Supplier onboarding is not a one-time event. Once a supplier is on the register, a certificate expires, the signing representative changes, another group company joins, a service condition is amended, or an instruction arrives to change the bank account. Each of those events opens work at the same time in procurement, in the team that maintains supplier master data, and in the functions that must review their own requirement.
The file gets pulled together from whatever is already in use: a Microsoft Excel form the supplier emails back, attachments dropped into Microsoft SharePoint under whatever name the uploader picked, and a side spreadsheet where someone tracks expiry dates. Each of those does a useful job on its own, and not one of them records which requirement was missing, who reviewed it, or under whose authority the change was posted.
The supplier ends up sending the same document twice, the buyer cannot tell whose review is holding things up, and the change gets posted because someone asked for it by email.
The risk is not the missing document. It is the change already sitting on the register that no one can account for: who reviewed it, who authorized it, and how its origin was verified.