FM
FlowMarket
MarketplaceRequest custom workSell
FM
FlowMarket

n8n automation services, setup and templates.

Navigation

  • Marketplace
  • Request custom work
  • Sell
  • Where to sell n8n workflows
  • Pricing & fees
  • How it works
  • Sell on FlowMarket
  • Setup guide
  • Maintenance guide
  • Tools

Terms

  • Terms of Use
  • Terms of Sale
  • Seller Terms

Legal

  • Legal Notice
  • Liability

Privacy

  • Privacy Policy
  • Cookies

Community

  • Guides
  • Support
  • FlowMarket LinkedIn
  • FlowMarket Discord

    Tickets, help, and community chat.

© 2026 FlowMarket — All rights reserved.

n8n marketplace · automation servicesStartup Fame

Back to blogVetting Is Now Evidence: Freight Automation After the 2026 Broker Liability Ruling

24 September 2026 · 15 min read

Vetting Is Now Evidence: Freight Automation After the 2026 Broker Liability Ruling

For most of the last decade, a freight brokerage could vet a carrier by glancing at an authority number and an insurance certificate, and the industry treated that as reasonable care. Three things happened in 2026 that ended the arrangement: the Supreme Court took away the legal shield brokers relied on, the FMCSA shortened the window for staying financially compliant from thirty days to seven, and cargo theft losses more than doubled year on year even as the number of incidents fell. Taken together, they turn carrier due diligence from an operational habit into an evidence pipeline — something you have to produce on demand, with timestamps, months or years after the load moved. That is an automation problem, and it is worth understanding even if you have never booked a truck in your life.

Three changes in nine months

The individual events have been covered separately in the trade press, but the compounding effect has not. Each one alone would have been absorbed as a cost of doing business. Arriving within nine months of each other, they changed what a defensible operation looks like.

On 14 May 2026, the Supreme Court decided Montgomery v. Caribe Transport II, LLC, holding unanimously that a state-law negligent hiring claim against a freight broker is not preempted by the Federal Aviation Administration Authorization Act of 1994, because the claim falls within the statute's safety exception. Law firms briefing clients afterwards were blunt about the consequence: the broad federal preemption defence that had let brokers dispose of negligent selection claims early in litigation is gone, and exposure, underwriting and commercial relationships across the sector will be reshaped around that. Some industry observers expect broker insurance costs to rise by a factor of three to five.

Four months earlier, on 16 January 2026, the FMCSA began enforcing its broker and freight forwarder financial responsibility rule after a two-year delay. The headline number did not change — a 75,000 dollar BMC-84 surety bond or BMC-85 trust fund — but the mechanics did. If the security is drawn below the threshold, it must be replenished within seven calendar days rather than thirty, the surety provider is now required to notify the FMCSA immediately, and failure means suspension of operating authority.

Meanwhile the loss data kept moving in an uncomfortable direction. Verisk CargoNet documented 677 supply chain theft incidents across the United States and Canada in the second quarter of 2026, a 26 percent decline against the same quarter of 2025 and 14 percent below the first quarter. Estimated losses, however, reached 304.6 million dollars against 135.7 million dollars a year earlier, with the average reported commodity value hitting 564,009 dollars. "Lower incident volume should not be mistaken for lower risk," said Keith Lewis, vice president of operations at Verisk CargoNet. The pattern follows a 2025 in which estimated losses reached roughly 725 million dollars.

Change Date What it actually shifts
FMCSA financial responsibility enforcement 16 January 2026 Seven-day replenishment window and immediate surety notification, so a counterparty's authority can lapse inside a single week
Montgomery v. Caribe Transport II 14 May 2026 Negligent selection claims survive preemption, so your vetting record becomes discoverable evidence rather than an internal note
SAFER Transport Act introduced (S.3950) 26 February 2026 Proposes a DOT–DOJ referral process for freight fraud and a five-year phase-out of MC numbers in favour of USDOT numbers only
Q2 2026 cargo theft data Published August 2026 Fewer, larger, more targeted losses, which shifts the risk from nuisance to balance-sheet event

The SAFER Transport Act, introduced by Senator Todd Young on 26 February 2026 and backed by the American Trucking Associations, is still sitting with the Senate Commerce Committee, and nothing in this article depends on it passing. It is worth watching for one detail, though: retiring MC numbers in favour of USDOT numbers is an identifier migration, and every system that stores, matches or validates carrier identity would have to be updated. Teams whose vetting logic lives in one place will do that in an afternoon. Teams whose logic lives in forty spreadsheets and a shared inbox will not.

Why the manual process stopped working

The traditional defence against fraudulent carriers was a human being who had been in the business long enough to smell something wrong. That instinct was genuinely effective when the fraud was crude. It is much less effective now, for reasons that have little to do with freight and everything to do with the cost of generating a convincing identity.

Business email compromise remained the primary access point behind the most sophisticated schemes in the second quarter of 2026: a compromised account hands the attacker communication history, transportation plans and the credibility to alter shipment details from inside a legitimate thread. Around that, a layer of synthetic identity work has become cheap. Fraudsters copy company names, USDOT numbers, logos and insurance certificates so that the shipper believes it is dealing with a trusted carrier while the load has been assigned to a criminal operation. Research circulating this year projects a steep rise in deepfake-driven identity fraud in 2026, and one frequently cited study found that people correctly identify an AI-generated voice only around 60 percent of the time. A dispatcher verifying a carrier by calling the number on the paperwork is running a test that no longer discriminates.

Double brokering sits on top of all this. Reported instances of the scheme grew by more than 400 percent between 2021 and 2024, and the structure is unchanged: a carrier accepts a load with no intention of hauling it, quietly re-brokers it, and the originating broker loses the carrier relationship, the liability chain and shipment visibility in one move. Before May 2026 that was an expensive operational failure. After Montgomery, if the substitute carrier causes harm, it is also a negligence question you must answer with documents.

The uncomfortable detail for small operators. Most brokerages under twenty people do vet carriers, and do it reasonably well. What they cannot do is prove it afterwards. The check happened in a browser tab, the judgement happened in someone's head, and the record is a note in the TMS saying "verified". That is now the gap — not the vetting itself, but the absence of evidence that it occurred.

What an evidence pipeline has to produce

The shift in the question is subtle but total. It used to be "did you check?" It is now: show me what you checked, show me when you checked it, and show me that nobody edited the file afterwards. That third clause is the one that breaks most homegrown setups, because a spreadsheet anyone can retype is not evidence of anything.

A pipeline that satisfies all three produces four artifacts for every counterparty relationship, and it produces them automatically, because anything that depends on a person remembering to save a PDF will fail in the week that matters most.

  • A point-in-time snapshot. The authority status, safety rating, insurance certificate and identifiers exactly as they read at the moment of booking, stored as a file rather than a link that will resolve differently next year.
  • A decision record. Which thresholds were applied, which ones the counterparty passed, and if someone approved an exception, who they were and what reason they gave.
  • A monitoring log. Evidence that the relationship was re-checked over its lifetime and not simply cleared once at onboarding, with the timestamps of each re-check.
  • A tamper-evident seal. A content hash written at creation time to storage with retention or object-lock enabled, so the file's integrity can be demonstrated rather than asserted.

None of this is exotic engineering. It is roughly a day of work per artifact on any competent automation platform, and it is the same discipline that surfaced elsewhere in compliance this year — the pattern we described in the questionnaire outran the regulator, where buyers and auditors began demanding continuous proof instead of annual attestation.

A reference workflow, and where each platform fits

The architecture that works is boring on purpose. A vetting data provider supplies the facts, a transport or operations system holds the relationship, an orchestration layer moves events between them and writes evidence, and object storage holds the artifacts. The valuable part is not any single vendor; it is that the evidence is produced as a by-product of work people were already doing.

  1. Trigger on counterparty creation. When a new carrier record appears in the TMS, the orchestration layer catches the event rather than waiting for someone to start a checklist.
  2. Pull and snapshot the source data. Query the vetting provider's API for authority, insurance, safety scores and identity signals, then render the response to a dated file and hash it before anything else touches it.
  3. Apply written thresholds. Encode the rules you would defend out loud — minimum authority age, insurance limits, safety score floors, flags on recently transferred authorities — and let the workflow approve, reject or escalate.
  4. Route exceptions to a named human. Approval belongs to a person with a reason field, not a button. That reason is the sentence a lawyer will read three years from now.
  5. Monitor continuously. Re-query on a schedule and on webhook alerts, and open a ticket when authority, insurance or a safety rating changes after onboarding.
  6. Re-verify at dispatch. Confirm identity and authority again at tender time, not only at onboarding, because the interval between the two is exactly where load interception happens.
  7. Watch the quiet fields. Alert on late changes to bank details, remittance addresses, phone numbers and email domains, which are the fingerprints of both business email compromise and double brokering.
Layer Typical options What to judge it on
Vetting data and identity Highway, Descartes MyCarrierPortal, Truckstop RMIS, Carrier Assure, Carrier411 API access rather than portal-only, webhook alerts on status change, and whether identity verification goes beyond document matching
System of record Your TMS, ERP or vendor management system Whether it emits events you can subscribe to, and whether custom fields can hold an evidence reference
Orchestration Zapier, Make, Power Automate, n8n, Workato Execution history retention, error handling on failed API calls, and whether you can self-host if data residency matters
Evidence storage Object storage with retention or object-lock, or a document system with immutability Write-once behaviour, retention policy length, and how quickly you can retrieve a specific dated file

Platform choice is genuinely secondary here, and the temptation to spend three weeks on it should be resisted. Zapier and Make will carry a small brokerage wiring a handful of alerts. Power Automate fits a Microsoft-centred back office that already has retention policies and wants the evidence to land inside them. n8n and Workato earn their place when you need self-hosted data residency, branching logic that reflects genuinely different carrier categories, or an enrichment step that calls a model. The failure mode is identical across all of them: a workflow that makes decisions but does not write down why.

One rule worth adopting immediately. Never let the workflow delete or overwrite a prior snapshot. Storage is a rounding error against a single negligence claim, and the version of the record you will most want is the one taken before the counterparty's status changed — precisely the one an "update-in-place" design throws away.

This is not really a trucking story

Freight is where these pressures collided first, but the mechanism generalises to any business that selects, trusts and pays third parties on the strength of documents. The pattern is the same in every case: an obligation that used to be satisfied by doing the work now has to be satisfied by proving the work, continuously, in a form someone else can audit.

You can see the same shape in e-invoicing mandates rolling across Europe, where the tax authority wants structured data rather than an annual reconciliation, a topic we covered in the three automation routes for e-invoicing mandates. You can see it in supplier due diligence, in financial services onboarding, and in the security questionnaires that now arrive quarterly instead of yearly. The specific regulator differs. The demand for a timestamped, tamper-evident trail does not.

Which means the practical question for an operations leader is not "should we buy carrier vetting software". It is narrower and more useful: for each relationship our business depends on, could we reconstruct in ten minutes what we knew about that counterparty on the day we committed, and prove the record has not been touched since? If the honest answer is no, the gap is worth closing before an incident forces the issue — and the same reasoning that applies to carriers applies to the rest of your logistics and supply chain automation.

What it costs, and what to do first

The economics are not close. A vetting data provider generally runs from a few hundred to a few thousand euros a month depending on volume, an orchestration subscription is a modest monthly line, and object storage for a few thousand PDFs a year costs less than a team lunch. Set that against broker insurance renewals that parts of the industry expect to multiply several times over after Montgomery, or against an average stolen load valued at 564,009 dollars, and the pipeline is the cheapest item in the risk budget.

The sequencing matters more than the spend, because teams that attempt everything at once generally ship nothing. In rough order of return on effort:

  1. Capture evidence for the vetting you already perform. One workflow, no process change, and it improves your legal position from the day it runs.
  2. Add continuous monitoring, so a status change after onboarding reaches a human instead of sitting unnoticed until a claim.
  3. Add dispatch-time re-verification, which closes the interception window between approval and tender.
  4. Add anomaly detection on payment and contact changes, the step that catches business email compromise before money moves.

Step one is the one to do this quarter. It is the smallest change, it requires no negotiation with anyone, and it addresses the precise deficiency the courts have now made expensive: not that businesses fail to check, but that they cannot prove they did.

Build the evidence layer before you need it

Browse ready-made vendor vetting, monitoring and document-archiving workflows you can adapt to your own counterparties and stack.

Explore automation workflows on FlowMarket

FAQ

What did the Supreme Court actually decide in Montgomery v. Caribe Transport II?

On 14 May 2026 the Court held unanimously that a state-law negligent selection claim against a freight broker is not preempted by the Federal Aviation Administration Authorization Act of 1994, because such a claim falls within the statute's safety exception. In practice it removes the early-stage preemption defence brokers had relied on for years, so how a carrier was chosen is now a question a jury can examine.

Is cargo theft actually getting worse, or better?

Both, depending on what you measure. Verisk CargoNet documented 677 supply chain theft incidents in the second quarter of 2026, down 26 percent year on year, but estimated losses reached 304.6 million dollars against 135.7 million dollars in the same quarter of 2025, with an average reported commodity value of 564,009 dollars. Fewer events, far larger individual losses.

What changed in the FMCSA financial responsibility rule?

Enforcement of the broker and freight forwarder financial responsibility rule began on 16 January 2026. Brokers still carry a 75,000 dollar BMC-84 bond or BMC-85 trust, but if that security is drawn below the threshold it must be replenished within seven calendar days instead of the previous thirty, sureties must notify the FMCSA immediately, and operating authority is suspended otherwise.

Can automation really stop double brokering?

Automation cannot stop a determined criminal, but it removes the gaps they exploit. Continuous authority and insurance monitoring, identity checks at dispatch rather than only at onboarding, telematics that confirm which truck is actually moving, and alerts on late-changed bank or contact details close most of the windows used for load interception.

Which platform should run this kind of workflow?

The orchestration layer matters less than the evidence it writes. Zapier and Make suit small brokerages wiring a handful of alerts, Power Automate fits Microsoft-centred back offices with existing retention policies, and n8n or Workato make sense when you need self-hosted data residency or complex branching. What all of them must produce is the same immutable record.

Why should a business outside freight care about this?

Because the underlying shift is not sector specific. Regulators, courts and insurers across e-invoicing, financial services and supplier due diligence are converging on the same demand: show what you checked, when you checked it, and prove nobody edited the record afterwards. Freight is simply where the consequences arrived first and hardest.

How much does an automated vetting pipeline cost to run?

A small brokerage typically spends somewhere between a few hundred and a few thousand euros a month on a vetting data provider, plus a modest orchestration subscription and object storage that costs very little. Against broker insurance renewals that some industry observers expect to rise several times over, the pipeline is usually the cheapest line in the risk budget.

Where should a team start if it has nothing today?

Start by capturing evidence for the vetting you already perform, because that is one workflow and it changes your legal position immediately. Add continuous monitoring second, dispatch-time re-verification third, and anomaly detection on payment and contact changes last. Attempting all four at once is how these projects stall.

Related articles

  • Veterinary Practice Automation in 2026: What to Fix First When You Can't Hire

    A 2026 field guide to veterinary practice automation: the staffing math, no-show costs, AI scribes, front-desk agents, and what to automate first when you can't hire.

  • What Does It Cost to Automate a Business Process in 2026?

    Real price ranges for automating a business process in 2026: templates, custom builds, and hiring experts. Know what drives cost before you buy.

  • When Your Automation Vendor Gets Acquired: A 2026 Buyer's Playbook

    SAP just backed n8n at $5.2B and Salesforce bought Informatica. A 2026 buyer's playbook for the automation consolidation wave: what an acquisition changes and how to protect yourself.

  • Why Your Automation ROI Is Lower Than Expected

    Automation ROI why automation fails: the root causes behind underperforming projects in 2026 and three fixes every operations team can apply now.