Industry Solutions

Business Credit Data APIs: The Definitive Guide for Commercial Lenders

How lenders access business credit data through one API: which bureaus, which scores, what public records, and how commercial pulls stay FCRA compliant.

CRS Credit Experts

February 25, 2026

Last updated: August 2026

Commercial lenders need more than a score. They need the business file, the owner file, and the public records behind both. And they need it fast enough to decide while the applicant is still engaged. This guide covers how that data is accessed and what each source provides. It also covers what changes when the data arrives through one integration.

Key takeaways

  • A business credit data API returns commercial credit files, scores, and public records in real time.
  • Business credit lives across several sources, so no single bureau holds a complete picture of a company.
  • Small business files are often thin, which is why lenders pull owner credit alongside the business file.
  • Accessing commercial credit data requires a permissible purpose and provider vetting, whichever vendor you use.

What is a business credit data API?

A business credit data API delivers commercial credit reports, scores, and public records through a single request. Your underwriting platform sends a query and receives structured data back in seconds. Modern versions return the business file, owner credit, and risk signals together rather than separately.

The alternative is manual. An analyst logs into a bureau portal, orders a report, waits, then re-keys the result into the loan file. That works at low volume. It breaks down when a lender processes dozens of applications a day. Every manual step adds time and introduces transcription error.

An API removes both problems. The request happens inside your existing workflow. The response arrives in a structured format your system can read. Decision rules run against the data automatically. That makes outcomes consistent across analysts and creates a clean audit record.

Manual business credit check API access
Speed Portal logins, manual entry Real-time API call
Coverage One source at a time Business plus consumer and identity
Scale One at a time Automated, high volume
Format PDF reports JSON, XML, or PDF

Which business credit bureaus can you access?

Business credit is fragmented across several sources, and each one sees a different slice of a company behavior. Dun and Bradstreet tracks supplier payments. Experian and Equifax hold commercial tradelines and public records. FICO layers a blended score on top. No single source is complete.

That fragmentation is the central problem in commercial underwriting. A company can look strong in one bureau and thin in another, purely because of which vendors report where. Lenders who pull one source make decisions on partial information without knowing it.

Source Primary score Strongest for
Dun and Bradstreet PAYDEX Supplier and vendor payment behavior, tracked by DUNS number
Experian Business Intelliscore Plus Commercial tradeline depth and blended risk scoring
Equifax Business Business Delinquency Risk Score Delinquency prediction and financial account performance
FICO SBSS Blended business and owner risk for small business and SBA lending

Coverage varies by provider agreement. Confirm which sources and scores you can access before building decision rules around any single one.

Why the same business scores differently at each bureau

Reporting to commercial bureaus is voluntary. A supplier may report to one bureau and not another. So a company with strong payment history can look thin at a bureau its vendors do not report to. The gap reflects reporting coverage, not different risk.

This matters because the two situations look identical on a score. A thin file and genuinely poor payment behavior can produce a similar number. Lenders who read a low score at one source as a risk signal sometimes decline a sound borrower. The useful question is whether the file is sparse or the behavior is bad.

How each source identifies a business

Identification differs by source, and this is where pulls quietly fail. Dun and Bradstreet organizes around the DUNS number. Other commercial sources match on legal name, address, and tax identification number. A business trading under a name different from its registered name can match at one source and miss at another.

Multi-location companies and recent relocations raise the failure rate further. Supplying more identifiers up front reduces near-match errors. Those errors matter more than they sound. A wrong match does not return an error. It returns a real credit file for the wrong company, and nothing in the response flags it.

Which sources to pull for which decision

Match the source to what you are underwriting. Trade credit and supplier terms lean on payment behavior data. Term loans and lines of credit lean on delinquency prediction and tradeline depth. SBA and small business lending lean on blended scores that weigh the owner alongside the business.

Pulling every source on every application costs more and rarely changes the outcome. Pulling a single source on every application is cheaper and occasionally changes it badly. Most lenders settle on a primary source, then pull a secondary only on exceptions and edge cases.

What to do when a business has no file

No-hit and thin-file results are common on companies under three years old. That is a data gap, not a decision. The usual sequence falls back to the owner personal credit, then adds public records to check for liens and judgments.

A no-hit at one bureau also justifies checking a second before concluding the business has no history. Reporting coverage varies enough that absence at one source is weak evidence on its own. Where cash-flow data is available, it fills the remaining gap on companies too young to have built a commercial file.

How CRS handles the fragmentation

CRS aggregates commercial credit sources alongside tri-bureau consumer credit in one request. That removes the sequencing problem above. You do not pull one source, read it, then decide whether to pull another. The underwriter receives the available files together.

The response arrives in the CRS Standard Format. A thin file at one source and a full file at another parse identically. Your decision logic does not branch by bureau. As a licensed consumer reporting agency recognized by all three national bureaus, CRS handles credentialing with each source. The lender contracts once rather than negotiating separate agreements per bureau.

Business credit scores and what they actually measure

A business credit score is a numerical evaluation of a company likelihood to meet its financial obligations. It is derived from trade history, public records, and bureau data. Lenders, suppliers, and insurers use these scores to gauge creditworthiness, calibrate credit limits, and price risk.

Scores draw on trade lines, payment timeliness, credit utilization, collections, liens and judgments, bankruptcies, and UCC filings. Some models also weigh firmographics and financial statements. Strong business credit can unlock better financing terms and lower insurance premiums. Weak or limited history constrains growth and raises costs.

Commercial scores are not interchangeable. PAYDEX runs 1 to 100 and reflects payment timing against terms. Experian Intelliscore Plus and the Equifax Business Delinquency Risk Score both predict future delinquency, but on different scales. FICO SBSS runs 0 to 300 and blends business data with the owner personal credit.

Because the scales differ, a lender cannot treat one score as a substitute for another. A policy written around a PAYDEX floor will not translate to an Intelliscore cutoff. Teams that pull multiple sources need score-specific rules, not one universal threshold.

SBSS is the outlier worth understanding. It deliberately mixes personal and business inputs. That makes it useful on young companies with thin business files. For the full input breakdown, see how the SBSS score is calculated. For a plain-language primer, see what SBSS is and how lenders use it. For where the score is sourced and which access route fits, see where to get SBSS via API.

One regulatory note that still surprises lenders. The SBA discontinued its SBSS prescreening requirement for 7(a) Small Loans effective March 1, 2026. Many lenders kept the score anyway. Any floor you apply today is your own credit policy, not an SBA rule.

Why lenders pull business and personal credit together

Small business files are frequently thin. A company two years old may have only a handful of trade references. That is not enough to predict repayment on its own. The owner personal credit fills that gap. On many small business decisions it carries more predictive weight than the business file.

This is why most commercial underwriting pulls both. The business file shows how the company pays vendors and lenders. The owner file shows how the guarantor has handled personal obligations over a longer history. Read together, they tell you something neither tells you alone.

The operational problem is that these usually come from different places. Business data comes from commercial bureaus. Consumer data comes from the three national bureaus. Lenders end up matching an owner to an entity across two systems by hand. That is slow and error-prone on common names.

A business lookup can return principal names from the business record itself. Where those names are present, they reduce the manual matching work. See principal matching in business credit for where that linkage breaks down. See pulling business and personal credit for commercial lending for how that request is structured.

Public records, liens, and judgments in commercial underwriting

Public records surface risk that credit files miss. Tax liens, judgments, bankruptcies, and UCC filings show legal and priority claims against a business. A company can pay vendors on time and still carry a senior lien that changes your recovery position entirely.

UCC filings deserve particular attention in commercial lending. They reveal existing secured obligations, including advances a borrower may not disclose. For funders working with merchants who take multiple advances, UCC data is often the clearest early signal of stacking.

These records normally arrive as a separate purchase from a separate vendor. That fragmentation is why some lenders skip them on smaller deals. Those are exactly where undisclosed obligations tend to hide. CRS returns public record data alongside credit. UCC filings and secretary of state registration records return through the same API, sourced from LexisNexis. Coverage runs across all 50 states. The check happens in the same request, not as an extra step someone has to remember. For the full record picture, see public business records and credit in one place.

Verifying that a business exists and who controls it

Entity verification confirms the applicant is a real, registered business and that the person applying can act for it. This runs before credit. Catching a fabricated entity early costs far less than catching it after underwriting.

Verification typically checks state registration and standing, the tax identification number, and the operating address. It also confirms the identity of the owners or officers. Many lenders screen against OFAC and sanctions lists at this stage. A hit there ends the application regardless of credit quality.

The failure mode worth planning for is the near match. Business names repeat across states. A wrong entity match returns a credit file for an unrelated company. Good verification returns enough identifying detail to confirm you have the right business, not just a plausible one.

CRS returns identity verification and OFAC screening through the same integration as credit. LexisNexis supplies the underlying business registration and principal data. That keeps this from becoming a separate vendor relationship.

How business credit data drives underwriting decisions

Business credit data reaches its value when it feeds rules rather than analyst judgment alone. Most automated commercial underwriting applies tiered logic: approve within policy, refer for review, or decline. The data determines which path an application takes, and the rules keep that determination consistent.

Consistency is not only an efficiency gain. It is what makes decisions defensible under review. Two applicants with the same profile should get the same outcome. You should be able to show which rule produced it.

The practical build is straightforward. Pull the business file, the owner file, and public records. Apply thresholds for score, time in business, and existing obligations. Route the file. Record which rule drove the outcome. For the full workflow, see the blueprint for automated SMB loan underwriting. For SBA specifically, see automating SBA 7(a) underwriting. Merchant funding works differently, covered in APIs for merchant cash advance underwriting.

Underwriting does not end at funding. Scheduled re-pulls surface new liens, new debt, and score deterioration before a payment is missed. Batch monitoring runs those checks across a portfolio on a set cadence.

Compliance and permissible purpose in commercial lending

Accessing credit data requires a permissible purpose under the FCRA, and providers must vet you before granting access. For commercial lending, evaluating a credit application and reviewing an existing account both qualify. Consumer data on business owners carries the full set of FCRA obligations, including adverse action.

Lenders sometimes assume business data sits outside these rules. That assumption is risky. Most small business underwriting pulls the owner personal credit. At that moment you are handling consumer report data, and consumer protections apply.

Soft and hard inquiries behave differently here. A soft pull supports prequalification and account review without affecting the consumer score. A hard pull belongs at formal application. Getting that boundary right matters for both compliance and applicant experience.

Vetting is also what sets your timeline. The technical build is usually the fast part. Provider review and documentation of your use case set the pace. Some providers also require a site inspection. Plan for that sequence rather than discovering it late.

CRS is a licensed consumer reporting agency recognized by all three national bureaus. It guides FCRA vetting as part of onboarding. See how CRS handles compliance and what a credit reporting agency is for the underlying framework. SBA lenders can review the tri-bureau credentialing process specifically.

Direct bureau relationships compared with unified access

Lenders reach commercial credit data two ways. They contract with each source directly, or they access multiple sources through one provider. The right choice depends on volume, engineering capacity, and how many data types the underwriting model needs.

Direct contracts suit a lender who needs one source and has engineers to spare. Volume also has to justify the per-report economics. The cost is repetition. Each bureau means separate credentialing, a separate integration, and a separate response format to normalize.

Direct relationships with each source Unified access through one provider
Integrations to build One per source One total
Credentialing Separate process per bureau One process
Response format Differs by source One normalized format
Added data types Separate vendors for identity, fraud, public records Available in the same request
Ongoing maintenance Every source maintained independently Maintained by the provider

Narrow resellers sit between these. They simplify one workflow well and stop there. That works until the lender needs widen beyond that use case.

Integrating a business credit API

Integration follows a predictable sequence. Define the use case and document permissible purpose. Review the documentation and test in a sandbox. Implement authentication and parsing. Run compliance and regression tests. Connect the result to your CRM or loan origination system.

SBSS integrations follow the same pattern with a few score-specific steps. See how to retrieve SBSS credit data via API for that walkthrough.

Authentication and security

Authentication verifies that a request comes from an approved system. Most providers issue credentials scoped to your account and use token-based access over encrypted transport. Rotate credentials on a schedule and store them outside application code. Log every request so the audit trail survives a compliance review.

Data formats and normalization

Each bureau returns a different structure. Normalization maps those responses into one schema so your parsing logic does not branch by source. This is the step that consumes the most engineering time on a direct integration. A provider that normalizes for you removes it entirely.

Sandbox, sample code, and go-live

A sandbox lets developers build against representative data before credentialing completes. That parallelizes the technical work with the vetting process. Sample code shortens the first successful call. Go-live is then a credential swap rather than a rebuild.

How CRS delivers business credit data

CRS aggregates commercial credit, consumer credit, identity, fraud, and public records through one integration. Business data comes from major commercial sources alongside tri-bureau consumer access. An underwriter pulls the entity, the owners, and the records behind both in one request.

The data returns in the CRS Standard Format, a single normalized structure across every source. That is the part that saves engineering time. Your team parses one schema instead of reconciling three. That removes most of the transformation work between a bureau response and a usable decision.

Responses return in under two seconds on average, with 99.9% uptime. That supports decisioning while an applicant is still engaged. Developers get sample code in nine languages and a self-serve sandbox for testing before credentialing completes. Most clients go live in about two weeks.

CRS is SOC 2 Type II certified and a licensed consumer reporting agency recognized by all three national bureaus. A team with over 25 years of credit industry experience configures each implementation. The build follows the lender underwriting model, not a standard package. Explore the business credit products, the commercial lending solution, or the credit data API.

Frequently asked questions

What is a business credit data API?

A business credit data API returns commercial credit reports, scores, and public records through a single request. It replaces manual bureau portal lookups with structured data your underwriting platform can read and act on in seconds.

Which bureaus provide business credit data?

Dun and Bradstreet, Experian Business, and Equifax Business are the main commercial sources. FICO provides the SBSS score, which blends business and owner data. Each source sees different payment behavior, so coverage varies by company.

Do I need both business and personal credit for commercial lending?

Most small business underwriting uses both. Business files are often thin on younger companies, so owner credit carries significant predictive weight. Reading the two together gives a fuller picture than either provides alone.

Is SBSS still required for SBA loans?

No. The SBA discontinued the SBSS prescreening requirement for 7(a) Small Loans effective March 1, 2026. Many lenders still use the score by choice, but any threshold is now the lender own credit policy.

Do I need a permissible purpose to pull business credit?

Yes. Accessing credit data requires a valid permissible purpose under the FCRA, and providers vet each customer before granting access. Evaluating a credit application and reviewing an existing account both qualify for commercial lending.

What is the difference between a soft pull and a hard pull?

A soft pull supports prequalification and account review without affecting the consumer score. A hard pull belongs at formal application and is visible to other lenders. Both return the same underlying data.

What identifiers are needed to pull a business credit report?

Most requests need the legal business name, address, and tax identification number. Owner name and address are added when the pull includes personal credit. Better identifiers reduce the risk of matching the wrong entity.

What public records matter in commercial underwriting?

Tax liens, judgments, bankruptcies, and UCC filings all affect risk and recovery position. UCC filings matter most for detecting existing secured obligations, including advances a borrower has not disclosed. CRS returns these through one API across all 50 states.

Which business credit sources does CRS use?

CRS aggregates major commercial credit sources alongside tri-bureau consumer access, identity, fraud, and public records. Available sources depend on your provider agreement, which is confirmed during onboarding.

How long does it take to integrate a business credit API?

It varies by provider and use case. With CRS, most clients go live in about two weeks. Sample code in nine languages and a self-serve sandbox speed the build.

Talk with our credit and compliance experts

See how CRS is configured for your underwriting model. Our team works through your data requirements, your decision rules, and the vetting process with you.

Related resources

Access fast & compliant credit data

 

Other articles

CRS can satisfy the most challenging credit data requirements. Try us.

© 2026 CRS Group, Inc.