts faster than the trade press covers it. Every new report, briefing, and analysis in your inbox — original reporting, no syndicated fluff.

Withdraw anytime via the unsubscribe link in any email or by writing to [email protected]. See our Privacy Notice for how we handle your data under the Digital Personal Data Protection Act, 2023.

Related content
Ready to claim what's yours?

We'll map your project against IIPA 2019 and Assam's incentive stack, complimentary, no commitment.

Get a Free Pre-Assessment