The vendor list mismatch: when your TCF vendor list does not match your actual ad partners
The TCF consent string your site generates names a specific set of vendors the visitor consented to. Your ad stack then shares data with the vendors it actually works with. When those two sets differ, the consent signal is making promises about one group of companies while data flows to another. That is the vendor list mismatch, and it is one of the most common findings in publisher consent audits.
The mismatch is rarely deliberate. Vendor lists are configured once in the consent platform and then forgotten, while the ad stack evolves constantly: new bidders get added to the wrapper, old ones get removed, analytics and identity vendors change. The consent configuration is a snapshot. The ad stack is a moving picture.
How the mismatch forms
It forms in both directions. The common direction is stack growth: the ad operations team adds bidders, the commercial team signs new partners, and nobody updates the consent platform's vendor list. The consent string keeps naming the old roster while data flows to companies the visitor never saw. The other direction is quieter: vendors get removed from the stack but stay on the consent list, so the string keeps granting permissions to companies that no longer receive data.
Resellers and sub-vendors add a third path. A bidder on your list may pass data to partners of its own that were never on any list you configured. The TCF framework has mechanisms for disclosing this, but they only work if someone maps the actual data flows instead of assuming the top-level vendor list covers everything downstream.
Why the mismatch matters
A consent signal that does not describe the actual data sharing is a defective signal. Downstream vendors receiving bid requests with a TCF string assume it covers them; if they are not on the list the string encodes, their processing rests on a permission that was never granted for them. That exposes both the publisher and the vendor.
It also corrupts measurement and troubleshooting. When a vendor reports low match rates or consent-related errors, the first suspect is usually the signal plumbing. In mismatch cases the plumbing is fine and the list is wrong, which sends teams chasing a technical problem that is actually a configuration problem. The audit that compares the two lists is cheaper than the debugging that happens without it.
How to audit the match
The audit has three inputs. First, export the vendor list from your consent platform: every vendor the TCF string can name. Second, inventory the actual stack: every bidder in the wrapper, every analytics and identity vendor firing on the page, and every vendor receiving data server-to-server. Third, get the sub-vendor disclosures from your partners for the downstream flows.
Then compare. Every vendor receiving data should appear on the consent list with the right purposes, and the consent list should not carry vendors that no longer receive anything. Pay special attention to vendors added in the last two quarters, because those are the ones the snapshot missed. Document the comparison, because this is the artifact an auditor or a questioning partner will ask for.
Keeping the list current
The durable fix is process, not a one-time cleanup. Tie vendor list updates to the same change control as stack changes: a new bidder does not go live until the consent configuration includes it. Make the comparison part of the quarterly consent review, and assign it to someone who can see both the consent platform and the ad stack, because the mismatch lives in the gap between two teams.
Also watch the framework itself. Vendor registrations change, purposes get redefined, and consent platform defaults do not always track those changes. A vendor list that was correct last year can drift out of alignment through framework updates alone. The quarterly check should verify the list against the current framework state, not just against the stack.
The bottom line
The consent string is a claim about who gets data. If the claim and the reality disagree, the signal is broken no matter how well the plumbing works. Reconcile the vendor list with the actual stack, wire the reconciliation into change control, and the mismatch stops being a recurring finding.