One-time onboarding was built for a slower kind of criminal, and a unanimous Supreme Court ruling in May raised the cost of relying on it.
A carrier packet answers one question: was this company acceptable on the day someone reviewed it. The load tendered eight months later asks a different question entirely, and most vetting processes were never built to answer it.
An operating authority can be revoked and re-formed under a new LLC. Insurance lapses between renewals. Phone numbers and email domains change hands. A motor carrier number with a clean history and a long record of delivered freight is a valuable thing to steal, which is why people steal them, and the theft is invisible to anyone checking the same number against the same public record that the thief has already updated.
Onboarding tells you who you approved, and the load tells you who showed up.
The FBI documented that last part directly in its April warning on cyber-enabled cargo theft, which describes attackers altering a compromised carrier's FMCSA registration and insurance records so the credentials continue to check out while someone else operates behind them. A file review confirms the paperwork. It cannot confirm that the paperwork still belongs to the company that filed it.
The market has priced this in. Carrier onboarding and risk monitoring has gone from a back office chore to an acquisition target, with Descartes paying $24 million upfront for MyCarrierPortal in 2024, plus a $6 million earnout, specifically to build out what the industry calls know-your-carrier capability.
The tooling has sorted itself into two jobs. Platforms like RMIS and MyCarrierPortal, the latter formerly MyCarrierPackets, do the work of digitizing the packet itself, so W-9s, signed agreements and insurance certificates are collected, stored and monitored in one place instead of chased across email. Highway, which launched in 2022, built around continuous identity, checking that the carrier behind a number today is the one that signed the original agreement. Those are not competing answers to one question. They are answers to two questions, and an operation that has solved the first has not necessarily touched the second.
The stakes changed in May: the Supreme Court held unanimously in Montgomery v. Caribe Transport II that state-law negligent hiring claims against freight brokers are not preempted by federal law, and brokers spent the summer reassessing which carriers they would hire at all. A defense that rests on having checked a carrier once, at intake, in a file nobody has opened since, is a weaker defense after that ruling than it was before it.
A signature on a packet is a moment. The liability runs for the life of the load.
That reframes verification from a cost center into something closer to documentation. The question is no longer whether a carrier cleared a threshold at some point in the past, but whether a company can show what it knew about that carrier at the moment it handed over the freight. Those are different records, and only one of them is useful when someone is reconstructing a decision after a loss.
None of this removes the need for judgment. It changes what judgment operates on, because reviewing a static file once a year is a different act from asking whether this load, today, is going to the carrier it was tendered to. The second is harder. It is also what shippers and insurers have started to expect, and what an adverse ruling will measure a broker against.
We treat carrier and broker identity as a rolling obligation rather than an intake step, which is the same reasoning behind how we handle counterparty verification on every load and the protocol we apply to high-value freight. The cost of that discipline is real and it is paid on every transaction. The cost of the alternative arrives all at once, usually in a deposition.




.png)
