The GST or HST Registry is the CRA’s official lookup tool for confirming whether a supplier’s tax registration is active for a given date. It is used to validate the registration number, business name, and tax status before claiming input tax credits. This makes it a core evidence source for tax due diligence.
What the GST/HST Registry Does
The GST/HST Registry is a verification tool, not a tax filing system. Its purpose is to help a buyer confirm that a supplier’s registration number, legal name, and active status match the date on which tax treatment matters.
That date-specific check is important because a registration can be active at one point in time and inactive later. The registry therefore supports evidence-based due diligence before an organisation treats charged tax as eligible for input tax credits.
Why Registry Verification Matters
Registry checks help reduce avoidable tax and accounting errors when organisations rely on supplier invoices. If a supplier is not properly registered on the relevant date, claiming credits on the assumption that the registration existed can create downstream compliance and recovery issues.
The registry also helps detect mismatches between what a supplier presents on an invoice and what the CRA records show. That makes it a practical control for procurement, accounts payable, and tax review workflows where evidence quality matters more than trust in the invoice alone.
How the Registry Should Be Used
The key practice is to verify the supplier against the registry at the right point in time, then retain the lookup result as part of the transaction record. A valid business name match, a valid registration number, and an active status together form stronger evidence than any one field on its own.
Because tax status can change, organisations should treat the registry as a point-in-time source of truth. For high-volume purchasing, the check is often most useful when paired with vendor onboarding controls and invoice validation rules, so that exceptions are caught before payment or credit claims are finalized.
Common Misunderstandings About the Registry
A common mistake is to assume that a registration number alone proves current validity. Another is to assume that a supplier’s own invoice language is enough to establish eligibility for input tax credits without independently checking the official registry.
It is also easy to overlook timing. A supplier may have been registered when first onboarded but not when a later invoice was issued. The registry is only useful when the lookup date aligns with the tax event being evaluated.
Risk and Threat Considerations
Misuse of the registry usually creates compliance and recovery risk rather than direct cyber risk. The main exposure is relying on stale, incorrect, or unaudited supplier information and then supporting a tax position that cannot be defended if questioned.
Failure mechanism: Teams rely on invoice text, a cached vendor record, or an outdated lookup instead of verifying the supplier’s registration status for the specific transaction date. That can allow invalid input tax credit claims or mask supplier-record mismatches.
Impact: The organisation may face denied credits, rework, audit findings, payment corrections, or broader control weakness in accounts payable and tax due diligence.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | Registry use supports tax due diligence and evidence handling in business operations. |
| Recommendation — Define registry-check ownership and align it to the transaction controls that depend on it. | ||
| NIST SP 800-53 Rev 5 | AU-10 — Non-repudiation | Point-in-time registry evidence supports defensible transaction records and auditability. |
| Recommendation — Retain lookup evidence with the invoice record so the tax decision can be audited later. | ||
| ISO/IEC 27001:2022 | A.5.33 — Protection of Records | Registry results are records that must be retained to support tax due diligence and review. |
| Recommendation — Protect and retain registry lookup records as part of the transaction evidence set. | ||
| GDPR | A.8.10 — Information deletion | If registry evidence contains personal data, retention must be limited to the documented purpose. |
| Recommendation — Limit retention of any personal data in lookup evidence to the period needed for the tax purpose. | ||
Practitioner Guidance
Why practitioners should care: The registry is most valuable when it is treated as a controlled evidence source, not a one-time onboarding check. For finance and tax teams, the question is whether the lookup result is captured, time-stamped, and tied to the exact invoice or purchase event being reviewed.
What to watch for: Watch for expired lookups, name mismatches, and manual overrides that bypass the registry check. Those are the conditions most likely to undermine defensibility when input tax credits are later reviewed.